IP Library Granted Patent US 11,641,341
Granted Patent B2
US 11,641,341 · App. 17/356,710 · Granted May 2, 2023

System and method for remotely filtering network traffic of a customer premise device

Inventors: Timothy Bleidorn (Colorado Springs, CO); Cheryl Warne (Lone Tree, CO); Shane Newberg (Aurora, CO); Christopher Teague (Highlands Ranch, CO)
Assignee: Charter Communications Operating, LLC
H04L61/5014H04L12/66H04L47/70H04L61/35H04L2101/618
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,641,341
App. No.
17/356,710
Granted
May 2, 2023
Kind
B2
Abstract

Systems, methods, and devices for performing targeted filtering of network traffic generated by user equipment (UE) devices connected to a customer premise equipment (CPE) device in a communication system that includes a distributed residential gateway. A network server may determine that the communication system includes a UE device that is compromised, misconfigured, or operating outside normal communication parameters, identify the UE device, determine an Internet protocol (IP) address or a media access control (MAC) address of the identified UE device, generate a quarantine request message that includes the IP address or the MAC address of the identified UE device in response to determining that the preconfigured virtual local area network access control list (VACL) on the CPE lists source IP addresses from which the CPE will filter outbound traffic, and send the generated quarantine request message to a bridged residential gateway (BRG) associated with the CPE device.

Claims (52)

1. A method for performing targeted filtering of network traffic generated by user equipment (UE) devices connected to a customer premise equipment (CPE) device in a communication system that includes a distributed residential gateway, the method comprising:

determining, by a processor in a computing device, that the communication system includes a UE device that is compromised, misconfigured, or operating outside normal communication parameters;

determining, by the processor in the computing device, at least one of an Internet protocol (IP) address or a media access control (MAC) address of the UE device;

determining, by the processor in the computing device, whether the UE device is a RFC 3203 compliant device connected to the CPE device in a home network;

determining, by the processor in the computing device, whether there is a preconfigured virtual local area network access control list (VACL) on the CPE device that lists source IP addresses from which the CPE device will filter outbound traffic in response to determining that the UE device is the RFC 3203 compliant device connected to the CPE device in the home network;

generating, by the processor in the computing device, a quarantine request message that includes at least one of the IP address or the MAC address of the UE device in response to determining that the preconfigured VACL on the CPE device lists source IP addresses from which the CPE device will filter outbound traffic; and

sending, by the processor in the computing device, the generated quarantine request message to a bridged residential gateway (BRG) associated with the CPE device.

2. The method of claim 1 , wherein the computing device is included in a security, mediation, control, identification, tracking or trending system.

3. The method of claim 1 , wherein the computing device implements a broadband network gateway (BNG) component.

4. The method of claim 1 , wherein determining whether there is the preconfigured VACL on the CPE device that lists source IP addresses from which the CPE device will filter outbound traffic comprises determining whether there is the preconfigured VACL on the CPE device that lists source IP addresses from which the CPE device will restrict, block, or drop outbound traffic.

5. The method of claim 1 , wherein determining whether there is the preconfigured VACL on the CPE device that lists source IP addresses from which the CPE device will filter outbound traffic comprises determining whether the CPE device includes at least one or more of a blocked IP list, a drop IP list, a restricted IP list, a layer 2 access list, a layer 3 access list, a layer 2/3 access list, an in-home only access list, a local area network (LAN) filter list, or a wide area network (WAN) filter list.

6. The method of claim 5 , further comprising receiving a confirmation message indicating that the UE device has been quarantined by assigning the UE device the IP address from at least one or more of the blocked IP list, the drop IP list, the restricted IP list, the layer 2 access list, the layer 3 access list, the layer 2/3 access list, the in-home only access list, the LAN filter list, or the WAN filter list.

7. The method of claim 1 , wherein determining, by the processor in the computing device, whether there is the preconfigured VACL on the CPE device that lists source IP addresses from which the CPE device will filter outbound traffic comprises determining whether the CPE device includes a layer 2/3 access list that identifies a range of IPs for which layer 2 or 3 communications with other UE devices connected to a local area network (LAN) interface will be prevented.

8. The method of claim 1 , wherein determining, by the processor in the computing device, whether there is the preconfigured VACL on the CPE device that lists source IP addresses from which the CPE device will filter outbound traffic comprises determining whether the CPE device includes a drop IP list that identifies a range of IPs for which layer 2 or 3 communications with other UE devices connected to a local area network (LAN) interface will be allowed and layer 2 and 3 communications with other UE devices connected to a wide area network (WAN) interface will be prevented.

