IP Library Granted Patent US 12,010,141
Granted Patent B1
US 12,010,141 · App. 18/349,848 · Granted Jun 11, 2024

System gateway while accessing protected non-web resources connected to internet

Inventors: Lokesh Mogra (Bangalore, IN); Balireddy Ramesh Kumar Reddy (Bangalore, IN); Satish M. Mohan (San Jose, CA); Vinay Adavi (Sunnyvale, CA); Ritesh R. Agrawal (San Jose, CA)
Assignee: Airgap Networks Inc.
H04L63/1466H04L12/4641H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,010,141
App. No.
18/349,848
Granted
Jun 11, 2024
Kind
B1
Abstract

A technique to improve security for a VLAN is disclosed. A security appliance is set as the default gateway for intra-LAN communication. Message traffic is analyzed and anomalies are detected relative to normal message traffic that correspond to device health problems that may require service by a field technician. Access to a cloud-based resource may be further protected by enforcing user-based access policies.

Claims (26)

1. A method for ransomware protection in a Virtual Local Area Network (VLAN), comprising:

setting a security appliance as a default gateway using a subnet mask of 255.255.255.255 to set the security appliance as a default gateway for a plurality of client endpoint devices of a shared VLAN environment, monitor intra-VLAN communication between the plurality of endpoint devices of the shared VLAN environment, and detect attributes of intra-LAN messages indicative of lateral propagation of ransomware between endpoint devices via intra-VLAN communication in the shared VLAN environment; and

managing a secure private tunnel between a client endpoint device and private applications using a cloud gateway to enforce at least one user-based policy to control access to a private application or private data resource.

2. The method of claim 1 , wherein the cloud gateway receives a user ID during a sign-in step, allocate a private tunnel IP address, and provide the private tunnel IP address to an agent on the client endpoint device, and use the user ID and a private tunnel IP mapping to identify policies for limiting or permitting the client endpoint device to access a request resource.

3. The method of claim 2 , wherein the at least one user-based policy is selectable.

4. A computer-implemented method of ransomware protection in a Virtual Local Area Network (VLAN), comprising:

setting a security appliance as a default gateway for a plurality of endpoint devices of the shared VLAN environment by using a subnet mask of 255.255.255.255, monitoring, by the security appliance, intra-VLAN communication between the plurality of endpoint devices of a shared VLAN environment, and detecting, by the security appliance, lateral propagation of ransomware between endpoint devices via intra-VLAN communication in the shared VLAN environment;

managing a secure tunnel between an endpoint device and a protected resource using a cloud-based gateway to implement at least one user-based access policy for a user to use the secure tunnel to access a private application or a private data resource.

5. The computer-implemented method of claim 4 , wherein the cloud gateway is configured to receive a user ID during a sign-in step, allocate a private tunnel IP address, and provide the tunnel IP address to an agent on the endpoint device, and use the user ID and a private tunnel IP mapping to identify policies for limiting or permitting the client endpoint device to access a request resource via the cloud.

6. The computer-implemented method of claim 5 , wherein the at least one user-based policy is selectable.

7. The computer-implemented method of claim 4 , wherein the cloud gateway comprises a backend and a front end:

the backend installing an agent in the endpoint device, receiving a user ID during a sign-in, allocating a private tunnel IP for a user, creating a user IP mapping, and sharing a private tunnel IP address with the endpoint device; and

the frontend receiving the user IP mapping and applying a user-based policy for user traffic of the private IP tunnel going through the frontend to allow or limit access to a data resource the endpoint device attempts to connect with using the private tunnel IP.

8. The computer-implemented method of claim 7 , wherein the policy applies a firewall to the private tunnel IP to block access to a private application.

9. The computer-implemented method of claim 7 , wherein the policy is executed to forward an access request to a private application.

10. The computer-implemented method of claim 7 , wherein user-based access policies are implemented for determining access to private applications.

11. The computer-implemented method of claim 7 , wherein the policy applies a firewall to the private tunnel IP to block access to a private application.

12. An apparatus for ransomware protection in a Virtual Local Area Network (VLAN), comprising:

computer program instructions, stored on a non-transitory computer readable medium, which when executed on a process implements a method comprising:

setting a security appliance as a default gateway for a plurality of endpoint devices of the shared VLAN environment by using a subnet mask of 255.255.255.255, monitoring, by the security appliance, intra-VLAN communication between the plurality of endpoint devices of the shared VLAN environment, and detecting, by the security appliance, lateral propagation of ransomware between endpoint devices via intra-VLAN communication in the shared VLAN environment; and

managing a secure tunnel between an endpoint device and a protected resource using a cloud-based gateway to implement at least one user-based access policy for a user to use the secure tunnel to access a private application or a private data resource.

13. The system of claim 12 , wherein the cloud gateway is configured to receive a user ID during a sign-in step, allocate a private tunnel IP address, and provide the tunnel IP address to an agent on the endpoint deice, and use the user ID and a private tunnel IP mapping to identify policies for limiting or permitting the endpoint device to access a request resource via the cloud.

14. The system of claim 13 , wherein the at least one user-based policy is selectable.

15. The system of claim 12 , wherein the cloud gateway comprises a backend and a front end, and the method implemented by the computer program instructions includes:

the backend installing an agent in the endpoint device, receiving a user ID during a sign-in, allocating a private tunnel IP for a user, creating a user IP mapping, and sharing a private tunnel IP address with the endpoint device; and

the frontend receiving the user IP mapping and applying a user-based policy for user traffic of the private IP tunnel going through the frontend to allow or limit access to a data resource the endpoint device attempts to connect with using the private tunnel IP.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 20, 2023
From: MOGRA, LOKESH; REDDY, BALIREDDY RAMESH KUMAR; MOHAN, SATISH M.; ADAVI, VINAY; AGRAWAL, RITESH R.
To: AIRGAP NETWORKS INC.
Reel/Frame 064973/0725 →
Continuity (4)
Continuation In Part 18064177 · Dec 9, 2022
Continuation In Part 17521092 · Nov 8, 2021
Continuation 17387615 · Jul 28, 2021
Continuation 17357757 · Jun 24, 2021
Cited By (6)
US 12,407,656 US 12,413,558 US 12,418,512 US 12,457,199 US 12,549,523 US 12,683,932