IP Library › Granted Patent US 8,495,726
Granted Patent B2
US 8,495,726 · App. 12/566,354 · Granted Jul 23, 2013

Trust based application filtering

Inventors: Amit Agarwal (Milpitas, CA); Steve Baker (Arvada, CO)
Assignee: Avaya Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,495,726
App. No.
12/566,354
Filed
Sep 24, 2009
Granted
Jul 23, 2013
Kind
B2
Examiner
SONG, HOSUK
Art Unit
2435
USPC
726/13
Abstract

Methods, devices, and systems are provided for filtering packets and other communication messages or portions thereof. Particularly, mechanisms are provided for efficiently determining and applying a set of trust-based filtering rules. Trust scores may be assigned to various connections and packets received on a particular connection may have filtering rules applied thereto in accordance with the trust score of the connection.

Claims (51)

1. A method, comprising:

determining a trust level for a connection established between a communication device and an enterprise server;

caching, at a socket layer module, the trust level for the connection;

receiving, at the socket layer module, a packet, the packet being received over the connection; and

tagging, by the socket layer module, the packet with the cached trust level for the connection.

2. The method of claim 1 , wherein the trust level for the connection is maintained at a centralized sessions table.

3. The method of claim 1 , wherein the connection comprises a trusted connection and wherein a header of the packet is tagged with information indicating that no filtering is necessary for the packet.

4. The method of claim 3 , wherein the connection comprises one or more of an intra-enterprise connection, an IPSec connection, a VPN connection, and a TLS connection.

5. The method of claim 1 , wherein the connection comprises a semi-trusted connection and wherein a packet transmission rate over the connection is monitored to determine if rate limit filtering is to be applied to the packets received over the connection.

6. The method of claim 5 , further comprising:

determining that the packet transmission rate is above a predetermined threshold; and

tagging the packet with information indicating that rate limit filtering is to be applied to the packet.

7. The method of claim 1 , wherein the connection comprises an untrusted connection and wherein the tag indicates that the packet is to be dropped.

8. The method of claim 7 , wherein the connection comprises a connection over which a user has provided an invalid or expired authentication certificate.

9. A method, comprising:

determining a trust level for a connection established between a communication device and an enterprise server;

caching, at a socket layer module, the trust level for the connection;

receiving, at the socket layer module, a packet, the packet being received over the connection;

tagging, by the socket layer module, the packet with the cached trust level for the connection;

passing the tagged packet to a packet filtering module;

receiving the tagged packet at the packet filtering module;

analyzing, by the packet filtering module, the tag of the received packet;

identifying, based on the tag of the packet, a trust-based filtering policy to be applied to the packet; and

applying the identified trust-based filtering policy to the packet.

10. The method of claim 9 , further comprising:

forwarding the filtered packet to a device an enterprise device for further processing.

11. The method of claim 1 , further comprising:

changing the trust level of the connection, wherein changing the trust level of the connection results in packets received prior to the change being assigned a first trust level and packets received after the change being assigned a second trust level different from the first trust level.

12. The method of claim 1 , further comprising:

defining filtering rules that comprise trust levels associated therewith; and

applying the filtering rules to the packet.

13. A server, comprising:

a sessions table comprising a mapping of connections established at the server to trust levels associated with each connection;

a socket layer module adapted to retrieve a trust level for a connection and further adapted to tag a packet received over the connection with the trust level of the connection; and

a filtering module adapted to apply trust-based filtering rules to the packet based on trust-level information contained in the tag of the packet.

14. The server of claim 13 , wherein the sessions table is centralized and shared among a plurality of different socket layer modules.

15. The server of claim 13 , wherein the connection comprises a trusted connection and wherein a header of the packet is tagged with information indicating that no filtering is necessary for the packet.

16. The server of claim 15 , wherein the connection comprises one or more of an intra-enterprise connection, an IPSec connection, a VPN connection, and a TLS connection.

17. The server of claim 13 , wherein the connection comprises a semi-trusted connection and wherein a packet transmission rate over the connection is monitored to determine if rate limit filtering is to be applied to the packets received over the connection.

18. The server of claim 17 , wherein the socket layer module is further adapted to determine that the packet transmission rate is above a predetermined threshold and tagging the packet with information indicating that rate limit filtering is to be applied to the packet.

19. The server of claim 13 , wherein the connection comprises an untrusted connection and wherein the tag indicates that the packet is to be dropped.

20. The server of claim 19 , wherein the connection comprises a connection over which a user has provided an invalid or expired authentication certificate.

21. A server, comprising:

a sessions table comprising a mapping of connections established at the server to trust levels associated with each connection;

a socket layer module adapted to retrieve a trust level for a connection and further adapted to tag a packet received over the connection with the trust level of the connection;

a filtering module adapted to apply trust-based filtering rules to the packet based on trust-level information contained in the tag of the packet, wherein the sessions table is adapted to be dynamically changed after the connection has been established and before the connection has been terminated, wherein a change to the sessions table results in a change to a trust level of the connection and wherein the change to the trust level of the connection results in packets received prior to the change being assigned a first trust level and packets received after the change being assigned a second trust level different from the first trust level.

22. A computer program product comprising computer executable instructions stored onto a non-transitory computer readable medium which, when executed by a processor of a computer, cause the processor to execute a method, the method comprising:

determining a trust level for a connection established at an enterprise server;

receiving a packet over the connection;

tagging the packet with the trust level for the connection; and

forwarding the tagged packet to a filtering module for filtering in accordance with the trust level of the connection.

Assignments (20)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 029608/0256 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 044891/0801 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 025863/0535 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST, NA
To: AVAYA INC.
Reel/Frame 044892/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 030083/0639 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 045012/0666 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
SECURITY AGREEMENT Recorded Mar 13, 2013
From: AVAYA, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., THE
Reel/Frame 030083/0639 →
SECURITY AGREEMENT Recorded Jan 10, 2013
From: AVAYA, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 029608/0256 →
SECURITY AGREEMENT Recorded Feb 22, 2011
From: AVAYA INC., A DELAWARE CORPORATION
To: BANK OF NEW YORK MELLON TRUST, NA, AS NOTES COLLATERAL AGENT, THE
Reel/Frame 025863/0535 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2009
From: AGARWAL, AMIT; BAKER, STEVE
To: AVAYA INC.
Reel/Frame 023311/0836 →
Continuity (1)
Related Publication 20110072508A1 · Mar 24, 2011