IP Library › Granted Patent US 9,104,874
Granted Patent B2
US 9,104,874 · App. 13/515,316 · Granted Aug 11, 2015

Method for detecting the hijacking of computer resources

Inventors: Laurent Clevy (Nozay, FR); Antony Martin (Nozay, FR)
Assignee: Alcatel Lucent
G06F21/566G06F21/55H04L63/0407H04L63/0236H04L63/0428H04L63/08H04L63/1408H04L63/1416H04L63/1458H04L63/1466H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,104,874
App. No.
13/515,316
Filed
Jun 26, 2012
Granted
Aug 11, 2015
Kind
B2
Art Unit
2407
USPC
726/22
Abstract

An exemplary technique is provided for detecting a hijacking of computer resources, located in an internal network implementing security criteria and confidentiality criteria specific to the internal network, connected to an external network with no security criteria and confidentiality criteria, through a connection managed by a service provider. The technique includes storing, at the internal network, a connection parameter implemented by the computer resources to communicate with the external network; processing, at the internal network, the stored connection parameter based on an irreversible function to generate a unique code that corresponds to the stored connection parameter but which does not allow the identification of the stored connection parameter from the corresponding generated unique code; and sending, at the internal network, the generated unique code to a server located on the external network so that the server can analyze an activity of the computer resources from the unique code and detect any hijacking of the computer resources.

Claims (19)

1. A method for detecting a hijacking of computer resources, located in an internal network implementing security criteria and confidentiality criteria specific to the internal network, connected to an external network with no security criteria and confidentiality criteria, through a connection managed by a service provider, comprising the steps of:

storing, at the internal network, a connection parameter implemented by the computer resources to communicate with the external network, wherein the connection parameter comprises a content of a body of a packet transmitted from the internal network to the external network or identifiers included in DNS server requests issued by the internal network to the external network;

processing, at the internal network, the stored connection parameter based on an irreversible function to generate a unique code that corresponds to said stored connection parameter but which does not allow the identification of said stored connection parameter from the corresponding generated unique code; and

sending, at the internal network, said generated unique code to a server located on the external network so that the server can analyze an activity of the computer resources from said unique code and detect any hijacking of the computer resources.

2. The method according to claim 1 , wherein at least one of the following elements comprises the connection parameter: the content of the body of the packet transmitted from the internal network to the external network, the identifiers included in DNS requests issued by the internal network to the external network, or identifiers of recipients of emails sent by the internal network to the external network.

3. The method according to claim 1 , further comprising the step of using, at the internal network, a hashing function to generate the unique code based on said stored connection parameter.

4. The method according to claim 1 , further comprising the step of carrying out an internal analysis of said connection parameter within the internal network prior to the processing of the stored connection parameter to detect the hijacking of resources or to generate a new connection parameter.

5. The method according to claim 4 , further comprising the step of transmitting, at the internal network, an internal analysis report to a remote server.

6. The method according to claim 5 , further comprising the step of sending, at the internal network, the new connection parameter with the generated unique codes to the remote server.

7. The method according to claim 6 , wherein the new connection parameter is an unprocessed connection parameter.

8. The method according to claim 1 , further comprising the step of considering, at the internal network, information on the user's conditions for using the resources to connect to the external network to detect the hijacking of computer resources.

9. The method according to claim 1 , further comprising the step of considering, at the internal network, information related to the user's conditions for using the resources to access the external network, the information being sent by the service provider to detect the hijacking of resources.

10. The method according to claim 1 , wherein the confidentiality criterion comprises a prohibition on identifying domain names requested by a given terminal.

11. The method according to claim 1 , wherein the security criterion comprises usage of an Asymmetric Digital Subscriber Line high speed connection to communicate with the external network.

12. Computer resources, located on an internal network, adapted to implement security and confidentiality criteria specific to the internal network, and connected to an external network with no security criteria and confidentiality criteria through a connection managed by a service provider, the computer resources being configured to:

store, at the internal network, a connection parameter implemented to communicate with the external network, wherein the connection parameter comprises a content of a body of a packet transmitted from the internal network to the external network or identifiers included in DNS server requests issued by the internal network to the external network;

process, at the internal network, the stored connection parameter based on an irreversible function to generate a unique code that corresponds to said stored connection parameter but which does not allow the identification of said stored connection parameter from the corresponding generated unique code; and

send, at the internal network, the generated unique codes to a server located on the external network so that the server can analyze an activity of the computer resources from said unique code and detect any hijacking of the computer resources.

13. A server for detecting a hijacking of computer resources on an internal network adapted to implement security and confidentiality criteria specific to the internal network, connected to an external network with no security criteria and confidentiality criteria, through a connection managed by a service provider, the server being located on the external network, and the server being configured to analyze the computer resources from unique codes generated by the computer resources in the internal network, wherein the unique code is generated from a connection parameter stored in the internal network that comprises a content of a body of a packet transmitted from the internal network to the external network or identifiers included in DNS server requests issued by the internal network to the external network.

Assignments (11)
PATENT SECURITY AGREEMENT Recorded Apr 22, 2023
From: RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 063429/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2021
From: PROVENANCE ASSET GROUP LLC
To: RPX CORPORATION
Reel/Frame 059352/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: CORTLAND CAPITAL MARKETS SERVICES LLC
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058983/0104 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: NOKIA US HOLDINGS INC.
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058363/0723 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Feb 14, 2019
From: NOKIA USA INC.
To: NOKIA US HOLDINGS INC.
Reel/Frame 048370/0682 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP, LLC
To: CORTLAND CAPITAL MARKET SERVICES, LLC
Reel/Frame 043967/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP LLC
To: NOKIA USA INC.
Reel/Frame 043879/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2017
From: NOKIA TECHNOLOGIES OY; NOKIA SOLUTIONS AND NETWORKS BV; ALCATEL LUCENT SAS
To: PROVENANCE ASSET GROUP LLC
Reel/Frame 043877/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2014
From: CREDIT SUISSE AG
To: ALCATEL LUCENT
Reel/Frame 033868/0555 →
SECURITY AGREEMENT Recorded Jan 30, 2013
From: ALCATEL LUCENT
To: CREDIT SUISSE AG
Reel/Frame 029821/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2012
From: CLEVY, LAURENT; MARTIN, ANTONY
To: ALCATEL LUCENT
Reel/Frame 028445/0886 →
Priority Claims (1)
FR 09 59335 · Dec 21, 2009 · national
Continuity (1)
Related Publication 20120272316A1 · Oct 25, 2012