IP Library Granted Patent US 12,395,481
Granted Patent B2
US 12,395,481 · App. 17/180,932 · Granted Aug 19, 2025

Methods and systems for certificate filtering

Inventors: Sean Moore (Hollis, NH); David K. Ahn (Winston-Salem, NC)
Assignee: Centripetal Networks, LLC
H04L63/0823H04L63/0884H04L63/0892H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,395,481
App. No.
17/180,932
Granted
Aug 19, 2025
Kind
B2
Abstract

SSL/TLS certificate filtering devices, systems and processes may filter packets based on risk associated with each packet. A risk score may be determined for each packet based on associated threats and risks. Risk scores may be determined based on certificates, certificate authorities, and/or end users associated with each packet. The certificates may be scored and/or categorized by threats and risk.

Claims (92)

1. A method comprising:

receiving, by a certificate data collector and from one or more threat intelligence providers, threat intelligence data associated with a plurality of hosts, wherein the threat intelligence data indicates a first host that has been identified as a potential threat by the one or more threat intelligence providers;

in response to receiving the threat intelligence data, determining, by the certificate data collector, one or more certificate authorities that have issued one or more certificates to the first host;

receiving, by the certificate data collector and from one or more external systems that identify certificates and certificate authorities associated with hosts, certificate authority intelligence information associated with the one or more certificate authorities that were determined to have issued the one or more certificates to the first host;

determining a risk score associated with each certificate authority of the one or more certificate authorities, wherein the risk score associated with a particular certificate authority is determined based on:

the threat intelligence data indicating that the first host has been identified as a potential threat by the one or more threat intelligence providers; and

the certificate authority intelligence information associated with the one or more certificate authorities indicating that the particular certificate authority issued a certificate to the first host;

sending, to a client system, the determined risk scores associated with each certificate authority of the one or more certificate authorities;

generating, based on the determined risk scores associated with each certificate authority, one or more packet-filtering rules; and

sending, to a packet-filtering device associated with the client system, the one or more packet-filtering rules, wherein the packet-filtering device is configured to apply the one or more packet-filtering rules to network traffic.

2. The method of claim 1 , wherein the client system is further configured to generate, based on the determined risk scores associated with each certificate authority, one or more second packet-filtering rules.

3. The method of claim 1 , wherein the threat intelligence data comprises at least one of:

a domain name associated with the first host; or

an internet protocol (IP) address associated with the first host.

4. The method of claim 1 , wherein the one or more certificates form a chain of trust.

5. The method of claim 1 , further comprising:

determining a first risk score associated with a first certificate authority based on identifying the first certificate authority as being associated with a cyber threat organization.

6. The method of claim 1 , wherein determining the risk score associated with each certificate authority comprises:

assigning, based on one or more threat indicators identified in the threat intelligence data, a risk score to each certificate authority that issued a certificate to the first host.

7. The method of claim 1 , further comprising:

determining, based on the threat intelligence data, a second risk score associated with each respective certificate of one or more certificates issued to the first host; and

sending, by the certificate data collector and to a packet-filtering device associated with the client system, the second risk score associated with each respective certificate of the one or more certificates issued to the first host, along with the risk scores associated with each certificate authority.

8. The method of claim 7 , further comprising:

generating, based on the risk scores associated with each certificate authority and based on the second risk score associated with each respective certificate of the one or more certificates, a packet-filtering rule.

9. The method of claim 1 , wherein the risk score associated with the particular certificate authority is further based on at least one of:

a determination of whether the particular certificate authority issued a second certificate to known malware sites;

a determination of whether a second certificate has been revoked; or

a determination that the certificate issued to the first host is a self-signed certificate.

10. The method of claim 1 , wherein the client system comprises a packet-filtering device that resides at a boundary between, and interfaces with, a protected network and an unprotected network.

11. The method of claim 1 , wherein the one or more packet-filtering rules comprise one or more rules configured to:

protect a network associated with the client system from malicious network traffic; or

prevent malicious traffic from leaving the network associated with the client system.

