IP Library Granted Patent US 12,206,690
Granted Patent B2
US 12,206,690 · App. 17/482,799 · Granted Jan 21, 2025

Methods, systems, articles of manufacture and apparatus to reduce computation corresponding to inspection of non-malicious data flows

Inventors: Tirumaleswar Reddy Konda (Bangalore, IN); Himanshu Srivastava (Bangalore, IN); Shashank Jain (Bangalore, IN)
Assignee: McAfee, LLC
H04L63/1425H04L63/0236H04L63/0272H04L63/029H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,206,690
App. No.
17/482,799
Granted
Jan 21, 2025
Kind
B2
Abstract

Methods, apparatus, systems, and articles of manufacture are disclosed to improve the inspection of network data flows. An example apparatus includes memory, and processor circuitry to execute machine readable instructions to at least identify network domains accessible by at least one client device in a geographic location of interest, associate the identified network domains with Autonomous System Numbers (ASNs), create a list of respective ones of the ASNs that include a non-malicious status corresponding to Internet protocol (IP) addresses associated with respective ones of the identified network domains, and in response to receiving a reputation request corresponding to a destination IP address, cause inspection of a data flow to be skipped when the destination IP address is associated with the list of non-malicious ASNs.

Claims (50)

1. An apparatus to inspect network data flows, the apparatus comprising:

interface circuitry;

machine readable instructions; and

at least one processor circuit to be programmed by the machine readable instructions to:

create a first list of first ones of a plurality of Autonomous System Numbers (ASNs) that include a non-malicious status, and a second list of second ones of the plurality of the ASNs that include an unknown status;

determine a first ASN of the plurality of ASNs associated with a destination Internet Protocol (IP) address based on a first reputation request from a first client device;

determine a reputation of the destination IP address based on the first ASN, the reputation corresponding to one of the first list or the second list;

cause a first inspection of a first data flow to occur for the first client device when the destination IP address is associated with the second list that includes the unknown status;

cause a second inspection of a second data flow to occur based on a result of the first inspection when a second reputation request is received from a second client device, the second reputation request directed to the destination IP address; and

after a determination that the second data flow is malicious, redirect the second client device to a block page to prevent connection to a malicious domain.

2. The apparatus as defined in claim 1 , wherein one or more of the at least one processor circuit is to designate the plurality of the ASNs with at least one of the non-malicious status or the unknown status based on at least one of reputation or category information.

3. The apparatus as defined in claim 1 , wherein one or more of the at least one processor circuit is to calculate a sharing ratio of the destination IP address.

4. The apparatus as defined in claim 3 , wherein one or more of the at least one processor circuit is to cause a network connection to be tunneled based on a threshold value of the sharing ratio.

5. The apparatus as defined in claim 3 , wherein one or more of the at least one processor circuit is to cause a virtual private network (VPN) tunnel to route the destination IP address when the sharing ratio satisfies a threshold value.

6. The apparatus as defined in claim 3 , wherein one or more of the at least one processor circuit is to bypass network tunneling when the sharing ratio does not satisfy a threshold value.

7. The apparatus as defined in claim 1 , wherein one or more of the at least one processor circuit is to retrieve handshake parameters corresponding to the first client device and the second client device associated with the destination IP address.

8. The apparatus as defined in claim 7 , wherein one or more of the at least one processor circuit is to:

compare the retrieved handshake parameters to handshake parameters of a greenlist; and

cause the second inspection of the second data flow when the retrieved handshake parameters do not match the handshake parameters of the greenlist.

9. The apparatus as defined in claim 1 , wherein one or more of the at least one processor circuit is to:

determine the reputation of the destination IP address at a first time;

determine an updated reputation of the destination IP address at a second time; and

determine to skip a third inspection of a third data flow based on the updated reputation, the skip of the third inspection to occur in response to a third reputation request, the third reputation request directed to the destination IP address.

10. The apparatus as defined in claim 1 , wherein the reputation of the destination IP address represents a level of security threat risk based on a leniency of a policy associated with the destination IP address.

11. An apparatus comprising:

greenlist generation circuitry to:

create a first list of first ones of a plurality of Autonomous System Numbers (ASNs) that include a non-malicious status, and a second list of second ones of the plurality of the ASNs that include an unknown status;

network traffic monitoring circuitry to;

determine a first ASN of the plurality of ASNs associated with a destination Internet Protocol (IP) address based on a first reputation request from a first client device;

determine a reputation of the destination IP address based on the first ASN, the reputation corresponding to one of the first list or the second list;

cause a first inspection of a first data flow to occur for the first client device when the destination IP address is associated with the second list that includes the unknown status;

cause a second inspection of a second data flow to occur based on a result of the first inspection when a second reputation request is received from a second client device, the second reputation request directed to the destination IP address; and

after a determination that the second data flow is malicious, redirect the second client device to a block page to prevent connection to a malicious domain.

