IP Library Granted Patent US 9,696,346
Granted Patent B2
US 9,696,346 · App. 14/797,925 · Granted Jul 4, 2017

Method and system for packet acquistion, analysis and intrusion detection in field area networks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,696,346
App. No.
14/797,925
Granted
Jul 4, 2017
Kind
B2
Abstract

A system for intrusion detection in a field area network where data is transmitted via packets, includes a processor for analyzing the packets to ascertain whether the packets conform to a sets of rules indicating an intrusion, and a database for storing an alert indicating an intrusion if the packets conform to at least one rule in the sets. The sets of rules are for field network layer data, internet protocol traffic data and field area application traffic data. A method for detecting intrusion in a field area network where data is transmitted via packets, including analyzing the packets to ascertain whether the packets conform to the sets of rules, and storing an alert indicating an intrusion if the packets conform to at least one rule in the sets of rules.

Claims (45)

1. A method for monitoring a field area network, the method comprising:

backhauling by a packet intercept system on a field area network, to at least one additional network, a traffic data stream intercepted by the packet intercept system from the field area network,

wherein the field area network comprises a plurality of network nodes,

wherein the packet intercept system is comprised of a plurality of probes along the field area network,

wherein the at least one additional network is distinct from the field area network, and

wherein the traffic data stream comprises at least one of: individual packets, packet detail or metadata generated by at least one probe of the plurality of probes, based on processing at least one intercepted packet from the field area network;

obtaining, by a processor, communicatively coupled to the at least one additional network, the traffic data stream, and processing the traffic data stream into a processed live traffic data stream; and

analyzing, by the processor, the processed live traffic data stream.

2. The method of claim 1 , wherein at least one of the field area network or the at least one network is a wireless network.

3. The method of claim 1 , wherein a portion of the plurality of probes are software probes.

4. The method of claim 1 , wherein the analyzing comprises applying behavior analytics to the processed live traffic data stream.

5. The method of claim 1 , wherein the analyzing the processed live traffic data stream comprises at least one of identifying anomalies, identifying intrusions, identifying events, or validating configurations.

6. The method of claim 1 , wherein the processing comprises one or more of: decrypting, decompressing, or descrambling bits in the traffic data stream.

7. The method of claim 1 , wherein the processing further comprises:

extracting, by the processor, connectivity and routing information from the traffic data, wherein the connectivity and routing information comprises packet information and node information.

8. The method of claim 1 , wherein the analyzing the processed live traffic data stream further comprises extracting protocol data units embedded in packets in the live traffic data stream.

9. A computer system for monitoring a field area network, the computer system comprising:

a memory; and

a processor in communications with the memory, wherein the computer system is configured to perform a method, said method comprising:

backhauling by a packet intercept system on a field area network, to at least one additional network, a traffic data stream intercepted by the packet intercept system from the field area network,

wherein the field area network comprises a plurality of network nodes,

wherein the packet intercept system is comprised of a plurality of probes along the field area network,

wherein the at least one additional network is distinct from the field area network, and

wherein the traffic data stream comprises at least one of: individual packets, packet detail or metadata generated by at least one probe of the plurality of probes, based on processing at least one intercepted packet from the field area network;

obtaining, by a processor, communicatively coupled to the at least one additional network, the traffic data stream, and processing the traffic data stream into a processed live traffic data stream; and

analyzing, by the processor, the processed live traffic data stream.

10. The computer system of claim 9 , wherein the analyzing comprises applying behavior analytics to the processed live traffic data stream.

11. The computer system of claim 9 , wherein at least one of the field area network or the at least one network is a wireless network.

12. The computer system of claim 9 , wherein a portion of the plurality of probes are software probes.

13. The computer system of claim 10 , wherein the behavior analytics comprise a set of rules, and wherein rules in the set of rules are at least one of: global, region specific, probe specific, fixed, dynamic, node specific, or protocol-specific.

14. The computer system of claim 9 , wherein the analyzing the processed live traffic data stream comprises at least one of identifying anomalies, identifying intrusions, identifying events, or validating configurations.

15. The computer system of claim 9 , wherein the processing comprises one or more of: decrypting bits in the traffic data stream, decompressing bits in the traffic data stream, descrambling bits in the traffic data stream, or extracting, by the processor, connectivity and routing information from the traffic data, wherein the connectivity and routing information comprises packet information and node information.

16. The computer system of claim 9 , wherein the plurality of probes intercept one of: a selection of a pre-determined number of channels, or a full spectrum of channels.

17. A computer program product for monitoring a field area network, the computer program product comprising:

a non-transitory computer readable storage medium readable by a processing circuit and storing instructions for execution by the processing circuit for performing a method comprising:

backhauling by a packet intercept system on a field area network, to at least one additional network, a traffic data stream intercepted by the packet intercept system from the field area network,

wherein the field area network comprises a plurality of network nodes,

wherein the packet intercept system is comprised of a plurality of probes along the field area network,

wherein the at least one additional network is distinct from the field area network, and

wherein the traffic data stream comprises at least one of: individual packets, packet detail or metadata generated by at least one probe of the plurality of probes, based on processing at least one intercepted packet from the field area network;

obtaining, by a processor, communicatively coupled to the at least one additional network, the traffic data stream, and processing the traffic data stream into a processed live traffic data stream; and

analyzing, by the processor, the processed live traffic data stream.

18. The computer program product of claim 17 , wherein a portion of the plurality of probes are software probes.

19. The computer program product of claim 18 , wherein the analyzing comprises applying behavior analytics to the processed live traffic data stream.

20. The computer program product of claim 18 , wherein at least one of the field area network or the at least one network is a wireless network.

Assignments (6)
FIRST LIEN SECURITY AGREEMENT Recorded May 6, 2021
From: PERSPECTA LABS INC.; PERSPECTA ENGINEERING INC.; PERSPECTA SERVICES & SOLUTIONS INC.; KNIGHT POINT SYSTEMS, LLC; DHPC TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 056168/0001 →
SECOND LIEN SECURITY AGREEMENT Recorded May 6, 2021
From: PERSPECTA LABS INC.; PERSPECTA ENGINEERING INC.; PERSPECTA SERVICES & SOLUTIONS INC.; KNIGHT POINT SYSTEMS, LLC; DHPC TECHNOLOGIES, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 056168/0378 →
CHANGE OF NAME Recorded Jan 30, 2019
From: VENCORE LABS, INC.
To: PERSPECTA LABS INC.
Reel/Frame 048189/0861 →
CHANGE OF NAME Recorded Jan 29, 2019
From: VENCORE LABS, INC.
To: PERSPECTA LABS INC.
Reel/Frame 049671/0724 →
CHANGE OF NAME Recorded Jan 17, 2019
From: TT GOVERNMENT SOLUTIONS, INC.
To: VENCORE LABS, INC.
Reel/Frame 048088/0979 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2019
From: PIETROWICZ, STANLEY; YOUZWAK, JSON; HALUSKA, JOHN
To: TT GOVERNMENT SOLUTIONS, INC.
Reel/Frame 048015/0297 →