9. The method of claim 1 , further comprising receiving a confirmation message indicating that the UE device has been at least one or more of:

quarantined at a local area network (LAN) interface of the CPE device; or

quarantined at a wide area network (WAN) interface of the CPE device.

10. A server computing device, comprising:

a processor configured with processor-executable instructions to:

determine that a communication system includes a user equipment (UE) device that is compromised, misconfigured, or operating outside normal communication parameters;

determine at least one of an Internet protocol (IP) address or a media access control (MAC) address of the UE device;

determine whether the UE device is a RFC 3203 compliant device connected to a customer premise equipment (CPE) device in a home network;

determine whether there is a preconfigured virtual local area network access control list (VACL) on the CPE device that lists source IP addresses from which the CPE device will filter outbound traffic in response to determining that the UE device is the RFC 3203 compliant device connected to the CPE device in the home network;

generate a quarantine request message that includes at least one of the IP address or the MAC address of the UE device in response to determining that the preconfigured VACL on the CPE device lists source IP addresses from which the CPE device will filter outbound traffic; and

send the generated quarantine request message to a bridged residential gateway (BRG) associated with the CPE device.

11. The server computing device of claim 10 , wherein the server computing device is included in a security, mediation, control, identification, tracking or trending system.

12. The server computing device of claim 10 , wherein the processor is further configured to implement a broadband network gateway (BNG) component.

13. The server computing device of claim 10 , wherein the processor is configured to determine whether there is the preconfigured VACL on the CPE device that lists source IP addresses from which the CPE device will filter outbound traffic by determining whether there is the preconfigured VACL on the CPE device that lists source IP addresses from which the CPE device will restrict, block, or drop outbound traffic.

14. The server computing device of claim 10 , wherein the processor is configured to determine whether there is the preconfigured VACL on the CPE device that lists source IP addresses from which the CPE device will filter outbound traffic by determining whether the CPE device includes at least one or more of a blocked IP list, a drop IP list, a restricted IP list, a layer 2 access list, a layer 3 access list, a layer 2/3 access list, an in-home only access list, a local area network (LAN) filter list, or a wide area network (WAN) filter list.

15. The server computing device of claim 14 , wherein the processor is further configured to receive a confirmation message indicating that the UE device has been quarantined by assigning the UE device the IP address from at least one or more of the blocked IP list, the drop IP list, the restricted IP list, the layer 2 access list, the layer 3 access list, the layer 2/3 access list, the in-home only access list, the LAN filter list, or the WAN filter list.

16. The server computing device of claim 10 , wherein the processor is configured to determine whether there is the preconfigured VACL on the CPE device that lists source IP addresses from which the CPE device will filter outbound traffic by determining whether the CPE device includes a layer 2/3 access list that identifies a range of IPs for which layer 2 or 3 communications with other UE devices connected to a local area network (LAN) interface will be prevented.

17. The server computing device of claim 10 , wherein the processor is configured to determine whether there is the preconfigured VACL on the CPE device that lists source IP addresses from which the CPE device will filter outbound traffic comprises determining whether the CPE device includes a drop IP list that identifies a range of IPs for which layer 2 or 3 communications with other UE devices connected to a local area network (LAN) interface will be allowed and layer 2 and 3 communications with other UE devices connected to a wide area network (WAN) interface will be prevented.

18. The server computing device of claim 10 , wherein the processor is further configured to receive a confirmation message indicating that the UE device has been at least one or more of:

quarantined at a local area network (LAN) interface of the CPE device; or

quarantined at a wide area network (WAN) interface of the CPE device.

19. A non-transitory computer readable storage medium having stored thereon processor-executable software instructions configured to cause a server processor to perform operations for accomplishing targeted filtering of network traffic generated by user equipment (UE) devices connected to a customer premise equipment (CPE) device in a communication system that includes a distributed residential gateway, the operations comprising:

determining that the communication system includes a UE device that is compromised, misconfigured, or operating outside normal communication parameters;

determining at least one of an Internet protocol (IP) address or a media access control (MAC) address of the UE device;

determining whether the UE device is a RFC 3203 compliant device connected to the CPE device in a home network;

determining whether there is a preconfigured virtual local area network access control list (VACL) on the CPE device that lists source IP addresses from which the CPE device will filter outbound traffic in response to determining that the UE device is the RFC 3203 compliant device connected to the CPE device in the home network;

generating a quarantine request message that includes at least one of the IP address or the MAC address of the UE device in response to determining that the preconfigured VACL on the CPE device lists source IP addresses from which the CPE device will filter outbound traffic; and

sending the generated quarantine request message to a bridged residential gateway (BRG) associated with the CPE device.

