IP Library Granted Patent US 7,401,353
Granted Patent B2
US 7,401,353 · App. 10/689,549 · Granted Jul 15, 2008

Detecting and blocking malicious connections

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,401,353
App. No.
10/689,549
Granted
Jul 15, 2008
Kind
B2
Abstract

In a device having data communication capability, a security method dynamically detecting a control connection, which originates from the device, and detecting a negotiation of a related connection within the control connection. The negotiation comprises at least defining a port of the device for said related connection. The method further checks if relationship between said port of the device and the control connection fulfills predefined criteria, and conditionally blocks said related connection, if said port of the device does not fulfill said predefined criteria. The method can be used for suppressing a vulnerability related to applets.

Claims (16)

1. A method of securing a device having data communication capability, comprising dynamically detecting a control connection, which originates from said device, noticing negotiation of a related connection within said control connection, said negotiation comprising at least defining a port of the device for said related connection, checking if relationship between said port of the device and the control connection fulfills predefined criteria, and conditionally blocking said related connection, if said port of the device does not fulfill said predefined criteria,

wherein said predefined criteria requires that said port of the device is opened within a predefined time window in relation to noticing negotiation of a related connection within said control connection, and wherein said predefined criteria requires that said control connection and said port of the device are opened by the same process family.

2. A method according to claim 1 , wherein said device is running an applet.

3. A method according to claim 2 , wherein said control connection originates from the applet.

4. A device having data communication capability and comprising a module, which is configured to dynamically detect a control connection, which originates from said device, notice negotiation of a related connection within said control connection, said negotiation comprising at least defining a port of the device for said related connection, check if relationship between said port of the device and the control connection fulfills predefined criteria, and conditionally block said related connection, if said port of the device does not fulfill said predefined criteria,

wherein said predefined criteria requires that said port of the device is opened within a predefined time window in relation to noticing negotiation of a related connection within said control connection, and wherein said predefined criteria requires that said control connection and said port of the device are opened by the same process family.

5. A device according to claim 4 , wherein said device is running an applet.

6. A computer readable storage medium comprising a computer program that carries out steps procedure which comprises dynamically detecting a control connection, which originates from said device, noticing negotiation of a related connection within said control connection, said negotiation comprising at least defining a port of the device for said related connection, checking if relationship between said port of the device and the control connection fulfills predefined criteria, and conditionally blocking said related connection, if said port of the device does not fulfill said predefined criteria,

wherein said predefined criteria requires that said port of the device is opened within a predefined time window in relation to noticing negotiation of a related connection within said control connection, and wherein said predefined criteria requires that said control connection and said port of the device are opened by the same process family.

7. A computer readable storage medium according to claim 6 , wherein said device is running an applet.

8. A computer readable storage medium according to claim 6 , wherein said control connection originates from the applet.

9. A computer readable storage medium, comprising a computer program that carries out a personal firewall process which further includes dynamically detecting a control connection, which originates from said device, noticing negotiation of a related connection within said control connection, said negotiation comprising at least defining a port of the device for said related connection, checking if relationship between said port of the device and the control connection fulfills predefined criteria, and conditionally blocking said related connection, if said port of the device does not fulfill said predefined criteria,

wherein said predefined criteria requires that said port of the device is opened within a predefined time window in relation to noticing negotiation of a related connection within said control connection, and wherein said predefined criteria requires that said control connection and said port of the device are opened by the same process family.

10. A device having data communication capability and comprising a first detector dynamically detecting a control connection, which originates from said device, a second detector detecting a negotiation of a related connection within said control connection, said negotiation comprising at least defining a port of the device for said related connection, a controller checking if relationship between said port of the device and the control connection fulfills predefined criteria, and said controller conditionally blocking said related connection, if said port of the device does not fulfill said predefined criteria,

wherein said predefined criteria requires that said port of the device is opened within a predefined time window in relation to noticing negotiation of a related connection within said control connection, and wherein said predefined criteria requires that said control connection and said port of the device are opened by the same process family.

11. A device according to claim 10 , wherein said device is running an applet.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2021
From: NANOGRIPTECH, INC.
To: SETEX TECHNOLOGIES, INC.
Reel/Frame 058468/0740 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056272/0475 →
CHANGE OF NAME Recorded May 10, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056183/0265 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0220 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 12, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 045312/0043 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: FORCEPOINT FINLAND OY
To: FORCEPOINT LLC
Reel/Frame 043156/0547 →
CHANGE OF NAME Recorded Apr 15, 2016
From: WEBSENSE FINLAND OY
To: FORCEPOINT FINLAND OY
Reel/Frame 038447/0441 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2016
From: STONESOFT OY DBA STONESOFT CORPORATION
To: WEBSENSE FINLAND OY
Reel/Frame 037828/0385 →