IP Library Granted Patent US 8,631,499
Granted Patent B2
US 8,631,499 · App. 13/345,332 · Granted Jan 14, 2014

Platform for analyzing the security of communication protocols and channels

Inventor: Kowsik Guruswamy (Sunnyvale, CA)
Assignee: Spirent Communications, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,631,499
App. No.
13/345,332
Granted
Jan 14, 2014
Kind
B2
Abstract

A security analyzer tests the security of a device by attacking the device and observing the device's response. Attacking the device includes sending one or more messages to the device. A message can be generated by the security analyzer or generated independently of the security analyzer. The security analyzer uses various methods to identify a particular attack that causes a device to fail or otherwise alter its behavior. Monitoring includes analyzing data (other than messages) output from the device in response to an attack. Packet processing analysis includes analyzing one or more messages generated by the device in response to an attack. Instrumentation includes establishing a baseline snapshot of the device's state when it is operating normally and then attacking the device in multiple ways while obtaining snapshots periodically during the attacks.

Claims (56)

1. A method of analyzing a security vulnerability of a network device under analysis (DUA) to protocol abuse of a network communication protocol, comprising:

establishing a baseline response of the DUA to a message that is valid with respect to the network communication protocol;

attacking the DUA multiple times, the attacks comprising sending to the DUA test messages that are invalid with respect to the network communication protocol;

periodically during the attacks sending additional messages to the DUA that are valid with respect to the network communication protocol and comparing additional responses of the DUA to the baseline response;

determining a changed response, based on the comparison of the additional responses to the baseline response and using the baseline response and the additional responses to identify which attack causes a security vulnerability.

2. The method of claim 1 , wherein establishing the baseline response of the DUA further comprises determining, responsive to receiving no response or an invalid response from the DUA for the valid message, that the DUA does not support the network communication protocol.

3. The method of claim 1 , further including establishing snapshots of the DUA based at least in part on the response of the DUA to the sent valid messages comprising:

observing a log output of the DUA after sending the valid message;

executing a command on the DUA to obtain information of the DUA after sending the valid message; and

establishing the snapshot of the DUA using the log output of the DUA and the information obtained through executing the command on the DUA.

4. The method of claim 3 , further comprising:

determining a probability that the identified attack actually caused the security vulnerability, based both on the log output and on the information obtained through executing the command on the DUA.

5. The method of claim 1 , wherein identifying which attack causes the security vulnerability further comprises:

using the additional responses received during the attacks to identify a subset of the attacks as candidate attacks;

restarting the DUA, thus restoring the DUA to its normal operation;

replaying the subset of attacks;

periodically during the replaying sending further messages to and receiving further responses from the DUA; and

using the baseline response and the further responses received during the replaying of the subset of attacks to identify which attack causes the security vulnerability.

6. A security analyzer device for analyzing a vulnerability of a network device under analysis (DUA) to protocol abuse of a network communications protocol, the security analyzer device comprising:

a computer processor for executing computer program instructions; and

a tangible computer-readable storage medium having executable computer program instructions stored thereon, the executable computer program instructions comprising instructions configured to cause the computer processor to perform the steps of:

establishing a baseline response of the DUA to a message that is valid with respect to the network communication protocol;

attacking the DUA multiple times, the attacks comprising sending to the DUA test messages that are invalid with respect to the network communication protocol;

periodically during the attacks sending additional messages to the DUA that are valid with respect to the network communication protocol and comparing additional responses of the DUA to the baseline response;

determining a changed response, based on the comparison of the additional responses to the baseline response and using the baseline response and the additional responses to identify which attack causes a security vulnerability.

7. The security analyzer device of claim 6 , wherein establishing the baseline response of the DUA further comprises determining, responsive to receiving no response or an invalid response from the DUA for the valid message, that the DUA does not support the network communication protocol.

8. The security analyzer device of claim 6 , further including establishing snapshots of the DUA based at least in part on the response of the DUA to the sent valid messages comprising:

observing a log output of the DUA after sending the valid message;

executing a command on the DUA to obtain information of the DUA after sending the valid message; and

establishing the snapshot of the DUA using the log output of the DUA and the information obtained through executing the command on the DUA.

