IP Library Granted Patent US 11,770,360
Granted Patent B1
US 11,770,360 · App. 17/942,708 · Granted Sep 26, 2023

Correlating protocol data units transiting networks with differing addressing schemes

Inventors: Victor Oppleman (Virginia Beach, VA); Daniel Ghiringhelli (Fort Mill, SC); Zachary Kanner (Virginia Beach, VA); Kristoffer Odland (Virginia Beach, VA)
Assignee: PACKET FORENSICS, LLC
H04L61/256H04L43/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,770,360
App. No.
17/942,708
Granted
Sep 26, 2023
Kind
B1
Abstract

A computer-implemented method of identifying associated communications between a first network with a first addressing scheme and a second network with a second addressing scheme is presented. The technique can include: detecting a first protocol data unit addressed from a first device in the first network and addressed to a destination in the second network, prior to translation by a network address translator; inserting, prior to translation from the first addressing scheme to the second addressing scheme, a breadcrumb protocol data unit that is addressed to the second network, the breadcrumb protocol data unit including, in a location immune from address translation by the network address translator, the source address of the first protocol data unit; receiving a translated breadcrumb protocol data unit; and reporting an association of the source address of the first protocol data unit with the translated source address of the first protocol data unit.

Claims (42)

1. A computer-implemented method of identifying associated communications between a first network with a first addressing scheme and a second network with a second addressing scheme, wherein a network address translator interposed between the first network and the second network translates between the first addressing scheme and the second addressing scheme, the method comprising:

detecting a first protocol data unit addressed from a first device in the first network in the first addressing scheme and addressed to a destination in the second network in the second addressing scheme, prior to translation of the first protocol data unit from the first addressing scheme to the second addressing scheme by the network address translator;

inserting, prior to translation from the first addressing scheme to the second addressing scheme by the network address translator, an additional protocol data unit comprising a breadcrumb protocol data unit that is addressed to the second network, the breadcrumb protocol data unit comprising, in a location subject to address translation by the network address translator, a source address of the first protocol data unit, the breadcrumb protocol data unit further comprising, in a location immune from address translation by the network address translator, the source address of the first protocol data unit;

receiving a translated breadcrumb protocol data unit, wherein the translated breadcrumb data protocol unit comprises the breadcrumb data protocol unit after translation from the first addressing scheme to the second addressing scheme by the network address translator, wherein the translated breadcrumb protocol data unit comprises a translated source address of the first protocol data unit, wherein the translated source address of the first protocol data unit comprises the source address of the first protocol data unit after translation from the first addressing scheme to the second addressing scheme by the network address translator, wherein the translated breadcrumb protocol data unit does not ever reach the destination; and

reporting an association of the source address of the first protocol data unit with the translated source address of the first protocol data unit.

2. The method of claim 1 , further comprising performing a network forensic traceback based on the association.

3. The method of claim 1 , wherein the breadcrumb protocol data unit comprises a private breadcrumb protocol data unit.

4. The method of claim 1 , wherein the first device comprises a network communication endpoint, wherein the network address translator comprises a network address translator (NAT) device at a gateway of the first network, and wherein the detecting the first data protocol unit and the inserting is performed by a sensor device.

5. The method of claim 1 ,

wherein the breadcrumb protocol data unit further comprises, in a location subject to address translation by the network address translator, a source port of the first protocol data unit, and wherein the breadcrumb protocol data unit further comprises, in a location immune from address translation by the network address translator, the source port of the first protocol data unit,

wherein the translated breadcrumb protocol data unit further comprises a translated source port of the first protocol data unit, wherein the translated source port of the first protocol data unit comprises the source port of the first protocol data unit after translation from the first addressing scheme to the second addressing scheme by the network address translator,

the method further comprising reporting an association of the source port of the first protocol data unit with the translated source port of the first protocol data unit.

6. The method of claim 1 , wherein the reporting comprises logging in persistent storage.

7. The method of claim 1 , wherein one of the first addressing scheme or the second addressing scheme comprises addressing for a private internet protocol address space, and wherein another of the first addressing scheme or the second addressing scheme comprises addressing for a global internet protocol address space.

8. The method of claim 1 , wherein the first protocol data unit and the breadcrumb protocol data unit comprise network layer packets.

9. The method of claim 1 , wherein the first protocol data unit and the breadcrumb protocol data unit comprise data link layer frames.

10. The method of claim 1 , wherein one of the source address or the translated source address comprises a multi-protocol label switching (MPLS) label.

11. The method of claim 1 , wherein the breadcrumb protocol data unit comprises data representing a predetermined time to live.

