IP Library Granted Patent US 10,819,723
Granted Patent B2
US 10,819,723 · App. 15/936,317 · Granted Oct 27, 2020

Securing port forwarding through a network traffic hub

Inventors: Leonid Kuperman (Los Angeles, CA); Einaras von Gravrock (Redondo Beach, CA)
Assignee: Cujo LLC
H04L63/1425H04L12/2803H04L12/2807H04L63/0884H04L63/102H04L63/20H04L61/103H04L61/2015H04L61/6022
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,819,723
App. No.
15/936,317
Granted
Oct 27, 2020
Kind
B2
Abstract

A network traffic hub is configured to receive a request for a port service (i.e., port forwarding or port triggering) from a smart appliance in a local network. The request may be a part of the UPnP protocol, which includes SSDP and IGDP. The request may be transmitted to the network traffic hub directly or the network traffic hub may intercept the request transmitted to a router of the local network. By receiving the request, the network traffic hub prevents automatic establishment of the port service between the smart appliance and the router until an approval or denial of the port service is received from a user. As such, the user is informed of the request and has the ability to approve or deny the port service. Furthermore, the network traffic hub can configure a network to perform a port service if the network does not allow for it natively.

Claims (47)

1. A method, comprising:

intercepting, by a network traffic hub, a request for port services from a smart appliance, the smart appliance and a router being on a same local area network, the request for port services comprising one of a request for port forwarding services or a request for port triggering services and being transmitted by the smart appliance toward the router;

inhibiting, by the network traffic hub, the request for port services from being sent to the router;

transmitting, by the network traffic hub, a request for authorization to an authorization device;

receiving, by the network traffic hub, an authorization message from the authorization device approving the request for port services from the smart appliance;

transmitting, by the network traffic hub, a second request for port services to the router, the second request for port services including instructions for the router to forward network traffic from a wide area network to the network traffic hub;

receiving, from the router by the network traffic hub, forwarded network traffic from the wide area network; and

monitoring, by the network traffic hub, the forwarded network traffic from the router to the smart appliance to identify malicious activity.

2. The method of claim 1 , wherein the request for port services is a part of the universal plug and play (UPnP) networking protocols set.

3. The method of claim 1 , further comprising:

creating a first subnetwork and a second subnetwork in the local area network, the first subnetwork including the smart appliance and the network traffic hub, and the second subnetwork including the router and the network traffic hub.

4. The method of claim 1 , wherein the network traffic hub receives the forwarded network traffic from the wide area network by intercepting the forwarded network traffic.

5. The method of claim 1 , further comprising:

receiving, from the router by the network traffic hub, a message from the authorization device removing approval of port services to the smart appliance; and

transmitting, by the network traffic hub, instructions to the router to cease forwarding traffic from the wide area network.

6. The method of claim 1 , wherein the received authorization message approves the port services request from the smart appliance for a time period, further comprising:

after the time period has expired, transmitting, by the network traffic hub, instructions to the router to cease forwarding traffic from the wide area network.

7. The method of claim 1 , wherein the router has dynamic host configuration protocol (DHCP) functions disabled, further comprising: assigning, by the network traffic hub through DHCP, an IP address to the smart appliance.

8. The method of claim 1 wherein the request for port services identifies a port number such that the router is to forward to the smart appliance all packets received from the wide area network that identify the port number as a destination port number.

9. A network traffic hub comprising:

a network interface communicatively coupled to a smart appliance via a first communication channel in a local area network and communicatively coupled to a router via a second communication channel, the router being in the same local area network;

a processor; and

a memory storing program code, the program code when executed causes the processor to:

intercept, via the first communication channel, a request for port services from the smart appliance, the request for port services comprising one of a request for port forwarding services or a request for port triggering services and being transmitted by the smart appliance toward the router;

inhibit, by the network traffic hub, the request for pot services from being sent to the router;

transmit, via the second communication channel, a request for authorization to an authorization device;

receive, via the second communication channel, an authorization message from the authorization device approving the request for port services from the smart appliance;

transmit, via the second communication channel, a second request for port services to the router, the second request for pot services including instructions for the router to forward network traffic from a wide area network to the network traffic hub;

receive, from the router via the second communication channel, forwarded network traffic from the wide area network; and

monitor the forwarded network traffic from the router to the smart appliance to identify malicious activity.

10. The network traffic hub of claim 9 , wherein the communication channels are established by creating two subnetworks, further comprising program code configures to cause the processor to:

create, two subnetworks in the local area network, the first subnetwork including the smart appliance and the network traffic hub, and the second subnetwork including the router and the network traffic hub.

11. The network traffic hub of claim 9 , further comprising program code configured to cause the processor to:

receive, via the second communication channel, a message from the authorization device removing approval of the port services to the smart appliance; and

transmit, via the second communication channel, instructions to the router to cease forwarding traffic from the wide area network.

12. The network traffic hub of claim 9 , wherein the received authorization message approves the port services request from the smart appliance for a time period, further comprising program code configured to cause the processor to:

after the time period has expired, transmit, via the second communication channel, instructions to the router to cease forwarding traffic from the wide area network.

13. The network traffic hub of claim 9 , wherein the router has dynamic host configuration protocol (DHCP) functions disabled, further comprising program code configured to cause the processor to:

assign, through DHCP, an IP address to the smart appliance.

14. A method, comprising:

receiving, by a network traffic hub from a smart appliance, a first port services request that is directed to a router, the smart appliance and the router being on a same local area network (LAN), the first port services request identifying a port number such that the router is to forward to the smart appliance all packets received from an external computing device that identify the port number as a destination port number, the external computing device being on a second network that is different from the LAN;

inhibiting, by the network traffic hub, the first port services request from being sent to the router;

transmitting, by the network traffic hub, a request for authorization of the first port services request to an authorization device;

receiving, by the network traffic hub, an authorization message from the authorization device approving the first port services request from the smart appliance;

transmitting, by the network traffic hub, a second port services request to the router, the second port services request including instructions for the router to forward network traffic from the external computing device to the network traffic hub;

receiving, from the router by the network traffic hub, forwarded network traffic from the external computing device; and

monitoring, by the network traffic hub, the forwarded network traffic from the router to the smart appliance to identify malicious activity.

Assignments (2)
SECURITY INTEREST Recorded Jun 20, 2019
From: CUJO LLC
To: CHARTER COMMUNICATONS HOLDING COMPANY, LLC
Reel/Frame 049537/0319 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2018
From: KUPERMAN, LEONID; VON GRAVROCK, EINARAS
To: CUJO LLC
Reel/Frame 046005/0423 →
Continuity (2)
Provisional Application 62477359 · Mar 27, 2017
Related Publication 20180278637A1 · Sep 27, 2018
Cited By (1)
US 12,676,879