IP Library › Granted Patent US 12,732,478
Granted Patent B2
US 12,732,478 · App. 18/477,349 · Granted Sep 8, 2026

Systems, methods and apparatus for local area network isolation

Inventor: Donald Van Oort (West Okoboji, IA)
Assignee: R & D Industries, Inc.
H04L63/0227H04L12/4641H04L63/10H04L63/1408H04L65/102H04L67/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,478
App. No.
18/477,349
Filed
Sep 28, 2023
Granted
Sep 8, 2026
Kind
B2
Art Unit
2431
USPC
726/3
Abstract

The disclosed apparatus, systems and methods relate to methods, systems, and devices for the isolation of devices on a LAN network. Route poisoning, ARP poisoning null routing, blackhole and/or firewall blocking are employed to prevent peer-to-peer network communications within the local area network.

Claims (38)

1 . A system for isolation of a local area network (LAN) comprising a plurality of network devices comprising a default gateway, a first host, and a second host, the system comprising:

a device comprising a hardware processor configured to execute a series of executable steps on the first host to allow communications with whitelist devices on the LAN and to prevent communications with the second host via ARP poisoning and one or more of route poisoning, null routing, and blackhole routing, wherein the route poisoning and null routing are applied to a data link layer or network layer, wherein the ARP poisoning comprises:

clearing an ARP table of the first host;

determining a valid host IP address space of the LAN:

determining a whitelist comprising IP addresses for all whitelist devices on the LAN, the whitelist devices comprising the default gateway; and

creating a false entry in the ARP table of the first host for each IP address within the valid host IP address space not in the whitelist, the false entry comprising a MAC address that is not the MAC address of any of the plurality of network devices on the LAN.

2 . The system of claim 1 , wherein the device processor is configured to enforce firewall rules on the first host on at least one of a transport layer, a session layer, a presentation layer, or an application layer.

3 . The system of claim 1 , wherein the first host comprises the device comprising the hardware processor.

4 . The system of claim 1 , wherein the first host is a virtualized server.

5 . The system of claim 1 , wherein the device comprising the hardware processor is configured to establish and enforce additional endpoint rules preventing communications with the network devices not on the whitelist.

6 . The system of claim 5 , wherein the whitelist comprises a printer.

7 . The system of claim 1 , wherein the device processor is configured to execute:

a series of executable steps on the second host to prevent communications with the first host via ARP poisoning and one or more of route poisoning, null routing, and blackhole routing.

8 . The system of claim 7 , wherein the device processor is configured to enforce firewall rules on the second host.

9 . A local area network host isolation system comprising:

a. a local area network (LAN) comprising a plurality of network devices comprising a default gateway, a first host, and a second host; and

b. a hardware processor, the hardware processor constructed and arranged to establish and enforce rules on the first and second hosts to allow communications with whitelist devices on the LAN and to prevent peer-to-peer communications within the LAN by implementing ARP poisoning and route poisoning, wherein the ARP poisoning comprises:

clearing an ARP table of the first host;

determining a valid host IP address space of the LAN;

determining a whitelist comprising IP addresses for all whitelist devices on the LAN, the whitelist devices comprising the default gateway; and

creating a false entry in the ARP table of the first host for each IP address within the valid host IP address space not in the whitelist, the false entry comprising a MAC address that is not the MAC address of any of the plurality of network devices on the LAN; and

implementing, with device comprising the hardware processor, two or more of route poisoning, null routing, and firewall rules, wherein the route poisoning and null routing are applied to a data link layer or network layer, and the firewall rules are applied to a transport layer, a session layer, a presentation layer, or an application layer.

10 . The system of claim 9 , wherein the first host and second host are connected to the internet via the default gateway.

11 . The system of claim 9 , wherein the platform is constructed and arranged for establishing and enforcing firewall rules on local area network hosts to prevent peer-to-peer communications between the hosts.

12 . The system of claim 9 , wherein the ARP poisoning further comprises:

clearing an ARP table of the second host; and

creating a false entry in the ARP table of the second host for each IP address within the valid host IP address space not in the whitelist, the false entry comprising a MAC address that is not the MAC address of any of the plurality of network devices on the LAN.

13 . The system of claim 11 , wherein the whitelisted devices comprise at least one of a default gateway, a server, a host and a printer and blacklist the first host on the second host.

14 . The system of claim 11 , wherein the device processor is configured to establish and enforce rules applied to at least one of a data link layer or a network layer.

15 . A method of isolating hosts on a local area network (LAN) comprising:

allowing a first host communicating with whitelist devices on the LAN and to prevent communications with a second host via ARP poisoning the first host on the LAN with a device comprising a hardware processor, comprising:

clearing an ARP table of the first host;

determining a valid host IP address space of the LAN:

determining a whitelist comprising IP addresses for all whitelist devices on the LAN the whitelist devices comprising the fault gateway; and creating a false entry in the ARP table of the first host for each IP address within the valid host IP address space not in the whitelist, the false entry comprising a MAC address that is not the MAC address of any network devices on the LAN; and

implementing, with the device comprising the hardware processor, two or more of route poisoning, null routing, and firewall rules, wherein the route poisoning and null routing are applied to a data link layer or network layer, and the firewall rules are applied to a transport layer, a session layer, a presentation layer, or an application layer.

16 . The method of claim 15 , further comprising detecting a network intrusion based on detecting a SYN-ACK message from the first host.

17 . The method of claim 15 , further comprising implementing a route based intrusion detection system.

18 . The method of claim 15 , further comprising detecting a network intrusion with a network sensor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2026
From: VAN OORT, DONALD
To: R&D INDUSTRIES, INC.
Reel/Frame 075253/0261 →
Continuity (3)
Continuation 16032924 · Jul 11, 2018
Provisional Application 62531231 · Jul 11, 2017
Related Publication 20240129275A1 · Apr 18, 2024
References Cited (7)
US 7640585B2 · Lee · 2009 [cited by applicant]
US 8249028B2 · Porras · 2012 [cited by applicant]
US 8718558B2 · Montemurro · 2014 [cited by applicant]
US 8996873B1 · Pahl · 2015 [cited by examiner]
US 9980213B2 · Lynch · 2018 [cited by examiner]
US 10389631B2 · Sheldon · 2019 [cited by applicant]
US 20080005285A1 · Robinson · 2008 [cited by examiner]