IP Library Granted Patent US 11,855,869
Granted Patent B2
US 11,855,869 · App. 17/852,754 · Granted Dec 26, 2023

Secure configuration of a network sensor on a network sensor host

Inventors: John Brosnan (Galway, IE); Jeff Myers (Somerville, MA); Andriy Lyubka (Galway, IE); Darragh Delaney (Claremorris, IE); Erran Carey (Newtownabbey, GB); Martin Hutchings (Lisburn, GB); Ralph McTeggart (Belfast, GB); Ryan Williams (Belfast, GB); Daniel Skelton (Belfast, GB); Luke Coughlan (Galway, IE); Gianpaolo Tedesco (Seoul, KR); Luis Ramos Dos Santos Lopes (Galway, IE); Lars-Kristian Svenoy (Belfast, GB); Dan-Adrian Moinescu (Braila, RO); Niall Cochrane (Belfast, GB); Morgan Doyle (Kinvara, IE); Sarah Addis (Belfast, GB)
Assignee: Rapid7, Inc.
H04L43/0894G06F9/445G06F9/455H04L43/028H04L63/14H04L69/16H04L41/046H04L41/0806
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,855,869
App. No.
17/852,754
Granted
Dec 26, 2023
Kind
B2
Abstract

Disclosed herein are methods, systems, and processes for centralized containerized deployment of network traffic sensors to network sensor hosts for deep packet inspection (DPI) that supports various other cybersecurity operations. A network sensor package containing a pre-configured network sensor container is received by a network sensor host from a network sensor deployment server. Installation of the network sensor package on the network sensor host causes execution of the network sensor container that further causes deployment of an on-premise network sensor along with a network sensor management system, a DPI system, and an intrusion detection/prevention (IDS/IPS) system. The configurable on-premise network sensor is deployed on multiple operating system distributions of the network sensor host and generates actionable network metadata using DPI techniques for optimized log search and management and improved intrusion detection and response (IDR) operations.

Claims (56)

1. A method, comprising:

performing, by one or more processors that implement a network sensor deployment (NSD) server:

identifying a network sensor host in a network to deploy a network sensor;

sending a network sensor package and a token to the network sensor host, wherein the network sensor package is configured to:

obtain a certificate and a private key using the token,

establish a secure connection with the NSD server using the certificate and the private key, and

deploy the network sensor on the network sensor host based on configuration information received via the secure connection;

receiving, from the network sensor package and over the secure connection, information about the network sensor host comprising an enumeration of network interfaces on the network sensor host; and

sending, to the network sensor host and over the secure connection, configuration information used to configure the network sensor that specifies one of the network interfaces as a dedicated sensor interface of the network sensor.

2. The method of claim 1 , wherein

the configuration information is sent by a sensor management component executing on the NSD server.

3. The method of claim 2 , wherein

the configuration information comprises user-specified information received by the sensor management component.

4. The method of claim 1 , wherein

the configuration information comprises a configuration file generated by a sensor configuration service executing on the NSD server.

5. The method of claim 4 , wherein

the network sensor implements an intrusion detection system (IDS) or an intrusion prevention system (IPS), and

the configuration file specifies one or more rulesets for the IDS or the IPS.

6. The method of claim 4 , further comprising the NSD server:

publishing additional rules for the IDS or IPS to the network sensor host after deployment of the network sensor.

7. The method of claim 1 , wherein

the received information about the network sensor host comprises a topology status of the network.

8. The method of claim 1 , wherein

the network sensor package comprises a bootstrap component that launches a container, and

the network sensor executes within the container.

9. The method of claim 1 , further comprising the NSD server:

receiving period beacons from the network sensor host indicating a hostname of the network sensor host and a health status of the network sensor; and

displaying the hostname and the health status on a user interface.

10. A system, comprising:

one or more processors with associated memory that implement a network sensor deployment (NSD) server, configured to:

identify a network sensor host in a network to deploy a network sensor;

send a network sensor package and a token to the network sensor host, wherein the network sensor package is configured to:

obtain a certificate and a private key using the token,

establish a secure connection with the NSD server using the certificate and the private key, and

deploy the network sensor on the network sensor host based on configuration information received via the secure connection;

receive, from the network sensor package and over the secure connection, information about the network sensor host comprising an enumeration of network interfaces on the network sensor host; and

send, to the network sensor host and over the secure connection, configuration information used to configure the network sensor that specifies one of the network interfaces as a dedicated sensor interface of the network sensor.

11. The system of claim 10 , wherein

the configuration information is sent by a sensor management component executing on the NSD server.

12. The system of claim 10 , wherein

the configuration information comprises user-specified information received by the sensor management component.

13. The system of claim 10 , wherein

the configuration information comprises a configuration file generated by a sensor configuration service executing on the NSD server.

14. The system of claim 13 , wherein:

the network sensor implements an intrusion detection system (IDS) or an intrusion prevention system (IPS); and

the configuration file specifies one or more rulesets for the IDS or the IPS.

15. The system of claim 13 , wherein the NSD server is configured to:

publish additional rules for the IDS or IPS to the network sensor host after deployment of the network sensor.

16. The system of claim 10 , wherein the dedicated sensor interface is selected based on user input received at the NSD server.

17. The system of claim 10 , wherein

the network sensor package comprises a bootstrap component that launches a container, and

the network sensor executes within the container.

18. The system of claim 10 , wherein

the NSD server is configured to:

receive period beacons from the network sensor host indicating a hostname of the network sensor host a health status of the network sensor, and

display the hostname and the health status on a user interface.

Assignments (3)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2024
From: ADDIS, SARAH; BROSNAN, JOHN; CAREY, ERRAN MARSHEA; COCHRANE, NIALL; COUGHLAN, LUKE; DELANEY, DARRAGH; DOYLE, MORGAN; HUTCHINGS, MARTIN TRAVIS; LOPES, LUIS RAMOS DOS SANTOS; LYUBKA, ANDRIY; MCTEGGART, RALPH; MOINESCU, DAN-ADRIAN; MYERS, JEFFREY DANIEL; SKELTON, DANIEL; SVENOY, LARS-KRISTIAN; TEDESCO, GIANPAOLO; WILLIAMS, RYAN
To: RAPID7, INC.
Reel/Frame 068702/0509 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2022
From: ADDIS, SARAH; BROSNAN, JOHN; CAREY, ERRAN; COCHRANE, NIALL; DELANEY, DARRAGH; DOYLE, MORGAN; LOPES, LUIS; MCTEGGART, RALPH; MOINESCU, DAN-ADRIAN; MYERS, JEFFREY; SKELTON, DANIEL; SVENOY, LARS-KRISTIAN; TEDESCO, GIANPAOLO; WILLIAMS, RYAN; HUTCHINGS, MARTIN TRAVIS; COUGHLAN, LUKE; LYUBKA, ANDRIY
To: RAPID7, INC.
Reel/Frame 061227/0586 →
Continuity (2)
Continuation 17462100 · Aug 31, 2021
Related Publication 20230064145A1 · Mar 2, 2023
Cited By (1)
US 12,712,890