IP Library Granted Patent US 10,931,797
Granted Patent B2
US 10,931,797 · App. 16/854,094 · Granted Feb 23, 2021

Correlating packets in communications networks

Inventors: David K. Ahn (Winston-Salem, NC); Peter P. Geremia (Portsmouth, NH); Pierre Mallett, III (Herndon, VA); Sean Moore (Hollis, NH); Robert T. Perry (Ashburn, VA)
Assignee: Centripetal Networks, Inc.
H04L69/22H04L43/026H04L43/04H04L43/12H04L45/745H04L47/2483H04L47/32H04L61/2567H04L63/0263H04L43/087H04L43/106H04L43/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,931,797
App. No.
16/854,094
Filed
Apr 21, 2020
Granted
Feb 23, 2021
Kind
B2
Examiner
HUQ, OBAIDUL
Art Unit
2473
USPC
370/329
Abstract

A computing system may identify packets received by a network device from a host located in a first network and may generate log entries corresponding to the packets received by the network device. The computing system may identify packets transmitted by the network device to a host located in a second network and may generate log entries corresponding to the packets transmitted by the network device. Utilizing the log entries corresponding to the packets received by the network device and the log entries corresponding to the packets transmitted by the network device, the computing system may correlate the packets transmitted by the network device with the packets received by the network device.

Claims (62)

1. A method comprising:

determining, by a computing system, a first plurality of log entries corresponding to a first plurality of packets received by a network device from a first host located in a first network;

determining a second plurality of log entries corresponding to a second plurality of packets transmitted by the network device to a second host located in a second network;

correlating, by the computing system, the second plurality of packets transmitted by the network device with the first plurality of packets received by the network device by comparing at least a first portion of the first plurality of log entries with at least a second portion of the second plurality of log entries;

determining a correlation based on correlating the first plurality of packets and the second plurality of packets;

generating, by the computing system and based on the determined correlation, one or more rules configured to identify packets received from the first host; and

provisioning a packet-filtering device with the one or more rules.

2. The method of claim 1 , further comprising:

provisioning, by the computing system and based on the determined correlation, a first tap associated with the first network with one or more first rules configured to identify the first plurality of packets received by the network device; and

provisioning, by the computing system and based on the determined correlation, a second tap associated with the second network with one or more second rules configured to identify the second plurality of packets transmitted by the network device.

3. The method of claim 1 , wherein comparing the at least the first portion of the first plurality of log entries with the at least the second portion of the second plurality of log entries comprises:

comparing one or more first ports indicated by the first plurality of log entries with one or more second ports indicated by the second plurality of log entries.

4. The method of claim 1 , wherein comparing the at least the first portion of the first plurality of log entries with the at least the second portion of the second plurality of log entries comprises:

comparing one or more first network-interface identifiers indicated by the first plurality of log entries with one or more second network-interface identifiers indicated by the second plurality of log entries.

5. The method of claim 1 , wherein comparing the at least the first portion of the first plurality of log entries with the at least the second portion of the second plurality of log entries comprises:

comparing one or more first times indicated by the first plurality of log entries with one or more second times indicated by the second plurality of log entries.

6. The method of claim 1 , wherein:

the first plurality of log entries comprises a first plurality of timestamps indicating times corresponding to receipt, by the network device, of the first plurality of packets received by the network device;

the second plurality of log entries comprises a second plurality of timestamps indicating times corresponding to transmission, by the network device, of the second plurality of packets transmitted by the network device; and

comparing the at least the first portion of the first plurality of log entries with the at least the second portion of the second plurality of log entries comprises comparing the first plurality of timestamps with the second plurality of timestamps.

7. The method of claim 1 , further comprising:

determining, by the computing system, that the first host is associated with a malicious entity; and

causing one or more computing devices associated with the first network to drop packets transmitted by the first host.

8. The method of claim 1 , further comprising:

generating, by the computing system, a message identifying the first host; and

sending the message.

9. The method of claim 1 , wherein the second plurality of packets transmitted by the network device are encrypted.

10. The method of claim 1 , wherein the second plurality of packets transmitted by the network device are encapsulated.

11. The method of claim 1 , wherein generating the one or more rules comprises:

receiving user input defining the one or more rules.