12. The apparatus as defined in claim 11 , wherein the greenlist generation circuitry is to designate the plurality of the ASNs with at least one of the non-malicious status or the unknown status based on at least one of reputation information or category information.

13. The apparatus as defined in claim 11 , wherein the greenlist generation circuitry is to calculate a sharing ratio of the destination IP address.

14. The apparatus as defined in claim 13 , further including ASN reputation request handling circuitry to cause a network connection to be tunneled based on a threshold value of the sharing ratio.

15. The apparatus as defined in claim 13 , further including flow controlling circuitry to cause a virtual private network (VPN) tunnel to route the destination IP address when the sharing ratio satisfied a threshold value.

16. The apparatus as defined in claim 13 , further including flow controlling circuitry to bypass network tunneling when the sharing ratio does not satisfy a threshold value.

17. The apparatus as defined in claim 11 , further including handshake parameter receiver circuitry to retrieve handshake parameters corresponding to the first client device and the second client device associated with the destination IP address.

18. The apparatus as defined in claim 17 , further including handshake inspection circuitry to:

compare the retrieved handshake parameters to handshake parameters corresponding to a greenlist; and

cause the second inspection of the second data flow when the retrieved handshake parameters do not match the handshake parameters of the greenlist.

19. At least one non-transitory machine readable medium comprising instructions to cause at least one processor circuit to at least:

create a first list of first ones of a plurality of Autonomous System Numbers (ASNs) that include a non-malicious status, and a second list of second ones of the plurality of the ASNs that include an unknown status;

determine a first ASN of the plurality of ASNs associated with a destination Internet Protocol (IP) address based on a first reputation request from a first client device;

determine a reputation of the destination IP address based on the first ASN, the reputation corresponding to one of the first list or the second list;

cause a first inspection of a first data flow to occur for the first client device when the destination IP address is associated with the second list that includes the unknown status;

cause a second inspection of a second data flow to occur based on a result of the first inspection when a second reputation request is received from a second client device, the second reputation request directed to the destination IP address; and

after a determination that the second data flow is malicious, redirect the second client device to a block page to prevent connection to a malicious domain.

