IP Library Granted Patent US 9,065,848
Granted Patent B2
US 9,065,848 · App. 14/064,597 · Granted Jun 23, 2015

Method and apparatus to perform multiple packet payloads analysis

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,065,848
App. No.
14/064,597
Filed
Oct 28, 2013
Granted
Jun 23, 2015
Kind
B2
Art Unit
2436
USPC
726/22
Abstract

A method and apparatus for identifying data patterns of a file are described herein. In one embodiment, an exemplary process includes, but is not limited to, receiving a data packet of a data stream containing a file segment of a file originated from an external host and destined to a protected host of a local area network (LAN), the file being transmitted via multiple file segments contained in multiple data packets of the data stream, and performing a data pattern analysis on the received data packet to determine whether the received data packet contains a predetermined data pattern, without waiting for a remainder of the data stream to arrive. Other methods and apparatuses are also described.

Claims (44)

1. A method for performing re-assembly free deep packet inspection, the method comprising:

receiving a data stream over a communication network, the received data stream comprising a plurality of data packets corresponding to a segment of a file being transmitted in a plurality of segments ordered in a predetermined order;

determining that the plurality of data packets in the data stream are not being received in the predetermined order associated with the corresponding file segment, wherein at least one data packet is received before a precedent data packet in the predetermined order is received;

storing a local copy of the at least one data packet, wherein the local copy is subsequently retrieved after the precedent data packet is received for comparison to an attack pattern; and

preventing the at least one data packet from reaching a recipient until it is verified that previous in-order packets do not contain elements of the attack pattern.

2. The method of claim 1 , further comprising forwarding the received data packet to the recipient if the received data packet does not contain any element of the attack pattern and preventing a remainder of the data stream from reaching the recipient when it is determined that the at least one data packet contains one of the elements of the attack pattern.

3. The method of claim 2 , further comprising notifying the recipient that the at least one data packet and the remainder of the data stream has been blocked.

4. The method of claim 3 , wherein the notification results in the recipient discarding previous packets in the data stream.

5. The method of claim 1 , further comprising performing an analysis to detect the attack pattern.

6. The method of claim 5 , wherein the analysis comprises updating a current state of the attack pattern to a next state corresponding to a next element of the attack pattern when a next element of the data packet matches a corresponding next element of the attack pattern.

7. The method of claim 6 , further comprising determining that the attack pattern is associated with a sequence of states.

8. The method of claim 7 , further comprising determining that the attack pattern is found when the current state corresponds to a final state of the sequence of states.

9. The method of claim 1 , further comprising:

determining an encoding method of the at least one data packet;

decoding the at least one data packet using a decoding method associated with the determined encoding method to generate a decoded data packet; and

performing a pattern analysis based on the decoded data packet.

10. The method of claim 1 , further comprising:

determining a compression method of the at least one data packet;

decompressing the at least one data packet using a decompression method associated with the determined compression method to generate one or more decompressed data blocks; and

performing a pattern analysis based on the one or more decompressed data blocks.

11. A system for performing re-assembly free deep packet inspection, the system comprising:

a communication interface that receives a data stream over a communication network, the received data stream comprising a plurality of data packets corresponding to a segment of a file being transmitted in a plurality of segments ordered in a predetermined order;

a processor that executes instructions stored in memory, wherein execution of the instructions determines that the plurality of data packets in the data stream are not being received in the predetermined order associated with the corresponding file segment, wherein at least one data packet is received before a precedent data packet in the predetermined order is received; and

memory that stores a local copy of the at least one data packet, wherein the local copy is subsequently retrieved after the precedent data packet is received for comparison to an attack pattern, wherein the at least one data packet is prevented from reaching a recipient until it is verified that previous in-order packets do not contain elements of the attack pattern.

12. The system of claim 11 , wherein the communication interface forwards the received data packet to the recipient if the received data packet does not contain any element of the attack pattern, and a remainder of the data stream is prevented from reaching the recipient when it is determined that the at least one data packet contains one of the elements of the attack pattern.

