IP Library Granted Patent US 10,880,269
Granted Patent B2
US 10,880,269 · App. 15/136,762 · Granted Dec 29, 2020

Secure labeling of network flows

Inventors: Daniel Salvatore Schiappa (Bedford, NH); Andrew J. Thomas (Oxfordshire, GB); Kenneth D. Ray (Seattle, WA); Joseph H. Levy (Eagle Mountain, UT)
Assignee: Sophos Limited
H04L63/0227H04L9/3247H04L63/02H04L63/0236H04L63/0428H04L63/126H04L63/14H04L63/1408H04L63/1441H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,880,269
App. No.
15/136,762
Granted
Dec 29, 2020
Kind
B2
Abstract

An enterprise security system is improved by instrumenting endpoints to explicitly label network flows with cryptographically secure labels that identify an application or other source of each network flow. Cryptographic techniques may be used, for example, to protect the encoded information in the label from interception by third parties or to support cryptographic authentication of a source of each label. A label may provide health, status, or other heartbeat information for the endpoint, and may be used to identify compromised endpoints, to make routing decisions for network traffic (e.g., allowing, blocking, rerouting, etc.), to more generally evaluate the health of an endpoint that is sourcing network traffic, or for any other useful purpose.

Claims (40)

1. A computer program product for managing network flows at an endpoint in a network, computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, performs the steps of:

providing a private key to the endpoint

receiving a network message from a process executing on the endpoint, wherein the process is based on an application and wherein the network message includes a payload and a header, the network message addressed to a remote location accessible from the endpoint through the network;

generating, at the endpoint, a label for the network message, the label including information about a source of the network message on the endpoint, the information about the source including an identifier for the application;

using the private key provided to the endpoint, cryptographically signing the label at the endpoint to provide a signed label verifying an identity of the application that generated the network message;

adding the signed label to the header of the network message;

transmitting the network message from the endpoint to the remote location through a gateway for the network;

at the gateway, cryptographically verifying an authenticity of the signed label using a corresponding public key;

determining a reputation of the application identified in the signed label; and

applying a routing rule at the gateway to conditionally route the network message to a destination address of the remote location based on the reputation of the application that generated the network message.

2. The computer program product of claim 1 wherein the label includes an identifier for the endpoint.

3. The computer program product of claim 1 wherein the label includes an identifier of a user of the process on the endpoint.

4. The computer program product of claim 1 further comprising code that performs the step of encrypting information within the label.

5. The computer program product of claim 1 wherein the label includes a health status of the endpoint.

6. A method for managing network flows at an endpoint in a network, the method comprising:

storing a private key on the endpoint;

receiving a network message from a process executing on the endpoint, wherein the process is based on an application and wherein the network message includes a payload and a header, the network message addressed to a remote location accessible from the endpoint through the network;

generating, at the endpoint, a label for the network message, the label including information about a source of the network message on the endpoint, the information about the source including an identifier for the application;

using the private key stored on the endpoint, cryptographically signing the label at the endpoint to provide a signed label verifying an identity of the application that generated the network message;

adding the signed label to the header of the network message;

transmitting the network message from the endpoint to the remote location through a gateway for the network;

at the gateway, cryptographically verifying an authenticity of the signed label using a corresponding public key;

determining a reputation of the application identified in the signed label; and

applying a routing rule at the gateway to conditionally route the network message to a destination address of the remote location based on the reputation of the application that generated the network message.

7. The method of claim 6 wherein the label includes an identifier for the endpoint.

8. The method of claim 6 wherein the label includes an identifier of a user of the process on the endpoint.

9. The method of claim 6 wherein the label includes a health status of the endpoint.

10. A system comprising:

an endpoint including a network interface configured to couple the endpoint in a communicating relationship with a data network;

a memory on the endpoint; and

a processor on the endpoint, the processor configured to execute instructions stored in the memory to perform the steps of receiving a network message from a process executing on the endpoint, wherein the process is based on an application and wherein the network message includes a payload and a header, the network message addressed to a remote location accessible from the endpoint through a network, generating, at the endpoint, a label for the network message, the label including information about a source of the network message on the endpoint, the information about the source including an identifier for the application, receiving a private key for digitally signing the label for the network message, cryptographically signing the label at the endpoint using the private key to provide a signed label verifying an identity of the application that generated the network message, adding the signed label to the header of the network message, transmitting the network message from the endpoint to the remote location through a gateway for the data network, at the gateway, cryptographically verifying an authenticity of the signed label using a corresponding public key, determining a reputation of the application identified in the signed label, and applying a routing rule at the gateway to conditionally route the network message to a destination address of the remote location based on the reputation of the application that generated the network message.

11. A method for managing network flows at a network device, the method comprising:

receiving, at the network device, a network message from an endpoint, the network message including a source address for the endpoint, a destination address for an intended recipient of the network message, a label cryptographically signed using a private key associated with the endpoint to provide a signed label verifying an identity an application, on the endpoint, that generated the network message and identifying a user of a process based on the application on the endpoint, and a payload of data;

processing the network message on the network device to extract the signed label;

cryptographically verifying an authenticity of the signed label using a corresponding public key;

determining a reputation of the application identified in the signed label; and

applying a routing rule at the network device to conditionally route the network message to the destination address based on the reputation of the application that generated the network message.

12. The method of claim 11 further comprising receiving an indication that the application is compromised and preventing routing of additional network traffic for the application through the network device.

13. The method of claim 11 further comprising detecting an absence of an expected heartbeat from the endpoint for the application and preventing routing of additional network traffic for the application through the network device until the expected heartbeat is received.

14. The method of claim 11 wherein the network device includes at least one of a gateway, a firewall, a router, and a threat management facility.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2016
From: SCHIAPPA, DANIEL SALVATORE; THOMAS, ANDREW J.; RAY, KENNETH D.; LEVY, JOSEPH H.
To: SOPHOS LIMITED
Reel/Frame 038636/0001 →
Continuity (1)
Related Publication 20170310708A1 · Oct 26, 2017