Methods and systems for protecting a secured network

US10749906B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10749906-B2
Application numberUS-201916448969-A
CountryUS
Kind codeB2
Filing dateJun 21, 2019
Priority dateApr 16, 2014
Publication dateAug 18, 2020
Grant dateAug 18, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at least one of multiple packet transformation functions specified by the dynamic security policy may be performed on the packets.

First claim

Opening claim text (preview).

What is claimed is: 1. A method of filtering packets at a packet security gateway configured for protection of a network and associated with a security policy management server external from the network, the method comprising: receiving, by the packet security gateway, a dynamic security policy comprising a first set of packet filtering rules from the security policy management server, wherein each packet filtering rule of the first set of packet filtering rules comprises at least one packet matching criterion and a corresponding packet transformation function, and wherein one or more first packet filtering rules of the first set of packet filtering rules were automatically created or altered by the security policy management server based on malicious traffic information received from a malicious host tracker service; performing, on a packet by packet basis, packet filtering on a first portion of packets associated with the network protected by the packet security gateway based on the first set of packet filtering rules by performing at least one of multiple packet transformation functions specified by at least one packet filtering rule of the first set of packet filtering rules on the first portion of packets, wherein at least one of the multiple packet transformation functions specified by the at least one packet filtering rule of the first set of packet filtering rules corresponds to a packet digest logging function that supports a network communications awareness service and comprises: identifying a subset of information specified by a packet matching the packet matching criterion of a packet filtering rule that specified the packet digest logging function; generating a record comprising the subset of information specified by the packet; reformatting the subset of information specified by the packet in accordance with a logging system standard; and routing, by the packet security gateway, the packet to a monitoring device; receiving, by the packet security gateway and after performing packet filtering on the first portion of the packets, an updated second set of packet filtering rules for the dynamic security policy from the security policy management server, wherein the updated second set of packet filtering rules comprises an update to the first set of packet filtering rules and was generated by the security policy management server based on updated malicious traffic information received from the malicious host tracker service; and performing, on a packet by packet basis, packet filtering on a second portion of the packets associated with the network protected by the packet security gateway based on the updated second set of packet filtering rules. 2. The method of claim 1 , wherein the at least one packet matching criterion comprises at least one network address associated with an indication of malicious network traffic. 3. The method of claim 1 , wherein at least one packet transformation function comprises a network protective action. 4. The method of claim 1 , wherein the dynamic security policy specifies that a first set of the packets should be placed in a first forwarding queue and a second set of the packets should be placed in a second forwarding queue, the first forwarding queue having a higher forwarding rate than the second forwarding queue, the method comprising: sending, by the packet security gateway, the first set of the packets in the first forwarding queue; and sending, by the packet security gateway, the second set of the packets in the second forwarding queue. 5. The method of claim 1 , further comprising: receiving, by the packet security gateway, packets in a network layer transparent manner using an interface that is not addressed at the network layer and performing the at least one of the multiple packet transformation functions at the network layer. 6. The method of claim 1 , wherein the network communications service comprises a network security awareness service or a network threat awareness service. 7. The method of claim 1 , wherein the network communications service is provided based on one or more criteria that are indicative of packet communications that are of interest to an organization that operates the secured network. 8. A packet security gateway configured to protect a network and associated with a security policy management server external from the network, comprising: at least one processor; and memory comprising instructions that, when executed by the at least one processor, cause the packet security gateway to: receive a dynamic security policy comprising a first set of packet filtering rules from the security policy management server, wherein each packet filtering rule of the first set of packet filtering rules comprises at least one packet matching criterion and a corresponding packet transformation function, and wherein one or more first packet filtering rules of the first set of packet filtering rules were automatically created or altered by the security policy management server based on malicious traffic information received from a malicious host tracker service; perform, on a packet by packet basis, packet filtering on a first portion of packets associated with the network protected by the packet security gateway based on the first set of packet filtering rules by performing at least one of multiple packet transformation functions specified by at least one packet filtering rule of the first set of packet filtering rules on the first portion of the packets, wherein at least one of the multiple packet transformation functions specified by the at least one packet filtering rule of the first set of packet filtering rules corresponds to a packet digest logging function that supports a network communications awareness service and comprises instructions that cause the packet security gateway to: identify a subset of information specified by a packet matching the packet matching criterion of a packet filtering rule that specified the packet digest logging function; generate a record comprising the subset of information specified by the packet; reformat the subset of information specified by the packet in accordance with a logging system standard; and route the packet to a monitoring device; receive, after performing packet filtering on the first portion of the packets, an updated second set of packet filtering rules for the dynamic security policy from the security policy management server, wherein the updated second set of packet filtering rules comprises an update to the first set of packet filtering rules and was generated by the security policy management server based on updated malicious traffic information received from the malicious host tracker service; and perform, on a packet by packet basis, packet filtering on a second portion of the packets associated with the network protected by the packet security gateway based on the updated second set of packet filtering rules. 9. The packet security gateway of claim 8 , wherein the at least one packet matching criterion comprises at least one network address associated with an indication of malicious network traffic. 10. The packet security gateway of claim 8 , wherein at least one packet transformation function comprises a network protective action. 11. The packet security gateway of claim 8 , wherein the dynamic security policy specifies that a first set of the packets should be placed in a first forwarding queue and a second set of the packets should be placed in a second forwarding queue, the first forwarding queue having a higher forwarding rate than the second forwarding queue, the memory further comprising instructions to cause the packet security gateway to: send the first se

Assignees

Inventors

Classifications

  • Session establishment or de-establishment · CPC title

  • for supporting key management in a packet data network (cryptographic mechanisms or cryptographic arrangements for key management H04L9/08) · CPC title

  • Filtering by address, protocol, port number or service, e.g. IP-address or URL · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • Architectural arrangements, e.g. perimeter networks or demilitarized zones · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10749906B2 cover?
Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at l…
Who is the assignee on this patent?
Centripetal Networks Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Aug 18 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).