IP Library Granted Patent US 9,210,187
Granted Patent B1
US 9,210,187 · App. 14/815,647 · Granted Dec 8, 2015

Transparent denial of service protection

Inventors: Michael Patrick Mackey (Lake Stevens, WA); Luis Gerardo Paris (Maple Valley, WA); Charles Hubbard Taylor (Seattle, WA)
Assignee: Centri Technology, Inc.
H04L63/1458H04L63/0428H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,210,187
App. No.
14/815,647
Granted
Dec 8, 2015
Kind
B1
Abstract

Embodiments are directed toward transparent denial of service protection. Instruction set information that references a seed file may be communicated to a client computer. A network packet key may be generated based on the instruction set information or encrypted and provided by a server. A client computer may generate a client network packet key based on the instruction set information provided by the network computer and a seed file installed on the client computer. The client computer may include the client network packet key the one or more network packets that it is sending to the network computer before they are provided to the network computer. A packet rule that includes the network packet key may be generated and installed in a packet inspection engine. If network packets are received, the packet inspection engine compares the network packet key to the network packets using the packet rule.

Claims (98)

1. A method for managing communication over a network using a network computer that performs actions, comprising:

generating instruction set information that references at least a seed file that is installed on the network computer;

communicating a copy of the instruction set information to a client computer;

generating a network packet key based on the instruction set information;

generating a packet rule that includes the network packet key, wherein the packet rule is installed in a packet inspection engine that is included in a hardware network interface; and

when one or more network packets are communicated to the network computer, the packet inspection engine performing further actions, including:

comparing the network packet key to the one or more network packets using the packet rule; and

accepting each of the one or more network packets that include the network packet key and discarding each of the one or more network packets that omit the network packet key, wherein the accepted one or more network packets are provided to an operating system of the network computer.

2. The method of claim 1 , further comprising:

employing the client computer to generate a client network packet key based on the provided instruction set information and at least another seed file that is installed on the client computer, wherein the client network packet key and the network packet key have the same value; and

including the client network packet key in the one or more network packets before they are provided to the network computer.

3. The method of claim 1 , further comprising, when the one or more network packets is encrypted by the client computer, decrypting the one or more encrypted network packets before comparing the network packet key to the one or more network packets using the packet rule.

4. The method of claim 1 , wherein generating the network packet key, further comprises:

determining the seed file from a plurality of seed files based on an identifier that is included in the instruction set information;

extracting a pass phrase from the seed file based on an offset value and a pass phrase length value that are included in the instruction set information; and

generating the network packet key based on the pass phrase that is extracted from the seed file.

5. The method of claim 1 , further comprising:

employing the client computer to generate security header information that includes the network packet key;

employing the client computer to include an application network packet in a security network packet that includes the security header information; and

employing the client computer to communicate the security network packet to the network computer.

6. The method of claim 1 , further comprising, registering the client computer with the network computer based on an exchange of credentials that includes at least a client identifier.

7. The method of claim 1 , wherein generating the network packet key further comprises employing a sensor to introduce entropy.

8. A system for managing communication over a network, comprising:

a network computer, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

a processor device that executes instructions that perform actions, including:

generating instruction set information that references at least a seed file that is installed on the network computer;

communicating a copy of the instruction set information to a client computer;

generating a network packet key based on the instruction set information;

generating a packet rule that includes the network packet key, wherein the packet rule is installed in a packet inspection engine that is included in a hardware network interface; and

when one or more network packets are communicated to the network computer, the packet inspection engine performing further actions, including:

comparing the network packet key to the one or more network packets using the packet rule; and

accepting each of the one or more network packets that include the network packet key and discarding each of the one or more network packets that omit the network packet key, wherein the accepted one or more network packets are provided to an operating system of the network computer; and

a client computer, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

a processor device that executes instructions that perform actions, including:

generating a client network packet key based on the provided instruction set information and at least another seed file that is installed on the client computer, wherein the client network packet key and the network packet key have the same value; and

including the client network packet key in the one or more network packets before they are provided to the network computer.

9. The system of claim 8 , wherein the network computer processor device executes instructions that perform further actions, comprising, when the one or more network packets is encrypted by the client computer, decrypting the one or more encrypted network packets before comparing the network packet key to the one or more network packets using the packet rule.

10. The system of claim 8 , wherein generating the network packet key, further comprises:

determining the seed file from a plurality of seed files based on an identifier that is included in the instruction set information;

extracting a pass phrase from the seed file based on an offset value and a pass phrase length value that are included in the instruction set information; and

generating the network packet key based on the pass phrase that is extracted from the seed file.

11. The system of claim 8 , wherein the client computer processor device executes instructions that perform further actions, comprising:

generating security header information that includes the network packet key;

including an application network packet in a security network packet that includes the security header information; and

communicating the security network packet to the network computer.

