IP Library Granted Patent US 8,819,285
Granted Patent B1
US 8,819,285 · App. 10/749,718 · Granted Aug 26, 2014

System and method for managing network communications

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,819,285
App. No.
10/749,718
Granted
Aug 26, 2014
Kind
B1
Abstract

The invention relates to managing network communications packets on a local segment of a network. If an attack on the network segment is detected, the system creates one or more synthetic hardware addresses for substitution with existing hardware address. If this substitution is maintained in address resolution tables, packets sent to or from an attacker may be monitored, managed, dropped, or responded to in a controlled manner while preventing communication with sensitive devices on the local network segment. If a permissible packet is sent to the synthetic hardware address, the packet may be reformulated by a server, workstation, smart router, or security device, among others and sent with the appropriate hardware address. The synthetic hardware address may be a hardware address not associated with a device on the local network segment. For example, the synthetic hardware address may be synthetic MAC address.

Claims (53)

1. A method of manipulating network traffic, the method comprising:

determining if a network packet on a local network segment is a threat by determining if a logical network address associated with the network packet has been identified as a network threat;

determining if a logical source address associated with the network packet is associated with a device on the local network segment; and

in response to determining that the network packet is a threat, sending an address resolution protocol control packet over the local network segment to cause an address resolution protocol table of a first device on the local network segment to replace a physical hardware address of a second device associated with the logical source address with a synthetic hardware address, wherein the synthetic hardware address is not associated with a device on the local network segment, to cause communications sent by the first device to the logical source address to be undeliverable.

2. The method of claim 1 , wherein the logical network address is an Internet Protocol address.

3. The method of claim 1 , the method further comprising:

determining whether a target hardware address is the synthetic hardware address; and

dropping the network packet when the target hardware address is the synthetic hardware address.

4. The method of claim 1 , the method further comprising:

determining whether a target hardware address is the synthetic hardware address; and

forwarding the network packet to an alternative device when the target hardware address is not the synthetic hardware address.

5. The method of claim 1 , the method further comprising:

for each device on the local network segment

sending the address resolution protocol control packet having a destination associated with a logical network address and hardware address associated with the respective device on the local network segment.

6. The method of claim 1 , the method further comprising:

if (1) a target address is associated with a synthetic hardware address and (2) the target address and the logical source address are not of interest:

replacing the synthetic hardware address in the network packet with a hardware address associated with a logical target device; and

sending the network packet over the local network segment.

7. A system for manipulating network traffic, the system comprising:

a network interface to capture network packets;

a processor configured to at least:

determine if a network packet on a local network segment is a threat by determining if a logical network address associated with the network packet has been identified as a network threat;

determine if a logical source address associated with the network packet is associated with a device on the local network; and

in response to determining that the network packet is a threat, send an address resolution protocol control packet over the local network to cause an address resolution protocol table of a first device on the local network segment, to replace a physical hardware address of a second device associated with the logical source address with a synthetic hardware address, wherein the synthetic hardware address is not associated with a device on the local network segment, to cause communications sent by the first device to the logical source address to be undeliverable.

8. The system of claim 7 , wherein the logical network address is an Internet Protocol address.

9. The system of claim 7 , wherein the processor is configured to:

determine whether a target hardware address is the synthetic hardware address; and

drop the network packet when the target hardware address is the synthetic hardware address.

10. The system of claim 7 , wherein the processor is configured to:

determine whether a target hardware address is the synthetic hardware address; and

forward the network packet to an alternate device when the target hardware address is not the synthetic hardware address.

11. The system of claim 7 , wherein the processor is configured to:

for each device on the local network send the address resolution protocol control packet having a destination associated with a logical network address and hardware address associated with each device on the local network.

12. The system of claim 7 , wherein the processor is configured to:

if (1) a target address is associated with a synthetic hardware address and (2) the target address and the logical source addresses address are not of interest, replace the synthetic hardware address in the network packet with a hardware address associated with a target device; and

send the network packet over the local network segment.

13. A computer readable storage disc or storage device comprising instructions that, when executed, cause a machine to:

determine if a network packet on a local network segment is a threat by determining if a logical network address associated with the network packet has been identified as a network threat;

determining if a logical source address associated with the network packet is associated with a device on the local network segment; and

in response to determining that the network packet is a threat, sending an address resolution protocol control packet over the local network segment to cause an address resolution protocol table of a first device on the local network segment to replace a physical hardware address of a second device associated with the logical source address with a synthetic hardware address, wherein the synthetic hardware address is not associated with a device on the local network segment, to cause communications sent by the first device to the logical source address to be undeliverable.

14. The computer readable storage disc or storage device of claim 13 , wherein the logical network address is an internet protocol address.

15. The computer readable storage disc or storage device of claim 13 , wherein the instructions, when executed, cause the machine to:

determine whether a target hardware address is the synthetic hardware address; and

drop the network packet when the target hardware address is the synthetic hardware address.

16. The computer readable storage disc or storage device of claim 13 , wherein the instructions, when executed, cause the machine to:

determine whether a target hardware address is the synthetic hardware address; and

forward the network packet to an alternative device when the target hardware address is not the synthetic hardware address.

17. The computer readable storage disc or storage device of claim 13 , wherein the instructions, when executed, cause the machine to:

for each device on the local network segment, send the address resolution protocol control packet having a destination associated with a logical network address and hardware address associated with the respective device on the local network segment.

18. The computer readable storage disc or storage device of claim 13 , wherein the instructions, when executed, cause the machine to:

if (1) a target address is associated with a synthetic hardware address and (2) the target address and the logical source address are not of interest:

replace the synthetic hardware address in the network packet with a hardware address associated with a logical target device; and

send the network packet over the local network segment.

Assignments (10)
SECURITY INTEREST Recorded Aug 6, 2024
From: SYSXNET LIMITED; CONTROLSCAN, INC.; VIKING CLOUD, INC.
To: MIDCAP FINANCIAL TRUST, AS COLLATERAL AGENT
Reel/Frame 068196/0462 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2022
From: TRUSTWAVE HOLDINGS, INC.
To: SYSXNET LIMITED
Reel/Frame 058748/0177 →
RELEASE OF SECURITY INTEREST Recorded Jul 11, 2012
From: SILICON VALLEY BANK
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 028526/0001 →
SECURITY AGREEMENT Recorded Jul 10, 2012
From: TRUSTWAVE HOLDINGS, INC.; TW SECURITY CORP.
To: WELLS FARGO CAPITAL FINANCE, LLC, AS AGENT
Reel/Frame 028518/0700 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDRESS OF THE RECEIVING PARTY PREVIOUSLY RECORDED ON REEL 027867 FRAME 0199. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT. Recorded Mar 19, 2012
From: TRUSTWAVE HOLDINGS, INC.
To: SILICON VALLEY BANK
Reel/Frame 027886/0058 →
SECURITY AGREEMENT Recorded Mar 15, 2012
From: TRUSTWAVE HOLDINGS, INC.
To: SILICON VALLEY BANK
Reel/Frame 027867/0199 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2012
From: TW ACQUISITION, INC.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 027489/0981 →
SECURITY AGREEMENT Recorded Oct 23, 2009
From: TW MIRAGE NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 023409/0894 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2009
From: WILKINSON, MARK L.; MILLER, RONALD J.; MCDANIELS, MICHAEL J.
To: MIRAGE NETWORKS, INC.
Reel/Frame 022403/0420 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2009
From: MIRAGE NETWORKS, INC.
To: TW ACQUISITION, INC.
Reel/Frame 022354/0865 →