IP Library › Granted Patent US 11,425,029
Granted Patent B2
US 11,425,029 · App. 16/919,132 · Granted Aug 23, 2022

Internal network monitoring system and method

Inventors: Hua-Chung Kung (New Taipei, TW); Shih-Chan Huang (New Taipei, TW)
Assignee: QNAP SYSTEMS, INC.
H04L45/22H04L45/74H04L47/12H04L67/1095H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,425,029
App. No.
16/919,132
Granted
Aug 23, 2022
Kind
B2
Abstract

In an internal network monitoring method for monitoring an internal network, a specified network packet, which is scheduled to be transmitted via a specified path, is inspected. A packet characteristic is extracted from a data link layer of the specified network packet. The specified network packet is directly transmitted via the specified path if the packet characteristic does not comply with a preset condition. The specified network packet is redirected to be transmitted via another path different from the specified path or mirroring the specified network packet to create a mirror packet if the packet characteristic complies with the preset condition.

Claims (32)

1. An internal network monitoring method for use with a network fire switch for monitoring an internal network, the network fire switch including a plurality of network connection ports, the method comprising:

inspecting a specified network packet received from a designated one of the plurality of network connection ports and scheduled to be transmitted to another one of the plurality of network connection ports via a specified path;

extracting a packet characteristic from a data link layer of the specified network packet;

directly transmitting the specified network packet to the another one of the plurality of network connection ports via the specified path if the packet characteristic does not comply with a preset condition; and

redirecting the specified network packet to be transmitted via another path different from the specified path or mirroring the specified network packet to create a mirror packet if the packet characteristic complies with the preset condition.

2. The method according to claim 1 , wherein the specified network packet is transmitted via the specified path while the mirror packet is created.

3. The method according to claim 1 , wherein the packet characteristic includes a network address of a source device initiating the specified network packet, and the preset condition is that the source device is new to the internal network within a specified period of time.

4. The method according to claim 1 , wherein the packet characteristic includes a network address of a source device initiating the specified network packet, and the preset condition is that a count of different destination network addresses that the source device visits within a specified duration reaches a threshold.

5. The method according to claim 1 , wherein the packet characteristic includes a network address of a source device initiating the specified network packet, and the preset condition is that a count of different communication interfaces that the source device visits within a specified duration reaches a threshold.

6. The method according to claim 1 , wherein the packet characteristic includes a destination network address that the specified network packet is to be transmitted to, and the preset condition is that a count of network packets to be transmitted from the source device to the destination network address reaches a preset value.

7. The method according to claim 1 , wherein the packet characteristic includes a destination network address that the specified network packet is to be transmitted to, and the preset condition is that a traffic between the source device and the destination network address reaches a threshold.

8. The method according to claim 1 , further comprising:

providing at least one bait device to camouflage an internal network device, and assigning a network address to each of the at least one bait device; and

when a destination network address that the specified network packet is to be transmitted to is the network address of the at least one bait device, increasing a count of network packets to be transmitted from the source device to the destination network address.

9. The method according to claim 8 , wherein the at least one bait device is implemented with a virtual device or a container.

10. The method according to claim 8 , wherein the at least one bait device includes a deeply inspecting module for analyzing network packets to be transmitted from the source device to the destination network address, which is the network address of the at least one bait device.

11. The method according to claim 1 , further comprising:

determining whether the specified network packet or the mirror packet complies with a preset rule; and

issuing an alarm signal, restricting a transmission rate via the specified path and/or interrupting the specified path if the specified network packet or the mirror packet complies with the preset rule.

12. An internal network monitoring system, comprising:

a network fire switch including a plurality of network connection ports, which include a first network connection port, which is designated to receive a specified network packet transmitted from a first internal network,

wherein in a case that the specified network packet received from the first network connection port is scheduled to be transmitted to another one of the plurality of network connection ports via a specified path, the network fire switch extracts a packet characteristic from a data link layer of the specified network packet; directly transmits the specified network packet to the another one of the plurality of network connection ports via the specified path if the packet characteristic does not comply with a preset condition; and redirects the specified network packet to be transmitted via another path different from the specified path or mirroring the specified network packet to create a mirror packet if the packet characteristic complies with the preset condition.

13. The system according to claim 12 , wherein the specified network packet is transmitted via the specified path while the mirror packet is created.

14. The system according to claim 12 , further comprising a network repeater, which includes a second network connection port in communication with the first internal network, and a plurality of third network connection ports, each in communication with a second internal network, wherein the specified network packet, if being received from the second internal network via one of the third network connection ports, is transmitted to the first internal network via the second network connection port without being transmitted via the other ones of the third network connection ports.

15. The system according to claim 12 , wherein the network fire switch includes:

a monitoring device electrically coupled to the first network connection port, inspecting the specified network packet, extracting the packet characteristic; directly transmitting the specified network packet via the specified path if the packet characteristic does not comply with the preset condition; and redirecting the specified network packet to be transmitted via the another path if the packet characteristic complies with the preset condition; and

a firewall device electrically coupled to the specified path for receiving the specified network packet, determining whether the specified network packet complies with a preset rule or not, and transmitting the specified network packet via still another path back to the specified path if the specified network packet does not comply with the preset rule.

16. The system according to claim 12 , wherein the network fire switch includes:

a monitoring device electrically coupled to the first network connection port, inspecting the specified network packet, extracting the packet characteristic; directly transmitting the specified network packet via the specified path if the packet characteristic does not comply with the preset condition; and mirroring the specified network packet to create the mirror packet if the packet characteristic complies with the preset condition; and

a firewall device electrically coupled to the specified path for receiving the mirror packet, determining whether the mirror packet complies with a preset rule or not, and issuing an alarm signal, restricting a transmission rate via the specified path and/or interrupting the specified path if the specified network packet complies with the preset rule.

17. The system according to claim 16 , wherein the network fire switch further includes at least one bait device, which camouflages an internal network device and is assigned with a network address, and the monitoring device records the network address of the at least one bait device, and determines that the specified network packet complies with the preset condition if a count of network packets to be transmitted from a source device initiating the specified network packet to a destination network address, which is the network address of the at least one bait device, reaches a threshold.

18. The system according to claim 15 , wherein the network fire switch further includes at least one bait device, which camouflages an internal network device and is assigned with a network address, and the monitoring device records the network address of the at least one bait device, and determines that the specified network packet complies with the preset condition if a count of network packets to be transmitted from a source device initiating the specified network packet to a destination network address, which is the network address of the at least one bait device, reaches a threshold.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2020
From: KUNG, HUA-CHUNG; HUANG, SHIH-CHAN
To: QNAP SYSTEMS, INC.
Reel/Frame 053105/0485 →
Continuity (2)
Provisional Application 62945938 · Dec 10, 2019
Related Publication 20210176164A1 · Jun 10, 2021