IP Library Granted Patent US 11,558,413
Granted Patent B2
US 11,558,413 · App. 17/721,514 · Granted Jan 17, 2023

Monitoring encrypted network traffic

Inventors: Benjamin Thomas Higgins (Shoreline, WA); Jeff James Costlow (Kingston, WA); John Gemignani, Jr. (Bremerton, WA); Michael Kerber Krause Montague (Lake Forest Park, WA); Eric James Rongo (Seattle, WA); Xue Jun Wu (Seattle, WA)
Assignee: ExtraHop Networks, Inc.
H04L63/1425H04L9/0819H04L43/062H04L43/0876H04L63/0209H04L63/0428H04L63/0807H04L63/0869
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,558,413
App. No.
17/721,514
Filed
Apr 15, 2022
Granted
Jan 17, 2023
Kind
B2
Art Unit
2494
USPC
713/169
Abstract

Embodiments are directed to monitoring network traffic using network monitoring computers (NMCs). Networks may be configured to protect servers using centralized security protocols. Centralized security protocols may depend on centralized control provided by authentication control servers. If a client intends to access protected servers it may communicate with the authentication control server to obtain keys that enable it to access the requested servers. NMCs may monitor network traffic the centralized security protocol to collect metrics associated with the control servers, clients, or resource servers.

Claims (76)

1. A method for monitoring communication over a network between one or more computers, with one or more network monitoring computers (NMCs) that enable performance of actions, comprising:

in response to determining a first communication between a client and a resource server that includes a request to authenticate the client with the resource server, monitoring a second communication between the resource server and a control server to authenticate the client with the resource server; and

in response to determining network traffic associated with a request from the client to access the resource server, performing further actions, including:

monitoring the first communication for a portion of the first communication that is encrypted with a client key associated with the client, and wherein the client is provided an authentication token associated with the control server;

monitoring the second communication for a request to access the resource server, wherein a portion of the second communication is encrypted with one or more of the client key or the authentication token, and wherein the control server provides an access token to the client that enables the client to access the resource server; and

generating one or more reports that include information associated with one or more of the client, the resource server, or the control server.

2. The method of claim 1 , further comprising:

monitoring other communication between the client and the resource server that includes the access token, wherein one or more portions of the other communication are encrypted with one or more of the access token or one or more other keys derived from one or more of the access token or one or more other portions of the other communication, and wherein the other communication enables the client to access the resource server.

3. The method of claim 1 , further comprising:

employing the control server to distribute one or more client keys to one or more of the client or the resource server.

4. The method of claim 1 , further comprising:

generating one or more metrics based on the network traffic associated with one or more of the first communication or the second communication.

5. The method of claim 1 , further comprising:

providing one or more keys to the NMC;

employing the one or more keys to decrypt one or more portions of one or more of the first communication, or the second communication; and

updating the one or more metrics based on the one or more decrypted portions of the one or more of the first communication, or the second communication.

6. The method of claim 1 , further comprising:

providing one or more sharing agents to the one or more computers;

determining one or more of the client key, the authentication token, or the access token based on information provided by the one or more sharing agents;

employing the one or more of the client key, the authentication token, or the access token to decrypt one or more portions of one or more of the first communication, or the second communication; and

updating one or more metrics based on the one or more decrypted portions of the one or more of the first communication, or the second communication.

7. The method of claim 1 , wherein monitoring the first communication between the client and the control server further comprises:

generating a portion of one or more metrics based on one or more characteristics of the network traffic associated the first communication, wherein the portion of the one or more metrics is based on one or more non-encrypted portions of the network traffic;

generating a second portion of the one or more metrics based on one or more other characteristics of the network traffic associated the second communication, wherein the second portion of the one or more metrics is based on one or more other non-encrypted portions network traffic; and

correlating the second communication with the first communication based on the first portion of the one or more metrics and the second portion of the one or more metrics.

8. The method of claim 1 , further comprising: employing a processor readable non-transitory storage media to include instructions for monitoring the network traffic using the one or more network monitoring computers, wherein execution of the instructions by the one or more networking monitoring computers enables performance of the method.

