IP Library Granted Patent US 11,463,466
Granted Patent B2
US 11,463,466 · App. 17/722,217 · Granted Oct 4, 2022

Monitoring encrypted network traffic

Inventors: Benjamin Thomas Higgins (Shoreline, WA); Jeff James Costlow (Kingston, WA); John Gemignani, Jr. (Bremerton, WA); Michael Kerber Krause Montague (Lake Forest Park, WA); Eric James Rongo (Seattle, WA); Xue Jun Wu (Seattle, WA)
Assignee: ExtraHop Networks, Inc.
H04L63/1425H04L43/062H04L63/062H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,463,466
App. No.
17/722,217
Filed
Apr 15, 2022
Granted
Oct 4, 2022
Kind
B2
Art Unit
2496
USPC
713/169
Abstract

Embodiments are directed to monitoring network traffic using network monitoring computers (NMCs). Networks may be configured to protect servers using centralized security protocols. Centralized security protocols may depend on centralized control provided by authentication control servers. If a client intends to access protected servers it may communicate with the authentication control server to obtain keys that enable it to access the requested servers. NMCs may monitor network traffic the centralized security protocol to collect metrics associated with the control servers, clients, or resource servers.

Claims (124)

1. A method for monitoring communication over a network between one or more computers, with one or more network monitoring computers (NMCs) that perform actions, comprising:

in response to determining network traffic associated with a request from a client to access a resource server using a centralized security protocol (CSP), performing further actions, including:

monitoring a first communication between the client and the resource server that includes a request to authenticate the client with the resource server, wherein a portion of the first communication associated with the resource server is encrypted with a client key associated with the client;

monitoring a second communication between the resource server and a control server that includes a request to authenticate the client, wherein a portion of the second communication includes the encrypted portion of the first communication;

determining the client key associated with the client based on an identity of the client;

determining a challenge nonce associated with the resource server in the second communication; and

determining an encrypted challenge nonce associated with the client in the second communication, wherein the encrypted challenge nonce is based on the challenge nonce and the client key; and

in response to the control server authenticating the client, monitoring other communication between the authenticated client and the resource server, wherein the other communication enables the authenticated client to access the resource server;

generating one or more metrics based on the network traffic associated with one or more of the first communication, the second communication, or the other communication; and

generating one or more reports that include information associated with one or more of the client, the authenticated client, the resource server, or the control server.

2. The method of claim 1 , further comprising:

employing the one or more NMCs to obtain the client key associated with the client from the control server; and

employing the client key to decrypt one or more portions of one or more of the first communication, the second communication, or the other communication.

3. The method of claim 1 , further comprising:

providing one or more client keys to one or more NMCs based on one or more control server credentials associated with the one or more NMCs;

employing the one or more client keys to decrypt one or more portions of one or more of the second communication, or the other communication; and

updating the one or more metrics based on the one or more decrypted portions of the one or more of the second communication, or the other communication.

4. The method of claim 1 , wherein monitoring the second communication between the resource server and the control server further comprises:

employing the client key to decrypt the encrypted challenge nonce, wherein the client is validated based on the challenge nonce matching the decrypted challenge nonce; and

associating the encrypted challenge nonce and the challenge nonce with the client, the resource, and the other communication.

5. The method of claim 1 , wherein generating the one or more metrics based on the network traffic associated with one or more of the first communication, the second communication, or the other communication, further comprises:

determining one or more characteristics associated with one or more of the first communication, the second communication, or the other communication based on one or more portions of non-encrypted network traffic, wherein the one or more characteristics include one or more of time of transmission, packet size, latency, source client, target resource server, tuple information, or application protocol;

determining one or more anomalous characteristics based on one or more values associated with the one or more characteristics, wherein the one or more values exceed one or more threshold values or violate one or more policies, and wherein the one or more anomalous characteristics include one or more of anomalous amount of time for a communication, an anomalous packet size, an anomalous latency, an anomalous source client, an anomalous target resource server, anomalous tuple information, or an anomalous application protocol; and

updating the one or more metrics based on the one or more anomalous characteristics.

