IP Library Granted Patent US 11,050,714
Granted Patent B2
US 11,050,714 · App. 16/170,859 · Granted Jun 29, 2021

System and method of utilizing network security devices for industrial device protection and control

Inventors: Martin Weisshaupt (Innsbruck, AT); Reinhard Staudacher (Innsbruck, AT); Christoph Rauchegger (Innsbruck, AT)
Assignee: Barracuda Networks, Inc.
H04L63/0263G05B19/4185H04L63/101H04L63/1416H04L63/1441H04L63/20H04L67/025H04L67/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,050,714
App. No.
16/170,859
Granted
Jun 29, 2021
Kind
B2
Abstract

A new network security device/appliance is proposed to not only protect, but also to control and operate an industrial IoT device. Specifically, the network security device is configured to detect and block cyber attacks such as viruses, hacking attempts, and other types of cyber threats launched from an outside network against the industrial IoT device based on a set of configurable rules. In addition, the network security device is further configured to control and operate the industrial IoT device remotely in response to the cyber attacks by issuing and communicating certain instructions/command to the industrial IoT device. Besides accepting and executing control command from the network security device, the industrial IoT device is also configured to send a request to the network security device to make certain adjustments to the rules concerning network traffic directed to the industrial IoT device.

Claims (44)

1. A system to support utilizing network security devices for industrial IoT device protection and control, comprising:

a network security device configured to

detect and block a cyber attack launched from an outside network against a network-enabled industrial IoT device based on a set of configurable rules;

issue and communicate a control command to the network-enabled industrial IoT device following a communication protocol to control and perform an operation of the network-enabled industrial IoT device remotely in response to the detected cyber attack;

adjust one or more of the configurable rules concerning network traffic directed to the network-enabled industrial IoT device in response to a request from the network-enabled industrial IoT device;

said network-enabled industrial IoT device configured to

accept and execute the control command from the network security device to perform the operation;

communicate said request to the network security device following the communication protocol to make certain adjustment to said one or more of the configurable rules concerning network traffic directed to the network-enabled industrial IoT device.

2. The system of claim 1 , wherein:

the communication protocol is a REpresentational State Transfer (REST), a HTTP or a HTTPS protocol.

3. The system of claim 1 , wherein:

the communication protocol is a proprietary network communication protocol.

4. The system of claim 1 , wherein:

the cyber attack is one of virus, a hacking attempt, a phishing attack.

5. The system of claim 1 , wherein:

the command issued by the network security device and the operations performed by the industrial IoT device as a result of executing the command are pre-defined, configured, and customized by the network security device and the industrial IoT device.

6. The system of claim 1 , wherein:

the network security device is configured to communicate the command to the network-enabled industrial IoT device by invoking an Application Program Interface (API) of the network-enabled industrial IoT device.

7. The system of claim 1 , wherein:

the one or more of the configurable rules include a block rule in place by default on the network security device to block all unauthorized access attempt to the industrial IoT device.

8. The system of claim 7 , wherein:

the one or more of the configurable rules further include an unblock rule on the network security device to allow certain network traffic to the industrial IoT device under certain circumstance and/or event.

9. The system of claim 8 , wherein:

the network security device is configured to

activate the unblock rule to allow network traffic directed to the network-enabled industrial IoT device during maintenance of the network-enabled industrial IoT device;

deactivate the unblock rule to block the network traffic directed to the network-enabled industrial IoT device after the maintenance of the network-enabled industrial IoT device.

10. A computer-implemented method to support utilizing network security devices for industrial IoT device protection and control, comprising:

detecting and blocking a cyber attack launched from an outside network against a network-enabled industrial IoT device based on a set of configurable rules;

issuing and communicating a control command to the network-enabled industrial IoT device following a communication protocol to control and perform an operation of the network-enabled industrial IoT device remotely in response to the detected cyber attack;

accepting and executing the control command from the network security device to perform the operation on the network-enabled industrial IoT device;

communicating said request to the network security device following the communication protocol to make certain adjustment to said one or more of the configurable rules concerning network traffic directed to the network-enabled industrial IoT device;

adjusting one or more of the configurable rules concerning network traffic directed to the network-enabled industrial IoT device in response to a request from the network-enabled industrial IoT device.

11. The method of claim 10 , further comprising:

pre-defining, configuring, and customizing the command issued by the network security device and the operations performed by the industrial IoT device as a result of executing the command by the network security device and the industrial IoT device.

12. The method of claim 10 , further comprising:

communicating the command to the network-enabled industrial IoT device by invoking an Application Program Interface (API) of the network-enabled industrial IoT device.

13. The method of claim 10 , further comprising:

activating an unblock rule to allow network traffic directed to the network-enabled industrial IoT device during a certain event.

14. The method of claim 13 , further comprising:

deactivating the unblock rule to block the network traffic directed to the network-enabled industrial IoT device after the event is over.

15. The method of claim 10 , further comprising:

deactivating a block rule, which blocks all unauthorized access attempt to the industrial IoT device by default, to allow the traffic to be processed by a following active unblock rule during a certain event.

16. The method of claim 15 , further comprising:

reactivating the block rule to block the network traffic directed to the network-enabled industrial IoT device after the event is over.

Assignments (8)
SECURITY INTEREST Recorded Mar 17, 2025
From: BARRACUDA NETWORKS, INC.
To: OAKTREE FUND ADMINISTRATION, LLC, AS COLLATERAL AGENT
Reel/Frame 070529/0123 →
SECURITY INTEREST Recorded Sep 3, 2022
From: BARRACUDA NETWORKS, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 061377/0208 →
SECURITY INTEREST Recorded Sep 3, 2022
From: BARRACUDA NETWORKS, INC.
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 061377/0231 →
RELEASE OF SUPPLEMENTAL FIRST LIEN SECURITY INTEREST IN IP RECORDED AT R/F 054260/0605 Recorded Aug 16, 2022
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 061179/0896 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN IP RECORDED AT R/F 054260/0746 Recorded Aug 16, 2022
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 061521/0086 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 30, 2020
From: BARRAUDA NETWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 054260/0746 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT Recorded Oct 30, 2020
From: BARRAUDA NETWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 054260/0605 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2018
From: WEISSHAUPT, MARTIN; STAUDACHER, REINHARD; RAUCHEGGER, CHRISTOPH
To: BARRACUDA NETWORKS, INC.
Reel/Frame 047314/0340 →