IP Library Granted Patent US 10,594,664
Granted Patent B2
US 10,594,664 · App. 15/457,306 · Granted Mar 17, 2020

Extracting data from encrypted packet flows

Inventors: Arthur L. Zaifman (Millburn, NJ); John M. Mocenigo (Califon, NJ)
Assignee: AT&T Intellectual Property I, L.P.
H04L63/0428H04L63/0823H04L63/30H04L63/1408H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,594,664
App. No.
15/457,306
Granted
Mar 17, 2020
Kind
B2
Abstract

In one example, the present disclosure describes a device, computer-readable medium, and method for extracting data from encrypted packet flows. For instance, in one example, a method includes detecting a data packet that belongs to an encrypted data flow traversing a network, determining whether the encrypted data flow is a new encrypted data flow or an existing encrypted data flow, based on an inspection of payloads of data packets belonging to the encrypted data flow for evidence of a transport control protocol handshake, forwarding the data packet to a first server pool that will truncate the data packet, when the encrypted data flow is an existing encrypted data flow, and forwarding the data packet to a second server pool that will inspect a payload of the data packet for a secure sockets layer certificate, when the encrypted data flow is a new encrypted data flow.

Claims (38)

1. A method, comprising:

detecting, by a processor, a data packet that belongs to an encrypted data flow traversing a network;

determining, by the processor, whether the encrypted data flow is a new encrypted data flow or an existing encrypted data flow, based on an inspection of payloads of data packets belonging to the encrypted data flow for evidence of a transport control protocol handshake;

forwarding, by the processor, the data packet to a first server pool that will truncate the data packet, only when the encrypted data flow is the existing encrypted data flow; and

forwarding, by the processor, the data packet to a second server pool that will inspect a payload of the data packet for a secure sockets layer certificate, only when the encrypted data flow is the new encrypted data flow.

2. The method of claim 1 , wherein the detecting comprises:

scanning a header of the data packet for a value that indicates that the data packet belongs to the encrypted data flow.

3. The method of claim 2 , wherein the value comprises a port number in a port number field of the header, and the port number indicates a port used for communications using secure sockets layer protocol.

4. The method of claim 3 , wherein the port number is 443.

5. The method of claim 1 , wherein the data packet is a replica of an original data packet.

6. A device, comprising:

a processor; and

a non-transitory computer-readable medium storing instructions which, when executed by the processor, cause the processor to perform operations, the operations comprising:

detecting a data packet that belongs to an encrypted data flow traversing a network;

determining whether the encrypted data flow is a new encrypted data flow or an existing encrypted data flow, based on an inspection of payloads of data packets belonging to the encrypted data flow for evidence of a transport control protocol handshake;

forwarding the data packet to a first server pool that will truncate the data packet, only when the encrypted data flow is the existing encrypted data flow; and

forwarding the data packet to a second server pool that will inspect a payload of the data packet for a secure sockets layer certificate, only when the encrypted data flow is the new encrypted data flow.

7. The device of claim 6 , wherein the detecting comprises:

scanning a header of the data packet for a value that indicates that the data packet belongs to the encrypted data flow.

8. The device of claim 7 , wherein the value comprises a port number in a port number field of the header, and the port number indicates a port used for communications using secure sockets layer protocol.

9. The device of claim 8 , wherein the port number is 443.

10. The device of claim 6 , wherein the data packet is a replica of an original data packet.

11. The device of claim 6 , wherein the operations further comprise:

receiving the data packet from a traffic analysis point.

12. The device of claim 11 , wherein the traffic analysis point is an optical traffic analysis point that mirrors the data packet from an original data packet of the encrypted data flow traversing the network.

13. The device of claim 6 , wherein the first server pool will truncate the data packet by discarding the payload from the data packet.

14. The device of claim 6 , wherein the processor comprises a multiplexer.

15. The device of claim 6 , wherein the second server pool will inspect the payload of the data packet for the secure sockets layer certificate until a threshold number of packets are inspected for the new encrypted data flow.

16. A non-transitory computer-readable medium storing instructions which, when executed by a processor, cause the processor to perform operations, the operations comprising:

detecting a data packet that belongs to an encrypted data flow traversing a network;

determining whether the encrypted data flow is a new encrypted data flow or an existing encrypted data flow, based on an inspection of payloads of data packets belonging to the encrypted data flow for evidence of a transport control protocol handshake;

forwarding the data packet to a first server pool that will truncate the data packet, only when the encrypted data flow is the existing encrypted data flow; and

forwarding the data packet to a second server pool that will inspect a payload of the data packet for a secure sockets layer certificate, only when the encrypted data flow is the new encrypted data flow.

17. The non-transitory computer-readable medium of claim 16 , wherein the detecting comprises:

scanning a header of the data packet for a value that indicates that the data packet belongs to the encrypted data flow.

18. The non-transitory computer-readable medium of claim 17 , wherein the value comprises a port number in a port number field of the header, and the port number indicates a port used for communications using secure sockets layer protocol.

19. The non-transitory computer-readable medium of claim 18 , wherein the port number is 443.

20. The non-transitory computer-readable medium of claim 16 , wherein the data packet is a replica of an original data packet.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2017
From: ZAIFMAN, ARTHUR L.; MOCENIGO, JOHN M.
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 041559/0619 →
Continuity (1)
Related Publication 20180262487A1 · Sep 13, 2018
Cited By (7)
US 12,225,030 US 12,309,192 US 12,355,816 US 12,483,384 US 12,587,535 US 12,647,441 US 12,652,312