IP Library Granted Patent US 10,834,116
Granted Patent B2
US 10,834,116 · App. 16/778,396 · Granted Nov 10, 2020

Secure digital traffic analysis

Inventors: Christopher D. Nyhuis (Mason, OH); Michael Pananen (Lebanon, OH)
Assignee: Vigilant IP Holdings LLC
H04L63/1425G06F21/53H04L9/3236H04L63/0428H04L63/0876H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,834,116
App. No.
16/778,396
Granted
Nov 10, 2020
Kind
B2
Abstract

A network monitoring “sensor” is built on initial startup by checking the integrity of the bootstrap system and, if it passes, downloading information from which it builds the full system including an encrypted and an unencrypted portion. Later, the sensor sends hashes of files, configurations, and other local information to a data center, which compares the hashes to hashes of known-good versions. If they match, the data center returns information (e.g., a key) that the sensor can use to access the encrypted storage. If they don't, the data center returns information to help remediate the problem, a command to restore some or all of the sensor's programming and data, or a command to wipe the encrypted storage. The encrypted storage stores algorithms and other data for processing information captured from a network, plus the captured/processed data itself.

Claims (24)

1. A network sensor comprising:

a network tap configured to receive a set of data traveling on a network;

an encrypted storage configured to store a set of threat analysis instructions;

a processor and memory configured to analyze the set of data and identify threats using the set of threat analysis instructions; and

a sandbox configured to store the set of data during analysis;

wherein the processor is configured to, during a boot process:

place the encrypted storage into an unmounted state;

receive a set of verification data from a remote server;

determine whether the encrypted storage is valid as a function of the set of verification data; and

if the encrypted storage is valid, mount the encrypted storage and complete the boot process.

2. The network sensor of claim 1 , wherein the processor is further configured to, if the encrypted storage is not valid, execute error-handling code.

3. The network sensor of claim 2 , wherein the error-handling code is configured to cause the processor to wipe the contents of the encrypted storage.

4. The network sensor of claim 2 , wherein the error-handling code is configured to cause the processor to restore the contents of the encrypted storage to a previous state.

5. The network sensor of claim 1 , wherein the verification data comprises a decryption key.

6. The network sensor of claim 1 , wherein the verification data comprises a first portion of a split key.

7. The network sensor of claim 6 , wherein a second portion of the split key is stored locally on the network sensor.

8. The network sensor of claim 7 , wherein the processor is configured to determine the validity of the encrypted storage as a function of both the first portion and the second portion of the split key.

9. A method for monitoring network traffic using a network sensor that comprises a network tap configured to receive a set of data traveling on a network, encrypted storage configured to store a set of threat analysis instructions, a processor and memory configured to analyze the set of data and identify threats using the set of threat analysis instructions, and a sandbox configured to store the set of data during analysis, the method comprising the steps: placing the encrypted storage into an unmounted state during a boot process; receiving a set of verification data from a remote server; as a function of the set of verification data, determining whether the encrypted storage is valid; and if the encrypted storage is valid, mounting the encrypted storage and completing the boot process.

10. The method of claim 9 , further comprising the step of, where the encrypted storage is not valid, executing error-handling code.

11. The network sensor of claim 10 , wherein the error-handling code is configured to cause the processor to wipe the contents of the encrypted storage.

12. The network sensor of claim 10 , wherein the error-handling code is configured to cause the processor to restore the contents of the encrypted storage to a previous state.

13. The method of claim 10 , wherein the verification data comprises a first portion of a split key.

14. The method of claim 13 , wherein a second portion of the split key is stored locally on the network sensor.

15. The method of claim 14 , wherein the processor is configured to determine the validity of the encrypted storage as a function of both the first portion and the second portion of the split key.

Assignments (3)
CHANGE OF ADDRESS Recorded Dec 11, 2020
From: VIGILANT IP HOLDINGS LLC
To: VIGILANT IP HOLDINGS LLC
Reel/Frame 054681/0469 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2020
From: NYHUIS, CHRISTOPHER M.; PANANEN, MICHAEL
To: VIGILANT, LLC
Reel/Frame 053457/0701 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2020
From: VIGILANT, LLC
To: VIGILANT IP HOLDINGS LLC
Reel/Frame 053457/0800 →
Continuity (4)
Division 15861150 · Jan 3, 2018
Division 14866834 · Sep 25, 2015
Provisional Application 62055043 · Sep 25, 2014
Related Publication 20200228556A1 · Jul 16, 2020