IP Library Granted Patent US 11,171,985
Granted Patent B1
US 11,171,985 · App. 17/357,757 · Granted Nov 9, 2021

System and method to detect lateral movement of ransomware by deploying a security appliance over a shared network to implement a default gateway with point-to-point links between endpoints

Inventors: Ritesh R. Agrawal (San Jose, CA); Vinay Adavi (Sunnyvale, CA); Satish M. Mohan (San Jose, CA)
Assignee: AIRGAP NETWORKS, INC.
H04L63/1466H04L12/4641H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,171,985
App. No.
17/357,757
Granted
Nov 9, 2021
Kind
B1
Abstract

A technique to stop lateral movement of ransomware between endpoints in a VLAN is disclosed. A security appliance is set as the default gateway for intra-LAN communication. Message traffic from compromised endpoints is detected. Attributes of ransomware may be detected in the message traffic, as well as attempts to circumvent the security appliance. Compromised devices may be quarantined.

Claims (38)

1. A computer-implemented method of ransomware protection in a Virtual Local Area Network (VLAN), comprising:

deploying a security appliance in an access or a trunk port of a shared VLAN environment;

using a subnet mask of 255.255.255.255 to set the security appliance as a default gateway for a plurality of endpoint devices of the shared VLAN environment;

monitoring, by the security appliance, intra-VLAN communication between the plurality of endpoint devices of the shared VLAN environment; and

detecting, by the security appliance, lateral propagation of ransomware between endpoint devices via intra-VLAN communication in the shared VLAN environment.

2. The computer-implemented method of claim 1 , further comprising: allowing, by the security appliance, only authorized communication between the plurality of endpoint devices of the shared VLAN environment.

3. The computer-implemented method of claim 2 , wherein the security appliance blocks unauthorized communication between the plurality of endpoint devices of the shared VLAN environment.

4. The computer-implemented method of claim 1 , further comprising: quarantining an endpoint device compromised by ransomware.

5. The computer-implemented method of claim 4 , wherein the quarantining comprises blocking intra-VLAN communication of the compromised endpoint device.

6. The computer-implemented method of claim 1 , wherein the detection comprises detecting a message attribute of a message originating from an endpoint device indicative of ransomware.

7. The computer-implemented method of claim 6 , wherein the message attribute comprises file scanning code or file encryption code.

8. The computer-implemented method of claim 6 , wherein the detection comprises detecting an attribute of message traffic, relative to a baseline profile of message traffic, indicative of an attempt to laterally propagate ransomware.

9. The computer-implemented method of claim 1 , wherein the detection comprises: detecting a response message from a first endpoint device to a second endpoint device not having a corresponding request message from the second endpoint device pass through the security appliance.

10. The computer-implemented method of claim 1 , further comprising generating an alert in response to detecting an attempt of a compromised endpoint device to laterally propagate ransomware via intra-VLAN communication.

11. The computer-implemented method of claim 1 , further comprising initiating an enhanced security measure in response to detecting an attempt of a compromised endpoint device to laterally propagate ransomware via intra-VLAN communication.

12. A computer program product for ransomware protection in a Virtual Local Area Network (VLAN) comprising computer program instructions, which when executed on a processor implement a method, comprising:

deploying a security appliance in an access or trunk port of a shared VLAN environment;

using a subnet mask of 255.255.255.255 to set the security appliance as a default gateway for a plurality of endpoint devices of the shared VLAN environment;

monitoring, by the security appliance, intra-VLAN communication between the plurality of endpoint devices of the shared VLAN environment; and

detecting, by the security appliance, lateral propagation of ransomware between endpoint devices via intra-VLAN communication in the shared VLAN environment.

13. A Virtual Local Area Network (VLAN) system, comprising:

a VLAN apparatus of a VLAN access or trunk port, the VLAN apparatus including a security appliance configured as a default gateway for intra-VLAN communication of a plurality of endpoint devices using a subnet mask of 255.255.255.255;

the security appliance configured to monitor intra-VLAN message traffic, allow only authorized intra-VLAN communication and detect lateral propagation of ransomware between endpoint devices via intra-VLAN communication in a shared VLAN environment.

14. The VLAN system of claim 13 , wherein the VLAN apparatus comprises an access port.

15. The VLAN system of claim 14 , wherein the security appliance includes computer program instructions stored on a memory associated with the access port and executable on a processor associated with the access port.

16. The VLAN system of claim 13 , wherein the VLAN apparatus comprises a trunk port.

17. The VLAN system of claim 16 , wherein the security appliance includes computer program instructions stored on a memory associated with the trunk port and executable on a processor associated with the trunk port.

18. A computer-implemented method of ransomware protection in a Virtual Local Area Network (VLAN), comprising:

deploying a security appliance in an access or a trunk port of a shared VLAN environment;

using a subnet mask of 255.255.255.255 to set the security appliance as a default gateway for a plurality of endpoint devices of the shared VLAN environment;

monitoring, by the security appliance, intra-VLAN communication between the plurality of endpoint devices of the shared VLAN environment;

detecting, by the security appliance, attributes of intra-LAN messages indicative of lateral propagation of ransomware between endpoint devices via intra-VLAN communication in the shared VLAN environment;

identifying attempts by individual endpoint devices to circumvent the security appliance by identifying response messages passing through the security appliance not having corresponding request messages;

allowing, by the security appliance, only authorized communication between the plurality of endpoint devices of the shared VLAN environment; and

quarantining an endpoint device compromised by ransomware by blocking intra-VLAN communication of the compromised endpoint device.

19. The computer-implemented method of claim 18 , wherein the detecting comprises detecting message attributes associated with file scanning code or file encryption code.

20. The computer-implemented method of claim 18 , wherein the detecting comprises detecting an attribute of message traffic, relative to a baseline profile of message traffic, indicative of an attempt to laterally propagate ransomware.

21. The computer-implemented method of claim 18 , wherein the detecting comprises: detecting a response message from a first endpoint device to a second endpoint device not having a corresponding request message from the second endpoint device pass through the security appliance.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2025
From: AIRGAP NETWORKS INC.
To: ZSCALER, INC.
Reel/Frame 072048/0358 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2021
From: AGRAWAL, RITESH R.; ADAVI, VINAY; MOHAN, SATISH M.
To: AIRGAP NETWORKS, INC.
Reel/Frame 056688/0355 →
Cited By (1)
US 12,483,589