IP Library Granted Patent US 11,133,999
Granted Patent B1
US 11,133,999 · App. 16/874,962 · Granted Sep 28, 2021

Network sensor deployment for deep packet inspection

Inventors: John Brosnan (Galway, IE); Jeff Myers (Somerville, MA); Andriy Lyubka (Galway, IE); Darragh Delaney (Claremorris, IE); Erran Carey (Newtownabbey, GB); Martin Hutchings (Lisburn, GB); Ralph McTeggart (Belfast, GB); Ryan Williams (Belfast, GB); Daniel Skelton (Belfast, GB); Luke Coughlin (Galway, IE); Gianni Tedesco (Seoul, KR); Luis Ramos dos Santos Lopes (Galway, IE); Lars-Kristian Svenoy (Belfast, GB); Dan-Adrian Moinescu (Braila, RO); Niall Cochrane (Belfast, GB); Morgan Doyle (Kinvara, IE); Sarah Addis (Belfast, GB)
Assignee: Rapid7, Inc.
H04L43/0894G06F9/445G06F9/455H04L47/2441H04L47/35H04L47/36H04L63/06H04L63/14H04L67/12H04L41/046H04L41/0806
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,133,999
App. No.
16/874,962
Granted
Sep 28, 2021
Kind
B1
Abstract

Disclosed herein are methods, systems, and processes for centralized containerized deployment of network traffic sensors to network sensor hosts for deep packet inspection (DPI) that supports various other cybersecurity operations. A network sensor package containing a pre-configured network sensor container is received by a network sensor host from a network sensor deployment server. Installation of the network sensor package on the network sensor host causes execution of the network sensor container that further causes deployment of an on-premise network sensor along with a network sensor management system, a DPI system, and an intrusion detection/prevention (IDS/IPS) system. The configurable on-premise network sensor is deployed on multiple operating system distributions of the network sensor host and generates actionable network metadata using DPI techniques for optimized log search and management and improved intrusion detection and response (IDR) operations.

Claims (14)

1. A computer-implemented method, comprising:

receiving a network sensor package from a network sensor deployment server at a network sensor host;

installing the network sensor package on the network sensor host; receiving a network sensor container from the network sensor deployment server based on the installation;

executing the network sensor container on the network sensor host upon receiving the network sensor container; and

deploying a network sensor on the network sensor host, wherein the network sensor package is associated with a token, the network sensor package utilizes the token to obtain a certificate and a private key to establish secure communication with the network sensor deployment server to receive the network sensor container, the network sensor package comprises at least a bootstrap, the network sensor container, and an agent, the network sensor package deploys the network sensor, and the bootstrap starts the network sensor container on the network sensor host, wherein the network sensor container isolates a plurality of network sensor applications executing on the network sensor host from a host operating system (OS) associated with the network sensor host, wherein the network sensor container comprises at least a network sensor deployment engine, a deep packet inspection (DPI) engine, and an intrusion detection system (IDS), wherein the network sensor deployment engine determines that the network sensor is in deployment mode, enumerates one or more network interface cards (NICs) on the sensor host, transmits a topology status to the network sensor deployment server, and requests a configuration file from the network sensor deployment server, wherein the network sensor deployment server identifies the network sensor, selects a network interface to utilize as a sensor interface, generates the configuration file, and transmits the configuration file to the network sensor, wherein the network sensor downloads the configuration file, validates the configuration file, and initiates the DPI engine and the IDS, wherein the network sensor transmits network events from the IDS and network metadata from the DPI engine to the network sensor deployment server via a socket associated with the network sensor host.

2. A non-transitory computer readable storage medium comprising program instructions executable to:

receive a network sensor package from a network sensor deployment server at a network sensor host;

install the network sensor package on the network sensor host; receive a network sensor container from the network sensor deployment server;

execute the network sensor container on the network sensor host; and deploy a network sensor on the network sensor host, wherein the network sensor Package is associated with a token, the network sensor Package utilizes the token to obtain a certificate and a private key to establish secure communication with the network sensor deployment server to receive the network sensor container, the network sensor package comprises at least a bootstrap, the network sensor container, and an agent, the network sensor package deploys the network sensor, the bootstrap starts the network sensor container on the network sensor host, the network sensor container isolates a plurality of network sensor applications executing on the network sensor host from a host operating system (OS) associated with the network sensor host, the network sensor container comprises at least a network sensor deployment engine, a deep packet inspection (DPI) engine, and an intrusion detection system (IDS), the network sensor deployment engine determines that the network sensor is in deployment mode, enumerates one or more network interface cards (NICs) on the sensor host, transmits a topology status to the network sensor deployment server, and requests a configuration file from the network sensor deployment server, the network sensor deployment server identifies the network sensor, selects a network interface to utilize as a sensor interface, generates the configuration file, and transmits the configuration file to the network sensor, the network sensor downloads the configuration file, validates the configuration file, and initiates the DPI engine and the IDS, and the network sensor transmits network events from the IDS and network metadata from the DPI engine to the network sensor deployment server via a socket associated with the network sensor host.

3. A system comprising:

one or more processors; and a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

receive a network sensor package from a network sensor deployment server at a network sensor host;

install the network sensor package on the network sensor host; receive a network sensor container from the network sensor deployment server;

execute the network sensor container on the network sensor host; and deploy a network sensor on the network sensor host, wherein the network sensor package is associated with a token, the network sensor package utilizes the token to obtain a certificate and a private key to establish secure communication with the network sensor deployment server to receive the network sensor container, the network sensor package comprises at least a bootstrap, the network sensor container, and an agent, the network sensor package deploys the network sensor, the bootstrap starts the network sensor container on the network sensor host, the network sensor container isolates a plurality of network sensor applications executing on the network sensor host from a host operating system (OS) associated with the network sensor host, the network sensor container comprises at least a network sensor deployment engine, a deep packet inspection (DPI) engine, and an intrusion detection system (IDS), the network sensor deployment engine determines that the network sensor is in deployment mode, enumerates one or more network interface cards (NICs) on the sensor host, transmits a topology status to the network sensor deployment server, and requests a configuration file from the network sensor deployment server, the network sensor deployment server identifies the network sensor, selects a network interface to utilize as a sensor interface, generates the configuration file, and transmits the configuration file to the network sensor, the network sensor downloads the configuration file, validates the configuration file, and initiates the DPI engine and the IDS, and the network sensor transmits network events from the IDS and network metadata from the DPI engine to the network sensor deployment server via a socket associated with the network sensor host.

Assignments (3)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2020
From: HUTCHINGS, MARTIN TRAVIS; LYUBKA, ANDRIY
To: RAPID7, INC.
Reel/Frame 053827/0522 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2020
From: ADDIS, SARAH; BROSNAN, JOHN; CAREY, ERRAN; COCHRANE, NIALL; COUGHLAN, LUKE; DELANEY, DARRAGH; DOYLE, MORGAN; LOPES, LUIS; MCTEGGART, RALPH; MOINESCU, DAN-ADRIAN; MYERS, JEFFREY; SKELTON, DANIEL; SVENOY, LARS-KRISTIAN; TEDESCO, GIANPAOLO; WILLIAMS, RYAN
To: RAPID7, INC.
Reel/Frame 053768/0049 →
Continuity (1)
Provisional Application 62910745 · Oct 4, 2019
Cited By (6)
US 12,438,955 US 12,455,968 US 12,474,950 US 12,476,862 US 12,500,944 US 12,712,890