IP Library Granted Patent US 10,225,235
Granted Patent B2
US 10,225,235 · App. 15/830,325 · Granted Mar 5, 2019

Non RFC-compliant protocol classification based on real use

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,225,235
App. No.
15/830,325
Granted
Mar 5, 2019
Kind
B2
Abstract

A firewall system determines whether a protocol used by an incoming data packet is a standard protocol compliant with Request For Comment (RFC) standards. In the event the protocol is RFC compliant, the firewall transmits the packet to the recipient according to firewall policies regarding the standard protocol. If the protocol is not that of an RFC standard, the firewall determines whether the protocol matches an RFC-exception protocol in a RFC-exception protocol database. If the protocol does match an RFC-exception, the firewall may transmit the packet to the recipient according to firewall policies regarding the RFC-exception protocol. If it does not match an RFC-exception, the firewall may transmit the packet or protocol to a support system where it may be quarantined until it is approved based on a decision that the protocol is safe and/or widely adopted.

Claims (57)

1. A method for processing data packets, the method comprising:

receiving a first data packet associated with a first set of communication traffic sent to a recipient computer via a computer network;

identifying that a protocol of the first data packet is not compliant with a standard communication protocol, wherein the first data packet is not associated with an exception rule associated with the standard communication protocol, and wherein the first data packet includes a characteristic that resembles without being identical to one or more characteristics associated with the standard communication protocol;

sending the first data packet to a support system for analysis, wherein the analysis identifies whether the first set of communication traffic is approved or denied to be sent to the recipient computer;

quarantining the first set of communication traffic until the support system approves or denies the first set of communication traffic based on the analysis of at least the first data packet; and

receiving an indication from the support system that the first set of communication traffic is approved to be sent to the recipient computer, wherein the first set of communication traffic is allowed to proceed to the recipient computer via the computer network based on the indication.

2. The method of claim 1 , further comprising:

storing the first data packet in a database of unclassified non-compliant protocols;

classifying the protocol associated with the first data packet as a known protocol based on the approval of the first set of communication traffic;

creating a new exception rule based on the classification of the protocol associated with the first data packet as the known protocol; and

storing the new exception rule in an exception rule database.

3. The method of claim 2 , further comprising:

receiving a second data packet associated with a second set of communication traffic;

identifying that the second data packet is associated with the new exception rule based on a protocol associated with the second data packet being consistent with the protocol of the first data packet; and

allowing the second set of communication traffic to proceed based at least in part on the identification that the second data packet is associated with the new exception rule.

4. The method of claim 3 , further comprising:

receiving information from a system administrator computer that identifies a custom non-compliant protocol; and

adding a second new exception rule to the exception rule database that includes the custom non-compliant protocol, wherein communication traffic associated with data packets sent according to the custom non-compliant protocol are allowed based at least in part on the second new exception rule being added to the exception rule database.

5. The method of claim 3 , further comprising:

receiving a third data packet associated with a third set of communication traffic; and

identifying that a policy allows the third set of communication traffic to proceed based on a protocol of the third data packet being associated with a custom non-compliant protocol exception rule.

6. The method of claim 1 , wherein the support system is a remote computer system accessible via the internet.

7. The method of claim 1 , wherein the support system analyzes the first data packet to identify whether the first data packet includes malware.

8. The method of claim 1 , wherein the support system accesses data in the first data packet to perform the analysis.

9. The method of claim 1 , wherein the protocol associated with the first data packet is analyzed by reviewing one or more portions of the first data packet.

10. The method of claim 1 , wherein a database of known exceptions stores information related to the known protocol and the database of known exceptions cross-references a protocol identifier with one or more policies.

11. The method of claim 10 , further comprising:

identifying an action associated with the one or more policies; and

initiating the identified action.

12. The method of claim 11 , wherein the initiated action includes scanning the traffic associated with the first data packet for viruses.

13. The method of claim 2 , wherein the database of unclassified non-compliant protocols cross-references a protocol identifier with a status, a status, and one or more data packets.

14. The method of claim 1 , wherein traffic associated with a second data packet is blocked based on an action associated with a policy rule.

15. The method of claim 1 , wherein traffic associated with a second data packet is blocked based on a policy rule.

16. A non-transitory computer-readable storage medium having embodied thereon a program for implementing a method for processing data packets, the method comprising:

receiving a first data packet associated with a first set of communication traffic sent to a recipient computer via a computer network;

identifying that a protocol of the first data packet is not compliant with a standard communication protocol, wherein the first data packet is not associated with an exception rule associated with the standard communication protocol, and wherein the first data packet includes a characteristic that resembles without being identical is similar to one or more characteristics associated with the standard communication protocol;

sending the first data packet to a support system for analysis, wherein the analysis identifies whether the first set of communication traffic is approved or denied to be sent to the recipient computer;

quarantining the first set of communication traffic until the support system approves or denies the first set of communication traffic based on the analysis of at least the first data packet; and

receiving an indication from the support system that the first set of communication traffic is approved to be sent to the recipient computer, wherein the first set of communication traffic is allowed to proceed to the recipient computer via the computer network based on the indication.

17. The non-transitory computer-readable storage medium of claim 16 , further comprising instructions executable to:

store the first data packet in a database of unclassified non-compliant protocols;

classify the protocol associated with the first data packet as a known protocol based on the first set of communication traffic being approved;

create a new exception rule based on the classification of the protocol associated with the first data packet as the known protocol; and

store the new exception rule in an exception rule database.

18. The non-transitory computer-readable storage medium of claim 17 , further comprising instructions executable to:

receive a second data packet associated with a second set of communication traffic;

identify that the second data packet is associated with the new exception rule based on a protocol associated with the second data packet being consistent with the protocol of the first data packet; and

allow the second set of communication traffic to proceed based at least in part on the identification that the second data packet is associated with the new exception rule.

19. The non-transitory computer-readable storage medium of claim 18 , further comprising instructions executable to:

receive information from a system administrator computer that identifies a custom non-compliant protocol; and

add a second new exception rule to the known exception rule database that includes information that identifies the custom non-compliant protocol, wherein communication traffic associated with data packets sent according to the custom non-compliant protocol are allowed based at least in part on the second new exception rule being added to the known exception rule database.

20. An apparatus for processing data packets, the apparatus comprising:

a network interface that receives a first data packet sent to a recipient computer and associated with a first set of communication traffic;

a memory; and

a processor that executes instructions out of the memory to:

identify that a protocol of the first data packet is not compliant with a standard communication protocol, wherein the first data packet is not associated with an exception rule associated with the standard communication protocol, wherein the first data packet includes a characteristic that resembles without being identical to one or more characteristics associated with the standard communication protocol, wherein the first data packet is sent to a support system for analysis of whether the first set of communication traffic is approved or denied to be sent to the recipient computer; and

quarantine the first set of communication traffic until the support system approves or denies the first set of communication traffic based on the analysis of at least the first data packet, wherein an indication from the support system that the quarantined traffic associated with the first data packet is approved to be sent to the recipient computer via the network interface and the traffic associated with the first data packet is allowed to proceed to the recipient computer based on the indication.

Assignments (3)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2022
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 059912/0097 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2019
From: CARAMES, HUGO VAZQUEZ
To: SONICWALL, INC.
Reel/Frame 048119/0973 →