IP Library Granted Patent US 10,154,049
Granted Patent B2
US 10,154,049 · App. 15/151,001 · Granted Dec 11, 2018

System and method for providing an in-line sniffer mode network based identity centric firewall

Inventors: Ajit Sancheti (San Francisco, CA); Roman Blachman (Givatayim, IL); Amir Jakoby (Nathania, IL); Eyal Karni (Kochav Yair, IL)
Assignee: Preempt Security, Inc.
H04L63/1416H04L63/0245H04L63/0272H04L63/20H04L67/20H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,154,049
App. No.
15/151,001
Granted
Dec 11, 2018
Kind
B2
Abstract

The instant disclosure is directed to an attack/unwanted activity detecting firewall for use in protecting authentication-based network resources. The instant system is adapted for installation inline or in sniffer mode. In various embodiments, defined rules are applied to network traffic to determine whether certain types of attacks are occurring on the network resources. If one such attack is detected, the system provides for several potential responses, including for example disconnecting the attacking remote machine, requiring the user at that machine to re-authenticate, and/or requiring a second factor of authentication from the user at that machine. In some example embodiments, regardless of any activity required of a user at the remote machine suspected of malicious behavior, the disclosed system generates an alarm or other alert for presentation as appropriate, such as via a graphical user interface or a third-party system using an API.

Claims (46)

1. An attack detection and response system comprising:

at least one processor;

at least one network interface device; and

at least one memory device which stores a plurality of instructions to cause the at least one processor to operate with the at least one network interface device to:

(a) receive all network traffic passing between an external network and a protected computer resource;

(b) analyze a first portion of the received network traffic from the external network to determine whether the first portion is indicative of an attack on the protected computer resource, wherein the network traffic includes authentication traffic, and the first portion is a request for at least one of access and service,

wherein the at least one memory device stores a second plurality of instructions indicative of a security policy, the second plurality of instructions are updated based on at least one of external network details, past analyzed external network weaknesses, and past analyzed external network patterns of activity, and

wherein the determination of whether the first portion is indicative of an attack is based on the security policy; and

(c) responsive to determining that the analyzed first portion is indicative of an attack on the protected computer resource, perform at least one action selected from the group consisting of: prevent a second portion of the received network traffic from reaching the protected computer resource; issue an alert; modify the second portion of the received traffic; and reconfigure network equipment or privileges.

2. The system of claim 1 , wherein the plurality of instructions cause the at least one processor to operate with the at least one network interface device to prevent the second portion of the received network traffic from reaching the protected computer resource by terminating at least one connection to the protected computer resource.

3. The system of claim 1 , wherein the plurality of instructions causing the at least one processor to operate with the at least one network interface device to analyze the first portion of the received network traffic includes determining whether the first portion of the received network traffic originates from an unrecognized source.

4. The system of claim 3 , wherein responsive to determining that the first portion of the received network traffic originates from the unrecognized source, the plurality of instructions cause the at least one processor to operate with the at least one network interface device to communicate a notification of a need for multi-factor authentication.

5. The system of claim 1 , wherein the at least one processor operates with the at least one network interface device to enforce the security policy.

6. The system of claim 1 , wherein the plurality of instructions further cause the at least one processor to operate with the at least one network interface device to receive the security policy from a third party resource.

7. An attack detection and response method comprising:

(a) receiving, by at least one processor operating with at least one network device, all network traffic passing between an external network and a protected computer resource;

(b) analyzing, by the at least one processor operating with the at least one network device, a first portion of the received network traffic from the external network to determine whether the first portion is indicative of an attack on the protected computer resource, wherein the network traffic includes authentication traffic, and the first portion is a request for at least one of access and service,

wherein at least one memory device stores a plurality of instructions indicative of a security policy, the plurality of instructions are updated based on at least one of external network details, past analyzed external network weaknesses, and past analyzed external network patterns of activity, and

wherein the determination of whether the first portion is indicative of an attack is based on the security policy; and

(c) responsive to determining that the analyzed first portion is indicative of an attack on the protected computer resource, performing at least one action selected from the following: preventing, by the at least one processor operating with the at least one network device, a second portion of the received network traffic from reaching the protected computer resource; issuing an alert, modifying the second portion of the received traffic; and reconfiguring network equipment or privileges.

8. The method of claim 7 , wherein preventing the second portion of the received network traffic from reaching the protected computer resource includes terminating at least one connection to the protected computer resource.

9. The method of claim 7 , wherein analyzing the first portion of the received network traffic includes determining whether the first portion of the received network traffic originates from an unrecognized source.

