IP Library › Granted Patent US 10,701,033
Granted Patent B2
US 10,701,033 · App. 15/895,946 · Granted Jun 30, 2020

Network layer signaling security with next generation firewall

Inventors: Sachin Verma (San Jose, CA); Leonid Burakovsky (Pleasanton, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/0236H04L63/164H04L63/20H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,701,033
App. No.
15/895,946
Granted
Jun 30, 2020
Kind
B2
Abstract

Techniques for network layer signaling security with next generation firewall are disclosed. In some embodiments, a system/process/computer program product for network layer signaling security with next generation firewall includes monitoring a network layer signaling protocol traffic on a service provider network at a security platform; and filtering the network layer signaling protocol traffic at the security platform based on a security policy.

Claims (27)

1. A system, comprising:

a processor configured to:

monitor a network layer signaling protocol traffic on a service provider network at a security platform;

filter the network layer signaling protocol traffic at the security platform based on a security policy, wherein the network layer signaling protocol is a Signaling Connection Control Part (SCCP) protocol, wherein a signaling transport protocol is a signaling transport (SIGTRAN) protocol; and

perform state and packet validation of the SCCP protocol per payload protocol identifier (PPID) and source/destination IP addresses while filtering SIGTRAN protocol messages; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system recited in claim 1 , wherein the security platform is configured with a plurality of security policies based on a Signaling Connection Control Part (SCCP) protocol.

3. The system recited in claim 1 , wherein the processor is further configured to perform security policy enforcement based on the network layer signaling protocol.

4. The system recited in claim 1 , wherein the processor is further configured to perform state and packet validation of the network layer signaling protocol based on the security policy.

5. The system recited in claim 1 , wherein the processor is further configured to perform threat prevention based on a signaling transport protocol.

6. The system recited in claim 1 , wherein the security platform monitors wireless interfaces including a plurality of interfaces for a signaling control protocol and user data traffic in a mobile core network for a 3G and/or 4G network.

7. The system recited in claim 1 , wherein the processor is further configured to block a message filtered in the network layer signaling protocol traffic based on the security policy.

8. The system recited in claim 1 , wherein the processor is further configured to block a message filtered in the network layer signaling protocol traffic or a higher layer of signaling traffic based on the security policy.

9. A method, comprising:

monitoring a network layer signaling protocol traffic on a service provider network at a security platform;

filtering the network layer signaling protocol traffic at the security platform based on a security policy, wherein the network layer signaling protocol is a Signaling Connection Control Part (SCCP) protocol, wherein a signaling transport protocol is a signaling transport (SIGTRAN) protocol; and

performing state and packet validation of the SCCP protocol per payload protocol identifier (PPID) and source/destination IP addresses while filtering SIGTRAN protocol messages.

10. The method of claim 9 , wherein the security platform is configured with a plurality of security policies based on a Signaling Connection Control Part (SCCP) protocol.

11. The method of claim 9 , wherein the method further comprises performing security policy enforcement based on the network layer signaling protocol.

12. The method of claim 9 , wherein the method further comprises performing state and packet validation of the network layer signaling protocol based on the security policy.

13. A computer program product, the computer program product being embodied in a non-transitory tangible computer readable storage medium and comprising computer instructions for:

monitoring a network layer signaling protocol traffic on a service provider network at a security platform;

filtering the network layer signaling protocol traffic at the security platform based on a security policy, wherein the network layer signaling protocol is a Signaling Connection Control Part (SCCP) protocol, wherein a signaling transport protocol is a signaling transport (SIGTRAN) protocol; and

performing state and packet validation of the SCCP protocol per payload protocol identifier (PPID) and source/destination IP addresses while filtering SIGTRAN protocol messages.

14. The computer program product recited in claim 13 , wherein the security platform is configured with a plurality of security policies based on a Signaling Connection Control Part (SCCP) protocol.

15. The computer program product recited in claim 13 , wherein the computer program product further comprises computer instructions for performing security policy enforcement based on the network layer signaling protocol.

16. The computer program product recited in claim 13 , wherein the computer program product further comprises computer instructions for performing state and packet validation of the network layer signaling protocol based on the security policy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 23, 2018
From: VERMA, SACHIN; BURAKOVSKY, LEONID
To: PALO ALTO NETWORKS, INC.
Reel/Frame 045887/0453 →
Continuity (1)
Related Publication 20190253388A1 · Aug 15, 2019