IP Library › Granted Patent US 10,129,239
Granted Patent B2
US 10,129,239 · App. 15/148,425 · Granted Nov 13, 2018

Systems and methods for performing targeted scanning of a target range of IP addresses to verify security certificates

Inventors: Kenneth Bell (Sunnyvale, CA); Anoop Reddy (San Jose, CA)
Assignee: Citrix Systems, Inc.
H04L63/0823H04L63/1433H04L43/0876H04L61/1511H04L61/2007H04L61/35
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,129,239
App. No.
15/148,425
Granted
Nov 13, 2018
Kind
B2
Abstract

The present disclosure is directed towards systems and methods for scanning of a target range of IP addresses to verify security certificates associated with the target range of IP addresses. Network traffic may be monitored between a plurality of clients and a plurality of servers over an IP address space. Traffic monitors positioned intermediary to the plurality of client and the plurality of servers can identify a target range of IP addresses in the address space for targeted scanning. The target range of IP address may be grouped into a priority queue and a scan can be performed of the target range of IP addresses to verify a security certificate associated with each IP address in the target range of IP addresses. In some embodiments, a rogue security certificate is detected that is associated with at least one IP address in the target range of IP addresses.

Claims (48)

1. A method of scanning Internet Protocol (IP) addresses, comprising:

identifying, by a device intermediary to a plurality of clients and a plurality of servers, a plurality of Internet Protocol (IP) addresses in an IP address space for targeted scanning to identify at least one IP address providing a rogue security certificate, each IP address of the plurality of IP addresses identified based on network activity corresponding to the IP address;

determining, by the device, for each IP address of the plurality of IP addresses, a priority level to assign to the IP address based on the network activity corresponding to the IP address;

assigning, by the device, the determined priority level to each IP address of the plurality of IP addresses; and

providing, by the device, the plurality of IP addresses and the corresponding assigned priority levels to a scanning agent to scan the plurality of IP addresses based on the corresponding assigned priority levels to identify the at least one IP address of the plurality of IP addresses that provides the rogue security certificate, the scanning agent performing a scan of the one or more IP addresses of the plurality of IP addresses to identify rogue security certificates by transmitting, to the one or more IP addresses of the plurality of IP addresses, a request to receive information relating to a security certificate of the respective one or more IP addresses.

2. The method of claim 1 , comprising determining, by the device, the priority level to assign the IP address based on at least one of a device type assigned to the respective IP address, a type of the activity corresponding to the respective IP address, and a frequency of the activity corresponding to the respective IP address.

3. The method of claim 1 , comprising generating, by the device, a priority queue including the plurality of IP addresses arranged by the determined priority levels of the plurality of IP addresses.

4. The method of claim 1 , comprising assigning, by the device, the plurality of IP addresses to the scanning agent.

5. The method of claim 1 , wherein the plurality of IP addresses and the assigned priority levels are used by the scanning agent to perform a throttling mechanism to select a frequency of the scanning of the plurality of IP addresses.

6. The method of claim 1 , wherein the plurality of IP addresses and the assigned priority levels are used by the scanning agent to:

transmit a request for a security certificate to a client of the plurality of clients or a server of the plurality of servers corresponding to the one IP address of the plurality of IP addresses;

subsequently receive the security certificate from the client or the server corresponding to the IP address; and

determine whether the IP address is associated with the rogue security certificate by comparing the received security certificate with a signed security certificate from a trusted certificate authority.

7. The method of claim 1 , comprising providing, by the device, a time period to the scanning agent, the time period corresponding to an amount of time the scanning agent can repeat scanning a particular IP address of the plurality of IP addresses.

8. The method of claim 1 , comprising:

generating, by the device, a scanning policy identifying a schedule according to which the scanning agent is to scan the plurality of IP addresses, the schedule specifying a time or a frequency of the scanning of each of the plurality of IP addresses; and

providing, by the device, the scanning policy to the scanning agent.