6. The method of claim 1 , further comprising:

determining one or more application protocols employed for one or more of the first communication, the second communication, or the other communication based on one or more characteristics of the network traffic associated with the one or more of the first communication, the second communication, or the other communication; and

generating one or more portions of the one or more metrics based on one or more portions of the first communication, the second communication, or the other communication that are included in payload network traffic associated with the one or more application protocols.

7. The method of claim 1 , wherein the first communication, the second communication, and the other communication conform to a New Technology Lan Manager (NTLM) authentication protocol.

8. A processor readable non-transitory storage media that includes instructions for monitoring network traffic using one or more network monitoring computers, wherein execution of the instructions by the one or more networking monitoring computers perform the method comprising:

in response to determining network traffic associated with a request from a client to access a resource server using a centralized security protocol (CSP), performing further actions, including:

monitoring a first communication between the client and the resource server that includes a request to authenticate the client with the resource server, wherein a portion of the first communication associated with the resource server is encrypted with a client key associated with the client;

monitoring a second communication between the resource server and a control server that includes a request to authenticate the client, wherein a portion of the second communication includes the encrypted portion of the first communication;

determining the client key associated with the client based on an identity of the client;

determining a challenge nonce associated with the resource server in the second communication; and

determining an encrypted challenge nonce associated with the client in the second communication, wherein the encrypted challenge nonce is based on the challenge nonce and the client key; and

in response to the control server authenticating the client, monitoring other communication between the authenticated client and the resource server, wherein the other communication enables the authenticated client to access the resource server;

generating one or more metrics based on the network traffic associated with one or more of the first communication, the second communication, or the other communication; and

generating one or more reports that include information associated with one or more of the client, the authenticated client, the resource server, or the control server.

9. The media of claim 8 , further comprising:

employing the one or more NMCs to obtain the client key associated with the client from the control server; and

employing the client key to decrypt one or more portions of one or more of the first communication, the second communication, or the other communication.

10. The media of claim 8 , further comprising:

providing one or more client keys to one or more NMCs based on one or more control server credentials associated with the one or more NMCs;

employing the one or more client keys to decrypt one or more portions of one or more of the second communication, or the other communication; and

updating the one or more metrics based on the one or more decrypted portions of the one or more of the second communication, or the other communication.

11. The media of claim 8 , wherein monitoring the second communication between the resource server and the control server further comprises:

employing the client key to decrypt the encrypted challenge nonce, wherein the client is validated based on the challenge nonce matching the decrypted challenge nonce; and

associating the encrypted challenge nonce and the challenge nonce with the client, the resource, and the other communication.

12. The media of claim 8 , wherein generating the one or more metrics based on the network traffic associated with one or more of the first communication, the second communication, or the other communication, further comprises:

determining one or more characteristics associated with one or more of the first communication, the second communication, or the other communication based on one or more portions of non-encrypted network traffic, wherein the one or more characteristics include one or more of time of transmission, packet size, latency, source client, target resource server, tuple information, or application protocol;

determining one or more anomalous characteristics based on one or more values associated with the one or more characteristics, wherein the one or more values exceed one or more threshold values or violate one or more policies, and wherein the one or more anomalous characteristics include one or more of anomalous amount of time for a communication, an anomalous packet size, an anomalous latency, an anomalous source client, an anomalous target resource server, anomalous tuple information, or an anomalous application protocol; and

updating the one or more metrics based on the one or more anomalous characteristics.

13. The media of claim 8 , further comprising:

determining one or more application protocols employed for one or more of the first communication, the second communication, or the other communication based on one or more characteristics of the network traffic associated with the one or more of the first communication, the second communication, or the other communication; and

generating one or more portions of the one or more metrics based on one or more portions of the first communication, the second communication, or the other communication that are included in payload network traffic associated with the one or more application protocols.

