IP Library Granted Patent US 11,483,394
Granted Patent B2
US 11,483,394 · App. 15/892,079 · Granted Oct 25, 2022

Delayed proxy-less network address translation decision based on application payload

Inventors: Valtteri Rahkonen (Helsinki, FI); Tuomo Syvänne (Helsinki, FI)
Assignee: Forcepoint LLC
H04L67/141H04L67/01
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,483,394
App. No.
15/892,079
Granted
Oct 25, 2022
Kind
B2
Abstract

A method, system, and computer-usable medium are disclosed for, responsive to communication of a client handshake to a server for establishing communications between the client and server, managing handshake messages between the client and server until an application layer message is communicated from the client, such that a connection between the client and the server appears to be established, and responsive to communication of the application layer message from the client, rendering a policy decision with respect to a connection between the client and the server based on a payload of the application layer message, the policy decision defining a selected path between the client and the server and including a chosen target device from a plurality of potential target devices, wherein the chosen target device is within the selected path and establishing the selected path for communication between the client and the server in accordance with the policy decision.

Claims (52)

1. A method for managing network communication, comprising:

responsive to communication of a client handshake from a client to a server for establishing communications between the client and the server, managing handshake messages between the client and the server until an application layer message is communicated from the client, wherein the managing includes altering the client handshake by removing at least one unsupported communication option from the client handshake and transmitting the altered client handshake to the server, such that during the managing of the handshake messages, from a perspective of the client, a connection between the client and the server appears to be fully established; and

responsive to communication of the application layer message from the client:

rendering a policy decision with respect to a connection between the client and the server based on a payload of the application layer message, the policy decision defining a selected path between the client and the server and including a chosen target device from a plurality of potential target devices, wherein the chosen target device is within the selected path; and

establishing the selected path for communication between the client and the server in accordance with the policy decision;

wherein the method further includes: responsive to receiving a handshake establishing message from the client, holding the handshake establishing message from the client until the policy decision is rendered and the chosen target device is selected, wherein holding the handshake establishing message includes maintaining a connection to the chosen target device in a partially opened state until the chosen target device is selected and then forwarding the handshake establishing message to the chosen target device.

2. The method of claim 1 , further comprising, responsive to the communication of the client handshake and prior to rendering the policy decision, opening at least one path between the client and the server.

3. The method of claim 2 , wherein:

opening at least one path between the client and the server comprises opening a plurality of partial connections from a security device to a plurality of potential target devices; and

the chosen target device comprises one of the plurality of potential target devices.

4. The method of claim 3 , further comprising, responsive to the rendering of the policy decision, closing the plurality of partial connections other than a connection to the chosen target device.

5. The method of claim 3 , wherein managing handshake messages between the client and the server comprises:

responsive to receiving a handshake acknowledgement from one of the plurality of potential target devices, forwarding a single handshake acknowledgement to the client.

6. The method of claim 2 , wherein opening at least one path between the client and the server comprises opening a single connection to an initial target device.

7. The method of claim 6 , wherein the initial target device is configured to render the policy decision.

8. The method of claim 6 , wherein managing handshake messages between the client and the server comprises:

responsive to receiving a handshake acknowledgement from the initial target device, forwarding the handshake acknowledgement to the client; and

responsive to receiving the handshake establishing message from the client, communicating the handshake establishing message to the server.

9. The method of claim 6 , further comprising buffering application layer messages from the client until the policy decision is rendered.

10. The method of claim 6 , wherein:

if the initial target device is the chosen target device, establishing the selected path for communication between the client and the server, the selected path including the initial target device; and

if a device other than the initial target device is the chosen target device, establishing the selected path for communication between the client and the server, the selected path including the device other than the initial target device, and closing the connection between the client and the initial target device.

