IP Library Granted Patent US 7,895,652
Granted Patent B2
US 7,895,652 · App. 11/325,234 · Granted Feb 22, 2011

System to enable detecting attacks within encrypted traffic

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,895,652
App. No.
11/325,234
Granted
Feb 22, 2011
Kind
B2
Abstract

A system and method for detecting network attacks within encrypted network traffic received by a protected network includes a decryption module and an adaptor module. This system and method can be inserted and used with multiple types of operating systems.

Claims (46)

1. A computer system for detecting network attacks within encrypted network traffic received by a protected network comprising:

a sensor module comprising storage media storing processor executable instructions to receive and analyze network traffic for attacks; and

a security module comprising storage media storing processor executable instructions to

decrypt encrypted network traffic and create decrypted traffic,

provide identification of the decrypted traffic as preprocessed network traffic before it is sent to the sensor module, wherein providing identification of the decrypted traffic comprises changing the destination IP address and port number of each decrypted packet to a predetermined IP address and port number that identifies the decrypted packet as being preprocessed, and

send the decrypted traffic to the sensor module,

wherein the sensor module further comprises processor executable instructions to analyze both the encrypted network traffic and the decrypted traffic provided by the security module for attacks or other anomalous behavior,

wherein the security module further comprises processor executable instructions to maintain a temporary mapping of encrypted network packets and decrypted network packets,

wherein the sensor module further comprises processor executable instructions to block decrypted network packets received from the security module if a threat is detected, and

wherein the security module further comprises processor executable instructions to detect when the sensor module blocks a decrypted network packet and to block an encrypted sensor packet corresponding to the decrypted packet blocked by the sensor module.

2. The system of claim 1 , wherein the security module further comprises instructions to decrypt secure sockets layer (SSL) traffic and the sensor module is configured to receive and analyze the decrypted SSL traffic.

3. A security module to provide an interface with a protected network for use with a sensor module which can analyze network traffic comprising:

a decryption module comprising media storing processor executable instructions to

receive encrypted network traffic,

decrypt the encrypted network traffic, and

transmit the decrypted network traffic;

a sensor module comprising media storing processor executable instructions to analyze network traffic and to block decrypted packets determined to be part of an attack, wherein the sensor module further comprises processor executable instructions to analyze both encrypted network traffic and decrypted traffic received from the decryption module for attacks or other anomalous behavior; and

an adaptor module comprising media storing processor executable instructions to

route network traffic from the protected network to the sensor module,

route encrypted network traffic from the protected network to the decryption module,

receive the decrypted network traffic from the decryption module,

provide identification of the decrypted network traffic as preprocessed network traffic before it is sent to the sensor module,

route the decrypted network traffic to the sensor module,

detect when the sensor module blocks a decrypted packet determined to be part of an attack, and

block an encrypted packet corresponding to the decrypted packet,

wherein the adaptor module further comprises processor executable instructions to maintain a temporary mapping of encrypted network packets and decrypted network packets,

wherein the sensor module further comprises processor executable instructions to block decrypted network packets received from the adaptor module if a threat is detected, and

wherein the adaptor module further comprises processor executable instructions to detect when the sensor module blocks a decrypted network packet and to block an encrypted sensor packet corresponding to the decrypted packet blocked by the sensor module.

4. The security module of claim 3 , wherein identification is provided to the decrypted network traffic by changing the destination IP address and port number of each decrypted packet.

5. The security module of claim 3 , wherein the adaptor module further comprises instructions to function at the operating system level.

6. The security module of claim 3 , wherein the decryption module further comprises instructions to monitor network traffic to specific web sites or addresses on the network.

7. The security module of claim 3 , further comprising instructions to hold multiple connections to secure web pages in a buffer.

8. A method for decrypting and processing network traffic for a sensor module, to protect a network from attacks, comprising the steps of:

receiving network traffic,

decrypting encrypted network traffic and changing the destination IP address and port number associated with the decrypted network traffic to a predetermined destination IP address and port number which identifies the decrypted network traffic as preprocessed network traffic,

adding decrypted network packets and encrypted network packets to a temporary mapping that identifies corresponding decrypted and encrypted network packets;

routing the decrypted network traffic to a first sensor,

analyzing the decrypted network traffic using the first sensor,

routing non-encrypted network traffic to a second sensor,

analyzing the non-encrypted network traffic using the second sensor,

blocking decrypted network traffic if a threat is detected in the decrypted network traffic;

identifying encrypted network packets corresponding to the blocked decrypted network traffic using the temporary mapping;

blocking the identified encrypted network packets;

routing the encrypted network traffic to a third sensor if the encrypted network traffic has not been blocked,

analyzing the encrypted network traffic with the third sensor,

blocking the encrypted network traffic if a threat is detected in the encrypted network traffic.