9. The security analyzer device of claim 8 , further comprising:

determining a probability that the identified attack actually caused the security vulnerability, based both on the log output and on the information obtained through executing the command on the DUA.

10. The security analyzer device of claim 6 , wherein identifying which attack causes the security vulnerability further comprises:

using the additional responses received during the attacks to identify a subset of the attacks as candidate attacks;

restarting the DUA, thus restoring the DUA to its normal operation;

replaying the subset of attacks;

periodically during the replaying sending further messages to and receiving further responses from the DUA; and

using the baseline response and the further responses received during the replaying of the subset of attacks to identify which attack causes the security vulnerability.

11. An article of manufacture, the article of manufacture including a non-transitory computer-readable recording medium having stored thereon executable computer program instructions for analyzing vulnerability of a network device under analysis (DUA) to protocol abuse of a network communication protocol tangibly embodied thereon, the executable computer program instructions comprising instructions for performing the steps of:

establishing a baseline response of the DUA to a message that is valid with respect to the network communication protocol;

attacking the DUA multiple times, the attacks comprising sending to the DUA test messages that are invalid with respect to the network communication protocol;

periodically during the attacks sending additional messages to the DUA that are valid with respect to the network communication protocol and comparing additional responses of the DUA to the baseline response;

determining a changed response, based on the comparison of the additional responses to the baseline response and using the baseline response and the additional responses to identify which attack causes a security vulnerability.

12. The article of manufacture of claim 11 , wherein establishing the baseline response of the DUA further comprises determining, responsive to receiving no response or an invalid response from the DUA for the valid message, that the DUA does not support the network communication protocol.

13. The article of manufacture of claim 11 , further including establishing snapshots of the DUA based at least in part on the response of the DUA to the sent valid messages comprising:

observing a log output of the DUA after sending the valid message;

executing a command on the DUA to obtain information of the DUA after sending the valid message; and

establishing the snapshot of the DUA using the log output of the DUA and the information obtained through executing the command on the DUA.

14. The article of manufacture of claim 13 , further comprising:

determining a probability that the identified attack actually caused the security vulnerability, based both on the log output and on the information obtained through executing the command on the DUA.

15. The article of manufacture of claim 11 , wherein identifying which attack causes the security vulnerability further comprises:

using the additional responses received during the attacks to identify a subset of the attacks as candidate attacks;

restarting the DUA, thus restoring the DUA to its normal operation;

replaying the subset of attacks;

periodically during the replaying sending further messages to and receiving further responses from the DUA; and

using the baseline response and the further responses received during the replaying of the subset of attacks to identify which attack causes the security vulnerability.

Assignments (7)
RELEASE OF SECURITY INTEREST AT REEL/FRAME 73189/0873 Recorded May 28, 2026
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: INERTIAL LABS, INC.; VIAVI SOLUTIONS INC.; VIAVI SOLUTIONS LICENSING LLC
Reel/Frame 075642/0381 →
SECURITY INTEREST Recorded Nov 14, 2025
From: VIAVI SOLUTIONS INC.; VIAVI SOLUTIONS LICENSING LLC; INERTIAL LABS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS AGENT
Reel/Frame 073571/0137 →
SECURITY AGREEMENT Recorded Oct 21, 2025
From: INERTIAL LABS, INC.; VIAVI SOLUTIONS INC.; VIAVI SOLUTIONS LICENSING LLC
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 073189/0873 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2025
From: SPIRENT COMMUNICATIONS, INC.
To: VIAVI SOLUTIONS LICENSING LLC
Reel/Frame 073121/0549 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2014
From: MU DYNAMICS, INC
To: SPIRENT COMMUNICATIONS, INC.
Reel/Frame 033099/0185 →
CHANGE OF NAME Recorded Jan 13, 2012
From: MU SECURITY, INC.
To: MU DYNAMICS, INC.
Reel/Frame 027532/0295 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2012
From: GURUSWAMY, KOWSIK
To: MU SECURITY, INC.
Reel/Frame 027530/0586 →
Continuity (3)
Continuation 11351403 · Feb 10, 2006
Provisional Application 60662430 · Mar 15, 2005
Related Publication 20120137370A1 · May 31, 2012