IP Library › Granted Patent US 7,953,973
Granted Patent B2
US 7,953,973 · App. 11/655,722 · Granted May 31, 2011

Systems, methods, and computer program products for passively routing secure socket layer (SSL) encoded network traffic

Assignee: Radware Ltd.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,953,973
App. No.
11/655,722
Granted
May 31, 2011
Kind
B2
Abstract

Methods, systems, and computer program products for passively routing secure socket layer (SSL) encoded network traffic are disclosed. According to one aspect, a method includes passively receiving a copy of SSL encoded network traffic. Further, the method includes passively parsing the received network traffic and generating an identical copy of the network traffic such that the network traffic is not decrypted and without interfering with the network traffic. A target output network device can be selected for transmission of the identical copy of the network traffic. The identical copy of the network traffic can be transmitted from the selected target output network device.

Claims (28)

1. A method for passively routing secure socket layer (SSL) encoded network traffic, the method comprising:

(a) passively receiving a copy of SSL encoded network traffic;

(b) passively parsing the received network traffic and generating an identical copy of the network traffic such that the network traffic is not decrypted and without interfering with the network traffic;

(c) selecting a target output network device for transmission of the identical copy of the network traffic; and

(d) transmitting the identical copy of the network traffic to an external network through the selected target output network device, wherein

passively parsing the received network traffic is performed such that decryption of the network traffic is not required,

passively parsing the received network traffic is performed without requiring access to SSL private keying information for decryption of the network traffic,

passively parsing the received network traffic includes extracting a unique identifier from an unencrypted portion of an SSL ServerHello message of the network traffic, and

selecting a target output network device includes selecting the target output network device based on the extracted unique identifier.

2. A method for passively routing secure socket layer (SSL) encoded network traffic, the method comprising:

(a) passively receiving a copy of SSL encoded network traffic;

(b) passively parsing the received network traffic and generating an identical copy of the network traffic such that the network traffic is not decrypted and without interfering with the network traffic;

(c) selecting a target output network device for transmission of the identical copy of the network traffic; and

(d) transmitting the identical copy of the network traffic to an external network through the selected target output network device, wherein passively parsing the received network traffic includes identifying an SSL server response message and using a session identifier in the message for grouping associated messages in the same session.

3. A computer program product comprising computer-executable instructions embodied in a non-transitory computer-readable medium for performing steps comprising:

(a) passively receiving a copy of SSL encoded network traffic;

(b) passively parsing the received network traffic and generating an identical copy of the network traffic such that the network traffic is not decrypted and without interfering with the network traffic;

(c) selecting a target output network device for transmission of the identical copy of the network traffic; and

(d) transmitting the identical copy of the network traffic to an external network through the selected target output network device, wherein

passively parsing the received network traffic is performed such that decryption of the network traffic is not required,

passively parsing the received network traffic is performed without requiring access to SSL private keying information for decryption of the network traffic,

passively parsing the received network traffic includes extracting a unique identifier from an unencrypted portion of an SSL ServerHello message of the network traffic, and

selecting a target output network device includes selecting the target output network device based on the extracted unique identifier.

4. A computer program product comprising computer-executable instructions embodied in a non-transitory computer-readable medium for performing steps comprising:

(a) passively receiving a copy of SSL encoded network traffic;

(b) passively parsing the received network traffic and generating an identical copy of the network traffic such that the network traffic is not decrypted and without interfering with the network traffic;

(c) selecting a target output network device for transmission of the identical copy of the network traffic; and

(d) transmitting the identical copy of the network traffic to an external network through the selected target output network device, wherein passively parsing the received network traffic includes identifying an SSL server response message and using a session identifier in the message for grouping associated messages in the same session.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2011
From: SOMERVILLE, GARTH DOUGLAS
To: RADWARE LTD.
Reel/Frame 025770/0104 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2009
From: BEAM, JAMES FREDERICK, II; HARGETT, BYRON LEE; HESTER, DOUGLAS WAYNE; WALKER, JASON MOORE; WALL, VIRGIL MONTGOMERY; WARD, ROBERT EDWARD
To: RADWARE LTD.
Reel/Frame 023036/0994 →
Continuity (1)
Related Publication 20080175245A1 · Jul 24, 2008