12. A computing device comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the computing device to:

determine a first plurality of log entries corresponding to a first plurality of packets received by a network device from a first host located in a first network;

determine a second plurality of log entries corresponding to a second plurality of packets transmitted by the network device to a second host located in a second network;

correlate the second plurality of packets transmitted by the network device with the first plurality of packets received by the network device by comparing at least a first portion of the first plurality of log entries with at least a second portion of the second plurality of log entries;

determine a correlation based on correlating the first plurality of packets and the second plurality of packets;

generate, based on the determined correlation, one or more rules configured to identify packets received from the first host; and

provision a packet-filtering device with the one or more rules.

13. The computing device of claim 12 , wherein the instructions, when executed by the one or more processors, further cause the computing device to:

provision, based on the determined correlation, a first tap associated with the first network with one or more first rules configured to identify the first plurality of packets received by the network device; and

provision, based on the determined correlation, a second tap associated with the second network with one or more second rules configured to identify the second plurality of packets transmitted by the network device.

14. The computing device of claim 12 , wherein the instructions, when executed by the one or more processors, further cause the computing device to compare the at least the first portion of the first plurality of log entries with the at least the second portion of the second plurality of log entries by:

comparing one or more first ports indicated by the first plurality of log entries with one or more second ports indicated by the second plurality of log entries.

15. The computing device of claim 12 , wherein the instructions, when executed by the one or more processors, further cause the computing device to compare the at least the first portion of the first plurality of log entries with the at least the second portion of the second plurality of log entries by:

comparing one or more first network-interface identifiers indicated by the first plurality of log entries with one or more second network-interface identifiers indicated by the second plurality of log entries.

16. The computing device of claim 12 , wherein the instructions, when executed by the one or more processors, further cause the computing device to compare the at least the first portion of the first plurality of log entries with the at least the second portion of the second plurality of log entries by:

comparing one or more first times indicated by the first plurality of log entries with one or more second times indicated by the second plurality of log entries.

17. One or more non-transitory computer-readable media comprising instructions that, when executed by one or more processors of a computing device, cause the computing device to:

determine a first plurality of log entries corresponding to a first plurality of packets received by a network device from a first host located in a first network;

determine a second plurality of log entries corresponding to a second plurality of packets transmitted by the network device to a second host located in a second network;

correlate the second plurality of packets transmitted by the network device with the first plurality of packets received by the network device by comparing at least a first portion of the first plurality of log entries with at least a second portion of the second plurality of log entries;

determine a correlation based on correlating the first plurality of packets and the second plurality of packets;

generate, based on the determined correlation, one or more rules configured to identify packets received from the first host; and

provision a packet-filtering device with the one or more rules.

18. The one or more non-transitory computer-readable media of claim 17 , wherein the instructions, when executed by the one or more processors of the computing device, further cause the computing device to:

provision based on the determined correlation, a first tap associated with the first network with one or more first rules configured to identify the first plurality of packets received by the network device; and

provision, based on the determined correlation, a second tap associated with the second network with one or more second rules configured to identify the second plurality of packets transmitted by the network device.

19. The one or more non-transitory computer-readable media of claim 17 , wherein the instructions, when executed by the one or more processors of the computing device, further cause the computing device to compare the at least the first portion of the first plurality of log entries with the at least the second portion of the second plurality of log entries by:

comparing one or more first ports indicated by the first plurality of log entries with one or more second ports indicated by the second plurality of log entries.

20. The one or more non-transitory computer-readable media of claim 17 , wherein the instructions, when executed by the one or more processors of the computing device, further cause the computing device to compare the at least the first portion of the first plurality of log entries with the at least the second portion of the second plurality of log entries by:

comparing one or more first network-interface identifiers indicated by the first plurality of log entries with one or more second network-interface identifiers indicated by the second plurality of log entries.

Assignments (2)
CHANGE OF NAME Recorded Jan 20, 2023
From: CENTRIPETAL NETWORKS, INC.
To: CENTRIPETAL NETWORKS, LLC
Reel/Frame 062446/0660 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2020
From: AHN, DAVID K.; GEREMIA, PETER P.; MALLETT, PIERRE, III; MOORE, SEAN; PERRY, ROBERT T.
To: CENTRIPETAL NETWORKS, INC.
Reel/Frame 052452/0811 →
Continuity (5)
Continuation 16554293 · Aug 28, 2019
Continuation 15413947 · Jan 24, 2017
Continuation 14714207 · May 15, 2015
Continuation 14618967 · Feb 10, 2015
Related Publication 20200252486A1 · Aug 6, 2020
Cited By (3)
US 12,248,616 US 12,647,336 US 12,712,898