IP Library Granted Patent US 10,326,741
Granted Patent B2
US 10,326,741 · App. 15/457,886 · Granted Jun 18, 2019

Secure communication secret sharing

Inventors: Jesse Abraham Rothstein (Seattle, WA); Benjamin Thomas Higgins (Shoreline, WA); Brian David Hatch (Seattle, WA)
Assignee: ExtraHop Networks, Inc.
H04L63/0428H04L43/0876H04L63/061H04L67/42H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,326,741
App. No.
15/457,886
Filed
Mar 13, 2017
Granted
Jun 18, 2019
Kind
B2
Art Unit
2434
USPC
713/171
Abstract

Embodiments are directed to sharing secure communication secrets with a network monitoring device (NMD). The NMD may passively monitor network packets communicated between client computers and server computers. If a secure communication session is established between a client computer and a server computer, a key provider may provide the NMD a session key that corresponds to the secure communication session. The NMD may buffer each network packet associated with the secure communication session until the NMD is provided a session key for the secure communication session. The NMD may use the session key to decrypt network packets communicated between the client computer and the server computer. The NMD may then proceed to analyze the secure communication session based on the contents of the decrypted network packets.

Claims (42)

1. A method for monitoring communication over a network with a network monitoring device (NMD) that performs actions, comprising:

passively monitoring a secure communication session based on correlation information for one or more network packets;

providing a session key and other correlation information that corresponds to the secure communication session;

identifying a network connection flow that corresponds to the secure communication session based on a comparison of the secure communication session's other correlation information with other correlation information provided by one or more key providers, wherein contents of one or more encrypted packets in the secure communication session are decrypted; and

providing a display to a user of the decrypted contents of the one or more decrypted packets in the secure communication session.

2. The method of claim 1 , further comprising employing the one or more key providers to provide the session key, wherein the one or more key providers include one or more of a client application, a server application, a session key broker, a hardware security module, a firewall, a proxy, a cache, or application delivery controller.

3. The method of claim 1 , further comprising an application that is instantiated to perform the actions of the method, wherein the application is arranged as one or more of an application, a plugin for another application, or the application is integrated with one or more other applications.

4. The method of claim 1 , further comprising providing two or more different sets of the secure communication's other correlation information, wherein each of these sets include different types of other correlation information that are compatible with two or more different key providers.

5. The method of claim 1 , further comprising buffering the one or more packets for the secure communication session until the session key is provided.

6. The method of claim 1 , further comprising employing the session key to decrypt a portion or more of the one or more network packets.

7. The method of claim 1 , further comprising employing the NMD to communicate one or more of the session key or the secure communication session's other correlation information to one or more other NMDs, wherein the one or more other NMD's employ the one or more of the communicated session key and other correlation information to decrypt the one or more network packets.

8. A network device for monitoring communication over a network, comprising:

a memory that stores instructions; and

one or more processors that execute the instructions to perform actions, including:

passively monitoring a secure communication session based on correlation information for one or more network packets;

providing a session key and other correlation information that corresponds to the secure communication session;

identifying a network connection flow that corresponds to the secure communication session based on a comparison of the secure communication session's other correlation information with other correlation information provided by one or more key providers, wherein contents of one or more encrypted packets in the secure communication session are decrypted; and

providing a display to a user of the decrypted contents of the one or more decrypted packets in the secure communication session.

9. The network device of claim 8 , further comprising employing the one or more key providers to provide the session key, wherein the one or more key providers include one or more of a client application, a server application, a session key broker, a hardware security module, a firewall, a proxy, a cache, or application delivery controller.

10. The network device of claim 8 , wherein execution of the instructions instantiates an application to perform the actions, wherein the application is arranged as one or more of an application, a plugin for another application, or the application is integrated with one or more other applications.

11. The network device of claim 8 , further comprising providing two or more different sets of the secure communication's other correlation information, wherein each of these sets include different types of other correlation information that are compatible with two or more different key providers.

12. The network device of claim 8 , further comprising buffering the one or more packets for the secure communication session until the session key is provided.

13. The network device of claim 8 , further comprising employing the session key to decrypt a portion or more of the one or more network packets.

14. The network device of claim 8 , further comprising employing the network device to communicate one or more of the session key or the secure communication session's other correlation information to one or more other network devices, wherein the one or more other network device's employ the one or more of the communicated session key and other correlation information to decrypt the one or more network packets.

15. A system for monitoring communication over a network, comprising:

a network monitoring device (NMD), including:

a transceiver for communicating over the network;

a memory that stores instructions; and

one or more processors that execute the instructions to perform actions, including:

passively monitoring a secure communication session based on correlation information for one or more network packets;

providing a session key and other correlation information that corresponds to the secure communication session;

identifying a network connection flow that corresponds to the secure communication session based on a comparison of the secure communication session's other correlation information with other correlation information provided by one or more key providers, wherein contents of one or more encrypted packets in the secure communication session are decrypted; and

a client device, comprising:

another transceiver for communicating over the network;

another memory that stores other instructions;

one or more other processors that execute the other memory's instructions to perform further actions, including:

providing a display to a user of the decrypted contents of the one or more decrypted packets in the secure communication session, wherein the decrypted contents is provided by the NMD.

16. The system of claim 15 , wherein the NMD's one or more processors' execution of the instructions instantiates an application to perform the actions, wherein the application is arranged as one or more of an application, a plugin for another application, or the application is integrated with one or more other applications.

17. The system of claim 15 , wherein the NMD's one or more processors' execution of the instructions performs other actions comprising providing two or more different sets of the secure communication's other correlation information, wherein each of these sets include different types of other correlation information that are compatible with two or more different key providers.

18. The system of claim 15 , wherein the NMD's one or more processors' execution of the instructions performs other actions comprising buffering the one or more packets for the secure communication session until the session key is provided.

19. The system of claim 15 , wherein the NMD's one or more processors' execution of the instructions performs other actions comprising employing the session key to decrypt a portion or more of the one or more network packets.

20. The system of claim 15 , wherein the NMD's one or more processors' execution of the instructions performs other actions comprising communicating one or more of the session key or the secure communication session's other correlation information to one or more other NMDs, wherein the one or more other NMD's employ the one or more of the communicated session key and other correlation information to decrypt the one or more network packets.

Assignments (6)
SECURITY INTEREST Recorded Jul 27, 2021
From: EXTRAHOP NETWORKS, INC.
To: SIXTH STREET SPECIALTY LENDING, INC., AS THE COLLATERAL AGENT
Reel/Frame 056998/0590 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0488 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0530 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 053756/0739 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK, AS AGENT
Reel/Frame 053756/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2017
From: ROTHSTEIN, JESSE ABRAHAM; HIGGINS, BENJAMIN THOMAS; HATCH, BRIAN DAVID
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 041993/0847 →
Continuity (3)
Continuation 15150354 · May 9, 2016
Continuation 14695690 · Apr 24, 2015
Related Publication 20180034783A1 · Feb 1, 2018
Cited By (8)
US 12,225,030 US 12,231,545 US 12,309,192 US 12,355,816 US 12,483,384 US 12,587,535 US 12,647,441 US 12,652,312