13. The system of claim 12 , wherein the recipient is notified that the at least one data packet and the remainder of the data stream has been blocked.

14. The system of claim 13 , wherein the notification results in the recipient discarding previous packets in the data stream.

15. The system of claim 11 , wherein the processor executes further instructions to perform an analysis to detect the attack pattern.

16. The system of claim 15 , wherein the analysis comprises updating a current state of the attack pattern to a next state corresponding to a next element of the attack pattern when a next element of the data packet matches a corresponding next element of the attack pattern.

17. The system of claim 16 , wherein the processor executes further instructions to determine that the attack pattern is associated with a sequence of states.

18. The system of claim 17 , wherein the processor executes further instructions to determine that the attack pattern is found when the current state corresponds to a final state of the sequence of states.

19. The system of claim 11 , wherein the processor executes further instructions to:

determine an encoding method of the at least one data packet;

decode the at least one data packet using a decoding method associated with the determined encoding method to generate a decoded data packet; and

perform a pattern analysis based on the decoded data packet.

20. The system of claim 11 , wherein the processor executes further instructions to:

determine a compression method of the at least one data packet;

decompress the at least one data packet using a decompression method associated with the determined compression method to generate one or more decompressed data blocks; and

perform a pattern analysis based on the one or more decompressed data blocks.

21. A non-transitory computer-readable storage medium, having embodied thereon a program executable by a processor to perform a method for performing re-assembly free deep packet inspection, the method comprising:

receiving a data stream over a communication network, the received data stream comprising a plurality of data packets corresponding to a segment of a file being transmitted in a plurality of segments ordered in a predetermined order;

determining that the plurality of data packets in the data stream are not being received in the predetermined order associated with the corresponding file segment, wherein at least one data packet is received before a precedent data packet in the predetermined order is received;

storing a local copy of the at least one data packet, wherein the local copy is subsequently retrieved after the precedent data packet is received for comparison to an attack pattern; and

preventing the at least one data packet from reaching a recipient until it is verified that previous in-order packets do not contain elements of the attack pattern.

Assignments (29)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
CHANGE OF NAME Recorded May 25, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046246/0059 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded May 16, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046169/0718 →
CHANGE OF NAME Recorded May 15, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046163/0137 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF REEL 032810 FRAME 0206 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; CREDANT TECHNOLOGIES, INC.; COMPELLENT TECHNOLOGIES, INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0204 →
RELEASE OF SECURITY INTEREST OF REEL 032809 FRAME 0930 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; CREDANT TECHNOLOGIES, INC.; COMPELLENT TECHNOLOGIES, INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
Reel/Frame 040045/0255 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 032809 FRAME 0887 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; CREDANT TECHNOLOGIES, INC.; COMPELLENT TECHNOLOGIES, INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
Reel/Frame 040017/0314 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR AND ASSIGNEE NAME PREVIOUSLY RECORDED AT REEL: 035679 FRAME: 0787. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jun 10, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 035875/0777 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME PREVIOUSLY RECORDED AT REEL: 035668 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jun 10, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 035875/0645 →
MERGER Recorded May 20, 2015
From: SONICWALL LLC
To: DELL SOFTWARE, INC.
Reel/Frame 035679/0787 →
CHANGE OF NAME Recorded May 14, 2015
From: SONICWALL, INC.
To: SONICWALL LLC
Reel/Frame 035668/0335 →
MERGER Recorded Feb 10, 2015
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC. C/O THOMA BRAVO, LLC
Reel/Frame 034933/0166 →
CHANGE OF NAME Recorded Feb 10, 2015
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 034933/0191 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2015
From: DUBROVSKY, ALEKSANDR; GMUENDER, JOHN EVERETT; YANOVSKY, BORIS; YANOVSKY, ROMAN; ZHU, SHUNHUI
To: SONICWALL, INC.
Reel/Frame 034933/0137 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded May 1, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 032810/0206 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded May 1, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 032809/0930 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded May 1, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032809/0887 →