IP Library Granted Patent US 8,077,708
Granted Patent B2
US 8,077,708 · App. 11/591,802 · Granted Dec 13, 2011

Systems and methods for determining a flow of data

Assignee: Techguard Security, LLC
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,077,708
App. No.
11/591,802
Granted
Dec 13, 2011
Kind
B2
Abstract

A method for determining a flow of data is described. The method includes determining whether a packet including a first number of at least one bit within a first set is assigned a classification value based on the at least one bit within the first set and determining a result to be applied to the packet upon determining that the packet is assigned the classification value. The method further includes analyzing, by a processor, at least one bit of a second number within a second set of the packet upon determining that the packet cannot be assigned the classification value based on the first number of at least one bit of the packet.

Claims (29)

1. A method for determining a flow of data, the method comprising:

a. receiving a data packet;

b. providing a memory device containing one or more tables, each one or more table being populated with a finite number of listed bit sets, each listed bit set having an equal number of bits as a set of bits previously designated for extraction from the packet and each listed bit set in the one or more tables being associated with either a predetermined classification value assignable to the packet or a designation that the packet cannot be classified;

the set of bits previously designated for extraction from the packet being: (1) one set among a plurality of sets of bits designated for extraction from the packet; and (2) comprising one or more bits, none of which bits are included in any other set of bits designated for extraction from the packet;

c. extracting from the packet a first set of bits designated for extraction;

d. inputting the extracted first set of bits designated for extraction into the memory device and comparing the extracted first set of bits with the finite number of listed bit sets in a table to determine whether the extracted first set of bits matches a listed bit set in the table;

e. determining whether the packet receives a predetermined classification value or a designation that the packet cannot be classified based upon which listed bit set in the table the extracted first set of bits matches;

f. applying a predetermined result or procedure to the packet upon determining that the packet can be assigned a classification value from the table; and

g. upon determining the packet cannot be classified, continuing to sequentially process the remaining sets of bits designated for extraction by repeating procedures c-f until such point that an extracted set of bits matches a bit set listed in a table that has an assigned classification value or all sets of bits in the packet designated for extraction have been extracted and compared to the entries of at least one table.

2. A method in accordance with claim 1 wherein a set of bits designated for extraction includes less than 32 bits of the IP network address of an IPv4 packet.

3. A method in accordance with claim 1 wherein a set of bits designated for extraction includes less than 128 bits of the IP network address of an IPv6 packet.

4. A method in accordance with claim 1 wherein a set of bits designated for extraction includes one or more bits other than those previously determined to be the most significant bits of the IP network address.

5. A method in accordance with claim 1 wherein a set of bits designated for extraction includes one or more bits other than those previously determined to be among the least significant bits of the IP network address.

6. A method in accordance with claim 1 wherein a set of bits designated for extraction includes one or more bits previously determined to be among the most significant bits of the IP network address.

7. A method in accordance with claim 1 wherein an extracted set of bits is extracted from the IP network address, the port address or the data of the packet.

8. A method in accordance with claim 1 wherein a portion of an extracted set of bits is extracted in part from the IP network address and the remainder of the first set of bits is extracted from the port address.

9. A method in accordance with claim 1 wherein each bit set listed in a table against which a set of bits is compared constitutes an IP network address sub-range.

10. A method in accordance with claim 1 wherein one or more of the classification values assigned to a bit set listed in a table against which a set of bits is compared constitute country codes.

11. A method in accordance with claim 1 , wherein the classification value comprises one of a code identifying a country, a code identifying a sub-region, a code identifying a computer hacker, a code identifying a computer spammer, a code identifying a computer virus, a code identifying a Trojan, a code identifying a computer worm, a code identifying a phisher, a code identifying an intruder, a code identifying a North Atlantic treaty organization country, a code identifying a corporation, a code identifying a government agency, a code identifying an Internet service provider, a code identifying an industrial sector, and a code identifying a Department of Defense.

12. A system for analyzing a data packet, the system comprising:

a memory device containing one or more tables, each one or more table being populated with a finite number of listed bit sets, each listed bit set having an equal number of bits as a set of bits previously designated for extraction from the packet and each listed bit set in the one or more tables being associated with either a predetermined classification value assignable to the packet or a designation that the packet cannot be classified;

the set of bits previously designated for extraction from the packet being: (1) one set among a plurality of sets of bits designated for extraction from the packet; and (2) comprising one or more bits, none of which bits are included in any other set of bits designated for extraction from the packet;

a processor configured to:

a. receive the data packet;

b. extract from the packet a first set of bits designated for extraction;

c. input the extracted first set of bits designated for extraction into the memory device and compare the extracted first set of bits with the finite number of listed bit sets in a table to determine whether the extracted first set of bits matches a listed bit set in the table;

d. determine whether the packet receives a predetermined classification value or a designation that the packet cannot be classified based upon which listed bit set in the table the extracted first set of bits matches;

e. apply a predetermined result or procedure to the packet upon determining that the packet can be assigned a classification value from the table; and

f. upon determining the packet cannot be classified, continue to sequentially process the remaining sets of bits designated for extraction by repeating procedures b-e until such point that an extracted set of bits matches a bit set listed in a table that has an assigned classification value or all sets of bits in the packet designated for extraction have been extracted and compared to the entries of at least one table.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Oct 15, 2025
From: CANADIAN IMPERIAL BANK OF COMMERCE
To: THREATER, INC.
Reel/Frame 072574/0252 →
SECURITY INTEREST Recorded Jun 7, 2024
From: THREATER, INC.
To: CANADIAN IMPERIAL BANK OF COMMERCE
Reel/Frame 067666/0565 →
CHANGE OF NAME Recorded Jan 24, 2024
From: THREATBLOCKR, INC.
To: THREATER, INC.
Reel/Frame 066366/0758 →
CHANGE OF NAME Recorded Jul 21, 2022
From: BANDURA CYBER, INC.
To: THREATBLOCKR, INC.
Reel/Frame 060804/0842 →
ENTITY CONVERSION Recorded Dec 5, 2018
From: BANDURA, LLC
To: BANDURA SYSTEMS, INC.
Reel/Frame 047729/0336 →
CHANGE OF NAME Recorded Dec 5, 2018
From: BANDURA SYSTEMS, INC.
To: BANDURA CYBER, INC.
Reel/Frame 047729/0478 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2015
From: TECHGUARD SECURITY, L.L.C.
To: BANDURA, LLC
Reel/Frame 034957/0056 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2008
From: MAESTAS, DAVID E.; COOPER, BRIAN L.
To: TECHGUARD SECURITY LLC
Reel/Frame 021979/0901 →
Continuity (2)
Provisional Application 60773820 · Feb 16, 2006
Related Publication 20080069093A1 · Mar 20, 2008