IP Library Granted Patent US 12,255,877
Granted Patent B1
US 12,255,877 · App. 18/661,092 · Granted Mar 18, 2025

Cloud packet tap

Inventors: Oleg Murat Smolsky (Sunnyvale, CA); Vishwanath U. Shenoy (Bengaluru, IN); Krishna Narayanaswamy (Saratoga, CA); Piyush Patel (San Jose, CA)
Assignee: Netskope, Inc.
H04L63/0281H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,255,877
App. No.
18/661,092
Granted
Mar 18, 2025
Kind
B1
Abstract

A cloud-based network security system that includes a packet tap and exposes a synthetic packet stream representing the bidirectional data between enterprise client devices and cloud hosted services is disclosed. The security system intercepts packets of communication sessions and uploads a copy of the packets to cloud storage. A proxy of the security system derives session keys for the communication session and uploads the session keys to the cloud storage. An enterprise stitcher obtains the packets from the cloud storage, stitches the packets together in sequential order, and modifies the Layer 3 and Layer 4 headers to generate synthetic packet streams representing the communication sessions. The stitcher may decrypt the packets or provide the session key with the synthetic packet stream. The stitcher provides the synthetic packet streams to enterprise packet analysis systems for storage, auditing, analysis, and the like.

Claims (87)

1. A system, comprising:

a gateway, interposed on a network between a client device associated with a first network address and a cloud hosted service associated with a second network address, wherein the gateway is configured to:

intercept packets of a communication session on the network between the client device and the cloud hosted service,

transmit the packets to an uploader, and

transmit the packets to a proxy;

the uploader configured to:

transmit the packets to a cloud storage location;

the proxy configured to:

derive a session key associated with the communication session, and

transmit the session key to the cloud storage location; and

a stitcher configured to:

obtain the packets and the session key from the cloud storage location,

correlate the packets of the communication session with the session key,

decrypt the packets using the session key to produce plain-text payloads of the packets, and

generate a synthetic packet stream of bidirectional data representing at least a portion of the communication session between the client device and the cloud hosted service based on the packets and using the plain-text payloads of the packets, wherein to generate the synthetic packet stream comprises:

ordering the packets into a sequential order; and

modifying at least one of a destination network address and a source network address in each packet to one of the first network address and the second network address based on an intended destination and a source of the respective packet.

2. The system of claim 1 , wherein the proxy is further configured to:

encrypt the session key, wherein the transmit the session key transmits the encrypted session key.

3. The system of claim 1 , wherein the stitcher is further configured to:

modify level 3 headers, level 4 headers, or both in the packets to generate the synthetic packet stream.

4. The system of claim 1 , further comprising:

a plurality of gateways, wherein:

each gateway of the plurality of gateways has a distinct geographic location;

a plurality of uploaders, wherein:

the uploader is co-located with the gateway, and

the cloud storage location is geo-optimized with the uploader; and

a plurality of stitchers, wherein:

the cloud storage location is geo-optimized with the stitcher.

5. The system of claim 1 , wherein the stitcher is further configured to:

export the synthetic packet stream to a requested format.

6. The system of claim 1 , wherein the stitcher is further configured to:

transmit the synthetic packet stream to an enterprise packet analysis system.

7. The system of claim 6 , wherein the stitcher is further configured to:

transmit the session key to the enterprise packet analysis system with the synthetic packet stream.

8. The system of claim 1 , wherein the stitcher is further configured to:

receive a request for the communication session, wherein the request comprises one or more filtering parameters;

access a time-based slice of data from the cloud storage location in response to the request, wherein the time-based slice of data comprises the packets;

filter the packets in the time-based slice based on the one or more filtering parameters; and

generate the synthetic packet stream using the filtered packets.

9. The system of claim 1 , wherein the uploader is further configured to:

batch the packets as they are transmitted from the gateway; and

transmit the packets to the cloud storage location in batches.

10. The system of claim 1 , wherein the stitcher is further configured to:

periodically poll the cloud storage location for new packets;

obtain the new packets; and

continuously generate synthetic packet streams using the new packets.

