IP Library Granted Patent US 10,791,135
Granted Patent B2
US 10,791,135 · App. 16/162,993 · Granted Sep 29, 2020

Inspection of network traffic in a security device at object level

Inventors: Mirja Halme (Helsinki, FI); Otto Airamo (Helsinki, FI); Valtteri Rahkonen (Helsinki, FI); Tuomo Syvänne (Helsinki, FI)
Assignee: Forcepoint LLC
H04L63/1425H04L12/66H04L47/6205H04L63/1416H04L63/164H04L63/20H04L69/04H04L69/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,791,135
App. No.
16/162,993
Granted
Sep 29, 2020
Kind
B2
Abstract

A method, system, and computer-usable medium are disclosed for, responsive to establishment of a connection between a first endpoint device and a second endpoint device: maintaining, by a security device interfaced between the first endpoint device and the second endpoint device for inspecting traffic transmitted over the connection, a first communication state to be identical to a communication state of the first endpoint device; and maintaining, by the security device, a second communication state to be identical to a communication state of the second endpoint device; and responsive to transmission of traffic from the first endpoint and intended for the second endpoint: inspecting individual objects of the traffic; modifying stream identifiers of the individual objects prior to retransmission of the traffic to the second endpoint to maintain ordering of stream identifiers as seen by the second endpoint; and maintaining a mapping of the modified stream identifiers such that the mapping is used by the security device such that responses transmitted by the second endpoint in response to the objects transmitted by first endpoint device are modified to their original stream identifiers of the objects transmitted by first endpoint device.

Claims (54)

1. A computer-implementable method for managing network communication, comprising:

responsive to establishment of a connection between a first endpoint device and a second endpoint device:

maintaining, by a security device interfaced between the first endpoint device and the second endpoint device for inspecting traffic transmitted over the connection, a first communication state to be identical to a communication state of the first endpoint device; and

maintaining, by the security device, a second communication state to be identical to a communication state of the second endpoint device; and

responsive to transmission of traffic from the first endpoint and intended for the second endpoint:

inspecting individual objects of the traffic;

modifying stream identifiers of the individual objects prior to retransmission of the traffic to the second endpoint to maintain ordering of stream identifiers as seen by the second endpoint; and

maintaining a mapping of the modified stream identifiers such that the mapping is used by the security device such that responses transmitted by the second endpoint in response to the objects transmitted by first endpoint device are modified to their original stream identifiers of the objects transmitted by first endpoint device.

2. The method of claim 1 , wherein the security device is a gateway device.

3. The method of claim 1 , wherein:

one of the first endpoint device and the second is a client device; and

the other of the first endpoint device and the second is a server device.

4. The method of claim 1 , wherein the connection is a Hypertext Transfer Protocol Version 2-compliant connection.

5. The method of claim 1 , further comprising:

maintaining, by the security device, a third communication state to be identical to a receiving communication state of the first endpoint device; and

maintaining, by the security device, a fourth communication state to be identical to a transmitting communication state of the second endpoint device.

6. The method of claim 1 , wherein the first communication state and the second communication state are each a communication state associated with a header compression algorithm for frames of the traffic.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

responsive to establishment of a connection between a first endpoint device and a second endpoint device:

maintaining, by a security device interfaced between the first endpoint device and the second endpoint device for inspecting traffic transmitted over the connection, a first communication state to be identical to a communication state of the first endpoint device; and

maintaining, by the security device, a second communication state to be identical to a communication state of the second endpoint device; and

responsive to transmission of traffic from the first endpoint and intended for the second endpoint:

inspecting individual objects of the traffic;

modifying stream identifiers of the individual objects prior to retransmission of the traffic to the second endpoint to maintain ordering of stream identifiers as seen by the second endpoint; and

maintaining a mapping of the modified stream identifiers such that the mapping is used by the security device such that responses transmitted by the second endpoint in response to the objects transmitted by first endpoint device are modified to their original stream identifiers of the objects transmitted by first endpoint device.

8. The system of claim 7 , wherein the security device is a gateway device.

9. The system of claim 7 , wherein:

one of the first endpoint device and the second is a client device; and

the other of the first endpoint device and the second is a server device.

10. The system of claim 7 , wherein the connection is a Hypertext Transfer Protocol Version 2-compliant connection.

11. The system of claim 7 , the instructions further configured for:

maintaining, by the security device, a third communication state to be identical to a receiving communication state of the first endpoint device; and

maintaining, by the security device, a fourth communication state to be identical to a transmitting communication state of the second endpoint device.

12. The system of claim 7 , wherein the first communication state and the second communication state are each a communication state associated with a header compression algorithm for frames of the traffic.

13. The medium of claim 7 , the instructions further configured for:

maintaining, by the security device, a third communication state to be identical to a receiving communication state of the first endpoint device; and

maintaining, by the security device, a fourth communication state to be identical to a transmitting communication state of the second endpoint device.

14. The medium of claim 7 , wherein the first communication state and the second communication state are each a communication state associated with a header compression algorithm for frames of the traffic.

15. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

responsive to establishment of a connection between a first endpoint device and a second endpoint device:

maintaining, by a security device interfaced between the first endpoint device and the second endpoint device for inspecting traffic transmitted over the connection, a first communication state to be identical to a communication state of the first endpoint device; and

maintaining, by the security device, a second communication state to be identical to a communication state of the second endpoint device; and

responsive to transmission of traffic from the first endpoint and intended for the second endpoint:

inspecting individual objects of the traffic;

modifying stream identifiers of the individual objects prior to retransmission of the traffic to the second endpoint to maintain ordering of stream identifiers as seen by the second endpoint; and

maintaining a mapping of the modified stream identifiers such that the mapping is used by the security device such that responses transmitted by the second endpoint in response to the objects transmitted by first endpoint device are modified to their original stream identifiers of the objects transmitted by first endpoint device.

16. The medium of claim 15 , wherein the security device is a gateway device.

17. The medium of claim 15 , wherein:

one of the first endpoint device and the second is a client device; and

the other of the first endpoint device and the second is a server device.

18. The medium of claim 15 , wherein the connection is a Hypertext Transfer Protocol Version 2-compliant connection.

Assignments (9)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2018
From: AIRAMO, OTTO; RAHKONEN, VALTTERI; SYVÄNNE, TUOMO
To: FORCEPOINT LLC
Reel/Frame 047201/0564 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2018
From: HALME, MIRJA
To: FORCEPOINT LLC
Reel/Frame 047259/0425 →