Methods for Internet Communication Security
The present disclosure relates to network security software cooperatively configured on plural nodes to authenticate and authorize devices, applications, users, and data protocol in network communications by exchanging nonpublic identification codes, application identifiers, and data type identifiers via pre-established communication pathways and comparing against pre-established values to provide authorized communication and prevent compromised nodes from spreading malware to other nodes.
1 . A product for securing communications of a plurality of networked computing devices, the product comprising a non-transitory computer-readable storage medium having computer-readable program code embodied therein, the computer-readable program code executable by a processor to perform communication management operations, the communication management operations comprising:
i) intercepting a first network packet to obtain a first payload with a higher-than-OSI layer three portion and a destination port number, the destination port number assigned to a destination port on one of the plurality of networked computing devices;
ii) confirming from the higher-than-OSI layer three portion of the first payload that the first payload conforms to at least one of a data model pre-assigned to the destination port number;
iii) after confirmation that the first payload conforms to the data model for the destination port, forming a second network packet comprising a second payload, and at least one of a local program identification code or a data model identification code; and
iv) executing at least one instruction to send the second network packet to network security software on the destination port on the one of the plurality of networked computing devices via a secure communication pathway.
2 . The product of claim 1 , wherein the first network packet is intercepted at a hypervisor.
3 . The product of claim 2 , wherein at least a portion of the first higher-than-OSI layer three portion of the first payload is decrypted using a single-use cryptographic key to obtain one or more first packet parameters.
4 . The product of claim 2 , wherein the confirmation occurs at the hypervisor.
5 . The product of claim 2 , wherein the confirmation comprises comparing one or more first packet parameters with one or more first expected values.
6 . The product of claim 1 , wherein the secure communication pathway is an IPSec tunnel between a remote user and an application formed by further communication management operations, the further communication management operations comprising:
a) sending a nonpublic first identification code to the network security software via a pre-established communication pathway;
b) receiving, in response to the sending, a nonpublic second identification code for the one of the plurality of networked computing devices; and
c) comparing the nonpublic second identification code with a pre-established value for the one of the plurality of networked computing devices.
7 . The product of claim 1 , wherein the plurality of networked computing devices communicates via a hybrid architecture comprising a wide area network and a software-defined network.
8 . The product of claim 6 , wherein the IPsec tunnel is established from a distributed network security software component to multiple hybrid architecture hubs.
9 . The product of claim 8 , wherein the hybrid architecture supports multiple transports.
10 . The product of claim 8 , wherein the hybrid architecture contains privilege access.
11 . The product of claim 10 , wherein the privilege access comprises identifying applications based on application identifiers at layer 7.
12 . The product of claim 11 , wherein the privilege access continuously verifies trust.
13 . The product of claim 8 , wherein the hybrid architecture comprises access control policies.
14 . The product of claim 13 , wherein the access control policies comprise identifying applications based on application identifiers.
15 . The product of claim 7 , wherein the hybrid architecture is configured to be deployed at least in part as a mesh network.
16 . The product of claim 1 , wherein the plurality of networked computing devices communicates via a full mesh network.
17 . The product of claim 16 , wherein the full mesh network comprises a plurality of hubs and a plurality of branch locations.
18 . The product of claim 17 , where at least two of the plurality of hubs are connected with at least two of the plurality of branch locations.
19 . The product of claim 18 , wherein at least two branches are interconnected using a secured VPN connection.
20 . The product of claim 1 , wherein the hybrid architecture is used as a sensor.
21 . The product of claim 1 , wherein each data packet of a series of data packets is verified to confirm it was transmitted from an authorized application or an authorized user of the source application.
22 . The product of claim 1 , further comprising a security processing unit or an application-specific integrated circuit.
23 . The product of claim 1 , further comprising IPsec VPN tunnels that are established to authorized devices.
24 . The product of claim 23 , wherein the VPN connections are created to include multiple sites.
25 . The product of claim 23 , wherein unique encryption keys are used per tunnel.
26 . The product of claim 1 , wherein the communication management operations further comprise conducting a higher than OSI layer three inspection on all or substantially all packets.
27 . The product of claim 1 , wherein the communication management operations enable customizable automated incident response.
28 . The product of claim 1 , wherein the communication management operations support multiple identity provider configurations.
29 . The product of claim 1 , wherein the communication management operations identify port-based rules.
30 . The product of claim 1 , wherein the data model comprises port-based rules that are converted to application-based whitelist rules.