IP Library › Granted Patent US 11,689,543
Granted Patent B2
US 11,689,543 · App. 16/939,233 · Granted Jun 27, 2023

System and method for detecting transmission of a covert payload of data

Inventor: John Rankin (Williamsport, OH)
Assignee: Rankin Labs, LLC
H04L63/1408H04L63/0209
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,689,543
App. No.
16/939,233
Granted
Jun 27, 2023
Kind
B2
Abstract

Systems and methods for detecting transmission of covert payloads of data are provided. A datagram is received at a host within a network. A determination is made that processing the datagram creates an error condition. A determination is made that that the datagram contains a payload intended for covert transmission where at least one suspicious condition is present. The suspicious conditions include an encrypted payload, a destination not matching any known address for hosts within the network, a time to live value matching the number of gateways traversed by the datagram within the network, and a particular type of error condition.

Claims (54)

1. A method for detecting transmission of covert payloads of data, said method comprising the steps of:

receiving a datagram at a host within a network;

determining that processing of the datagram creates an error condition;

determining that the datagram comprises at least each of the following suspicious conditions:

an encrypted payload;

a destination not matching any known address for hosts within the network;

a time to live value matching a number of gateways traversed by said datagram within said network; and

the error condition being of a particular type; and

subsequently, determining that the datagram contains a payload intended for covert transmission.

2. The method of claim 1 wherein:

the determination that the datagram comprises the suspicious conditions is made at the host.

3. The method of claim 1 wherein:

the network is an IP network.

4. The method of claim 3 wherein:

the host is configured to generate ICMP error messages.

5. The method of claim 1 further comprising the steps of:

generating an alert message indicating the presence of the suspicious conditions.

6. The method of claim 1 wherein:

the particular type of error condition comprises statistically uncommon errors relative to a sample pool of datagrams.

7. The method of claim 1 wherein:

the particular type of error condition comprises statistically common errors relative to a sample pool of datagrams.

8. The method of claim 1 wherein:

the particular type of error condition is related to fragmentation.

9. The method of claim 1 wherein:

the particular type of error condition is related to formation of the datagram.

10. The method of claim 1 wherein:

the particular type of error condition is unrelated to activity expected on the network.

11. A system for detecting transmission of covert payloads of data comprising:

a network comprising a number of hosts, wherein each of said hosts comprises an address; and

software instructions, located at each of said hosts, which when executed configures each of the hosts to:

receive a number of datagrams;

process each of said datagrams in accordance with preprogrammed protocols;

identify received datagrams creating an error condition when processed according to said preprogrammed protocols;

determine if suspicious conditions exist in the identified datagrams, said suspicious conditions comprising: an encrypted payload, a destination address comprising a valid address not matching any of said addresses for said hosts, a time to live value matching a number of gateways traversed by said datagram within said network, and the error condition being of a particular type;

subsequently, determine that the datagram contains a payload intended for covert transmission where at least one or more of said suspicious conditions are present; and

generate an alert message regarding the payload intended for covert transmission.

12. The system of claim 11 wherein:

the particular type is selected from the group consisting of: statistically uncommon error conditions relative to a sample pool of datagrams, statistically common error conditions relative to the sample pool of datagrams, error conditions related to fragmentation, error conditions related to formation of the datagram, and error conditions unrelated to activity expected on the network.

13. The system of claim 11 wherein:

the network is an IP network; and

each of said hosts are configured to generate ICMP error messages upon determination of said error condition.

14. A method for detecting transmission of covert payloads of data comprising the steps of:

receiving datagrams at a host within an IP network comprising a number of blind hosts, each associated with an address and configured to generate error messages upon receipt of datagrams meeting certain error conditions in accordance with preprogrammed protocols;

determining that processing of at least one of the datagram creates an error condition under said preprogrammed protocols;

determining that the at least one datagram comprises each of the following suspicious conditions:

an encrypted payload;

a destination of a valid address not matching any of said addresses for said hosts within the network;

a time to live value matching a number of gateways traversed within said network;

the error condition is statistically uncommon relative to a sample pool of datagrams; and

the error condition is at least one of: related to fragmentation, related to formation of the datagram, and unrelated to activity expected on the network;

subsequently, determining that the at least one the datagram contains a payload intended for covert transmission;

isolating the at least one datagram;

generating an alert message regarding the at least one datagram; and

eliminating the at least one datagram.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2020
From: RANKIN, JOHN
To: RANKIN LABS, LLC
Reel/Frame 054617/0780 →
Continuity (3)
Continuation In Part 16534511 · Aug 7, 2019
Provisional Application 62717202 · Aug 10, 2018
Related Publication 20200358791A1 · Nov 12, 2020