20. The non-transitory computer readable storage medium of claim 19 , wherein the server processor is included in a security, mediation, control, identification, tracking or trending system.

21. The non-transitory computer readable storage medium of claim 19 , wherein the server processor is included a computing device that implements a broadband network gateway (BNG) component.

22. The non-transitory computer readable storage medium of claim 19 , wherein the stored processor-executable software instructions are configured to cause a processor to perform operations such that determining whether there is the preconfigured VACL on the CPE device that lists source IP addresses from which the CPE device will filter outbound traffic comprises determining whether there is the preconfigured VACL on the CPE device that lists source IP addresses from which the CPE device will restrict, block, or drop outbound traffic.

23. The non-transitory computer readable storage medium of claim 19 , wherein the stored processor-executable software instructions are configured to cause a processor to perform operations such that determining whether there is the preconfigured VACL on the CPE device that lists source IP addresses from which the CPE device will filter outbound traffic comprises determining whether the CPE device includes at least one or more of a blocked IP list, a drop IP list, a restricted IP list, a layer 2 access list, a layer 3 access list, a layer 2/3 access list, an in-home only access list, a local area network (LAN) filter list, or a wide area network (WAN) filter list.

24. The non-transitory computer readable storage medium of claim 23 , wherein the stored processor-executable software instructions are configured to cause a processor to perform operations such that receiving a confirmation message indicating that the identified UE device has been quarantined by assigning the identified UE device the IP address from at least one or more of the blocked IP list, the drop IP list, the restricted IP list, the layer 2 access list, the layer 3 access list, the layer 2/3 access list, the in-home only access list, the LAN filter list, or the WAN filter list.

25. The non-transitory computer readable storage medium of claim 24 , wherein the stored processor-executable software instructions are configured to cause a processor to perform operations such that determining whether there is the preconfigured VACL on the CPE device that lists source IP addresses from which the CPE device will filter outbound traffic comprises determining whether the CPE device includes a layer 2/3 access list that identifies a range of IPs for which layer 2 or 3 communications with other UE devices connected to a local area network (LAN) interface will be prevented.

26. The non-transitory computer readable storage medium of claim 19 , wherein the stored processor-executable software instructions are configured to cause a processor to perform operations such that determining whether there is the preconfigured VACL on the CPE device that lists source IP addresses from which the CPE device will filter outbound traffic comprises determining whether the CPE device includes a drop IP list that identifies a range of IPs for which layer 2 or 3 communications with other UE devices connected to a local area network (LAN) interface will be allowed and layer 2 and 3 communications with other UE devices connected to a wide area network (WAN) interface will be prevented.

27. The non-transitory computer readable storage medium of claim 19 , wherein the stored processor-executable software instructions are configured to cause a processor to perform operations further comprising receiving a confirmation message indicating that the UE device has been at least one or more of:

quarantined at a local area network (LAN) interface of the CPE device; or

quarantined at a wide area network (WAN) interface of the CPE device.

Assignments (4)
SECURITY INTEREST Recorded Sep 22, 2022
From: CHARTER COMMUNICATIONS OPERATING, LLC; TIME WARNER CABLE ENTERPRISES, LLC
To: WELLS FARGO TRUST COMPANY, N.A.
Reel/Frame 061503/0937 →
SECURITY INTEREST Recorded Sep 22, 2022
From: CHARTER COMMUNICATIONS OPERATING, LLC; TIME WARNER CABLE ENTERPRISES, LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 061504/0307 →
SUPPLEMENTAL SECURITY AGREEMENT Recorded Aug 10, 2022
From: CHARTER COMMUNICATIONS OPERATING, LLC; TIME WARNER CABLE ENTERPRISES LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 061633/0069 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2021
From: BLEIDORN, TIMOTHY; WARNE, CHERYL; NEWBERG, SHANE; TEAGUE, CHRISTOPHER
To: CHARTER COMMUNICATIONS OPERATING, LLC
Reel/Frame 056651/0375 →
Continuity (2)
Continuation 16245423 · Jan 11, 2019
Related Publication 20210344639A1 · Nov 4, 2021