IP Library Granted Patent US 9,912,689
Granted Patent B2
US 9,912,689 · App. 14/838,279 · Granted Mar 6, 2018

Anonymized network data collection and network threat assessment and monitoring systems and methods

Inventors: William Peteroy (Redmond, WA); Josh Carlson (Carnation, WA)
H04L63/1441H04L63/0421H04L63/0471H04L69/08H04L69/22H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,912,689
App. No.
14/838,279
Granted
Mar 6, 2018
Kind
B2
Abstract

Systems and methods for data collection and processing in a network, including one or more sensors disposed in a network interface and configured to collect raw signal traffic data where each sensor is further configured to parse the raw signal traffic data into network protocols; split the network protocols into content data and metadata; derive contextual metadata from the content data; compile the metadata and the derived metadata to produce anonymized metadata; encrypt the anonymized metadata; and transmit to the encrypted anonymized metadata to a unified data server.

Claims (29)

1. A computer implemented method comprising:

obtaining a plurality of network communications from a network, including a first network communication;

identifying a communication protocol related to said first network communication;

identifying a network metadata portion of said first network communication, based at least partially on said communication protocol;

identifying a data portion of said first network communication based at least partially on said communication protocol;

generating anonymized contextual metadata based on said data portion;

combining said network metadata and said anonymized contextual metadata into a first anonymized network communication generating a plurality of encrypted anonymized network communications, including an encrypted version of said first anonymized network communications; and

providing said plurality of encrypted anonymized network communications to a remote server.

2. The method of claim 1 , wherein said contextual metadata is derived from characteristics of said first network communication including authorization traffic, HTTP flow, encryption, VPN activity, encryption certificates, passive fingerprints and application traffic.

3. A non-transitory computer-readable medium have contents which configure a computing system to perform a method, the method comprising:

obtaining a plurality of network communications from a network, including a first network communication;

identifying a communication protocol related to said first network communication;

identifying a network metadata portion of said first network communication, based at least partially on said communication protocol;

identifying a data portion of said first network communication based at least partially on said communication protocol;

generating anonymized contextual metadata based on said data portion;

combining said network metadata and said anonymized contextual metadata into a first anonymized network communication generating a plurality of encrypted anonymized network communications, including an encrypted version of said first anonymized network communications; and

providing said plurality of encrypted anonymized network communications to a remote server.

4. The non-transitory computer-readable medium of claim 3 wherein said contextual metadata is derived from characteristics of said first network communication including authorization traffic, HTTP flow, encryption, VPN activity, encryption certificates, passive fingerprints and application traffic.

5. A system, comprising:

one or more memories; and

processing circuitry coupled to the one or more memories, wherein the processing circuitry, in operation, controls a process, the process comprising:

obtaining a plurality of network communications from a network, including a first network communication;

identifying a communication protocol related to said first network communication;

identifying a network metadata portion of said first network communication, based at least partially on said communication protocol;

identifying a data portion of said first network communication based at least partially on said communication protocol;

generating anonymized contextual metadata based on said data portion;

combining said network metadata and said anonymized contextual metadata into a first anonymized network communication generating a plurality of encrypted anonymized network communications, including an encrypted version of said first anonymized network communications; and

providing said plurality of encrypted anonymized network communications to a remote server.

6. The system of claim 5 wherein said contextual metadata is derived from characteristics of said first network communication including authorization traffic, HTTP flow, encryption, VPN activity, encryption certificates, passive fingerprints and application traffic.

Assignments (9)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2023
From: ICEBRG LLC
To: FORTINET, INC.
Reel/Frame 062364/0854 →
RELEASE OF SECURITY INTEREST Recorded Dec 23, 2022
From: JEFFERIES FINANCE LLC
To: ICEBRG LLC
Reel/Frame 062194/0522 →
ENTITY CONVERSION Recorded Dec 2, 2022
From: ICEBRG INC.
To: ICEBRG LLC
Reel/Frame 062048/0167 →
SECURITY INTEREST Recorded Mar 11, 2022
From: GIGAMON INC.; ICEBRG LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 059362/0717 →
RELEASE OF SECURITY INTEREST Recorded Mar 11, 2022
From: JEFFERIES FINANCE LLC
To: ICEBRG INC.
Reel/Frame 059245/0607 →
SECOND LIEN PATENT SECURITY AGREEMENT RELEASE RECORDED AT REEL 047102/FRAME 0452 Recorded Feb 18, 2020
From: JEFFERIES FINANCE LLC
To: ICEBRG INC.
Reel/Frame 051965/0619 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2019
From: PETEROY, WILLIAM; CARLSON, JOSH
To: ICEBRG INC.
Reel/Frame 049612/0913 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 18, 2018
From: ICEBRG INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 047102/0369 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 18, 2018
From: ICEBRG INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 047102/0452 →
Continuity (2)
Provisional Application 62042726 · Aug 27, 2014
Related Publication 20160065610A1 · Mar 3, 2016