IP Library Granted Patent US 12,401,629
Granted Patent B2
US 12,401,629 · App. 18/361,831 · Granted Aug 26, 2025

System and method for midserver facilitation of mass scanning network traffic detection and analysis

Inventors: Jason Crabtree (Vienna, VA); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX LLC
H04L63/0428H04L9/3236H04L9/3239H04L63/0807H04L63/0815H04L63/1425H04L63/1433H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,629
App. No.
18/361,831
Filed
Jul 29, 2023
Granted
Aug 26, 2025
Kind
B2
Examiner
KORSAK, OLEG
Art Unit
2492
USPC
713/180
Abstract

A system and method that uses midservers located between an enterprise network and an external network to provide mass scanning network traffic detection and analysis capabilities for the enterprise network. The midserver may be loaded with configurations that allow it to operate as a mass scan event detector capable of detecting network sniffers, botnets, and malicious peer-to-peer connections which can lead to security vulnerabilities. In such configurations, midserver may receive and analyze network traffic to determine if the network traffic is suspicious based on heuristic and signature-based techniques, and then generate an appropriate response action which can be implemented to mitigate the risk.

Claims (41)

1. A system for network traffic mass scan event detection and analysis:

a midserver comprising at least a processor, a memory, and a plurality of programming instructions stored in the memory and operating on the processor, wherein the plurality of programming instructions, when operating on the processor, cause the processor to:

automatically install a virtual appliance software application, the virtual appliance software application configured to automatically load a plurality of stored configurations on the midserver;

establish a secure network connection to an external network;

receive data over a local network from a plurality of computing devices;

receive network traffic bound for the local network;

analyze the network traffic to identify if the network traffic is suspicious;

determine if the network traffic is associated with a botnet by performing heuristic analysis on network traffic identified as suspicious, wherein the heuristic analysis comprises monitoring the behavior of the network traffic; and

execute a responsive action on the local network based on the results of the heuristic analysis.

2. The system of claim 1 , wherein the responsive action is generating an alert to a network administrator, the alert indicating a mass scan event has been detected.

3. The system of claim 2 , wherein the mass scan event is performed by a botnet.

4. The system of claim 1 , wherein at least one computing device of the plurality of computing devices has a software agent stored and operating on the at least one computing device, the software agent configured to generate and transmit a trap packet to the midserver.

5. The system of claim 4 , wherein the midserver is further configured to:

receive the trap packet from the software agent;

determine if the network traffic is associated with a network sniffer by configuring the midserver to determine whether received network traffic is the trap packet or a non-trap packet based on at least a subset of the stored plurality of configurations on the midserver;

generate an alert to a network administrator, the alert indicating a mass scan event has been detected.

6. The system of claim 5 , wherein the mass scan event is performed by a network sniffer.

7. The system of claim 1 , wherein the midserver is further configured to:

determine if the network traffic is associated with a request for information from a peer-to-peer (P2P) application by using protocol-based signature detection; and

execute a responsive action on the local network based on the results of the protocol-based signature detection.

8. The system of claim 7 , wherein the responsive action is blocking the P2P application from connecting with local network.

9. A method for network traffic mass scan event detection and analysis, comprising the steps of:

automatically installing a virtual appliance software application, the virtual appliance software application configured to automatically load a plurality of stored configurations on the midserver;

establishing a secure network connection to an external network;

receiving data over a local network from a plurality of computing devices;

receiving network traffic bound for the local network;

analyzing the network traffic to identify if the network traffic is suspicious;

determining if the network traffic is associated with a botnet by performing heuristic analysis on network traffic identified as suspicious, wherein the heuristic analysis comprises monitoring the behavior of the network traffic; and

executing a responsive action on the local network based on the results of the heuristic analysis.

10. The method of claim 9 , wherein the responsive action is generating an alert to a network administrator, the alert indicating a mass scan event has been detected.

11. The method of claim 10 wherein the mass scan event is performed by a botnet.

12. The method of claim 9 , wherein at least one computing device of the plurality of computing devices has a software agent stored and operating on the at least one computing device, the software agent configured to generate and transmit a trap packet to the midserver.

