IP Library Granted Patent US 12,732,519
Granted Patent B2
US 12,732,519 · App. 18/593,251 · Granted Sep 8, 2026

Identifying cryptography usage risks

Inventors: Justin Mathews (Waterloo, CA); Rob Williams (Waterloo, CA); Atsushi Yamada (Waterloo, CA)
Assignee: ISARA Corporation
H04L63/1425H04L63/20H04L63/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,519
App. No.
18/593,251
Granted
Sep 8, 2026
Kind
B2
Abstract

In a general aspect, risks associated with cryptography usage in network communication between computing nodes are identified. In some aspects, a network packet capture agent obtains cryptography usage data by examining network traffic communicated by computing nodes in the computing environment. A cryptography usage analysis agent identifies cryptography usage risks based on the cryptography usage data. A cryptographic risk identification agent identifies one or more applications associated with the cryptography usage risks.

Claims (65)

1 . A method of identifying cryptography usage risks in a computing environment, the method comprising:

by operation of a cryptography usage analysis agent: receiving cryptography usage data obtained by examining network traffic communicated by computing nodes in the computing environment; and

identifying cryptography usage risks within the computing environment based on the cryptography usage data;

by operation of a cryptographic risk identification agent, identifying one or more applications associated with the cryptography usage risks, wherein identifying the one or more applications comprises: identifying a subset of the network traffic associated with the cryptography usage risks;

extracting communication metadata from the subset of the network traffic;

identifying a subset of the computing nodes that communicated the subset of the network traffic;

receiving application network connectivity information from the subset of the computing nodes;

identifying the one or more applications based on the application network connectivity information and the communication metadata; and

associating the cryptography usage risks with the one or more identified applications; and

further comprising identifying, by operation of a root cause identification agent, one or more root causes of the identified cryptography usage risks.

2 . The method of claim 1 , comprising,

by operation of an active probe agent, initiating communication between at least two computing nodes to obtain the cryptography usage data, wherein the cryptography usage analysis agent receives the cryptography usage data from the active probe agent.

3 . The method of claim 1 , comprising obtaining the cryptography usage data by operation of a network packet capture agent, wherein obtaining the cryptography usage data comprises:

capturing packets communicated by the computing nodes within the network environment; and

extracting communication metadata from the captured packets.

4 . The method of claim 1 , wherein the communication metadata comprises respective IP addresses associated with the subset of the computing nodes that communicated the subset of the network traffic, and the method comprises identifying the subset of the computing nodes according to the respective IP addresses.

5 . The method of claim 1 , wherein identifying the one or more applications comprises comparing the communication metadata and the application network connectivity information.

6 . The method of claim 1 , wherein the communication metadata indicates a first list of ports associated with the subset of the network traffic, the application network connectivity information indicates a second list of ports used by the one or more applications, and identifying the one or more applications comprises correlating the first list of ports with the second list of ports.

7 . The method of claim 1 , comprising: receiving, by operation of the root cause identification agent, scanner information from at least one of a source file scanner module, a certificate scanner module, or a software library scanner module, and identifying the one or more root causes of the cryptography usage risks comprises at least one of: scanning, by operation of the source code analysis module, source codes to identify one or more source codes that cause the identified cryptography usage risks; scanning, by operation of the certificate scanner module, certificates to identify one or more certificates that cause the identified cryptography usage risks; or scanning, by operation of the software library scanner module, software libraries to identify library usage related to the identified cryptography usage risks.

8 . The method of claim 1 , wherein the identified cryptography usage risks comprise at least one of:

packets communicated using vulnerable cryptographic algorithms breakable with current technology;

packets communicated using weak cryptographic algorithms breakable with future technology;

packets communicated using misused cryptographic algorithms;

packets communicated using non-standard cryptographic algorithms that do not comply with policies;

packets communicated using unrecommended cryptographic algorithms that cause overuse of computing resources;

packets communicated without using cryptographic algorithms;

packets communicated using vulnerable cryptographic algorithms breakable by quantum computers; or

packets communicated using user-defined cryptographic algorithms.

9 . The method of claim 8 , wherein the user-defined cryptographic algorithms comprise geopolitically unfavorable cryptographic algorithms.

