Filtering network data transfers
US-9160713-B2 · Oct 13, 2015 · US
US10749906B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10749906-B2 |
| Application number | US-201916448969-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jun 21, 2019 |
| Priority date | Apr 16, 2014 |
| Publication date | Aug 18, 2020 |
| Grant date | Aug 18, 2020 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at least one of multiple packet transformation functions specified by the dynamic security policy may be performed on the packets.
Opening claim text (preview).
What is claimed is: 1. A method of filtering packets at a packet security gateway configured for protection of a network and associated with a security policy management server external from the network, the method comprising: receiving, by the packet security gateway, a dynamic security policy comprising a first set of packet filtering rules from the security policy management server, wherein each packet filtering rule of the first set of packet filtering rules comprises at least one packet matching criterion and a corresponding packet transformation function, and wherein one or more first packet filtering rules of the first set of packet filtering rules were automatically created or altered by the security policy management server based on malicious traffic information received from a malicious host tracker service; performing, on a packet by packet basis, packet filtering on a first portion of packets associated with the network protected by the packet security gateway based on the first set of packet filtering rules by performing at least one of multiple packet transformation functions specified by at least one packet filtering rule of the first set of packet filtering rules on the first portion of packets, wherein at least one of the multiple packet transformation functions specified by the at least one packet filtering rule of the first set of packet filtering rules corresponds to a packet digest logging function that supports a network communications awareness service and comprises: identifying a subset of information specified by a packet matching the packet matching criterion of a packet filtering rule that specified the packet digest logging function; generating a record comprising the subset of information specified by the packet; reformatting the subset of information specified by the packet in accordance with a logging system standard; and routing, by the packet security gateway, the packet to a monitoring device; receiving, by the packet security gateway and after performing packet filtering on the first portion of the packets, an updated second set of packet filtering rules for the dynamic security policy from the security policy management server, wherein the updated second set of packet filtering rules comprises an update to the first set of packet filtering rules and was generated by the security policy management server based on updated malicious traffic information received from the malicious host tracker service; and performing, on a packet by packet basis, packet filtering on a second portion of the packets associated with the network protected by the packet security gateway based on the updated second set of packet filtering rules. 2. The method of claim 1 , wherein the at least one packet matching criterion comprises at least one network address associated with an indication of malicious network traffic. 3. The method of claim 1 , wherein at least one packet transformation function comprises a network protective action. 4. The method of claim 1 , wherein the dynamic security policy specifies that a first set of the packets should be placed in a first forwarding queue and a second set of the packets should be placed in a second forwarding queue, the first forwarding queue having a higher forwarding rate than the second forwarding queue, the method comprising: sending, by the packet security gateway, the first set of the packets in the first forwarding queue; and sending, by the packet security gateway, the second set of the packets in the second forwarding queue. 5. The method of claim 1 , further comprising: receiving, by the packet security gateway, packets in a network layer transparent manner using an interface that is not addressed at the network layer and performing the at least one of the multiple packet transformation functions at the network layer. 6. The method of claim 1 , wherein the network communications service comprises a network security awareness service or a network threat awareness service. 7. The method of claim 1 , wherein the network communications service is provided based on one or more criteria that are indicative of packet communications that are of interest to an organization that operates the secured network. 8. A packet security gateway configured to protect a network and associated with a security policy management server external from the network, comprising: at least one processor; and memory comprising instructions that, when executed by the at least one processor, cause the packet security gateway to: receive a dynamic security policy comprising a first set of packet filtering rules from the security policy management server, wherein each packet filtering rule of the first set of packet filtering rules comprises at least one packet matching criterion and a corresponding packet transformation function, and wherein one or more first packet filtering rules of the first set of packet filtering rules were automatically created or altered by the security policy management server based on malicious traffic information received from a malicious host tracker service; perform, on a packet by packet basis, packet filtering on a first portion of packets associated with the network protected by the packet security gateway based on the first set of packet filtering rules by performing at least one of multiple packet transformation functions specified by at least one packet filtering rule of the first set of packet filtering rules on the first portion of the packets, wherein at least one of the multiple packet transformation functions specified by the at least one packet filtering rule of the first set of packet filtering rules corresponds to a packet digest logging function that supports a network communications awareness service and comprises instructions that cause the packet security gateway to: identify a subset of information specified by a packet matching the packet matching criterion of a packet filtering rule that specified the packet digest logging function; generate a record comprising the subset of information specified by the packet; reformat the subset of information specified by the packet in accordance with a logging system standard; and route the packet to a monitoring device; receive, after performing packet filtering on the first portion of the packets, an updated second set of packet filtering rules for the dynamic security policy from the security policy management server, wherein the updated second set of packet filtering rules comprises an update to the first set of packet filtering rules and was generated by the security policy management server based on updated malicious traffic information received from the malicious host tracker service; and perform, on a packet by packet basis, packet filtering on a second portion of the packets associated with the network protected by the packet security gateway based on the updated second set of packet filtering rules. 9. The packet security gateway of claim 8 , wherein the at least one packet matching criterion comprises at least one network address associated with an indication of malicious network traffic. 10. The packet security gateway of claim 8 , wherein at least one packet transformation function comprises a network protective action. 11. The packet security gateway of claim 8 , wherein the dynamic security policy specifies that a first set of the packets should be placed in a first forwarding queue and a second set of the packets should be placed in a second forwarding queue, the first forwarding queue having a higher forwarding rate than the second forwarding queue, the memory further comprising instructions to cause the packet security gateway to: send the first se
Session establishment or de-establishment · CPC title
for supporting key management in a packet data network (cryptographic mechanisms or cryptographic arrangements for key management H04L9/08) · CPC title
Filtering by address, protocol, port number or service, e.g. IP-address or URL · CPC title
Traffic logging, e.g. anomaly detection · CPC title
Architectural arrangements, e.g. perimeter networks or demilitarized zones · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.