9. A system for monitoring network traffic in a network:

one or more network monitoring computers (NMCs), comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

in response to determining a first communication between a client and a resource server that includes a request to authenticate the client with the resource server, monitoring a second communication between the resource server and a control server to authenticate the client with the resource server; and

in response to determining network traffic associated with a request from the client to access the resource server, performing further actions, including:

monitoring the first communication for a portion of the first communication that is encrypted with a client key associated with the client, and wherein the client is provided an authentication token associated with the control server;

monitoring the second communication for a request to access the resource server, wherein a portion of the second communication is encrypted with one or more of the client key or the authentication token, and wherein the control server provides an access token to the client that enables the client to access the resource server; and

generating one or more reports that include information associated with one or more of the client, the resource server, or the control server; and

one or more client computers, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that enable performance of actions, including:

providing at least a portion of one or more of the first communication, or the second communication.

10. The system of claim 9 , further comprising:

monitoring other communication between the client and the resource server that includes the access token, wherein one or more portions of the other communication are encrypted with one or more of the access token or one or more other keys derived from one or more of the access token or one or more other portions of the other communication, and wherein the other communication enables the client to access the resource server.

11. The system of claim 9 , further comprising:

employing the control server to distribute one or more client keys to one or more of the client or the resource server.

12. The system of claim 9 , further comprising:

generating one or more metrics based on the network traffic associated with one or more of the first communication or the second communication.

13. The system of claim 9 , further comprising:

providing one or more keys to the NMC;

employing the one or more keys to decrypt one or more portions of one or more of the first communication, or the second communication; and

updating the one or more metrics based on the one or more decrypted portions of the one or more of the first communication, or the second communication.

14. The system of claim 9 , further comprising:

providing one or more sharing agents to the one or more computers;

determining one or more of the client key, the authentication token, or the access token based on information provided by the one or more sharing agents;

employing the one or more of the client key, the authentication token, or the access token to decrypt one or more portions of one or more of the first communication, or the second communication; and

updating one or more metrics based on the one or more decrypted portions of the one or more of the first communication, or the second communication.

15. The system of claim 9 , wherein monitoring the first communication between the client and the control server further comprises:

generating a portion of one or more metrics based on one or more characteristics of the network traffic associated the first communication, wherein the portion of the one or more metrics is based on one or more non-encrypted portions of the network traffic;

generating a second portion of the one or more metrics based on one or more other characteristics of the network traffic associated the second communication, wherein the second portion of the one or more metrics is based on one or more other non-encrypted portions network traffic; and

correlating the second communication with the first communication based on the first portion of the one or more metrics and the second portion of the one or more metrics.

16. A network monitoring computer (NMC) for monitoring network traffic between one or more computers, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that enable performance of actions, including:

in response to determining a first communication between a client and a resource server that includes a request to authenticate the client with the resource server, monitoring a second communication between the resource server and a control server to authenticate the client with the resource server; and

in response to determining network traffic associated with a request from the client to access the resource server, performing further actions, including:

monitoring the first communication for a portion of the first communication that is encrypted with a client key associated with the client, and wherein the client is provided an authentication token associated with the control server;

monitoring the second communication for a request to access the resource server, wherein a portion of the second communication is encrypted with one or more of the client key or the authentication token, and wherein the control server provides an access token to the client that enables the client to access the resource server; and

generating one or more reports that include information associated with one or more of the client, the resource server, or the control server.

17. The NMC of claim 16 , further comprising:

monitoring other communication between the client and the resource server that includes the access token, wherein one or more portions of the other communication are encrypted with one or more of the access token or one or more other keys derived from one or more of the access token or one or more other portions of the other communication, and wherein the other communication enables the client to access the resource server.

18. The NMC of claim 16 , further comprising:

employing the control server to distribute one or more client keys to one or more of the client or the resource server.

19. The NMC of claim 16 , further comprising:

generating one or more metrics based on the network traffic associated with one or more of the first communication or the second communication.

20. The NMC of claim 16 , further comprising:

providing one or more keys to the NMC;

employing the one or more keys to decrypt one or more portions of one or more of the first communication, or the second communication; and

updating the one or more metrics based on the one or more decrypted portions of the one or more of the first communication, or the second communication.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2022
From: HIGGINS, BENJAMIN THOMAS; COSTLOW, JEFF JAMES; GEMIGNANI, JOHN, JR.; MONTAGUE, MICHAEL KERBER KRAUSE; RONGO, ERIC JAMES; WU, XUE JUN
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 059608/0554 →
Continuity (3)
Continuation 17483148 · Sep 23, 2021
Provisional Application 63082262 · Sep 23, 2020
Related Publication 20220239685A1 · Jul 28, 2022
Cited By (12)
US 12,223,357 US 12,223,359 US 12,225,030 US 12,309,192 US 12,346,595 US 12,355,816 US 12,361,430 US 12,363,203 US 12,483,384 US 12,587,535 US 12,647,441 US 12,652,312