10 . A computing system comprising a first computing device associated with a first entity, the first computing device comprising: one or more processors; and memory storing instructions that are operable when executed by the one or more processors to perform operations comprising:

by operation of a cryptography usage analysis agent;

receiving cryptography usage data obtained by examining network traffic communicated by computing nodes in the computing environment; and identifying cryptography usage risks within the computing environment based on the cryptography usage data;

by operation of a cryptographic risk identification agent, identifying one or more applications associated with the cryptography usage risks, wherein identifying the one or more applications comprises: identifying a subset of the network traffic associated with the cryptography usage risks;

extracting communication metadata from the subset of the network traffic;

identifying a subset of the computing nodes that communicated the subset of the network traffic;

receiving application network connectivity information from the subset of the computing nodes;

identifying the one or more applications based on the application network connectivity information and the communication metadata; and

associating the cryptography usage risks with the one or more identified applications; and

further comprising identifying, by operation of a root cause identification agent, one or more root causes of the identified cryptography usage risks.

11 . The system of claim 10 , wherein the operations comprise:

by operation of an active probe agent, initiating communication between at least two computing nodes to obtain the cryptography usage data, wherein the cryptography usage analysis agent receives the cryptography usage data from the active probe agent.

12 . The system of claim 10 , wherein the operations comprise obtaining the cryptography usage data by operation of a network packet capture agent, wherein obtaining the cryptography usage data comprises:

capturing packets communicated by the computing nodes within the network environment; and

extracting communication metadata from the captured packets.

13 . The system of claim 10 , wherein the communication metadata comprises respective IP addresses associated with the subset of the computing nodes that communicated the subset of the network traffic, and the method comprises identifying the subset of the computing nodes according to the respective IP addresses.

14 . The system of claim 10 , wherein identifying the one or more applications comprises comparing the communication metadata and the application network connectivity information.

15 . The system of claim 10 , wherein the communication metadata indicates a first list of ports associated with the subset of the network traffic, the application network connectivity information indicates a second list of ports used by the one or more applications, and identifying the one or more applications comprises correlating the first list of ports with the second list of ports.

16 . A non-transitory computer-readable medium storing instructions that are operable when executed by data processing apparatus to perform operations comprising: by operation of a cryptography usage analysis agent:

receiving cryptography usage data obtained by examining network traffic communicated by computing nodes in the computing environment; and

identifying cryptography usage risks within the computing environment based on the cryptography usage data;

by operation of a cryptographic risk identification agent, identifying one or more applications associated with the cryptography usage risks, wherein identifying the one or more applications comprises: identifying a subset of the network traffic associated with the cryptography usage risks;

extracting communication metadata from the subset of the network traffic; identifying a subset of the computing nodes that communicated the subset of the network traffic;

receiving application network connectivity information from the subset of the computing nodes;

identifying the one or more applications based on the application network connectivity information and the communication metadata; and

associating the cryptography usage risks with the one or more identified applications; and

further comprising identifying, by operation of a root cause identification agent, one or more root causes of the identified cryptography usage risks.

17 . The non-transitory computer-readable medium of claim 16 , wherein the operations comprise:

by operation of an active probe agent, initiating communication between at least two computing nodes to obtain the cryptography usage data, wherein the cryptography usage analysis agent receives the cryptography usage data from the active probe agent.

18 . The non-transitory computer-readable medium of claim 16 , wherein the operations comprise obtaining the cryptography usage data by operation of a network packet capture agent, wherein obtaining the cryptography usage data comprises:

capturing packets communicated by the computing nodes within the network environment; and

extracting communication metadata from the captured packets.

19 . The non-transitory computer-readable medium of claim 16 , wherein the communication metadata comprises respective IP addresses associated with the subset of the computing nodes that communicated the subset of the network traffic, and the method comprises identifying the subset of the computing nodes according to the respective IP addresses.

20 . The method of claim 1 , wherein the identified cryptography usage risks comprise packets communicated without using a cryptographic algorithm.

21 . The system of claim 10 , wherein the identified cryptography usage risks comprise packets communicated without using a cryptographic algorithm.

