IP Library Granted Patent US 10,469,386
Granted Patent B2
US 10,469,386 · App. 15/676,774 · Granted Nov 5, 2019

Network shunt with bypass

Inventor: Xiaoheng Yang (Vancouver, CA)
Assignee: General Electric Company
H04L47/12H04L43/0894H04L43/16H04L63/0254H04L63/20H04L43/12H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,469,386
App. No.
15/676,774
Granted
Nov 5, 2019
Kind
B2
Abstract

A network firewall receives a first incoming data packet that is transmitted from an outside network to a destination within an internal network secured by the network firewall. The network firewall is configured to restrict access to the internal network based on a set of network policies. The network firewall compares a current inbound traffic rate at the network firewall to a threshold inbound traffic rate, yielding a comparison. The network firewall determines, based on the comparison, that the current inbound traffic rate at the network firewall is greater than a threshold inbound traffic rate, and forwards the first incoming data packet to the destination within the internal network without inspecting the first incoming data packet based on the set of network policies.

Claims (69)

1. A method comprising:

receiving, by a network firewall, a first incoming data packet that is transmitted from an outside network to a destination within an internal network secured by the network firewall, the network firewall configured to restrict access to the internal network based on a set of network policies;

comparing, by the network firewall, a current inbound traffic rate at the network firewall to a threshold inbound traffic rate, yielding a comparison;

determining, based on the comparison, that the current inbound traffic rate at the network firewall is greater than the threshold inbound traffic rate;

forwarding, by the network firewall, the first incoming data packet to the destination within the internal network without inspecting the first incoming data packet based on the set of network policies when the current inbound traffic rate at the network firewall is greater than the threshold inbound traffic rate;

receiving, at the network firewall, a second incoming data packet that is transmitted from the outside network to a second destination within the internal network;

determining that the current inbound traffic rate at the network firewall is not greater than the threshold inbound traffic rate; and

inspecting, by the network firewall, the second incoming data packet according to the set of network policies when the current inbound traffic rate at the network firewall is not greater than the threshold inbound traffic rate, yielding an inspection.

2. The method of claim 1 , further comprising:

determining, based on the inspection, that the second incoming data packet satisfies the set of network policies; and

forwarding the second incoming data packet to the second destination within the internal network.

3. The method of claim 1 , further comprising:

determining, based on the inspection, that the second incoming data packet does not satisfy the set of network policies; and

blocking the second incoming data packet from entering the internal network.

4. The method of claim 1 , further comprising:

determining an acceptable network latency level associated with the first incoming data packet; and

determining, based on the acceptable network latency level associated with the first incoming data packet, to forward the first incoming data packet to the destination within the internal network without inspecting the first incoming data packet based on the set of network policies.

5. The method of claim 4 , further comprising:

receiving, at the network firewall, a second incoming data packet that is transmitted from the outside network to a second destination within the internal network when the current inbound traffic rate at the networking firewall is greater than the threshold inbound traffic rate;

determining an acceptable latency level associated with the second incoming data packet, the acceptable latency level associated with the second incoming data packet being higher than the acceptable latency level associated with the first incoming data packet; and

determining, based on the acceptable latency level associated with the second incoming data packet, to inspect the second inbound data packet based on the set of network policies.

6. The method of claim 1 , further comprising:

determining a messaging protocol of the first incoming data packet; and

determining, based on the messaging protocol of the first incoming data packet, to forward the first incoming data packet to the destination within the internal network without inspecting the first incoming data packet based on the set of network policies.

7. The method of claim 6 , further comprising:

receiving, at the network firewall, a second incoming data packet that is transmitted from the outside network to a second destination within the internal network when the current inbound traffic rate at the networking firewall is greater than the threshold inbound traffic rate;

determining a messaging protocol of the second incoming data packet, the messaging protocol of the second incoming data packet being different than the messaging protocol of the first incoming data packet; and

determining, based on the messaging protocol of the second incoming data packet, to inspect the second inbound data packet based on the set of network policies.

8. The method of claim 7 , wherein the messaging protocol of the first incoming data packet is an information technology protocol and the messaging protocol of the second incoming data packet is an operational technology protocol.

