×

Intrusion detection using a heartbeat

  • US 10,673,873 B2
  • Filed: 02/23/2018
  • Issued: 06/02/2020
  • Est. Priority Date: 04/28/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • receiving, at a gateway interposed between a second network and an endpoint in an enterprise network, a heartbeat from the endpoint in communication with the second network via the gateway, the heartbeat addressed to the gateway, the heartbeat including a signal communicated from the endpoint to the gateway, and the heartbeat containing cryptographically secured information including a security health status of the endpoint, the security health status based on monitoring, by a health monitor on the endpoint, software items executing on the endpoint, and the security health status indicating an uncompromised security health status when the endpoint is uncompromised;

    detecting a change in the security health status included in the heartbeat at the gateway;

    following detecting the change of the security health status included in the heartbeat at the gateway, receiving, by the gateway, network traffic other than the heartbeat from the endpoint, the network traffic addressed for forwarding by the gateway via the second network to a second destination address outside the gateway from the enterprise network; and

    responding to the change of the security health status included in the heartbeat in combination with the network traffic received following the change, the response including blocking, by the gateway, the network traffic other than the heartbeat from the endpoint.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×