IP Library Granted Patent US 8,001,244
Granted Patent B2
US 8,001,244 · App. 12/758,456 · Granted Aug 16, 2011

Deep packet scan hacker identification

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,001,244
App. No.
12/758,456
Granted
Aug 16, 2011
Kind
B2
Abstract

Securing an accessible computer system typically includes receiving a data packet that includes a payload portion and an attribute portion, where the data packet is communicated between at least one access requestor and at least one access provider. At least the payload portion of the received data packet typically is monitored, where monitoring includes scanning the payload portion for at least one predetermined pattern. When the payload portion is determined to include at least one predetermined pattern, access by the access requestor to the access provider may be controlled . Monitoring the data packet may include scanning the payload portion while handling the data packet with a switch. Controlling access may include denying access by the access requestor to the access provider.

Claims (46)

1. A computer-implemented method of securing an accessible computer system, the method comprising:

scanning a plurality of data packets communicated between a plurality of access requestors and an access provider to detect one or more predetermined patterns;

in response to detecting that a number of data packets, transmitted between a first access requestor and the access provider, that include the one or more predetermined patterns exceeds a first configurable threshold, blacklisting the first access requestor; and

in response to detecting the transmission, between a second access requestor and the access provider, of a configurable number of data packets in which an occurrence of the one or more predetermined patterns is below a second configurable threshold, ceasing to scan data packets between the second access requestor and the access provider to detect occurrences of the one or more predetermined patterns.

2. The method of claim 1 , wherein the predetermined pattern comprises a login request message communicated from an access provider to the access requestor.

3. The method of claim 1 , wherein the predetermined pattern comprises a login failure message communicated from the access provider to an access requestor.

4. The method of claim 3 , wherein the login failure message includes a signature located at a specific offset.

5. The method of claim 3 , wherein the login failure message includes login failure reasons.

6. The method of claim 1 , wherein blacklisting the first access requestor comprises:

decreasing available bandwidth for communications from the first access requestor to the access provider.

7. The method of claim 1 , wherein blacklisting the first access requestor comprises:

rerouting communications from the first access requestor to the access provider.

8. The method of claim 1 , wherein blacklisting the first access requestor comprises:

denying communications from the first access requestor to the access provider that occur within a configurable period of time.

9. The method of claim 1 , wherein blacklisting the first access requestor comprises:

denying communications from the first access requestor to the access provider that include the one or more predetermined patterns.

10. The method of claim 1 , further comprising:

blacklisting the second access requestor in response to detecting a data packet communicated between the second access requestor and the access provider that includes the one or more predetermined patterns; and

removing the second access requestor from the blacklisting in response to detecting the transmission, between the second access requestor and the access provider, of the configurable number of data packets in which the occurrence of the one or more predetermined patterns is below the second configurable threshold.

11. The method of claim 1 , wherein:

the first configurable threshold comprises one of a number and a ratio; and

the second configurable threshold comprises one of a number and a ratio.

12. A computer system, comprising:

a processing system, comprising one or more processors;

a memory device, comprising one or more computer-readable media, wherein the computer-readable media include stored computer instructions that, when executed by the processing system, cause the processing system to perform the operations of:

scanning a plurality of data packets communicated between a plurality of access requestors and an access provider to detect one or more predetermined patterns;

in response to detecting that a number of data packets, transmitted between a first access requestor and the access provider, that include the one or more predetermined patterns exceeds a first configurable threshold, blacklisting the first access requestor; and

in response to detecting the transmission, between a second access requestor and the access provider, of a configurable number of data packets in which an occurrence of the one or more predetermined patterns is below a second configurable threshold, ceasing to scan data packets between the second access requestor and the access provider to detect occurrences of the one or more predetermined patterns.

13. The system of claim 12 , wherein the predetermined pattern comprises a login request message communicated from an access provider to the access requestor.

14. The system of claim 12 , wherein the predetermined pattern comprises a login failure message communicated from the access provider to an access requestor.

15. The system of claim 14 , wherein the login failure message includes a signature located at a specific offset.

16. The system of claim 14 , wherein the login failure message includes login failure reasons.

17. The system of claim 12 , wherein blacklisting the first access requestor comprises:

decreasing available bandwidth for communications from the first access requestor to the access provider.

18. The system of claim 12 , wherein blacklisting the first access requestor comprises:

rerouting communications from the first access requestor to the access provider.

19. The system of claim 12 , wherein blacklisting the first access requestor comprises:

denying communications from the first access requestor to the access provider that occur within configurable period of time.

20. The system of claim 12 , wherein blacklisting the first access requestor comprises:

denying communications from the first access requestor to the access provider that include the one or more predetermined patterns.

21. The system of claim 12 , the operations executed by the processing system further comprising:

blacklisting the second access requestor in response to detecting a data packet communicated between the second access requestor and the access provider that includes the one or more predetermined patterns; and

removing the second access requestor from the blacklisting in response to detecting the transmission, between the second access requestor and the access provider, of the configurable number of data packets in which the occurrence of the one or more predetermined patterns is below the second configurable threshold.

22. The system of claim 12 , wherein:

the first configurable threshold comprises one of a number and a ratio; and

the second configurable threshold comprises one of a number and a ratio.

Assignments (10)
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2012
From: AOL, INC.; RELEGANCE CORPORATION
To: CITRIX SYSTEMS, INC.
Reel/Frame 028391/0832 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2010
From: JACOBY, BRIAN; WRIGHT, CHRISTOPHER J.
To: AMERICA ONLINE, INC.
Reel/Frame 024221/0725 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2010
From: AOL LLC
To: AOL INC.
Reel/Frame 024221/0797 →
CHANGE OF NAME Recorded Apr 13, 2010
From: AMERICA ONLINE, INC.
To: AOL LLC
Reel/Frame 024221/0794 →