22 . The non-transitory computer-readable medium of claim 16 , wherein the identified cryptography usage risks comprise packets communicated without using a cryptographic algorithm.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2024
From: MATHEWS, JUSTIN; WILLIAMS, ROB; YAMADA, ATSUSHI
To: ISARA CORPORATION
Reel/Frame 066713/0183 →
Continuity (2)
Continuation 18461399 · Sep 5, 2023
Related Publication 20250080558A1 · Mar 6, 2025
References Cited (38)
US 7512980B2 · Copeland et al. · 2009 [cited by applicant]
US 8074267B1 · Stimpson · 2011 [cited by examiner]
US 9288234B2 · Barr et al. · 2016 [cited by applicant]
US 9660978B1 · Truskovsky et al. · 2017 [cited by applicant]
US 10362373B2 · Anderson et al. · 2019 [cited by applicant]
US 10681060B2 · Scheidler · 2020 [cited by examiner]
US 10805341B2 · Anderson et al. · 2020 [cited by applicant]
US 10855705B2 · Robertson · 2020 [cited by examiner]
US 10868834B2 · Anderson · 2020 [cited by examiner]
US 11038900B2 · Jusko et al. · 2021 [cited by applicant]
US 11265159B1 · Truskovsky et al. · 2022 [cited by applicant]
US 11310205B2 · Kleopa et al. · 2022 [cited by applicant]
US 11563771B2 · Anderson et al. · 2023 [cited by applicant]
US 20100218250A1 · Mori · 2010 [cited by examiner]
US 20140059216A1 · Jerrim · 2014 [cited by examiner]
US 20180103056A1 · Kohout · 2018 [cited by examiner]
US 20190260796A1 · Hamdi · 2019 [cited by examiner]
US 20200244706A1 · Young · 2020 [cited by examiner]
US 20200252435A1 · Robertson · 2020 [cited by examiner]
US 20200336508A1 · Srivastava · 2020 [cited by examiner]
US 20210194894A1 · Anderson et al. · 2021 [cited by applicant]
US 20220078208A1 · Anderson et al. · 2022 [cited by applicant]
US 20230156034A1 · Naidoo · 2023 [cited by examiner]
US 20240250974A1 · Chemiakin · 2024 [cited by examiner]
ISA, International Search Report and Written Opinion issued in Application No. PCT/CA2023/051675 on May 15, 2024, 8 pages. [cited by applicant]
USPTO, Notice of Allowance issued in U.S. Appl. No. 18/461,399 on Oct. 27, 2023, 19 pages. [cited by applicant]
USPTO, Corrected Notice of Allowability issued in U.S. Appl. No. 18/461,399 on Jan. 23, 2024, 7 pages. [cited by applicant]
Barnes, Richard , “The Poodle Attack and the End of SSL 3.0”, https://blog.mozilla.org/security/2014/10/14/the-poodle-attack-and-the-end-of-ssl-3-0/, Oct. 14, 2014, 21 pages. [cited by applicant]
Combs, Gerald , “Wireshark”, https://en.wikipedia.org/w/index.php?title=Wireshark&oldid=1172113406 (version dated Aug. 25, 2023). [cited by applicant]
Harris, Guy , et al., “PCAP Capture File Format”, https://datatracker.ietf.org/doc/id/draft-gharris-opsawg-pcap-00.html, Dec. 22, 2020, 6 pages. [cited by applicant]
ISARA Corp , “ISARA Advance Crypo Agility Suite”, ISARA Corp., “ISARA Advance Crypo Agility Suite,” product brochure available from ISARA, dated 2021, 2 pages., Jun. 27, 2021, 2 pages. [cited by applicant]
ISARA Corp , “ISARA Advance Crypo Inventory and Planning”, ISARA Corp., “ISARA Advance Crypo Inventory and Planning,” product brochure available from ISARA, dated 2021, 2 pages., Jun. 27, 2021, 2 pages. [cited by applicant]
Quantum Xchange , “Quantum Xchange Announces the General Availability of CipherInsights for Cryptographic Risk Management”, Press Release, Jun. 28, 2023, 1 pages, 1 page. [cited by applicant]
Tanium , “Tanium Platform”, Tanium Platform, product brochure available from https://site.tanium.com/rs/790-QFJ-925/images/PB-Tanium-Platform.pdf, dated 2021, 3 pages., 3 pages. [cited by applicant]
Tuexen, Michael , et al., “PCAP Next Generation (pcapng) Capture File Format”, https://www.ietf.org/staging/draft-tuexen-opsawg-pcapng-02.html, Jun. 23, 2021, 42 pages. [cited by applicant]
Wikipedia , “ExtraHop Networks”, https://en.wikipedia.org/w/index.php?title=ExtraHop_Networks&oldid=1153890094 (version dated May 8, 2023), 5 pages. [cited by applicant]
Wikipedia , “MD5”, https://en.wikipedia.org/w/index.php?title=MD5&oldid=1172812859 (version dated Aug. 29, 2023), Aug. 29, 2023, 13 pages. [cited by applicant]
Wikipedia , “Static application security testing”, https://en.wikipedia.org/w/index.php?title=Static_application_security_testing&oldid=1172300977 (version dated Aug. 26, 2023), 5 pages. [cited by applicant]