10. The method of claim 9 , wherein responsive to determining that the first portion of the received network traffic originates from the unrecognized source, communicating, by the at least one processor operating with the at least one network interface device, a notification of a need for multi-factor authentication.

11. The method of claim 7 , further comprising enforcing, by the at least one processor operating with the at least one network interface device, the security policy.

12. The method of claim 11 , further comprising receiving, by the at least one processor operating with the at least one network interface device, the security policy from a third party resource.

13. A computer-readable non-transitory storage medium storing executable instructions for attack detection and response, which when executed by a computer system, cause the computer system to:

(a) receive, by at least one processor operating with at least one network device, all network traffic passing between an external network and a protected computer resource;

(b) analyze, by the at least one processor operating with the at least one network device, a first portion of the received network traffic from the external network to determine whether the first portion is indicative of an attack on the protected computer resource, wherein the network traffic includes authentication traffic, and the first portion is a request for at least one of access and service,

wherein at least one memory device stores a plurality of instructions indicative of a security policy, the plurality of instructions are updated based on at least one of external network details, past analyzed external network weaknesses, and past analyzed external network patterns of activity, and

wherein the determination of whether the first portion is indicative of an attack is based on the security policy; and

(c) responsive to determining that the analyzed first portion is indicative of an attack on the protected computer resource, perform at least one of the following actions: prevent, by the at least one processor operating with the at least one network device, a second portion of the received network traffic from reaching the protected computer resource; issue an alert; modify the second portion of the received traffic; and reconfigure network equipment or privileges.

14. The computer-readable non-transitory storage medium of claim 13 , wherein preventing the second portion of the received network traffic from reaching the protected computer resource includes terminating at least one connection to the protected computer resource.

15. The computer-readable non-transitory storage medium of claim 13 , wherein analyzing the first portion of the received network traffic includes determining whether the first portion of the received network traffic originates from an unrecognized source.

16. The computer-readable non-transitory storage medium of claim 15 , wherein responsive to determining that the first portion of the received network traffic originates from the unrecognized source, the plurality of instructions, when executed by the computer system, further cause the computer system to communicate, by the at least one processor operating with the at least one network interface device, a notification of a need for multi-factor authentication.

17. The computer-readable non-transitory storage medium of claim 13 , wherein the plurality of instructions, when executed by the computer system, further cause the computer system to enforce, by the at least one processor operating with the at least one network interface device, the security policy.

18. The system of claim 1 , wherein the second portion of the received network traffic contains an indication of approval.

19. An attack detection and response system comprising:

at least one processor;

at least one network interface device; and

at least one memory device which stores a plurality of instructions to cause the at least one processor to operate with the at least one network interface device to:

(a) receive all network traffic passing between an external network and a protected computer resource;

(b) analyze a first portion of the received network traffic from the external network to determine whether the first portion is indicative of an attack on the protected computer resource, wherein the first portion is a request for at least one of access and service;

(c) responsive to determining that the analyzed first portion is indicative of an attack on the protected computer resource, request the external network to verify an identity by at least one of two-factor authentication, multi-factor authentication, re-authentication, and notification to an administrator; and

(d) responsive to a verification failure, perform at least one action selected from the group consisting of: prevent a second portion of the received network traffic from reaching the protected computer resource; issue an alert; modify the second portion of the received traffic; and reconfigure network equipment or privileges.

20. The system of claim 19 , wherein the plurality of instructions further cause the at least one processor to operate with the at least one network interface device to update a security policy based on at least one of external network details, past analyzed external network weaknesses, and past analyzed external network patterns of activity.

21. The system of claim 19 , wherein the second portion of the received network traffic contains an indication of approval.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Jan 6, 2026
From: FIRST-CITIZENS BANK & TRUST COMPANY
To: CROWDSTRIKE HOLDINGS, INC.; CROWDSTRIKE, INC.
Reel/Frame 074202/0710 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2021
From: PREEMPT SECURITY, INC.
To: PREEMPT SECURITY, LLC
Reel/Frame 055844/0738 →
MERGER Recorded Mar 12, 2021
From: PREEMPT SECURITY, LLC
To: CROWDSTRIKE, INC.
Reel/Frame 055574/0822 →
PATENT SECURITY AGREEMENT Recorded Jan 5, 2021
From: CROWDSTRIKE HOLDINGS, INC.; CROWDSTRIKE, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 054899/0848 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2018
From: SANCHETI, AJIT; BLACHMAN, ROMAN; JAKOBY, AMIR; KARNI, EYAL
To: PREEMPT SECURITY, INC.
Reel/Frame 047453/0464 →
Continuity (2)
Provisional Application 62160748 · May 13, 2015
Related Publication 20170244730A1 · Aug 24, 2017