IP Library Granted Patent US 10,785,191
Granted Patent B2
US 10,785,191 · App. 15/791,144 · Granted Sep 22, 2020

Device, system and method for defending a computer network

Inventor: Christopher J. Jordan (Leesburg, VA)
Assignee: McAfee, LLC
H04L63/0245H04L63/0227H04L63/1416H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,785,191
App. No.
15/791,144
Granted
Sep 22, 2020
Kind
B2
Abstract

A router includes a processor-readable medium including code representing instructions to cause a processor to perform operations. The operations include routing received information communicated from a first network to a component associated with a service within a second network, responsive to a determination that the received information is to be handled by a service that exists within the second network. The operations also include routing the received information to a predetermined component, responsive to a determination that the received information is to be handled by a service that does not exist within the second network.

Claims (45)

1. A router, comprising:

a non-transitory, processor-readable medium including code representing instructions to cause a processor to perform operations including

routing received information communicated from a first network to a component associated with a first service within a second network, responsive to a determination that the received information is to be handled by the first service; and

routing the received information to a predetermined component within the second network, responsive to a determination that the received information is to be handled by a second service that does not exist within the second network.

2. The router of claim 1 , wherein the operations further include:

determining, based on information at a layer above a data link layer of the received information, if the received information is to be handled by the first service.

3. The router of claim 1 , wherein the operations further include:

routing the received information to another service responsive to the determination that the received information is to be handled by the second service, and

responding to the first network based on information from the another service, wherein the information from the another service is the same as information from the second service.

4. The router of claim 1 , wherein the operations further include:

removing network traits from internet protocol (IP) datagrams during transmission of information from a component within the second network.

5. The router of claim 1 , wherein the operations further include:

modifying a payload of a packet to remove traits of the second network and to provide apparent traits.

6. The router of claim 1 , wherein the operations further include:

performing network address translation at least partially based on a determination that a packet matching content of a payload of the received information is a known good packet.

7. The router of claim 1 , wherein the received information is received with a wireless connection.

8. The router of claim 1 , wherein all services within the second network respond as active.

9. A non-transitory, processor-readable medium including code representing instructions to cause a processor to perform operations comprising:

routing received information communicated from a first network to a component associated with a first service within a second network, responsive to a determination that the received information is to be handled by the first service; and

routing the received information to a predetermined component within the second network, responsive to a determination that the received information is to be handled by a second service that does not exist within the second network.

10. The non-transitory, processor-readable medium of claim 9 , wherein the operations further comprise:

determining, based on information at a layer above a data link layer of the received information, if the received information is to be handled by the first service.

11. The non-transitory, processor-readable medium of claim 9 , wherein the operations further comprise:

routing the received information to another service, responsive to the determination that the received information is to be handled by the second service; and

responding to the first network based on information from the another service, wherein the information from the another service is the same as information from the second service.

12. The non-transitory, processor-readable medium of claim 9 , wherein the operations further comprise:

removing network traits from internet protocol (IP) datagrams during transmission of information from a component within the second network.

13. The non-transitory, processor-readable medium of claim 9 , wherein the operations further comprise:

modifying a payload of a packet to remove traits of the second network and to provide apparent traits.

14. The non-transitory, processor-readable medium of claim 9 , wherein the operations further comprise:

performing network address translation at least partially based on a determination that packet matching content of a payload of the received information is a known good packet.

15. The non-transitory, processor-readable medium of claim 9 , wherein the received information is received with a wireless connection.

16. A method, comprising:

routing received information communicated from a first network to a component associated with a first service within a second network, responsive to a determination that the received information is to be handled by the first service; and

routing the received information to a predetermined component within the second network, responsive to a determination that the received information is to be handled by a second service that does not exist within the second network.

17. The method of claim 16 , further comprising:

determining, based on information at a layer above a data link layer of the received information, if the received information is to be handled by the first service.

18. The method of claim 16 , further comprising:

routing the received information to another service, responsive to the determination that the received information is to be handled by the second service, and

responding to the first network based on information from the another service, wherein the information from the another service is the same as information from the second service.

19. The method of claim 16 , further comprising:

removing network traits from internet protocol (IP) datagrams during transmission of information from a component within the second network.

20. The method of claim 16 , further comprising:

performing network address translation at least partially based on a determination that a packet matching content of a payload of the received information is a known good packet.

21. The method of claim 16 , wherein the received information is received with a wireless connection.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
Continuity (4)
Continuation 14486740 · Sep 15, 2014
Continuation 10990329 · Nov 17, 2004
Provisional Application 60520577 · Nov 17, 2003
Related Publication 20180041473A1 · Feb 8, 2018