12. A certificate data collector comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the certificate data collector to:

receive, from one or more threat intelligence providers, threat intelligence data associated with a plurality of hosts, wherein the threat intelligence data indicates a first host that has been identified as a potential threat by the one or more threat intelligence providers;

determine, in response to receiving the threat intelligence data, one or more certificate authorities that have issued one or more certificates to the first host;

receive, from one or more external systems that identify certificates and certificate authorities associated with hosts, certificate authority intelligence information associated with the one or more certificate authorities that were determined to have issued the one or more certificates to the first host;

determine a risk score associated with each certificate authority of the one or more certificate authorities, wherein the risk score associated with a particular certificate authority is determined based on:

the threat intelligence data indicating that the first host has been identified as a potential threat by the one or more threat intelligence providers; and

the certificate authority intelligence information associated with the one or more certificate authorities indicating that the particular certificate authority issued a certificate to the first host;

send, to a client system, the determined risk scores associated with each certificate authority of the one or more certificate authorities;

generate, based on the determined risk scores associated with each certificate authority, one or more packet-filtering rules; and

send, to a packet-filtering device associated with the client system, the one or more packet-filtering rules, wherein the packet-filtering device is configured to apply the one or more packet-filtering rules to network traffic.

13. The certificate data collector of claim 12 , wherein the client system is further configured to generate, based on the determined risk scores associated with each certificate authority, one or more second packet-filtering rules.

14. The certificate data collector of claim 12 , wherein the threat intelligence data comprises at least one of:

a domain name associated with the first host; or

an internet protocol (IP) address associated with the first host.

15. The certificate data collector of claim 12 , wherein the one or more certificates form a chain of trust.

16. The certificate data collector of claim 12 , wherein the instructions, when executed by the one or more processors, cause the certificate data collector to determine a first risk score associated with a first certificate authority by identifying the first certificate authority as being associated with a cyber threat organization.

17. The certificate data collector of claim 12 , wherein the instructions, when executed by the one or more processors, cause the certificate data collector to determine the risk score associated with the certificate authority by assigning, based on one or more threat indicators identified in the threat intelligence data, a risk score to each certificate authority that issued a certificate to the first host.

18. The certificate data collector of claim 12 , wherein the instructions, when executed by the one or more processors, cause the certificate data collector to:

determine, based on the threat intelligence data, a second risk score associated with each respective certificate of one or more certificates issued to the first host; and

send, to a packet-filtering device associated with the client system, the second risk score associated with each respective certificate of the one or more certificates issued to the first host along with the risk scores associated with each certificate authority.

19. The certificate data collector of claim 18 , wherein the instructions, when executed by the one or more processors, cause the certificate data collector to generate, based on the risk scores associated with each certificate authority and based on the second risk score associated with each respective certificate of the one or more certificates, a packet-filtering rule.

20. The certificate data collector of claim 12 , wherein the risk score associated with the particular certificate authority is further based on at least one of:

a determination of whether the particular certificate authority issued a second certificate to known malware sites;

a determination of whether a second certificate has been revoked; or

a determination that the certificate issued to the first host is a self-signed certificate.

21. The certificate data collector of claim 12 , wherein the client system comprises a packet-filtering device that resides at a boundary between, and interfaces with, a protected network and an unprotected network.

22. The certificate data collector of claim 12 , wherein the one or more packet-filtering rules comprise one or more rules configured to:

protect a network associated with the client system from malicious network traffic; or

prevent malicious traffic from leaving the network associated with the client system.

23. A non-transitory computer-readable medium comprising instructions that, when executed, cause a certificate data collector to:

receive, from one or more threat intelligence providers, threat intelligence data associated with a plurality of hosts, wherein the threat intelligence data indicates a first host that has been identified as a potential threat by the one or more threat intelligence providers;

determine, in response to receiving the threat intelligence data, one or more certificate authorities that have issued one or more certificates to the first host;

receive, from one or more external systems that identify certificates and certificate authorities associated with hosts, certificate authority intelligence information associated with the one or more certificate authorities that were determined to have issued the one or more certificates to the first host;

determine a risk score associated with each certificate authority of the one or more certificate authorities, wherein the risk score associated with a particular certificate authority is determined based on:

the threat intelligence data indicating that the first host has been identified as a potential threat by the one or more threat intelligence providers; and

the certificate authority intelligence information associated with the one or more certificate authorities indicating that the particular certificate authority issued a certificate to the first host; and

send, to a client system, the determined risk scores associated with each certificate authority of the one or more certificate authorities;

generate, based on the determined risk scores associated with each certificate authority, one or more packet-filtering rules; and

send, to a packet-filtering device associated with the client system, the one or more packet-filtering rules, wherein the packet-filtering device is configured to apply the one or more packet-filtering rules to network traffic.