14. The media of claim 8 , wherein the first communication, the second communication, and the other communication conform to a New Technology Lan Manager (NTLM) authentication protocol.

15. A system for monitoring network traffic in a network:

one or more network monitoring computers (NMCs), comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that enable performance of actions, including:

in response to determining network traffic associated with a request from a client to access a resource server using a centralized security protocol (CSP), performing further actions, including:

monitoring a first communication between the client and the resource server that includes a request to authenticate the client with the resource server, wherein a portion of the first communication associated with the resource server is encrypted with a client key associated with the client;

monitoring a second communication between the resource server and a control server that includes a request to authenticate the client, wherein a portion of the second communication includes the encrypted portion of the first communication;

determining the client key associated with the client based on an identity of the client;

determining a challenge nonce associated with the resource server in the second communication; and

determining an encrypted challenge nonce associated with the client in the second communication, wherein the encrypted challenge nonce is based on the challenge nonce and the client key; and

in response to the control server authenticating the client, monitoring other communication between the authenticated client and the resource server, wherein the other communication enables the authenticated client to access the resource server;

generating one or more metrics based on the network traffic associated with one or more of the first communication, the second communication, or the other communication; and

generating one or more reports that include information associated with one or more of the client, the authenticated client, the resource server, or the control server; and

one or more client computers, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that enable performance of actions, including:

providing at least a portion of one or more of the first communication, the second communication, or the other communication.

16. The system of claim 15 , wherein the one or more NMC processors execute instructions that perform actions, further comprising:

employing the one or more NMCs to obtain the client key associated with the client from the control server; and

employing the client key to decrypt one or more portions of one or more of the first communication, the second communication, or the other communication.

17. The system of claim 15 , wherein the one or more NMC processors execute instructions that perform actions, further comprising:

providing one or more client keys to one or more NMCs based on one or more control server credentials associated with the one or more NMCs;

employing the one or more client keys to decrypt one or more portions of one or more of the second communication, or the other communication; and

updating the one or more metrics based on the one or more decrypted portions of the one or more of the second communication, or the other communication.

18. The system of claim 15 , wherein monitoring the second communication between the resource server and the control server further comprises:

employing the client key to decrypt the encrypted challenge nonce, wherein the client is validated based on the challenge nonce matching the decrypted challenge nonce; and

associating the encrypted challenge nonce and the challenge nonce with the client, the resource, and the other communication.

19. The system of claim 15 , wherein generating the one or more metrics based on the network traffic associated with one or more of the first communication, the second communication, or the other communication, further comprises:

determining one or more characteristics associated with one or more of the first communication, the second communication, or the other communication based on one or more portions of non-encrypted network traffic, wherein the one or more characteristics include one or more of time of transmission, packet size, latency, source client, target resource server, tuple information, or application protocol;

determining one or more anomalous characteristics based on one or more values associated with the one or more characteristics, wherein the one or more values exceed one or more threshold values or violate one or more policies, and wherein the one or more anomalous characteristics include one or more of anomalous amount of time for a communication, an anomalous packet size, an anomalous latency, an anomalous source client, an anomalous target resource server, anomalous tuple information, or an anomalous application protocol; and

updating the one or more metrics based on the one or more anomalous characteristics.

20. The system of claim 15 , wherein the one or more NMC processors execute instructions that perform actions, further comprising:

determining one or more application protocols employed for one or more of the first communication, the second communication, or the other communication based on one or more characteristics of the network traffic associated with the one or more of the first communication, the second communication, or the other communication; and

generating one or more portions of the one or more metrics based on one or more portions of the first communication, the second communication, or the other communication that are included in payload network traffic associated with the one or more application protocols.

21. The system of claim 15 , wherein the first communication, the second communication, and the other communication conform to a New Technology Lan Manager (NTLM) authentication protocol.

