IP Library Granted Patent US 11,831,609
Granted Patent B2
US 11,831,609 · App. 17/659,561 · Granted Nov 28, 2023

Network security system with enhanced traffic analysis based on feedback loop

Inventors: Eugene (“John”) Neystadt (Kfar Saba, IL); Eyal Heiman (Ramot Hashavim, IL); Elisha Ben-Zvi (Hod Hasharon, IL); Asaf Nadler (Hod Hasharon, IL)
Assignee: Akamai Technologies, Inc.
H04L63/0245G06N20/00H04L47/263H04L61/4511H04L63/0236H04L63/101H04L63/1425H04L63/1441H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,831,609
App. No.
17/659,561
Granted
Nov 28, 2023
Kind
B2
Abstract

This document describes among other things, network security systems that incorporate a feedback loop so as to automatically and dynamically adjust the scope of network traffic that is subject to inspection. Risky traffic can be sent for inspection; risky traffic that is demonstrated to have high rate of threats can be outright blocked without further inspection; traffic that is causing errors due to protocol incompatibility or should not be inspected for regulatory or other reasons can be flagged so it bypasses the security inspection system. The system can operate on a domain by domain basis, IP address basis, or otherwise.

Claims (40)

1. A system for automatically adjusting a scope of network traffic that is subject to security inspection, the system comprising one or more hardware processors and memory storing computer program instructions for execution on the one or more hardware processors to provide:

a first network device that in operation directs network traffic that was sent from a client for a server instead to a second network device for inspection, said directing being in accord with a configuration;

a second network device that in operation receives said network traffic directed by the first network device to the second network device for inspection, and performs said inspection; and,

a feedback analysis system that observes results of inspections by the second network device and adjusts a scope of said network traffic directed by the first network device to the second network device;

wherein the feedback analysis system bases said adjustment on observing at least one of the following classes of network traffic and taking an action with respect thereto:

(a) a class of network traffic that, upon inspection by the second network device, produces errors that cause the feedback analysis system to deem the class of network traffic incompatible with inspection at the second network device, and,

(b) a class of network traffic that, upon inspection by the second network device, contains sensitive data that causes the feedback analysis system to deem the class of network traffic not suitable for inspection at the second network device,

the classes of network traffic (a) and (b) each being defined by any of domain names and IP addresses.

2. The system of claim 1 , wherein said adjusting of the scope of the network traffic directed by the first network device to the second network device comprises the feedback analysis system instructing the first network device to stop directing the class of network traffic upon which the adjustment was based to the second network device.

3. The system of claim 1 , wherein each of the classes of network traffic (a), (b) are defined by domain names.

4. The system of claim 1 , wherein each of the classes of network traffic (a), (b) are defined by IP addresses.

5. The system of claim 1 , wherein the feedback analysis system bases said adjustment on at least:

(a) the class of network traffic that, upon inspection by the second network device, produces errors that cause the feedback analysis system to deem the class of network traffic incompatible with inspection at the second network device.

6. The system of claim 1 , wherein the feedback analysis system bases said adjustment on at least:

(b) the class of network traffic that, upon inspection by the second network device, contains sensitive data that causes the feedback analysis system to deem the class of network traffic not suitable for inspection at the second network device.

7. The system of claim 6 , wherein the sensitive data comprises any of: payment information and medical information.

8. The system of claim 6 , wherein the sensitive data comprises personal identifying information.

9. A method for automatically adjusting a scope of network traffic that is subject to security inspection, comprising:

directing network traffic that was sent from a client for a server instead to a network device for inspection, said directing being in accord with a configuration; and,

observing results of inspection by the network device and adjusting a scope of said network traffic directed to the network device;

wherein adjustment is based on observing at least one of the following classes of network traffic and taking an action with respect thereto:

(a) a class of network traffic that, upon inspection by the network device, produces errors that cause a feedback analysis system to deem the class of network traffic incompatible with inspection at the network device, and,

(b) a class of network traffic that, upon inspection by the network device, contains sensitive data that causes the feedback analysis system to deem the class of network traffic not suitable for inspection at the network device,

the classes of network traffic (a) and (b)each being defined by any of domain names and IP addresses.

10. The method of claim 9 , wherein said adjusting of the scope of the network traffic directed to the network device comprises stopping the directing of the class of network traffic upon which the adjustment was based to the network device.

11. The method of claim 9 , wherein each of the classes of network traffic (a), (b) are defined by domain names.

12. The method of claim 9 , wherein each of the classes of network traffic (a), (b) are defined by IP addresses.

13. The method of claim 9 , wherein the adjustment is based on at least:

(a) the class of network traffic that, upon inspection by the network device, produces errors that cause the feedback analysis system to deem the class of network traffic incompatible with inspection at the network device.

14. The method of claim 9 , wherein the adjustment is based on at least:

(b) the class of network traffic that, upon inspection by the network device, contains sensitive data that causes the feedback analysis system to deem the class of network traffic not suitable for inspection at the network device.

15. The method of claim 14 , wherein the sensitive data comprises any of: payment information and medical information.

16. The method of claim 14 , wherein the sensitive data comprises personal identifying information.

17. A non-transitory computer-readable medium storing computer program instructions for execution by one or more processors in one or more computers, the computer program instructions including instructions that upon said execution cause the one or more computers to:

direct network traffic that was sent from a client for a server instead to a network device for inspection, said directing being in accord with a configuration; and

observe results of inspection by the network device and adjust a scope of said network traffic directed to the network device;

wherein adjustment is based on observing at least one of the following classes of network traffic and taking an action with respect thereto:

(a) a class of network traffic that, upon inspection by the network device, produces errors that cause a feedback analysis system to deem the class of network traffic incompatible with inspection at the network device, and,

(b) a class of network traffic that, upon inspection by the network device, contains sensitive data that causes the feedback analysis system to deem the class of network traffic not suitable for inspection at the network device,

the classes of network traffic (a), and (b) each being defined by any of domain names and IP addresses.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: NEYSTADT, EUGENE (JOHN); HEIMAN, EYAL; BEN-ZVI, ELISHA; NADLER, ASAF
To: AKAMAI TECHNOLOGIES, INC.
Reel/Frame 060896/0203 →
Continuity (2)
Continuation 16168451 · Oct 23, 2018
Related Publication 20220385633A1 · Dec 1, 2022
Cited By (2)
US 12,289,293 US 12,580,886