11. A computer-implemented method, comprising:

intercepting, at a gateway of a network security system interposed on a network between a client device associated with a first network address and a cloud hosted service associated with a second network address, packets of a communication session on the network between the client device and the cloud hosted service;

transmitting, by an uploader of the network security system, the packets to a cloud storage location;

deriving, by a proxy of the network security system, a session key associated with the communication session from the packets;

transmitting, by the proxy, the session key to the cloud storage location;

obtaining, by a stitcher, the packets and the session key from the cloud storage location;

correlating, by the stitcher, the packets of the communication session with the session key;

decrypting, by the stitcher, the packets using the session key to produce plain-text payloads of the packets; and

stitching, by the stitcher, the packets together into a synthetic packet stream of bidirectional data representing at least a portion of the communication session using the plain-text payloads of the packets, wherein the stitching the packets together comprises:

ordering the packets into a sequential order; and

modifying at least one of a destination address and a source address in each packet to one of the first network address and the second network address based on an intended destination and a source of the respective packet.

12. The method of claim 11 , further comprising:

encrypting, by the proxy, the session key, wherein transmitting the session key transmits the encrypted session key.

13. The method of claim 11 , wherein the stitching the packets together further comprises modifying level 3 headers, level 4 headers, or both in the packets to generate the synthetic packet stream.

14. The method of claim 11 , wherein:

the gateway is a first gateway of a plurality of gateways;

each gateway of the plurality of gateways has a distinct geographic location;

the uploader is a first uploader of a plurality of uploaders;

the first uploader is co-located with the first gateway;

the cloud storage location is geo-optimized with the first uploader;

the stitcher is a first stitcher of a plurality of stitchers; and

the first stitcher is geo-optimized with the cloud storage location.

15. The method of claim 11 , further comprising:

exporting, by the stitcher, the synthetic packet stream to a requested format.

16. The method of claim 11 , further comprising:

transmitting, by the stitcher, the synthetic packet stream to a packet analysis system.

17. The method of claim 16 , further comprising:

transmitting, by the stitcher, the session key to the packet analysis system with the synthetic packet stream.

18. The method of claim 11 , further comprising:

receiving, by the stitcher, a request for the communication session, wherein the request includes one or more filtering parameters;

accessing, by the stitcher, a time-based slice of data from the cloud storage location based on the request, wherein the time-based slice of data comprises the packets;

filtering, by the stitcher, the packets in the time-based slice based on the one or more filtering parameters; and

generating, by the stitcher, the synthetic packet stream using the filtered packets.

19. The method of claim 11 , further comprising:

batching, by the uploader, the packets as they are intercepted by the gateway; and

transmitting, by the uploader the packets to the cloud storage location in batches.

20. The method of claim 11 , further comprising;

periodically polling, by the stitcher, the cloud storage location for new packets;

obtaining, by the stitcher, the new packets; and

continuously generating, by the stitcher, synthetic packet streams using the new packets.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2024
From: SMOLSKY, OLEG MURAT; SHENOY, VISHWANATH U.; NARAYANASWAMY, KRISHNA; PATEL, PIYUSH
To: NETSKOPE, INC.
Reel/Frame 067388/0476 →
References Cited (117)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8745384B2 · Persaud · 2014 [cited by examiner]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8819285B1 · Wilkinson · 2014 [cited by examiner]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 11297106B2 · Masciarelli · 2022 [cited by examiner]
US 11750405B2 · Devarajan · 2023 [cited by examiner]
US 11770380B1 · Goeringer · 2023 [cited by examiner]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-Lemair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20060262808A1 · Lin · 2006 [cited by examiner]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20140366155A1 · Chang · 2014 [cited by examiner]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20150363611A1 · Redberg · 2015 [cited by examiner]
US 20150379292A1 · Lewis · 2015 [cited by examiner]
US 20160065364A1 · Amiri · 2016 [cited by examiner]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20230239270A1 · Nahas · 2023 [cited by examiner]
EP 1063833A2 · 2000 [cited by applicant]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff “Ending Clear Text Protocols,” Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Newton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
McCullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al., “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., “Farsite: Federated, available, and reliable storage for an incompletely trusted environment,” SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al., Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html#:˜:text=mode of communication.-,What are the different email protoco… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” TechTarget, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?Offer=ab… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1, Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet, FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/10.1007/978-3-319-61… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al., “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&P 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management for Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]
Cited By (1)
US 12,615,242