IP Library › Granted Patent US 11,916,882
Granted Patent B2
US 11,916,882 · App. 17/953,318 · Granted Feb 27, 2024

Methods and apparatus for controlling and implementing firewalls

Inventor: Mark Reimer (Denver, CO)
Assignee: Charter Communications Operating, LLC
H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,916,882
App. No.
17/953,318
Granted
Feb 27, 2024
Kind
B2
Abstract

Network traffic through a router, e.g., home router, operating as a firewall is monitored and analyzed the network to identify devices and the type of one or more of the identified devices. In some embodiments, the device type identification is performed using a neural network. The router stores a set of firewall templates. At different times, different templates are applied, e.g. based on mode of operation, user selection, and/or time information. Rules in a firewall template, applicable at a given time to traffic corresponding to identified devices, that are attempting to send or receive via the router, are applied. Different rules may, and sometimes do, apply to different device type classifications.

Claims (49)

1. A method, the method comprising:

operating a firewall device at a first customer premises to pass network traffic corresponding to at least a first device as part of the first device communicating over a network with at least one device outside the first customer premises without applying firewall rules to the traffic corresponding to the first device

monitoring, at the firewall device, network traffic through the firewall device corresponding to the first device communicating over the network with at least one device outside the first customer premises without subjecting said traffic corresponding to the first device to rules in a firewall template for a period of time;

analyzing, prior to applying firewall rules at the firewall device to traffic corresponding to the first device communicating over the network with at least one device outside the first customer premises, the network traffic corresponding to the first device passing through the firewall device, to identify a device type of the first device, said analyzing identifying the first device as a first type device; and

applying, at the firewall device, a first rule in a firewall template applicable to devices of the first type, said applying the first rule including applying the first rule to traffic corresponding to the first device when the first device attempts to send or receive traffic via the firewall device, said applying of the first rule following identifying the first device as a device of the first type based on traffic passed through the firewall device.

2. The method of claim 1 , further comprising, prior to applying the first rule to the traffic corresponding to the first device:

storing a set of firewall templates, said set of firewall templates including at least a first firewall template including at least one firewall rule to be applied to devices of the first type, said devices of the first type being one of a video player device type, video camera device type, a voice assistant device type, a gaming console device type or a cell phone device type; and

determining the firewall template that is applicable at a given time from the stored set of firewall templates based on one or more of: i) a current day of the week, ii) a time of day, iii) a date, or iv) user input.

3. The method of claim 1 ,

wherein analyzing the network traffic to identify the type of one or more of the identified devices includes identifying the device type of the first device as being a video camera device type or a voice assistant device type.

4. The method of claim 3 , further comprising:

identifying devices located at said first customer premises where said firewall device is located based on a destination address included in detected network traffic, said first device being an identified device.

5. The method of claim 3 , wherein analyzing the network traffic corresponding to the first device to identify the device type of the first device includes using a neural network trained to identify device types based on monitored.

6. The method of claim 1 , further comprising:

providing a user an opportunity to populate templates for different modes of operation, each template including network traffic restrictions to be applied by the firewall for one or more types of devices.

7. The method of claim 1 , wherein the applied firewall template includes information indicating different types of device to be blocked from accessing the Internet for a specified period of time, said first type device being one of the types of devices to be blocked for the specified period of time.

8. The method of claim 1 , wherein the applied firewall template applicable is a first template that indicates specific devices which are to be permitted Internet access.

9. The method of claim 1 , wherein the applied firewall template limits devices of the first type to a specified amount of access to one or more networks outside the customer premises within a predetermined recurring time.

10. The method of claim 1 , wherein the applied firewall template which blocks video player type devices, gaming console type devices, mobile phone devices, computer type devices and streaming music player devices from communicating through the firewall device.