24. The non-transitory computer-readable medium of claim 23 , wherein the client system is further configured to generate, based on the determined risk scores associated with each certificate authority, one or more second packet-filtering rules.

25. The non-transitory computer-readable medium of claim 23 , wherein the threat intelligence data comprises at least one of:

a domain name associated with the first host; or

an internet protocol (IP) address associated with the first host.

26. The non-transitory computer-readable medium of claim 23 , wherein the one or more certificates form a chain of trust.

27. The non-transitory computer-readable medium of claim 23 , wherein the instructions, when executed, cause the certificate data collector to determine a first risk score associated with a first certificate authority by identifying the first certificate authority as being associated with a cyber threat organization.

28. The non-transitory computer-readable medium of claim 23 , wherein the instructions, when executed, cause the certificate data collector to determine the risk score associated with each certificate authority by assigning, based on one or more threat indicators identified in the threat intelligence data, a risk score to each certificate authority that issued a certificate to the first host.

29. The non-transitory computer-readable medium of claim 23 , wherein the instructions, when executed, cause the certificate data collector to:

determine, based on the threat intelligence data, a second risk score associated with each respective certificate of the one or more certificates issued to the first host; and

send, to a packet-filtering device associated with the client system, the second risk score associated with each respective certificate of the one or more certificates issued to the first host along with the risk scores associated with each certificate authority.

30. The non-transitory computer-readable medium of claim 29 , wherein the instructions, when executed, cause the certificate data collector to generate, based on the risk scores associated with each certificate authority and based on the second risk score associated with each certificate of the one or more certificates, a packet-filtering rule.

31. The non-transitory computer-readable medium of claim 23 , wherein the risk score associated with the particular certificate authority is further based on at least one of:

a determination of whether the particular certificate authority issued a second certificate to known malware sites;

a determination of whether a second certificate has been revoked; or

a determination that the certificate issued to the first host is a self-signed certificate.

32. The non-transitory computer-readable medium of claim 23 , wherein the client system comprises a packet-filtering device that resides at a boundary between, and interfaces with, a protected network and an unprotected network.

33. The non-transitory computer-readable medium of claim 23 , wherein the one or more packet-filtering rules comprise one or more rules configured to:

protect a network associated with the client system from malicious network traffic; or

prevent malicious traffic from leaving the network associated with the client system.