22. A network monitoring computer (NMC) for monitoring network traffic between one or more computers, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that enable performance of actions, including:

in response to determining network traffic associated with a request from a client to access a resource server using a centralized security protocol (CSP), performing further actions, including:

monitoring a first communication between the client and the resource server that includes a request to authenticate the client with the resource server, wherein a portion of the first communication associated with the resource server is encrypted with a client key associated with the client;

monitoring a second communication between the resource server and a control server that includes a request to authenticate the client, wherein a portion of the second communication includes the encrypted portion of the first communication;

determining the client key associated with the client based on an identity of the client;

determining a challenge nonce associated with the resource server in the second communication; and

determining an encrypted challenge nonce associated with the client in the second communication, wherein the encrypted challenge nonce is based on the challenge nonce and the client key; and

in response to the control server authenticating the client, monitoring other communication between the authenticated client and the resource server, wherein the other communication enables the authenticated client to access the resource server;

generating one or more metrics based on the network traffic associated with one or more of the first communication, the second communication, or the other communication; and

generating one or more reports that include information associated with one or more of the client, the authenticated client, the resource server, or the control server.

23. The NMC of claim 22 , wherein the one or more processors execute instructions that perform actions, further comprising:

employing the one or more NMCs to obtain the client key associated with the client from the control server; and

employing the client key to decrypt one or more portions of one or more of the first communication, the second communication, or the other communication.

24. The NMC of claim 22 , wherein the one or more processors execute instructions that perform actions, further comprising:

providing one or more client keys to one or more NMCs based on one or more control server credentials associated with the one or more NMCs;

employing the one or more client keys to decrypt one or more portions of one or more of the second communication, or the other communication; and

updating the one or more metrics based on the one or more decrypted portions of the one or more of the second communication, or the other communication.

25. The NMC of claim 22 , wherein monitoring the second communication between the resource server and the control server further comprises:

employing the client key to decrypt the encrypted challenge nonce, wherein the client is validated based on the challenge nonce matching the decrypted challenge nonce; and

associating the encrypted challenge nonce and the challenge nonce with the client, the resource, and the other communication.

26. The NMC of claim 22 , wherein generating the one or more metrics based on the network traffic associated with one or more of the first communication, the second communication, or the other communication, further comprises:

determining one or more characteristics associated with one or more of the first communication, the second communication, or the other communication based on one or more portions of non-encrypted network traffic, wherein the one or more characteristics include one or more of time of transmission, packet size, latency, source client, target resource server, tuple information, or application protocol;

determining one or more anomalous characteristics based on one or more values associated with the one or more characteristics, wherein the one or more values exceed one or more threshold values or violate one or more policies, and wherein the one or more anomalous characteristics include one or more of anomalous amount of time for a communication, an anomalous packet size, an anomalous latency, an anomalous source client, an anomalous target resource server, anomalous tuple information, or an anomalous application protocol; and

updating the one or more metrics based on the one or more anomalous characteristics.

27. The NMC of claim 22 , further comprising:

determining one or more application protocols employed for one or more of the first communication, the second communication, or the other communication based on one or more characteristics of the network traffic associated with the one or more of the first communication, the second communication, or the other communication; and

generating one or more portions of the one or more metrics based on one or more portions of the first communication, the second communication, or the other communication that are included in payload network traffic associated with the one or more application protocols.

28. The NMC of claim 22 , wherein the first communication, the second communication, and the other communication conform to a New Technology Lan Manager (NTLM) authentication protocol.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2022
From: HIGGINS, BENJAMIN THOMAS; COSTLOW, JEFF JAMES; GEMIGNANI, JOHN, JR.; MONTAGUE, MICHAEL KERBER KRAUSE; RONGO, ERIC JAMES; WU, XUE JUN
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 059801/0840 →
Continuity (3)
Continuation In Part 17483148 · Sep 23, 2021
Provisional Application 63082262 · Sep 23, 2020
Related Publication 20220247771A1 · Aug 4, 2022
Cited By (8)
US 12,225,030 US 12,309,192 US 12,355,816 US 12,483,384 US 12,587,535 US 12,627,639 US 12,647,441 US 12,652,312