12. The method of claim 1 , wherein the first protocol data unit is part of a communication session, and wherein the inserting occurs a predetermined number of times during the communication session.

13. The method of claim 1 , further comprising generating the breadcrumb protocol data unit.

14. The method of claim 1 , wherein the detecting and the inserting is performed by the first device.

15. A computer system for identifying associated communications between a first network with a first addressing scheme and a second network with a second addressing scheme, wherein a network address translator interposed between the first network and the second network translates between the first addressing scheme and the second addressing scheme, the system comprising:

a first sensor, comprising an electronic processor, communicatively coupled to a first device in the first network to detect a first protocol data unit addressed from a first device in the first network in the first addressing scheme and addressed to a destination in the second network in the second addressing scheme, prior to translation of the first protocol data unit from the first addressing scheme to the second addressing scheme by the network address translator,

wherein the first sensor is configured to insert, prior to translation from the first addressing scheme to the second addressing scheme by the network address translator, an additional protocol data unit comprising a breadcrumb protocol data unit that is addressed to the second network, the breadcrumb protocol data unit comprising, in a location subject to address translation by the network address translator, a source address of the first protocol data unit, the breadcrumb protocol data unit further comprising, in a location immune from address translation by the network address translator, the source address of the first protocol data unit; and

a second sensor, comprising an electronic processor, communicatively coupled to the network address translator to receive a translated breadcrumb protocol data unit, wherein the translated breadcrumb data protocol unit comprises the breadcrumb data protocol unit after translation from the first addressing scheme to the second addressing scheme by the network address translator, wherein the translated breadcrumb protocol data unit comprises a translated source address of the first protocol data unit, wherein the translated source address of the first protocol data unit comprises the source address of the first protocol data unit after translation from the first addressing scheme to the second addressing scheme by the network address translator, wherein the translated breadcrumb protocol data unit does not ever reach the destination,

wherein the computer system is configured to report an association of the source address of the first protocol data unit with the translated source address of the first protocol data unit.

16. The computer system of claim 15 , wherein the computer system is further configured to perform a network forensic traceback based on the association.

17. The computer system of claim 15 , wherein the breadcrumb protocol data unit comprises a private breadcrumb protocol data unit.

18. The computer system of claim 15 , wherein the first device comprises a network communication endpoint, and wherein the network address translator comprises a network address translator (NAT) device at a gateway of the first network.

19. The computer system of claim 15 ,

wherein the breadcrumb protocol data unit further comprises, in a location subject to address translation by the network address translator, a source port of the first protocol data unit, and wherein the breadcrumb protocol data unit further comprises, in a location immune from address translation by the network address translator, the source port of the first protocol data unit,

wherein the translated breadcrumb protocol data unit further comprises a translated source port of the first protocol data unit, wherein the translated source port of the first protocol data unit comprises the source port of the first protocol data unit after translation from the first addressing scheme to the second addressing scheme by the network address translator,

wherein the computer system is further configured to report an association of the source port of the first protocol data unit with the translated source port of the first protocol data unit.

20. The computer system of claim 15 , wherein the computer system comprises persistent storage, and wherein the computer system reports the association by logging the association in the persistent storage.

21. The computer system of claim 15 , wherein one of the first addressing scheme or the second addressing scheme comprises addressing for a private internet protocol address space, and wherein another of the first addressing scheme or the second addressing scheme comprises addressing for a global internet protocol address space.

22. The computer system of claim 15 , wherein the first protocol data unit and the breadcrumb protocol data unit comprise network layer packets.

23. The computer system of claim 15 , wherein the first protocol data unit and the breadcrumb protocol data unit comprise data link layer frames.

24. The computer system of claim 15 , wherein one of the source address or the translated source address comprises a multi-protocol label switching (MPLS) label.

25. The computer system of claim 15 , wherein the breadcrumb protocol data unit comprises data representing a predetermined time to live.

26. The computer system of claim 15 , wherein the first protocol data unit is part of a communication session, and wherein the first sensor is configured to insert a breadcrumb protocol data unit a predetermined number of times during the communication session.

27. The computer system of claim 15 , wherein the first sensor is configured to generate the breadcrumb protocol data unit.

28. The computer system of claim 15 , wherein the first sensor is in the first device.

Assignments (2)
SECURITY INTEREST Recorded Jul 28, 2025
From: PACKET FORENSICS, LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 071846/0604 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2022
From: OPPLEMAN, VICTOR; GHIRINGHELLI, DANIEL; KANNER, ZACHARY; ODLAND, KRISTOFFER
To: PACKET FORENSICS, LLC
Reel/Frame 061063/0396 →
Continuity (1)
Continuation 17884122 · Aug 9, 2022