IP Library Granted Patent US 8,484,338
Granted Patent B2
US 8,484,338 · App. 12/568,073 · Granted Jul 9, 2013

Application detection architecture and techniques

Inventor: Steven B. Paster (San Carlos, CA)
Assignee: Actiance, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,484,338
App. No.
12/568,073
Granted
Jul 9, 2013
Kind
B2
Abstract

An application detection architecture and related techniques are provided for detecting, identifying, and managing network-based applications. In various embodiments, a combined layered approach to application detection and various application-detection techniques provide for quick assessments that move from simplest to complex for rapid detection of unauthorized or misbehaving applications in communication with one or more computer networks. This layering, in some embodiments, further provides scalability and speed for determining and implementing policies that may be applicable to detected network-based application, users, groups, or devices associated with unauthorized network-based applications sending or receiving data via a computer network.

Claims (50)

1. A method for detecting network-based applications based on network traffic generated by the network-based applications, the method comprising:

receiving network traffic at a computer system;

generating first results information in response to analyzing, in a first phase associated with the network traffic, the network traffic with an ordered sequence of a plurality of single inspection point engines using a processor associated with the computer system based on whether a single inspection point of the network traffic satisfies at least one of the plurality of single inspection point engines;

generating second results information in response to analyzing, in a second phase associated with the network traffic, the network traffic and results information associated with the one or more single inspection point engines with one or more multiple inspection point engines using the processor associated with the computer system to determine whether a plurality of inspection points of the network traffic satisfy at least one of the multiple inspection point engines;

generating third results information in response to analyzing, in a third phase associated with the network traffic, the network traffic, results information associated with the one or more single inspection point engines, and results information associated with the one or more multiple inspection point engines with one or more custom inspection point engines using the processor associated with the computer system to determine whether the network traffic satisfies at least one of the custom inspection point engines based on a determination using the second results information;

identifying, with the processor associated with the computer system, a network-based application that generated the network traffic based on results information obtained from at least one of the second phase or the third phase;

determining, with the processor associated with the computer system, a policy that is applicable to the network-based application; and

performing an action defined by the policy in regard to the network-based application.

2. The method of claim 1 wherein analyzing, in the first phase associated with the network traffic, the network traffic with the one or more single inspection point engines provided by the processor associated with the computer system comprises analyzing the network traffic for an IP address, an IP port, presence of a single value in a packet header, or presence of a single value in a packet body.

3. The method of claim 1 wherein analyzing, in the second phase associated with the network traffic, the network traffic and results information associated with the one or more single inspection point engines with the one or more multiple inspection point engines provided by the processor associated with the computer system comprises analyzing the network traffic for a combination of IP address and an IP port, presence of a plurality of values in a packet header, presence of a plurality of values in a packet body, or combinations thereof.

4. The method of claim 1 wherein analyzing, in the third phase associated with the network traffic, the network traffic, results information associated with the one or more single inspection point engines, and results information associated with the one or more multiple inspection point engines with one or more custom inspection point engines provided by the processor associated with the computer system comprises analyzing the network traffic according to processing logic specified by the one or more custom inspection point engines.

5. The method of claim 1 wherein analyzing, in the third phase associated with the network traffic, the network traffic, results information associated with the one or more single inspection point engines, and results information associated with the one or more multiple inspection point engines with one or more custom inspection point engines provided by the processor associated with the computer system comprises maintaining state information with the one or more custom inspection point engines across one or more packets.

6. The method of claim 1 wherein determining, with the processor associated with the computer system, the policy that is applicable to the network-based application comprises determining a set of policies based on one or more characteristics of the network-based application.

7. The method of claim 1 wherein determining, with the processor associated with the computer system, the policy that is applicable to the network-based application comprises:

determining one or more users associated with the network-based application; and

determining a set of policies based on information associated with the one or more user.

8. The method of claim 1 wherein performing the action defined by the policy comprises blocking the network traffic generated by the network-based application.

9. The method of claim 1 wherein performing the action defined by the policy comprises modifying the network traffic generated by the network-based application.

10. The method of claim 1 further comprising:

receiving, at the computer system, one or more updates from a service provider that configure at least one of the single inspection point engines, the multiple inspection point engines, or the custom inspection point engines for determining whether the network traffic satisfies a particular inspection point engine.

11. A non-transitory computer-readable storage medium storing a computer program product executable by one or more computer systems for detecting network-based applications based on network traffic generated by the network-based applications, the non-transitory computer-readable storage medium comprising:

code for receiving network traffic;

code for generating first results information in response to analyzing, in a first phase associated with the network traffic, the network traffic with an ordered sequence of a plurality of single inspection point engines to determine whether a single inspection point of the network traffic satisfies at least one of the plurality of single inspection point engines;

code for generating second results information in response to analyzing, in a second phase associated with the network traffic, the network traffic and results information associated with the one or more single inspection point engines with one or more multiple inspection point engines to determine whether a plurality of inspection points of the network traffic satisfy at least one of the multiple inspection point engines;

code for generating third results information in response to analyzing, in a third phase associated with the network traffic, the network traffic, results information associated with the one or more single inspection point engines, and results information associated with the one or more multiple inspection point engines with one or more custom inspection point engines to determine whether the network traffic satisfies at least one of the custom inspection point engines based on a determination using the second results information;

code for identifying a network-based application that generated the network traffic based on results information obtained from at least one of the second phase or the third phase;

code for determining a policy that is applicable to the network-based application; and

code for performing an action defined by the policy in regard to the network-based application.

12. The non-transitory computer-readable storage medium of claim 11 wherein the code for analyzing, in the first phase associated with the network traffic, the network traffic with the one or more single inspection point engines comprises code for analyzing the network traffic for an IP address, an IP port, presence of a single value in a packet header, or presence of a single value in a packet body.