9. The method of claim 1 , wherein the network firewall is a virtual network firewall.

10. A network firewall system comprising:

one or more computer processors; and

one or more computer-readable mediums storing instructions that, when executed by the one or more computer processors, cause the network firewall system to perform operations comprising:

receiving a first incoming data packet that is transmitted from an outside network to a destination within an internal network secured by the network firewall system, the network firewall system configured to restrict access to the internal network based on a set of network policies;

comparing a current inbound traffic rate at the network firewall system to a threshold inbound traffic rate, yielding a comparison;

determining, based on the comparison, that the current inbound traffic rate at the network firewall system is greater than the threshold inbound traffic rate; and

forwarding the first incoming data packet to the destination within the internal network without inspecting the first incoming data packet based on the set of network policies when the current inbound traffic rate at the network firewall system is greater than the threshold inbound traffic rate;

receiving a second incoming data packet that is transmitted from the outside network to a second destination within the internal network;

determining that the current inbound traffic rate at the network firewall system is not greater than the threshold inbound traffic rate; and

inspecting the second incoming data packet according to the set of network policies when the current inbound traffic rate at the network firewall system is not greater than the threshold inbound traffic rate, yielding an inspection.

11. The network firewall system of claim 10 , the operations further comprising:

determining, based on the inspection, that the second incoming data packet satisfies the set of network policies; and

forwarding the second incoming data packet to the second destination within the internal network.

12. The network firewall system of claim 10 , the operations further comprising:

determining, based on the inspection, that the second incoming data packet does not satisfy the set of network policies; and

blocking the second incoming data packet from entering the internal network.

13. The network firewall system of claim 10 , the operations further comprising:

determining an acceptable network latency level associated with the first incoming data packet; and

determining, based on the acceptable network latency level associated with the first incoming data packet, to forward the first incoming data packet to the destination within the internal network without inspecting the first incoming data packet based on the set of network policies.

14. The network firewall system of claim 13 , the operations further comprising:

receiving a second incoming data packet that is transmitted from the outside network to a second destination within the internal network when the current inbound traffic rate at the network firewall system is greater than the threshold inbound traffic rate;

determining an acceptable latency level associated with the second incoming data packet, the acceptable latency level associated with the second incoming data packet being higher than the acceptable latency level associated with the first incoming data packet; and

determining, based on the acceptable latency level associated with the second incoming data packet, to inspect the second inbound data packet based on the set of network policies.

15. The network firewall system of claim 10 , the operations further comprising:

determining a messaging protocol of the first incoming data packet; and

determining, based on the messaging protocol of the first incoming data packet, to forward the first incoming data packet to the destination within the internal network without inspecting the first incoming data packet based on the set of network policies.

16. The network firewall system of claim 15 , the operations further comprising:

receiving a second incoming data packet that is transmitted from the outside network to a second destination within the internal network when the current inbound traffic rate at the network firewall system is greater than the threshold inbound traffic rate;

determining a messaging protocol of the second incoming data packet, the messaging protocol of the second incoming data packet being different than the messaging protocol of the first incoming data packet; and

determining, based on the messaging protocol of the second incoming data packet, to inspect the second inbound data packet based on the set of network policies.

17. The network firewall system of claim 16 , wherein the messaging protocol of the first incoming data packet is an information technology protocol and the messaging protocol of the second incoming data packet is an operational technology protocol.

18. A non-transitory computer-readable medium storing instructions that, when executed by one or more computer processors of a network firewall, cause the network firewall to perform operations comprising:

receiving, by the network firewall, a first incoming data packet that is transmitted from an outside network to a destination within an internal network secured by the network firewall, the network firewall configured to restrict access to the internal network based on a set of network policies;

comparing, by the network firewall, a current inbound traffic rate at the network firewall to a threshold inbound traffic rate, yielding a comparison;

determining, based on the comparison, that the current inbound traffic rate at the network firewall in greater than the threshold inbound traffic rate;

forwarding, by the network firewall, the first incoming data packet to the destination within the internal network without inspecting the first incoming data packet based on the set of network policies when the current inbound traffic rate at the network firewall is greater than the threshold inbound traffic rate;

receiving, at the network firewall, a second incoming data packet that is transmitted from the outside network to a second destination within the internal network;

determining that the current inbound traffic rate at the network firewall is not greater than the threshold inbound traffic rate; and

inspecting, by the network firewall, the second incoming data packet according to the set of network policies when the current inbound traffic rate at the network firewall is not greater than the threshold inbound traffic rate, yielding an inspection.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2023
From: GENERAL ELECTRIC COMPANY
To: GE DIGITAL HOLDINGS LLC
Reel/Frame 065612/0085 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2017
From: YANG, XIAOHENG
To: GENERAL ELECTRIC COMPANY
Reel/Frame 043288/0082 →
Continuity (2)
Provisional Application 62507623 · May 17, 2017
Related Publication 20180337858A1 · Nov 22, 2018