IP Library Granted Patent US 11,588,840
Granted Patent B2
US 11,588,840 · App. 16/778,325 · Granted Feb 21, 2023

Automated encryption degradation detection, reporting and remediation

Inventor: Ramesh Ramani (Sunnyvale, CA)
Assignee: SALESFORCE, INC.
H04L63/1425H04L63/0209H04L63/105H04L63/126H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,588,840
App. No.
16/778,325
Granted
Feb 21, 2023
Kind
B2
Abstract

Communication security is an ongoing problem. Over time, various protocols have been used and then replaced due to insufficient protection. For example, some client/server web communication used to rely on Secure Socket Layers (SSL) to protect communication, but was replaced with a more secure Transport Layer Security (TLS) protocol. TLS itself has undergone several revisions, and TLS 1.0 is now considered not secure. TLS and other protocols provide backwards compatibility, so while a higher security level is desired, communication may fallback to an undesirable level, e.g., TLS 1.0, if required by either communication endpoint. An intermediary to communication with an organization may capture data to facilitate analyzing it to determine what caused a fallback, and to decide if and how to remediate it. Remediation may vary depending on, for example, whether the cause was from within the organization, or external, such as from a client.

Claims (96)

1. A method to remediate a communication using one or more network, from a source through an intermediary to a destination, the one or more network communicatively coupled with a data exchange service providing a messaging system, the method comprising:

negotiating a negotiated security level for the communication using the one or more network, the negotiating including monitoring a handshake between the source and the destination;

determining an origin for a request during the handshake for the communication at a preferred security level;

evaluating whether the negotiated security level is below a threshold;

capturing, based at least in part on the evaluating the threshold, at least a portion of data passing between the source and the destination;

determining characteristics of the communication based at least in part on the capturing;

sending a message identifying at least the characteristics by the messaging system provided by the data exchange service; and

performing a threat assessment for the communication based at least in part on the source, the destination, the origin, and the characteristics.

2. The method of claim 1 , in which the negotiated security level failing the threshold, the method further comprising:

configuring the destination to communicate at the preferred security level satisfying the threshold; and

switching, based at least in part on the origin, from the preferred security level to the negotiated security level.

3. The method of claim 1 , in which a cloud service hosts the destination and the cloud service provides a detector service, the method further comprising:

instructing the intermediary to perform the capturing;

enabling the detector service to receive the characteristics of the communication; and

receiving an analysis of the communication from the detector service indicating at least an origin of the negotiated security level below the threshold;

wherein the sending the message by the messaging system operates independently of the negotiating the negotiated security level for the communication.

4. The method of claim 1 , in which one or more clients, including the source, communicate with one or more servers, including the destination, through one or more firewalls, including the intermediary, the method further comprising:

selecting the intermediary from among the one or more firewalls; instructing the intermediary to perform the capturing the at least a portion of data passing between the source and the destination; and

instructing the intermediary to block the communication between the source and the destination based at least in part on the threat assessment.

5. The method of claim 4 , in which a detector service is configured to execute a program to direct the detector service to:

perform the threat assessment; and

monitor the handshake between the source and the destination to at least identify the origin for the request for, communication at the preferred security level, the handshake establishing the negotiated security level below the threshold.

6. The method of claim 5 , further comprising:

determining the origin is the source; and

instructing the intermediary to block at least communication from the source using the negotiated security level failing the threshold.

7. The method of claim 1 , in which a firewall including the intermediary is communicatively coupled over the one or more network with a communication server including the data exchange service providing the messaging system, the method further comprising:

including the characteristics in the message;

sending the message to the communication server; and

storing the characteristics of the communication with a cloud service, wherein the cloud service is to run a detector service to access the firewall and direct the firewall to perform the capturing the portion of data.

8. The method of claim 1 , in which multiple destinations share a network address with the destination and the negotiated security level being below the threshold, the method further comprising:

analyzing the portion of data to identify a server name provided by the source to identify the destination for the communication, wherein the destination is configured to respond with an identity certificate corresponding to the server name;

identifying the origin for the request for the negotiated security level below the threshold; and

including, in the characteristics, at least the server name and the origin.

9. The method of claim 8 , the method further comprising:

capturing the portion of data with the intermediary;

if the origin for the request is the source: configuring the intermediary to block a further communication from the source, and including an indicator of blocking the further communication in the characteristics; and

if the origin for the request is the destination: flagging the communication for review.

10. A system to remediate a communication using one or more network, from a source through an intermediary to a destination, the one or more network also communicatively coupled with a data exchange service providing a messaging system, comprising: a processor; and memory coupled to the processor and storing instructions that, when executed by the processor, cause the system to:

negotiate a negotiated security level for the communication using the one or more network, the negotiate to include to monitor a handshake between the source and the destination;

determine an origin for a request during the handshake for the communication at a preferred security level;

evaluate whether the negotiated security level is below a threshold;

capture, based at least in part on the evaluating the threshold, at least a portion of data passing between the source and the destination;

determine characteristics of the communication based at least in part on the capturing;

send a message to identify at least the characteristics by the messaging system provided by the data exchange service; and

perform a threat assessment for the communication based at least in part on the source, the destination, the origin, and the characteristics.

