IP Library › Granted Patent US 8,677,474
Granted Patent B2
US 8,677,474 · App. 13/557,921 · Granted Mar 18, 2014

Detection of rogue client-agnostic NAT device tunnels

Inventors: Paul S. Bostrom (Austin, TX); Jason J. Jaramillo (Austin, TX); Tommy L. McLane (Hutto, TX); Eduardo L. Reyes (Austin, TX)
Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,677,474
App. No.
13/557,921
Granted
Mar 18, 2014
Kind
B2
Abstract

Provided are techniques for the prevention of certain types of attacks on computing systems. The current disclosure, which describes one particular type of attack, is directed to the detection and prevention of an attack rather than the mechanics of the particular described attack. The claimed subject matter both detects and prevents an attack without exposing a network to denial-of-service (DoS) attacks by being too restrictive.

Claims (13)

1. A method for providing computer security, comprising:

examining a packet to determine whether the packet is an incoming packet or an outgoing packet, wherein the packet corresponds to a source internet protocol (IP) address, a destination IP address and a port number;

processing an outgoing packet, comprising storing in a table, in conjunction with the source IP address and the port number, an indication that the source IP address represents a potential threat; and

processing an incoming packet, comprising:

correlating the destination IP address and port number with source IP address and port numbers, respectively of entries in the table; and

if the destination IP address and the port number match a source LP address and port number of an entry in the table, storing, in conjunction with all entries in the table with a source IP address corresponding to the destination IP address, an indication that the source IP represents a non-threat; and

if the destination IP address matches a source IP address and the port number does not correlate to a corresponding port number, storing, in conjunction with all entries in the table with a source IP address corresponding to the destination, an indication that the source IP address represents a threat.

2. The method of claim 1 , the processing of the incoming packet further comprising blacklisting the source IP address if the destination IP address and the port number do not correlate with a source IP address and port number of an entry in the table.

3. The method of claim 1 , the processing of the incoming packet further comprising preventing transmission of the packet to the destination IP address if the destination IP address has been indicated as a threat.

4. The method of claim 1 , the processing of the incoming packet further comprising transmitting the packet to the destination IP address and port number if the destination IP address is stored in conjunction with an indication that the destination is a non-threat.

5. The method of claim 1 , wherein the packet is received and the method is implemented at a firewall.

6. The method of claim 5 , wherein the packet is received at the firewall via a network.

7. The method of claim 1 , wherein the table is a port address translation (PAT) table.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2012
From: BOSTROM, PAUL S.; JARAMILLO, JASON J.; MCLANE, TOMMY L.; REYES, EDUARDO L.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 028640/0213 →
Continuity (2)
Continuation 13169163 · Jun 27, 2011
Related Publication 20120331544A1 · Dec 27, 2012