12. The system of claim 8 , further comprising, registering the client computer with the network computer based on an exchange of credentials that includes at least a client identifier.

13. The system of claim 8 , wherein generating the network packet key further comprises employing a sensor to introduce entropy.

14. A processor readable non-transitory storage media that includes instructions for managing communication over a network, wherein execution of the instructions by a hardware processor performs actions, comprising:

generating instruction set information that references at least a seed file that is installed on the network computer;

communicating a copy of the instruction set information to a client computer;

generating a network packet key based on the instruction set information;

generating a packet rule that includes the network packet key, wherein the packet rule is installed in a packet inspection engine that is included in a hardware network interface; and

when one or more network packets are communicated to the network computer, the packet inspection engine performing further actions, including:

comparing the network packet key to the one or more network packets using the packet rule; and

accepting each of the one or more network packets that include the network packet key and discarding each of the one or more network packets that omit the network packet key, wherein the accepted one or more network packets are provided to an operating system of the network computer.

15. The media of claim 14 , further comprising:

employing the client computer to generate a client network packet key based on the provided instruction set information and at least another seed file that is installed on the client computer, wherein the client network packet key and the network packet key have the same value; and

including the client network packet key in the one or more network packets before they are provided to the network computer.

16. The media of claim 14 , further comprising, when the one or more network packets is encrypted by the client computer, decrypting the one or more encrypted network packets before comparing the network packet key to the one or more network packets using the packet rule.

17. The media of claim 14 , wherein generating the network packet key, further comprises:

determining the seed file from a plurality of seed files based on an identifier that is included in the instruction set information;

extracting a pass phrase from the seed file based on an offset value and a pass phrase length value that are included in the instruction set information; and

generating the network packet key based on the pass phrase that is extracted from the seed file.

18. The media of claim 14 , further comprising:

employing the client computer to generate security header information that includes the network packet key;

employing the client computer to include an application network packet in a security network packet that includes the security header information; and

employing the client computer to communicate the security network packet to the network computer.

19. The media of claim 14 , further comprising, registering the client computer with the network computer based on an exchange of credentials that includes at least a client identifier.

20. The media of claim 14 , wherein generating the network packet key further comprises employing a sensor to introduce entropy.

21. A network computer for managing communication over a network, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

a processor device that executes instructions that perform actions, including:

generating instruction set information that references at least a seed file that is installed on the network computer;

communicating a copy of the instruction set information to a client computer;

generating a network packet key based on the instruction set information;

generating a packet rule that includes the network packet key, wherein the packet rule is installed in a packet inspection engine that is included in a hardware network interface; and

when one or more network packets are communicated to the network computer, the packet inspection engine performing further actions, including:

comparing the network packet key to the one or more network packets using the packet rule; and

accepting each of the one or more network packets that include the network packet key and discarding each of the one or more network packets that omit the network packet key, wherein the accepted one or more network packets are provided to an operating system of the network computer.

22. The network computer of claim 21 , further comprising:

employing the client computer to generate a client network packet key based on the provided instruction set information and at least another seed file that is installed on the client computer, wherein the client network packet key and the network packet key have the same value; and

including the client network packet key in the one or more network packets before they are provided to the network computer.

23. The network computer of claim 21 , further comprising, when the one or more network packets is encrypted by the client computer, decrypting the one or more encrypted network packets before comparing the network packet key to the one or more network packets using the packet rule.

24. The network computer of claim 21 , wherein generating the network packet key, further comprises:

determining the seed file from a plurality of seed files based on an identifier that is included in the instruction set information;

extracting a pass phrase from the seed file based on an offset value and a pass phrase length value that are included in the instruction set information; and

generating the network packet key based on the pass phrase that is extracted from the seed file.

25. The network computer of claim 21 , further comprising:

employing the client computer to generate security header information that includes the network packet key;

employing the client computer to include an application network packet in a security network packet that includes the security header information; and

employing the client computer to communicate the security network packet to the network computer.

26. The network computer of claim 21 , further comprising, registering the client computer with the network computer based on an exchange of credentials that includes at least a client identifier.

27. The network computer of claim 21 , wherein generating the network packet key further comprises employing a sensor to introduce entropy.

Assignments (2)
SECURITY INTEREST Recorded Feb 20, 2020
From: CENTRI TECHNOLOGY, INC.
To: PERKINS COIE LLP
Reel/Frame 051870/0861 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2015
From: MACKEY, MICHAEL PATRICK; PARIS, LUIS GERARDO; TAYLOR, CHARLES HUBBARD
To: CENTRI TECHNOLOGY, INC.
Reel/Frame 036232/0326 →
Continuity (1)
Provisional Application 62102942 · Jan 13, 2015