11. A firewall device comprising:

memory including processor executable instructions for controlling the firewall device, said firewall device being a router, said firewall device being in a network; and

a processor configured to execute the processor executable instructions stored in memory and control the firewall device to:

pass network traffic corresponding to at least a first device without applying firewall rules to the traffic corresponding to the first device as part of the first device communicating over a network with at least one device outside a first customer premises;

monitor, at the firewall device, network traffic through the firewall device corresponding to the first device communicating over the network with at least one device outside the first customer premises without subjecting said traffic corresponding to the first device to rules in a firewall template for a period of time;

analyze, prior to applying firewall rules at the firewall device to traffic corresponding to the first device communicating over the network with at least one device outside the first customer premises, the network traffic corresponding to the first device passing through the firewall device, to identify a device type of the first device, said analyzing identifying the first device as a first type device; and

apply, at the firewall device, a first rule in a firewall template applicable to devices of the first type, said applying the first rule including applying the first rule to traffic corresponding to the first device when the first device attempts to send or receive traffic via the firewall device, said applying of the first rule following identifying the first device as a device of the first type based on traffic passed through the firewall device.

12. The firewall device of claim 11 , wherein said processor is further configured to:

store a set of firewall templates, said set of firewall templates including at least a first firewall template including at least one firewall rule to be applied to devices of a first type, said devices of a first type being one of a video player device type, video camera device type, a voice assistant device type, a gaming console device type or a cell phone device type; and

determine the firewall template that is applicable at a given time from the stored set of firewall templates based on one or more of: i) a current day of the week, ii) a time of day, iii) a date, or iv) user input,

said storing a set of firewall templates and said determining the firewall template that is applicable at a given time, being performed prior to applying the rules in the firewall template applicable at the given time.

13. The firewall device of claim 12 , wherein at least some of said stored firewall templates include user specified restrictions to be applied by the firewall to devices of the first type.

14. The firewall device of claim 11 , wherein said processor is further configured to:

identify devices located at said first customer premises where said firewall device is located based on at least one of a source address and a destination address included in detected network traffic.

15. The firewall device of claim 11 , wherein said processor is further configured to:

use a neural network trained to identify device types based on monitored traffic to determine a device type corresponding to an identified device.

16. The firewall device of claim 12 wherein the firewall device is a router.

17. A system comprising:

a firewall device located at a first customer premises and operating as a router, said firewall device being in a network, the firewall device including:

memory including processor executable instructions for controlling the firewall device; and

a first processor configured, under control of the processor executable instructions, to control the firewall device to:

pass network traffic corresponding to at least a first device without applying firewall rules to the traffic corresponding to the first device as part of the first device communicating over a network with at least one device outside the first customer premises;

monitor, at the firewall device, network traffic through the firewall device corresponding to the first device communicating over the network with at least one device outside the first customer premises without subjecting said traffic corresponding to the first device to rules in a firewall template for a period of time;

analyze, prior to applying firewall rules at the firewall device to traffic corresponding to the first device communicating over the network with at least one device outside the first customer premises, the network traffic corresponding to the first device passing through the firewall device, to determine a device type of the first device, said analyzing identifying the first device as a first type device; and

apply, at the firewall device, a first rule in a firewall template applicable to devices of the first type, said applying the first rule including applying the first rule to traffic corresponding to the first device when the first device attempts to send or receive traffic via the firewall device, said applying of the first rule following identifying the first device as a device of the first type based on traffic passed through the firewall device.

18. The system of claim 17 , wherein said first processor is further configured to:

store a set of firewall templates, said set of firewall templates including at least a first firewall template including at least one firewall rule to be applied to devices of the first type, said devices of a first type being one of a video player device type, video camera device type, a voice assistant device type, a gaming console device type or a cell phone device type.

19. The system of claim 18 , wherein said first processor is further configured to:

determine the firewall template that is applicable at a given time from the stored set of firewall templates based on one or more of: i) a current day of the week, ii) a time of day, iii) a date, or iv) user input.

20. The system of claim 18 , wherein the firewall device is a router.

Continuity (2)
Continuation 16357199 · Mar 18, 2019
Related Publication 20230012719A1 · Jan 19, 2023