Assignments (22)
SECURITY INTEREST Recorded Feb 18, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 073824/0146 →
SECURITY INTEREST Recorded Jan 30, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 073649/0743 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 071508/0540 Recorded Aug 18, 2025
From: LEVELBLUE, LLC
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 072510/0679 →
SECURITY INTEREST Recorded Jun 24, 2025
From: TRUSTWAVE HOLDINGS, INC.
To: LEVELBLUE, LLC
Reel/Frame 071508/0540 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 070952/0452 Recorded Jun 24, 2025
From: STG V, L.P.; STG VI, L.P.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 071723/0263 →
SECURITY INTEREST Recorded Apr 25, 2025
From: TRUSTWAVE HOLDINGS, INC.
To: STG V, L.P.; STG VI, L.P.
Reel/Frame 070952/0452 →
SECURITY INTEREST Recorded Oct 22, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: CYBEREASON INC.
Reel/Frame 068974/0691 →
SECURITY INTEREST Recorded Sep 12, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: CYBEREASON INC.
Reel/Frame 068572/0937 →
SECURITY INTEREST Recorded Jan 8, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: SINGTEL ENTERPRISE SECURITY (US), INC.
Reel/Frame 066050/0947 →
RELEASE OF SECURITY INTEREST Recorded Jul 11, 2012
From: SILICON VALLEY BANK
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 028526/0001 →
SECURITY AGREEMENT Recorded Jul 10, 2012
From: TRUSTWAVE HOLDINGS, INC.; TW SECURITY CORP.
To: WELLS FARGO CAPITAL FINANCE, LLC, AS AGENT
Reel/Frame 028518/0700 →
RELEASE OF SECURITY INTEREST Recorded Jul 10, 2012
From: SILICON VALLEY BANK
To: TW BREACH SECURITY, INC.
Reel/Frame 028519/0348 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDRESS OF THE RECEIVING PARTY PREVIOUSLY RECORDED ON REEL 027867 FRAME 0199. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT. Recorded Mar 19, 2012
From: TRUSTWAVE HOLDINGS, INC.
To: SILICON VALLEY BANK
Reel/Frame 027886/0058 →
SECURITY AGREEMENT Recorded Mar 15, 2012
From: TRUSTWAVE HOLDINGS, INC.
To: SILICON VALLEY BANK
Reel/Frame 027867/0199 →
SECURITY AGREEMENT Recorded Mar 8, 2011
From: TW BREACH SECURITY, INC.
To: SILICON VALLEY BANK
Reel/Frame 025914/0284 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2011
From: TW BREACH SECURITY, INC.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 025590/0351 →
MERGER Recorded Oct 21, 2010
From: BREACH SECURITY, INC.
To: TW BREACH SECURITY, INC.
Reel/Frame 025169/0652 →
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2010
From: SRBA #5, L.P. (SUCCESSOR IN INTEREST TO ENTERPRISE PARTNERS V, L.P. AND ENTERPRISE PARTNERS VI, L.P.); EVERGREEN PARTNERS US DIRECT FUND III, L.P.; EVERGREEN PARTNERS DIRECT FUND III (ISRAEL) L.P.; EVERGREEN PARTNERS DIRECT FUND III (ISRAEL 1) L.P.
To: BREACH SECURITY, INC.
Reel/Frame 024869/0883 →
RELEASE OF SECURITY INTEREST Recorded Jun 28, 2010
From: COMERICA BANK
To: BREACH SECURITY, INC.
Reel/Frame 024599/0435 →
SECURITY AGREEMENT Recorded Feb 17, 2009
From: BREACH SECURITY, INC.
To: COMERICA BANK
Reel/Frame 022266/0646 →
SECURITY AGREEMENT Recorded Jan 23, 2009
From: BREACH SECURITY, INC.
To: ENTERPRISE PARTNERS V, L.P.; SRBA # 5, L.P.; ENTERPRISE PARTNERS VI, L.P.
Reel/Frame 022151/0041 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2006
From: KOLTON, DORON; STAV, ADI; WEXLER, ASAF; FRYDMAN, ARIEL; ZAHAVI, YORAM
To: BREACH SECURITY, INC.
Reel/Frame 017558/0817 →