13. The non-transitory computer-readable storage medium of claim 11 wherein the code for analyzing, in the second phase associated with the network traffic, the network traffic and results information associated with the one or more single inspection point engines with the one or more multiple inspection point engines comprises code for analyzing the network traffic for a combination of IP address and an IP port, presence of a plurality of values in a packet header, presence of a plurality of values in a packet body, or combinations thereof.

14. The non-transitory computer-readable storage medium of claim 11 wherein the code for analyzing, in the third phase associated with the network traffic, the network traffic, results information associated with the one or more single inspection point engines, and results information associated with the one or more multiple inspection point engines with one or more custom inspection point engines comprises code for analyzing the network traffic according to processing logic specified by the one or more custom inspection point engines.

15. The non-transitory computer-readable storage medium of claim 11 wherein the code for analyzing, in the third phase associated with the network traffic, the network traffic, results information associated with the one or more single inspection point engines, and results information associated with the one or more multiple inspection point engines with one or more custom inspection point engines comprises code for maintaining state information with the one or more custom inspection point engines across one or more packets.

16. The non-transitory computer-readable storage medium of claim 11 wherein the code for determining the policy that is applicable to the network-based application comprises code for determining a set of policies based on one or more characteristics of the network-based application.

17. The non-transitory computer-readable storage medium of claim 11 wherein the code for determining the policy that is applicable to the network-based application comprises:

code for determining one or more users associated with the network-based application; and

code for determining a set of policies based on information associated with the one or more user.

18. The non-transitory computer-readable storage medium of claim 11 wherein the code for performing the action defined by the policy comprises code for blocking the network traffic generated by the network-based application.

19. The non-transitory computer-readable storage medium of claim 11 wherein the code for performing the action defined by the policy comprises code for modifying the network traffic generated by the network-based application.

20. The non-transitory computer-readable storage medium of claim 11 further comprising:

code for receiving one or more updates from a service provider that configure at least one of the single inspection point engines, the multiple inspection point engines, or the custom inspection point engines for determining whether the network traffic satisfies a particular inspection point engine.

21. A network appliance for detecting network-based applications based on network traffic generated by the network-based applications, the network appliance comprising:

a database storing information for configuring one or more single inspection point engines, one or more multiple inspection point engines, and one or more custom inspection point engines;

a communications interface configured to be coupled to a communications network and receive network traffic;

a processor configured to:

configure the one or more single inspection point engines and generate first results information in response to analyzing, in a first phase associated with the network traffic, the network traffic with an ordered sequence of a plurality of single inspection point engines to determine whether a single inspection point of the network traffic satisfies at least one of the plurality of single inspection point engines;

configure the one or more multiple inspection point engines and generate second results information in response to analyzing, in a second phase associated with the network traffic, the network traffic and results information associated with the one or more single inspection point engines with the one or more multiple inspection point engines to determine whether a plurality of inspection points of the network traffic satisfy at least one of the multiple inspection point engines;

configure the one or more custom inspection point engines and generate third results information in response to analyzing, in a third phase associated with the network traffic, the network traffic, results information associated with the one or more single inspection point engines, and results information associated with the one or more multiple inspection point engines with the one or more custom inspection point engines to determine whether the network traffic satisfies at least one of the custom inspection point engines based on a determination using the second results information;

identify a network-based application that generated the network traffic based on results information obtained from at least one of the second phase or the third phase;

determine a policy that is applicable to the network-based application; and

perform an action defined by the policy in regard to the network-based application.

Assignments (9)
CHANGE OF NAME Recorded Feb 24, 2025
From: ACTIANCE, INC.
To: ACTIANCE, LLC
Reel/Frame 070306/0814 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT AT REEL/FRAME NO. 45065/0916 Recorded Feb 22, 2022
From: PNC BANK, NATIONAL ASSOCIATION
To: MOBILEGUARD, LLC; SMARSH INC.; SKYWALKER INTERMEDIATE HOLDINGS, INC.; ACTIANCE, INC.; ACTIANCE HOLDINGS, INC.
Reel/Frame 059315/0572 →
PATENT SECURITY AGREEMENT Recorded Feb 18, 2022
From: ACTIANCE, INC.
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 059191/0423 →
RELEASE OF SECURITY INTEREST REEL/FRAME: 035527 / 0923 Recorded Jan 31, 2022
From: GOLUB CAPITAL LLC
To: ACTIANCE, INC.
Reel/Frame 058906/0160 →
SECURITY INTEREST Recorded Feb 28, 2018
From: MOBILEGUARD, LLC; SMARSH INC.; SKYWALKER INTERMEDIATE HOLDINGS, INC.; ACTIANCE, INC.; ACTIANCE HOLDINGS, INC.
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 045065/0916 →
CHANGE OF NAME Recorded May 15, 2015
From: FACETIME COMMUNICATIONS, INC.
To: ACTIANCE, INC.
Reel/Frame 035705/0823 →
SECURITY INTEREST Recorded Apr 29, 2015
From: ACTIANCE, INC.
To: GOLUB CAPITAL LLC, AS AGENT
Reel/Frame 035527/0923 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2009
From: PASTER, STEVEN B.
To: FACETIME COMMUNICATIONS, INC.
Reel/Frame 023517/0248 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 5, 2009
From: PASTER, STEVEN B.
To: FACETIME COMMUNICATIONS, INC.
Reel/Frame 023475/0668 →
Continuity (2)
Provisional Application 61102343 · Oct 2, 2008
Related Publication 20100085883A1 · Apr 8, 2010