20. The at least one non-transitory machine readable medium as defined in claim 19 , wherein the instructions are to cause one or more of the at least one processor circuit to designate the ASNs with at least one of the non-malicious status or the unknown status based on at least one of reputation or category information.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2022
From: KONDA, TIRUMALESWAR REDDY; SRIVASTAVA, HIMANSHU; JAIN, SHASHANK
To: MCAFEE, LLC
Reel/Frame 059609/0547 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
Continuity (1)
Related Publication 20230093904A1 · Mar 30, 2023
References Cited (44)
US 9106661B1 · Stamos · 2015 [cited by applicant]
US 9923923B1 · Mehr et al. · 2018 [cited by applicant]
US 10291584B2 · Koripella · 2019 [cited by examiner]
US 10623284B2 · Yadav · 2020 [cited by examiner]
US 11245685B2 · Konda et al. · 2022 [cited by applicant]
US 20040098588A1 · Ohba et al. · 2004 [cited by applicant]
US 20080046717A1 · Kanekar et al. · 2008 [cited by applicant]
US 20080126794A1 · Wang et al. · 2008 [cited by applicant]
US 20100199099A1 · Wu · 2010 [cited by applicant]
US 20100299525A1 · Shah et al. · 2010 [cited by applicant]
US 20110154026A1 · Edstrom et al. · 2011 [cited by applicant]
US 20110219114A1 · Yang · 2011 [cited by examiner]
US 20140259140A1 · Subramanian · 2014 [cited by examiner]
US 20160080328A1 · Bollay et al. · 2016 [cited by applicant]
US 20190058714A1 · Joshi et al. · 2019 [cited by applicant]
US 20190074982A1 · Hughes · 2019 [cited by applicant]
US 20190173863A1 · Chen et al. · 2019 [cited by applicant]
US 20190387005A1 · Zawoad · 2019 [cited by examiner]
US 20210051160A9 · Abu-Nimeh · 2021 [cited by examiner]
US 20210075671A1 · Li · 2021 [cited by examiner]
EP 3935781A1 · 2022 [cited by examiner]
KR 20160005113 · 2016 [cited by applicant]
Dynamic Attribute-based Reputation scoring for Malicious IP Address Detection NPL (Year: 2018). [cited by examiner]
American Registry for Internet Numbers, “Autonomous Systems Numbers,” retrieved from https://www.arin.net/resources/guide/asn/, 2 pages. [cited by applicant]
Google Cloud, “Configuring Private Google Access for on-premises hosts,” retrieved from https://cloud.google.com/vpc/docs/configure-private-google-access-hybrid, last updated Dec. 20, 2021, 10 pages. [cited by applicant]
Microsoft Docs, “Microsoft 365 and Office 365 URLs and IP address Ranges,” retrieved from https://docs.microsoft.com/en-us/microsoftteams/office-365-urls-ip-address-ranges, Aug. 26, 2021, 2 pages. [cited by applicant]
“Internet Engineering Task Force, Client Subnet in DNS Queries,” retrieved from https://datatracker.ietf.org/doc/html/rfc7871, May 2016, 30 pages. [cited by applicant]
International Searching Authority, “Written Opinion,” issued in connection with International Patent Application No. PCT/US2019/068837, dated Apr. 29, 2020, 5 pages. [cited by applicant]
International Searching Authority, “Search Report,” issued in connection with International Patent Application No. PCT/US2019/068837, dated Apr. 29, 2020, 4 pages. [cited by applicant]
Fischlin et al., “Replay Attacks on Zero Round-Trip Time: The Case of the TLS 1.3 Handshake Candidates,” [https://eprint.iacr.org/2017/082.pdf], 2nd IEEE European Symposium on Security and Privacy (S&P 2017), Feb. 2, 20… [cited by applicant]
Breedijk, “TLS Renegotiation Attack. More Bad News fro SSL,” [https://stories.schubergphilis.com/tls-renegotiation-attack-more-bad-news], Nov. 8, 2009, retrieved on Nov. 11, 2018, 4 pages. [cited by applicant]
Anderson et al., “Deciphering Malware's Use of TLS (without Decryption),” [https://arxiv.org/pdf/1607.01639], arXiv:1607.01639v1, Jul. 6, 2016, 15 pages. [cited by applicant]
Mozilla Security Blog, “Distrust of Symantec TLS Certificates,” [https://blog/mozilla.org/security/2018/03/12/distrust-symantec-tls-certificates/], Mar. 12, 2018, Accessed via [https://web.archive.org/web/20180313053149… [cited by applicant]
Speccy, “Fast, lightweight, advances system information tool for your PC,” [https://www.ccleaner.com/speecy], 5 pages. Jan. 25, 2018, Accessed via [https://web.archive.org/web20180125015519/https://www.ccleaner.com/spec… [cited by applicant]
Brandom, “Hackers emptied Ethereum wallets by breaking the basic infrastructure of the internet,” [https://www.theverge.com/2018/4/24/17275982/myetherwallet-hack-bgp-dns-hijacking-stolen-ethereum], Apr. 24, 2018, 3 page… [cited by applicant]
Sheffer et al., “Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS),” [https://tools.ietf.org/html/rfc7525], Internet Engineering Task Force, May 2015, 27 pages. [cited by applicant]
Rescorla, “The Transport Layer Security (TLS) Protocol Version 1.3,” [https://tools.ietf.org/html/rfc8446], Internet Engineering Task Force, Aug. 2018, 160 pages. [cited by applicant]
Leyden, “Samsung smart fridge leaves Gmail logins open to attack,” [https://www.theregister.co.uk/2015/08/24/smart_fridge_security_fuber/], Aug. 24, 2015, 6 pages. [cited by applicant]
Brumaghin et al., CCleanup: A Vast Number of Machines at Risk, [https://blog.talosintelligence.com/2017/09/avast-distributes-malware.html], Sep. 18, 2017, 23 pages. [cited by applicant]
O'Neill, “Trustico revokes 23,000 SSL certificated due to compromise,” [https://www.cyberscoop.com/trustico-digicert-ssl-certificates-revoked/], Feb. 28, 2018, 6 pages. [cited by applicant]
United States Patent and Trademark Office, “Non-Final Office Action,” issued Mar. 8, 2021 in connection with U.S. Appl. No. 16/296,199, 13 pages. [cited by applicant]
United States Patent and Trademark Office, “Final Office Action,” issued Jul. 19, 2021 in connection with U.S. Appl. No. 16/296,199, 13 pages. [cited by applicant]
United States Patent and Trademark Office, “Advisory Action,” issued Sep. 24, 2021 in connection with U.S. Appl. No. 16/296,199, 2 pages. [cited by applicant]
United States Patent and Trademark Office, “Non-Final Office Action,” issued Nov. 11, 2021 in connection with U.S. Appl. No. 16/296,199, 8 pages. [cited by applicant]
Cited By (1)
US 12,563,078