11. The system of claim 10 , the instructions including further instructions to cause the system to:

configure the destination to communicate at the preferred security level satisfying the threshold; and

switch, based at least in part on the origin, from the preferred security level to the negotiated security level, the negotiated security level failing the threshold.

12. The system of claim 10 , in which a cloud service hosts the destination and the cloud service provides a detector service, the instructions including further instructions to cause the system to:

instruct the intermediary to perform the capturing;

enable the detector service to receive the characteristics of the communication; and

receive an analysis of the communication from the detector service indicating at least an origin of the negotiated security level below the threshold;

wherein the sending the message by the messaging system operates independently of the negotiating the negotiated security level for the communication.

13. The system of claim 10 , in which the intermediary is a firewall, and the destination has associated therewith a detector service to perform the threat assessment, the instructions including further instructions to cause the system to:

select the intermediary from a plurality of firewalls associated with the destination;

enable the intermediary to capture the portion of data passing between the source and the destination;

instruct the intermediary to block the communication between the source and the destination based at least in part on the threat assessment;

monitor the handshake between the source and the destination to at least identify the origin for the request for, communication at the preferred security level, the handshake establishing the negotiated security level failing the threshold; and

instruct the intermediary to block, at least temporarily, selected communication from the origin.

14. The system of claim 10 , in which a firewall including the intermediary is communicatively coupled over the one or more network with a communication server including the data exchange service providing the messaging system, the instructions including further instructions to cause the system to:

send the message to the communication server, the message to include the characteristics;

store the characteristics of the communication with a cloud service; and

instruct the cloud service to run a detector service to access the intermediary and direct the intermediary to perform the capturing the portion of data.

15. The system of claim 10 , in which a server name for the destination is included in the negotiating, the instructions including further instructions to cause the system to:

analyze the portion of data to identify the server name;

identify the origin of the negotiated security level below the threshold, and if the origin for the request is the destination, flagging the communication for review; and

include within the characteristics at least the server name and the origin.

16. A non-transitory computer readable medium having instructions stored thereon to remediate a communication using a network, from a source through an intermediary to a destination, the network communicatively coupled with a data exchange service providing a chat-based messaging system, the instructions that, in response to execution by a processor, are operable to:

negotiate a negotiated security level for the communication using the network, the negotiation to include to monitor a handshake between the source and the destination;

determine an origin for a request during the handshake for the communication at a preferred security level;

evaluate whether the negotiated security level is below a threshold;

capture, based at least in part on the evaluate the threshold, at least a portion of data passing between the source and the destination;

determine characteristics of the communication based at least in part on the capturing;

send a message to identify at least the characteristics by the chat-based messaging system; and

perform a threat assessment for the communication based at least in part on the source, the destination, the origin, and the characteristics.

17. The medium of claim 16 , the instructions including further instructions that, in response to execution by a processor, are operable to:

configure an endpoint to the communication to establish the communication at the preferred security level, the preferred security level satisfying the threshold; and

switch, based at least in part on the origin, from the preferred security level to the negotiated security level, the negotiated security level failing the threshold.

18. The medium of claim 17 , in which a cloud service hosts the destination and the cloud service provides a detector service, the instructions including further instructions that, in response to execution by a processor, are operable to:

instruct the intermediary to perform the capturing;

enable the detector service to receive the characteristics of the communication from the detector service; and

receive an analysis of the communication indicating at least an-origin of the negotiated security level below the threshold;

wherein the sending the message by the messaging system operates independently of the negotiating the negotiated security level for the communication.

19. The medium of claim 16 , in which the intermediary is a firewall, and the destination has associated therewith a detector service to perform the threat assessment, the instructions including further instructions that, in response to execution by a processor, are operable to:

select the intermediary from a plurality of firewalls associated with the destination;

enable the intermediary to capture the portion of data passing between the source and the destination;

instruct the intermediary to block the communication between the source and the destination based at least in part on the threat assessment;

monitor the handshake between the source and the destination, the handshake at least partially configured for communication at the preferred security level, and the handshake establishing the negotiated security level failing the threshold;

instruct the intermediary to provide the portion of data to the detector service;

receive from the detector service an indicator of the origin for the handshake establishing the negotiated security level;

determine the origin is the source; and

instruct the intermediary to block, at least temporarily, selected communication from a responsible entity.

20. The medium of claim 16 , in which a first server name for the destination is identified in the negotiation with the destination, the instructions including further instructions that, in response to execution by a processor, are operable to:

analyze the portion of data to identify the first server name, and to identify a second server name corresponding to the source;

identify the origin of the negotiated security level below the threshold, and if the origin for the request is the destination, flagging the communication for review; and

include within the characteristics at least the first server name, the second server name, and the origin.

Assignments (2)
CHANGE OF NAME Recorded Sep 20, 2023
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 064975/0892 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2020
From: RAMANI, RAMESH
To: SALESFORCE.COM, INC.
Reel/Frame 051684/0219 →
Continuity (1)
Related Publication 20210243209A1 · Aug 5, 2021