IP Library Granted Patent US 10,997,303
Granted Patent B2
US 10,997,303 · App. 15/795,747 · Granted May 4, 2021

Managing untyped network traffic flows

Inventor: Chris Douglas Kraft (Vancouver, CA)
Assignee: Sophos Limited
G06F21/606G06F12/0813G06F21/44G06F21/50G06F21/51G06F21/54G06F21/55G06F21/554G06F21/57G06F21/602H04L9/0891H04L9/321H04L9/3247H04L9/3268H04L43/028H04L43/045H04L43/062H04L47/2475H04L63/02H04L63/0218H04L63/0227H04L63/0236H04L63/0263H04L63/14H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/168H04L63/20H04L63/205G06F2212/1052G06F2212/60G06F2212/62H04L9/30H04L43/026H04L43/10H04L63/145H04L67/2842
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,997,303
App. No.
15/795,747
Granted
May 4, 2021
Kind
B2
Abstract

An enterprise security system is improved by managing network flows based on an application type. When a network message having an unknown application type is received at a gateway, firewall, or other network device/service from an endpoint, the endpoint that originated the network message may be queried for identifying information for the source of the network message and the application type may be determined, or the endpoint may periodically communicate application type information to the network device in a heartbeat or other periodic communication or the like. The network message may be managed along with other network traffic according to the application type.

Claims (26)

1. A method for managing network flows for an enterprise, the method comprising:

receiving a network message at a network device from an end user device within an enterprise network;

in response to the network message containing a known application type based on first identifying information in the network message providing an application type for a source of the network message on the end user device, using the first identifying information in the network message to determine the application type;

in response to the network message having an unknown application type, querying an endpoint security agent executing on the end user device to retrieve second identifying information for a process that was the source of the network message from a process cache in a kernel space of the end user device storing process metadata and determining the application type for the source of the network message based on the second identifying information retrieved from the end user device, wherein querying the endpoint security agent is through a secure connection between the network device and the end user device; and

managing a network traffic flow including the network message at the network device according to the application type.

2. The method of claim 1 wherein managing the network traffic flow includes applying a security policy to the network traffic flow according to the application type.

3. The method of claim 1 wherein managing the network traffic flow includes associating the network traffic flow with the application type.

4. The method of claim 1 wherein the network device includes a gateway for the enterprise network.

5. The method of claim 1 wherein the network device includes a cloud-based network device.

6. The method of claim 1 wherein the network device includes a firewall on the end user device.

7. The method of claim 1 wherein the first identifying information or the second identifying information includes an application name for the source of the network message.

8. The method of claim 1 wherein the first identifying information or the second identifying information includes application data for the source of the network message.

9. The method of claim 1 wherein determining the application type includes forwarding the first identifying information or the second identifying information to a threat management facility for analysis and receiving an identification of the application type from the threat management facility.

10. The method of claim 1 wherein the secure connection between the network device and the end user device is on a channel separate from the network message.

11. A computer program product for managing network flows comprising computer executable code embodied on a non-transitory computer readable medium that, when executing on a network device, performs the steps of:

receiving a network message in one of a number of network traffic flows at the network device from an end user device within an enterprise network, the network message having an unknown application type;

in response to the network message having the unknown application type, querying an endpoint security agent executing on the end user device to retrieve identifying information from a process cache in a kernel space of the end user device storing process metadata for a source of the network message, wherein querying the endpoint security agent is through a secure connection between the network device and the end user device;

determining an application type for the source of the network message based on the identifying information; and

managing the network message within the number of network traffic flows according to the application type.

12. The computer program product of claim 11 further comprising code that performs the steps of:

determining one or more additional application types for each of the number of network traffic flows at the network device; and

managing the number of network traffic flows based on the application type and the one or more additional application types, each corresponding to one or more applications communicating through the number of network traffic flows.

13. The computer program product of claim 12 wherein managing the number of network traffic flows includes applying a security policy to each of the number of network traffic flows according to the application type.

14. The computer program product of claim 11 wherein managing the network message includes associating the one of the number of network traffic flows containing the network message with the application type.

15. The computer program product of claim 11 wherein the network device includes at least one of a gateway for the enterprise network, a firewall on the end user device, and a cloud-based network device.

16. The computer program product of claim 11 wherein the secure connection between the network device and the end user device is on a channel separate from the network message.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2018
From: KRAFT, CHRIS DOUGLAS
To: SOPHOS LIMITED
Reel/Frame 044783/0223 →
Continuity (4)
Provisional Application 62557703 · Sep 12, 2017
Provisional Application 62571759 · Oct 12, 2017
Provisional Application 62572548 · Oct 15, 2017
Related Publication 20190081976A1 · Mar 14, 2019