Assignments (2)
CHANGE OF NAME Recorded Feb 7, 2023
From: CENTRIPETAL NETWORKS, INC.
To: CENTRIPETAL NETWORKS, LLC
Reel/Frame 062666/0239 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 22, 2021
From: MOORE, SEAN; AHN, DAVID K.
To: CENTRIPETAL NETWORKS
Reel/Frame 055348/0345 →
Continuity (2)
Continuation 16293087 · Mar 5, 2019
Related Publication 20210266310A1 · Aug 26, 2021
References Cited (51)
US 7568095B2 · Thornton et al. · 2009 [cited by applicant]
US 8161547B1 · Jennings et al. · 2012 [cited by applicant]
US 8286239B1 · Sutton · 2012 [cited by examiner]
US 8327441B2 · Kumar et al. · 2012 [cited by applicant]
US 8443434B1 · Zuk · 2013 [cited by applicant]
US 8683052B1 · Brinskelle · 2014 [cited by applicant]
US 8726379B1 · Stiansen et al. · 2014 [cited by applicant]
US 9166999B1 · Kulkarni et al. · 2015 [cited by applicant]
US 9866576B2 · Ahn et al. · 2018 [cited by applicant]
US 9917856B2 · Ahn et al. · 2018 [cited by applicant]
US 10708256B1 · Kane-Parry · 2020 [cited by examiner]
US 11200324B1 · Manral · 2021 [cited by examiner]
US 20090064332A1 · Porras et al. · 2009 [cited by applicant]
US 20120227109A1 · Dimuro · 2012 [cited by examiner]
US 20120290829A1 · Altman · 2012 [cited by applicant]
US 20130312054A1 · Wang et al. · 2013 [cited by applicant]
US 20140310396A1 · Christodorescu et al. · 2014 [cited by applicant]
US 20150052345A1 · Martini · 2015 [cited by applicant]
US 20160267408A1 · Singh et al. · 2016 [cited by applicant]
US 20160277193A1 · Sabin · 2016 [cited by examiner]
US 20160308894A1 · Ahn et al. · 2016 [cited by applicant]
US 20160330236A1 · Reddy · 2016 [cited by examiner]
US 20160337127A1 · Schultz et al. · 2016 [cited by applicant]
US 20160373433A1 · Rivers · 2016 [cited by examiner]
US 20170005805A1 · Wang et al. · 2017 [cited by applicant]
US 20170012967A1 · Holloway · 2017 [cited by examiner]
US 20170264597A1 · Pizot · 2017 [cited by examiner]
US 20180124110A1 · Hunt et al. · 2018 [cited by applicant]
US 20190251251A1 · Carson · 2019 [cited by examiner]
US 20200067944A1 · Dave · 2020 [cited by examiner]
Alrawi, O., et al., “Chains of Distrust: Towards Understanding Certificates Used for Signing Malicious Applications”, International World Wide Web Conference, Apr. 11-15, 2016, Montreal, Quebec, Canada, retrieved from <… [cited by applicant]
Cooper, D., et al, “RFC 5280—Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile,” Network Working Group, Standards Track, May 2008, 152 pages. [cited by applicant]
Eastlake, D., “Transport Layer Security (TLS) Extensions: Extension Definitions,” Internet Engineering Task Force (IETF)—Standards Track, ISSN: 2070-1721, Huawei, Jan. 2011, 25 pages. [cited by applicant]
Felt, Adrienne Porter, et al., “Improving SSL Warnings: Comprehension and Adherence,” CHI 2015, Apr. 18-23, 2015, Seoul, Republic of South Korea, retrieved from <http://research.google.com/pubs/pub43265.html>, 10 pages. [cited by applicant]
Liu, Y., et al., “An End-to-End Measurement of Certificate Revocation in the Web's PKI,” IMC '15 Proceedings of the 2015 ACM Conference on Internet Measurement Conference, Oct. 28-30, 2015, retrieved from <https://www.c… [cited by applicant]
Proofpoint, “Emerging Threat Intelligence—Cyber Threat Solutions,” Copyright 2018, retrieved Feb. 22, 2019, from <https://www.proofpoint.com/us/solutions/products/threat-intelligence>, 6 pages. [cited by applicant]
Shbair, et al., “Efficiently Bypassing SNI-Based HTTPS Filtering”, 2015 IFIP/IEEE International Symposium on Integrated Network Management (IM), Nov. 2015, pp. 990-995. [cited by applicant]
Langley, Adam, “Public Key Pinning”, imperialviolet.org, May 4, 2011. [cited by applicant]
Georgiev, Martin, et al., “The Most Dangerous Code in the World: Validating SSL Certificates in Non-Browser Software”, CCS '12 Proceedings of the 2012 ACM Conference on Computer and Communications Security, Oct. 2012, p… [cited by applicant]
Kankowski, Peter, “Beware of Unverified TLS Certificates in PHP & Python”, retrieved from https://blog.sucuri.net/2016/03/beware-unverified-tls-certificates-php-python.html, Mar. 31, 2016. [cited by applicant]
Jun. 27, 2019 (US) Non-Final Office Action—U.S. Appl. No. 16/293,087. [cited by applicant]
Apr. 2, 2020, International Search Report of PCT/US2020/015329. [cited by applicant]
U.S. Appl. No. 16/293,087, filed Mar. 5, 2019. [cited by applicant]
Sep. 2009, Scarfone, K.; Hoffman, P.; Guidelines on Firewalls and Firewall Policy, Recommendations of the National Institute of Standards and Technology. [cited by applicant]
2014, Sourcefire SSL Appliance Administration & Deployment Guide for SSL1500, SSL2000, and SSL8200, Software Version 3.6, Cisco. [cited by applicant]
2013, User Guide for ASA CX and Cisco Prime Security Manager 9.1, Cisco. [cited by applicant]
Jul. 14, 2010, Kirk, A.: New Rule Categories, VRT, URL: <http://vrt-blog.snort.org/2010/07/new-rule-categories.html>, Archived in <http://www.archive.org> on Jan. 17, 2011. [cited by applicant]
Mar. 25, 2011, Snort Users Manual 2.9.0, The Snort Project. [cited by applicant]
Mar. 7, 2023, Interim Statement in the Opposition Proceedings against DE Utility Model No. 20 2016 008 885.9. [cited by applicant]
Feb. 3, 2022, Request for Cancellation of DE Utility Model 20 2016 008 885.9. [cited by applicant]
Mar. 8, 2022, Response to the Request for Cancellation of DE Utility Model 20 2016 008 885.9. [cited by applicant]