9. The method of claim 1 , comprising:

receiving, by the device, from a first traffic monitor, a first set of IP addresses;

receiving, by the device, from a second traffic monitor, a second set of IP addresses;

removing, by the device, from the second set of IP addresses, common IP addresses included in the first set of IP addresses; and

merging, by the device, the first set of IP addresses and IP addresses remaining in the second set of IP addresses.

10. The method of claim 1 , comprising:

monitoring, by a traffic monitor of the device, the network activity between the plurality of clients and the plurality over the IP address space.

11. A system for scanning Internet Protocol (IP) addresses, comprising:

a device intermediary to a plurality of clients and a plurality of servers, the device comprising:

an Internet Protocol (IP) address monitor executing on the device and configured to identify a plurality of IP addresses in an IP address space for targeted scanning to identify at least one IP address providing a rogue security certificate-, each IP address of the plurality of IP addresses identified based on network activity corresponding to the IP address; and

a priority level assigner executing on the device and configured to:

determine, for each IP address of the plurality of IP addresses, a priority level to assign to the IP address based on the network activity corresponding to the IP address;

assign the determined priority level to each IP address of the plurality of IP addresses; and

provide the plurality of IP addresses and the corresponding assigned priority levels to a scanning agent to scan the plurality of IP addresses based on the corresponding assigned priority levels to identify the at least one IP address of the plurality of IP addresses that provides the rogue security certificate, the scanning agent performing a scan of the one or more IP addresses of the plurality of IP addresses to identify rogue security certificates by transmitting, to the one or more IP addresses of the plurality of IP addresses, a request to receive information relating to a security certificate of the respective one or more IP addresses.

12. The system of claim 11 , wherein the priority level assigner is further configured to determine the priority level to assign the IP address based on at least one of a device type assigned to the respective IP address, a type of the activity corresponding to the respective IP address, and a frequency of the activity corresponding to the respective IP address.

13. The system of claim 11 , wherein the priority level assigner is further configured to generate a priority queue including the plurality of IP addresses arranged by the determined priority levels of the plurality of IP addresses.

14. The system of claim 11 , wherein the priority level assigner is further configured to assign the plurality of IP addresses to the scanning agent.

15. The system of claim 11 , wherein the plurality of IP addresses and the assigned priority levels are used by the scanning agent to perform a throttling mechanism to select a frequency of the scanning of the plurality of IP addresses.

16. The system of claim 11 , wherein the plurality of IP addresses and the assigned priority levels are used by the scanning agent to:

transmit a request for a security certificate to a client of the plurality of clients or a server of the plurality of servers corresponding to the one IP address of the plurality of IP addresses;

subsequently receive the security certificate from the client or the server corresponding to the IP address; and

determine whether the IP address is associated with the rogue security certificate by comparing the received security certificate with a signed security certificate from a trusted certificate authority.

17. The system of claim 11 , wherein the priority level assigner is further configured to provide a time period to the scanning agent, the time period corresponding to an amount of time the scanning agent can repeat scanning a particular IP address of the plurality of IP addresses.

18. The system of claim 11 , wherein the priority level assigner is further configured to

generate a scanning policy identifying a schedule according to which the scanning agent is to scan the plurality of IP addresses, the schedule specifying a time or a frequency of the scanning of each of the plurality of IP addresses; and

provide the scanning policy to the scanning agent.

19. The system of claim 11 , wherein the IP address monitor is further configured to receive, from a first traffic monitor, a first set of IP addresses and to receive, from a second traffic monitor, a second set of IP addresses; and

wherein the priority level assigner is further configured to:

remove, from the second set of IP addresses, common IP addresses included in the first set of IP addresses; and

merge the first set of IP addresses and IP addresses remaining in the second set of IP addresses.

20. The system of claim 11 , wherein the device comprises a traffic monitor configured to monitor the network activity between the plurality of clients and the plurality over the IP address space.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2016
From: BELL, KENNETH; REDDY, ANOOP
To: CITRIX SYSTEMS, INC.
Reel/Frame 038917/0114 →
Continuity (2)
Provisional Application 62158897 · May 8, 2015
Related Publication 20160330245A1 · Nov 10, 2016
Cited By (1)
US 12,483,548