Methods and systems for protecting a secured network

US12563103B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12563103-B2
Application numberUS-202418657111-A
CountryUS
Kind codeB2
Filing dateMay 7, 2024
Priority dateOct 22, 2012
Publication dateFeb 24, 2026
Grant dateFeb 24, 2026

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at least one of multiple packet transformation functions specified by the dynamic security policy may be performed on the packets.

First claim

Opening claim text (preview).

The invention claimed is: 1 . A security policy management server comprising: one or more processors and memory storing instructions that, when executed by the one or more processors, cause the security policy management server to: receive, from a plurality of malicious host tracker services, one or more network addresses identifying one or more malicious hosts that have been determined, by at least one of the plurality of malicious host tracker services, to have transmitted malicious network traffic; determine that a first portion of the one or more network addresses provided by a first malicious host tracker service of the plurality of malicious host tracker services and a second portion of the one or more network addresses provided by a second malicious host tracker service of the plurality of malicious host tracker services are correlated based on comparing the first portion of the one or more network addresses and the second portion of the one or more network addresses; automatically create, based on receiving the one or more network addresses and based on the first portion of the one or more network addresses being correlated with the second portion of the one or more network addresses, a packet filtering rule for a dynamic security policy, wherein the packet filtering rule comprises: one or more packet matching criteria that encompasses the first portion of the one or more network addresses and the second portion of the one or more network addresses, and one or more corresponding packet transformation functions that are applicable to packets matching the one or more packet matching criteria; and send, to a packet security gateway located at boundary between a first network protected by the packet security gateway and a second network, the packet filtering rule for the dynamic security policy, wherein the packet filtering rule is configured to cause the packet security gateway to: encapsulate each of one or more packets corresponding to the one or more packet matching criteria with an Internet Protocol header specifying a network address; strip, on a packet-by-packet basis and from the encapsulated one or more packets, the Internet Protocol header specifying the network address; and forward the one or more packets corresponding to the one or more packet matching criteria toward their respective destinations without the Internet Protocol header specifying the network address. 2 . The security policy management server of claim 1 , wherein the instructions, when executed by the one or more processors, further cause the security policy management server to: add the packet filtering rule to the dynamic security policy, wherein the instructions, when executed by the one or more processors, cause the security policy management server to send the packet filtering rule by transmitting the dynamic security policy to the packet security gateway. 3 . The security policy management server of claim 1 , wherein the packet security gateway is configured to filter one or more packets by applying the one or more corresponding packet transformation functions to the packets matching the one or more packet matching criteria. 4 . The security policy management server of claim 1 , wherein the instructions, when executed by the one or more processors, further cause the security policy management server to: create a plurality of packet filtering rules comprising the packet filtering rule and one or more second packet filtering rules, wherein each packet filtering rule of the one or more second packet filtering rules comprises: one or more second packet matching criteria different from the one or more packet matching criteria, and one or more corresponding second packet transformation functions that are applicable to packets matching the one or more second packet matching criteria. 5 . The security policy management server of claim 1 , wherein the instructions, when executed by the one or more processors, cause the security policy management server to determine that the first portion of the one or more network addresses provided by the first malicious host tracker service of the plurality of malicious host tracker services and the second portion of the one or more network addresses provided by the second malicious host tracker service of the plurality of malicious host tracker services are correlated by causing the security policy management server to: determine that at least a first network address of the first portion of the one or more network addresses is a duplicate of at least a second network address of the second portion of the one or more network addresses. 6 . The security policy management server of claim 1 , wherein the instructions, when executed by the one or more processors, cause the security policy management server to determine that the first portion of the one or more network addresses provided by the first malicious host tracker service of the plurality of malicious host tracker services and the second portion of the one or more network addresses provided by the second malicious host tracker service of the plurality of malicious host tracker services are correlated by causing the security policy management server to: determine that a first range of network addresses of the first portion of the one or more network addresses overlaps a second range of network addresses of the second portion of the one or more network addresses. 7 . The security policy management server of claim 1 , wherein the one or more packet matching criteria comprise: a set of network addresses; and a session initiation protocol uniform resource identifier. 8 . The security policy management server of claim 1 , wherein the one or more packet matching criteria comprises a range of network addresses that encompasses the first portion of the one or more network addresses and the second portion of the one or more network addresses. 9 . A method comprising: receiving, by a security policy management server and from a plurality of malicious host tracker services, one or more network addresses identifying one or more malicious hosts that have been determined, by at least one of the plurality of malicious host tracker services, to have transmitted malicious network traffic; determining that a first portion of the one or more network addresses provided by a first malicious host tracker service of the plurality of malicious host tracker services and a second portion of the one or more network addresses provided by a second malicious host tracker service of the plurality of malicious host tracker services are correlated based on comparing the first portion of the one or more network addresses and the second portion of the one or more network addresses; automatically create, based on receiving the one or more network addresses and based on the first portion of the one or more network addresses being correlated with the second portion of the one or more network addresses, a packet filtering rule for a dynamic security policy, wherein the packet filtering rule comprises: one or more packet matching criteria that encompasses the first portion of the one or more network addresses and the second portion of the one or more network addresses, and one or more corresponding packet transformation functions that are applicable to packets matching the one or more packet matching criteria; and sending, to a packet security gateway located at boundary between a first network protected by the packet security gateway and a second network, the packet filtering rule for the dynamic security policy, wherein the packet filtering rule is configured to cause the packet security gateway to: encapsulate each of one or more packets corresponding to the one or

Assignees

Inventors

Classifications

  • based on web technology, e.g. hypertext transfer protocol [HTTP] · CPC title

  • Architectural arrangements, e.g. perimeter networks or demilitarized zones · CPC title

  • Session establishment or de-establishment · CPC title

  • above the transport layer · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12563103B2 cover?
Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at l…
Who is the assignee on this patent?
Centripetal Networks Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/0218. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Feb 24 2026 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).