11. A system comprising:

a processor; and

a non-transitory, computer-readable storage medium embodying instructions executable by the processor for:

responsive to communication of a client handshake from a client to a server for establishing communications between the client and the server, managing handshake messages between the client and the server until an application layer message is communicated from the client, wherein the managing includes altering the client handshake by removing at least one unsupported communication option from the client handshake and transmitting the altered client handshake to the server, such that during the managing of the handshake messages, from a perspective of the client, a connection between the client and the server appears to be fully established; and

responsive to communication of the application layer message from the client:

rendering a policy decision with respect to a connection between the client and the server based on a payload of the application layer message, the policy decision defining a selected path between the client and the server and including a chosen target device from a plurality of potential target devices, wherein the chosen target device is within the selected path; and

establishing the selected path for communication between the client and the server in accordance with the policy decision;

wherein the instructions are further executable for: responsive to receiving a handshake establishing message from the client, holding the handshake establishing message from the client until the policy decision is rendered and the chosen target device is selected, wherein holding the handshake establishing message includes maintaining a connection to the chosen target device in a partially opened state until the chosen target device is selected and then forwarding the handshake establishing message to the chosen target device.

12. The system of claim 11 , the instructions further configured for, responsive to the communication of the client handshake and prior to rendering the policy decision, opening at least one path between the client and the server.

13. The system of claim 12 , wherein:

opening at least one path between the client and the server comprises opening a plurality of partial connections from a security device to a plurality of potential target devices; and

the chosen target device comprises one of the plurality of potential target devices.

14. The system of claim 13 , the instructions further configured for, responsive to the rendering of the policy decision, closing the plurality of partial connections other than a connection to the chosen target device.

15. The system of claim 13 , wherein managing handshake messages between the client and the server comprises:

responsive to receiving a handshake acknowledgement from one of the plurality of potential target devices, forwarding a single handshake acknowledgement to the client.

16. The system of claim 12 , wherein opening at least one path between the client and the server comprises opening a single connection to an initial target device.

17. The system of claim 16 , wherein the initial target device is configured to render the policy decision.

18. The system of claim 16 , wherein managing handshake messages between the client and the server comprises:

responsive to receiving a handshake acknowledgement from the initial target device, forwarding the handshake acknowledgement to the client; and

responsive to receiving the handshake establishing message from the client, communicating the handshake establishing message to the server.

19. The system of claim 16 , the instructions further configured for buffering application layer messages from the client until the policy decision is rendered.

20. The system of claim 16 , wherein the instructions are further configured for:

if the initial target device is the chosen target device, establishing the selected path for communication between the client and the server, the selected path including the initial target device; and

if a device other than the initial target device is the chosen target device, establishing the selected path for communication between the client and the server, the selected path including the device other than the initial target device, and closing the connection between the client and the initial target device.

21. A non-transitory, computer-readable storage medium embodying computer executable instructions configured for:

responsive to communication of a client handshake from a client to a server for establishing communications between the client and the server, managing handshake messages between the client and the server until an application layer message is communicated from the client, wherein the managing includes altering the client handshake by removing at least one unsupported communication option from the client handshake and transmitting the altered client handshake to the server, such that during the managing of the handshake messages, from a perspective of the client, a connection between the client and the server appears to be fully established; and

responsive to communication of the application layer message from the client:

rendering a policy decision with respect to a connection between the client and the server based on a payload of the application layer message, the policy decision defining a selected path between the client and the server and including a chosen target device from a plurality of potential target devices, wherein the chosen target device is within the selected path; and

establishing the selected path for communication between the client and the server in accordance with the policy decision;

wherein the instructions are further configured for: responsive to receiving a handshake establishing message from the client, holding the handshake establishing message from the client until the policy decision is rendered and the chosen target device is selected, wherein holding the handshake establishing message includes maintaining a connection to the chosen target device in a partially opened state until the chosen target device is selected and then forwarding the handshake establishing message to the chosen target device.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055492/0266 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Jul 6, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 046495/0561 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2018
From: RAHKONEN, VALTTERI; SYVÄNNE, TUOMO
To: FORCEPOINT LLC
Reel/Frame 044873/0312 →
Continuity (1)
Related Publication 20190245930A1 · Aug 8, 2019