IP Library Patent Application 19300536
Patent Application
App. No. 19/300,536

Methods for Internet Communication Security

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/300,536
Abstract

The present disclosure relates to network security software cooperatively configured on plural nodes to authenticate and authorize devices, applications, users, and data protocol in network communications by exchanging nonpublic identification codes, application identifiers, and data type identifiers via pre-established communication pathways and comparing against pre-established values to provide authorized communication and prevent compromised nodes from spreading malware to other nodes.

Claims (35)

1 . A product for securing communications of a plurality of networked computing devices, the product comprising a non-transitory computer-readable storage medium having computer-readable program code embodied therein, the computer-readable program code executable by a processor to perform communication management operations, the communication management operations comprising:

i) consuming a first network packet to obtain a first payload and a destination port number, the destination port number assigned to a destination port on one of the plurality of networked computing devices;

ii) confirming the first payload conforms to at least one of a data model pre-assigned to the destination port number;

iii) after confirmation that the first payload conforms to the data model for the destination port, forming a second network packet comprising a second payload, and at least one of (a) a local program identification code, or (b) a data model identification code; and

iv) executing at least one instruction to send the second network packet to network security software to the destination port on the one of the plurality of networked computing devices via a secure communication pathway;

wherein the communication management operations further comprise access control policies.

2 . The product of claim 1 , wherein the first network packet is intercepted at a hypervisor.

3 . The product of claim 1 , wherein a parameter in at least a higher-than-OSI-layer three portion of the first payload is evaluated against at least a portion of the access control policies.

4 . The product of claim 1 , wherein the communication management operations further comprise confirming the first payload at a hypervisor based on a comparison of the one or more first packet parameters with one or more first expected values.

5 . The product of claim 1 , wherein the communication management operations further comprise establishing authorized encrypted communication pathways for port-to-port network communications among the plurality of networked computing devices.

6 . The product of claim 1 , wherein the communication management operations further comprise authorizing the encrypted communication pathway, comprising comparing a computing device identifier, a user-application identifier, and a payload data-type identifier received from the encrypted communication pathway with a preconfigured, predefined, pre-established and/or preprovisioned authorization code.

7 . The product of claim 1 , wherein the communication management operations further comprise performing communication processing functions on at least a portion of port-to-network communications.

8 . The product of claim 1 , wherein the communication management operations further comprise performing communication processing functions on all port-to-network communications.

9 . The product of claim 1 , wherein the communication management operations further comprise receiving data packets from a user-application process via a loopback interface or by kernel read and/or write calls.

10 . The product of claim 1 , wherein the communication management operations further comprise identifying preconfigured, predefined, pre-established and/or preprovisioned tunnel port numbers, wherein the tunnel port numbers have a one-to-one correspondence with one of the associated destination port numbers.

11 . The product of claim 1 , wherein the communication management operations further comprise assembling packet segments, wherein the packet segments comprise one of the payloads, an associated user-application process identifier, and a payload data type descriptor.

12 . The product of claim 11 , wherein the associated user-application process identifier comprises a process identifier and/or a process owner.

13 . The product of claim 11 , wherein the associated user-application process identifier, and the payload data type descriptor may be combined (or concatenated) in a metadata portion of the packet segment.

14 . The product of claim 1 , wherein the communication management operations further comprise requesting transmission of network packets through network tunnels for at least a different network tunnel for each application-to-application communication of a specified data protocol type.

15 . The product of claim 1 , wherein the communication management operations are transparent to all user-application processes on at least one of the plurality of networked computing devices.

16 . The product of claim 1 , wherein the communication management operations are transparent to all user-application processes on all of the plurality of networked computing devices.

17 . The product of claim 9 , wherein the receiving may occur in kernel spaces of the plurality of computing devices or in application spaces of the plurality of computing devices.

18 . The product of claim 9 , wherein the received data packet may be received from user-application processes executing in application spaces of the plurality of computing devices.

19 . The product of claim 1 , wherein the communication management operations further comprise setting connection status indicators to a non-operative state if the difference between rejected and successful requests to transmit network packets exceeds a fixed number.

20 . The product of claim 19 , wherein the communication management operations further comprise checking a connection status of the network tunnels by checking lists maintained in kernel memory of the plural networked computing devices.

21 . The product of claim 1 , wherein the payloads are translated into a common format prior to the assembling.

22 . The product of claim 1 , wherein the communication management operations further comprise performing communication processing functions on port-to-network communications of the plurality of computing devices.

23 . The product of claim 1 , wherein the communication management operations further comprise receiving data packets from source ports.

24 . The product of claim 23 , wherein the communication management operations further comprise verifying that the source ports are authorized to communicate with ports having the associated destination port numbers.

25 . The product of claim 1 , wherein the payloads in the transmitted network packets are re-associated with the destination port numbers only after the transmitted network packets are received at one or more second computing devices of the plurality of networked computing devices.

26 . The product of claim 1 , wherein the communication management operations further comprise conducting a higher than OSI layer three inspection on all or substantially all packets.

27 . The product of claim 1 , wherein the communication management operations enable customizable automated incident response.

28 . The product of claim 1 , wherein the communication management operations support multiple identity provider configurations.

29 . The product of claim 1 , wherein the communication management operations identify port-based rules.

30 . The product of claim 1 , wherein the data model comprises port-based rules that are converted to application-based whitelist rules.