13. The method of claim 12 , further comprising the steps of:

receiving the trap packet from the software agent;

determining if the network traffic is associated with a network sniffer by configuring the midserver to determine whether received network traffic is the trap packet or a non-trap packet based on at least a subset of the stored plurality of configurations on the midserver; and

generating an alert to a network administrator, the alert indicating a mass scan event has been detected.

14. The method of claim 13 , wherein the mass scan event is performed by a network sniffer.

15. The method of claim 9 , further comprising the steps of:

determining if the network traffic is associated with a request for information from a peer-to-peer (P2P) application by using protocol-based signature detection; and

executing a responsive action on the local network based on the results of the protocol-based signature detection.

16. The method of claim 15 , wherein the responsive action is blocking the P2P application from connecting with local network.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE SECOND INVENTOR'S LAST NAME PREVIOUSLY RECORDED AT REEL: 66428 FRAME: 848. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 22, 2024
From: CRABTREE, JASON; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 067504/0393 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2023
From: CRABTREE, JASON; KELLY, RICHARD
To: QOMPLX, INC.
Reel/Frame 064428/0848 →
Continuity (44)
Continuation In Part 18336873 · Jun 16, 2023
Continuation In Part 18297500 · Apr 7, 2023
Continuation In Part 18169203 · Feb 14, 2023
Continuation In Part 17245162 · Apr 30, 2021
Continuation In Part 16412340 · May 14, 2019
Continuation In Part 16267893 · Feb 5, 2019
Continuation In Part 16248133 · Jan 15, 2019
Continuation In Part 15849901 · Dec 21, 2017
Continuation 15837845 · Dec 11, 2017
Continuation In Part 15835312 · Dec 7, 2017
Continuation In Part 15835436 · Dec 7, 2017
Continuation In Part 15825350 · Nov 29, 2017
Continuation In Part 15813097 · Nov 14, 2017
Continuation In Part 15806697 · Nov 8, 2017
Continuation In Part 15790457 · Oct 23, 2017
Continuation 15790327 · Oct 23, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15673368 · Aug 9, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15376657 · Dec 13, 2016
Continuation In Part 15376657 · Dec 13, 2016
Continuation In Part 15343209 · Nov 4, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15229476 · Aug 5, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62596105 · Dec 7, 2017
Provisional Application 62568298 · Oct 4, 2017
Provisional Application 62568291 · Oct 4, 2017
Related Publication 20240022547A1 · Jan 18, 2024
References Cited (21)
US 7072863B1 · Phillips et al. · 2006 [cited by applicant]
US 8533819B2 · Hoeflin · 2013 [cited by examiner]
US 9088606B2 · Ranum · 2015 [cited by examiner]
US 20070021955A1 · Tolone et al. · 2007 [cited by applicant]
US 20070043656A1 · Lancaster · 2007 [cited by applicant]
US 20080010225A1 · Gonsalves · 2008 [cited by examiner]
US 20080027690A1 · Watts · 2008 [cited by applicant]
US 20080221949A1 · Delurgio et al. · 2008 [cited by applicant]
US 20090222562A1 · Liu et al. · 2009 [cited by applicant]
US 20110154492A1 · Jeong · 2011 [cited by examiner]
US 20110208681A1 · Kuecuekyan · 2011 [cited by applicant]
US 20120116743A1 · Ayala et al. · 2012 [cited by applicant]
US 20140156806A1 · Karpistsenko et al. · 2014 [cited by applicant]
US 20140279762A1 · Xaypanya et al. · 2014 [cited by applicant]
US 20150186427A1 · Logothetis et al. · 2015 [cited by applicant]
US 20150215177A1 · Pietrowicz · 2015 [cited by examiner]
US 20150379424A1 · Dirac et al. · 2015 [cited by applicant]
US 20160078361A1 · Brueckner et al. · 2016 [cited by applicant]
US 20160092557A1 · Stojanovic et al. · 2016 [cited by applicant]
US 20160164905A1 · Wood et al. · 2016 [cited by applicant]
US 20170193110A1 · Crabtree et al. · 2017 [cited by applicant]
Cited By (1)
US 12,609,952