IP Library Granted Patent US 8,646,081
Granted Patent B1
US 8,646,081 · App. 11/872,171 · Granted Feb 4, 2014

Method and system to detect a security event in a packet flow and block the packet flow at an egress point in a communication network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,646,081
App. No.
11/872,171
Granted
Feb 4, 2014
Kind
B1
Abstract

An ingress point receives a packet flow from a first communication device. The ingress point copies the packet flow, transmits the packet flow to an egress point over a network path, and processes the copy to determine if the packet flow represents a security event. If the packet flow represents a security event, the ingress point transmits a blocking instruction to the egress point over an alarm link and the egress point blocks the packet flow representing the security event. If the packet flow does not represent a security event, the egress point transmits the packet flow to a second communication device.

Claims (30)

1. A method of operating a communication network having an ingress point and an egress point to detect security events in packet flows, the method comprising:

at the ingress point, receiving a packet flow from a first communication device;

copying the packet flow, transmitting the packet flow to the egress point over a network path, and processing the copy to determine if the packet flow represents a security event, wherein the security event comprises a virus;

if the packet flow represents the security event, then transmitting a blocking instruction for the packet flow to the egress point over an alarm link that is faster than the network path, wherein the blocking instruction reaches the egress point before the packet flow reaches the egress point, and at the egress point, blocking the packet flow representing the security event, processing the packet flow representing the security event to remove the virus from the packet flow, resulting in a clean packet flow, transmitting the clean packet flow to a second communication device, and transmitting a security message to the second communication device, wherein the security message instructs the second communication device to determine whether recent packet flows were previously received from the first communication device, and if the recent packet flows were previously received from the first communication device, process the recent packet flows to remove the virus from the recent packet flows; and

if the packet flow does not represent the security event, then at the egress point, transmitting the packet flow to the second communication device.

2. The method of claim 1 wherein transmitting the blocking instruction to the egress point comprises translating a destination address of the packet flow at the ingress point to identify the egress point.

3. The method of claim 1 wherein transmitting the blocking instruction to the egress point comprises:

transmitting an alarm instruction indicating a destination address of the packet flow to a routing system;

translating the destination address in the routing system to identify the egress point; and

transmitting the blocking instruction from the routing system to the egress point.

4. The method of claim 1 wherein transmitting the blocking instruction to the egress point comprises transmitting an identity of the first communication device and an identity of the second communication device.

5. The method of claim 1 further comprising transmitting an additional blocking instruction for the packet flow to an additional egress point.

6. The method of claim 1 wherein the security message indicates the identity of the first communication device.

7. The method of claim 1 wherein the security message comprises a virus removal application.

8. A communication system comprising:

an ingress point configured to receive a packet flow from a first communication device, copy the packet flow, transmit the packet flow to an egress point over a network path, process the copy to determine if the packet flow represents a security event, wherein the security event comprises a virus, and if the packet flow represents the security event, transmit a blocking instruction for the packet flow to the egress point over an alarm link that is faster than the network path; and

the egress point configured to block the packet flow representing the security event in response to receiving the blocking instruction, wherein the blocking instruction reaches the egress point before the packet flow reaches the egress point, process the packet flow representing the security event to remove the virus from the packet flow, resulting in a clean packet flow, transmit the clean packet flow to a second communication device, and transmit a security message to the second communication device, wherein the security message instructs the second communication device to determine whether recent packet flows were previously received from the first communication device, and if the recent packet flows were previously received from the first communication device, process the recent packet flows to remove the virus from the recent packet flows; and

the egress point configured to, if the blocking instruction is not received, transmit the packet flow to the second communication device.

9. The communication system of claim 8 wherein the ingress point is configured to translate a destination address of the packet flow to identify the egress point.

10. The communication system of claim 8 wherein the security message indicates the identity of the first communication device.

11. The communication system of claim 8 wherein the security message comprises a virus removal application.

12. A communication system comprising:

an ingress point configured to receive a packet flow from a first communication device, copy the packet flow, transmit the packet flow over a network path, process the copy to determine if the packet flow represents a security event, wherein the security event comprises a virus, and if the packet flow represents the security event, transmit an alarm instruction indicating a destination address of the packet flow;

a routing system configured to receive the alarm instruction, translate the destination address to identify an egress point, and transmit a blocking instruction to the egress point over an alarm link that is faster than the network path, wherein the blocking instruction reaches the egress point before the packet flow reaches the egress point; and

the egress point configured to block the packet flow representing the security event in response to receiving the blocking instruction, process the packet flow representing the security event to remove the virus from the packet flow, resulting in a clean packet flow, transmit the clean packet flow to a second communication device, and transmit a security message to the second communication device, wherein the security message instructs the second communication device to determine whether recent packet flows were previously received from the first communication device, and if the recent packet flows were previously received from the first communication device, process the recent packet flows to remove the virus from the recent packet flows; and

the egress point configured to, if the blocking instruction is not received, transmit the packet flow to the second communication device.

13. The communication system of claim 12 wherein the routing system is configured to transmit an identity of the first communication device and an identity of the second communication device.

14. The communication system of claim 12 wherein the routing system is configured to transmit an additional blocking instruction for the packet flow to an additional egress point.

15. The communication system of claim 12 wherein the security message indicates the identity of the first communication device.

16. The communication system of claim 12 wherein the security message comprises a virus removal application.

Assignments (3)
TERMINATION AND RELEASE OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2020
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 052969/0475 →
GRANT OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Mar 6, 2017
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 041895/0210 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2007
From: XUE, WEN; ZHOU, TONG
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 019961/0943 →