IP Library › Granted Patent US 11,916,957
Granted Patent B1
US 11,916,957 · App. 18/064,177 · Granted Feb 27, 2024

System and method for utilizing DHCP relay to police DHCP address assignment in ransomware protected network

Inventors: Raymond Wing Chon Cheh (Sunnyvale, CA); Chia Chi Cheng (Belmont, CA); Satish M. Mohan (San Jose, CA); Ritesh R. Agrawal (San Jose, CA); Vinay Adavi (Sunnyvale, CA)
Assignee: AIRGAP NETWORKS INC.
H04L63/1466H04L12/4641H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,916,957
App. No.
18/064,177
Granted
Feb 27, 2024
Kind
B1
Abstract

A technique to stop lateral movement of ransomware between endpoints in a VLAN is disclosed. A security appliance is set as the default gateway for intra-LAN communication by overwriting the DHCP responses. Message traffic from compromised endpoints is detected. Attributes of ransomware may be detected in the message traffic, as well as attempts to circumvent the security appliance. Compromised devices may be quarantined. Additionally, the DHCP address assignment may be policed to ensure accuracy and correctness to provide an additional layer of security.

Claims (27)

1. A computer-implemented method of ransomware protection in a Virtual Local Area Network (VLAN) network, comprising:

configuring a security appliance as a DHCP relay for a Dynamic Host Configuration Protocol (DHCP) server in the VLAN network;

receiving, by the security appliance, responses from the DHCP server to DHCP requests and the security appliance further overwriting a subnet mask associated with the responses to 255.255.255.255 to set the security appliance as a default gateway for a plurality of endpoint devices of the VLAN network; and

intercepting, by the security appliance, DHCP packets between the DHCP server and endpoint devices and policing, by the security appliance, 1) Internet Protocol (IP) addresses requested by client endpoint devices, and 2) IP addresses proposed by the DHCP server; and

wherein the policing of IP address assignments by the security appliance is selected to aid in protecting the security of the endpoint devices from ransomware.

2. The computer-implemented method of claim 1 , further comprising configuring IP addresses of the DHCP server and the DHCP relay to include at least one of a dynamic IP pool, reserved addresses, Media Access Control (MAC) addresses, and static IP addresses.

3. The computer-implemented method of claim 2 , wherein an assignment of different types of IP addresses assigned to particular endpoint devices is implemented to enhance security against ransomware attacks by preventing malevolent entities from acquiring a valid client endpoint device via DHCP.

4. The computer-implemented method of claim 1 , wherein the policing of IP address assignments comprises performing at least one action to stop, reject, or decline accepting IP addresses with pre-selected address attributes.

5. The computer-implemented method of claim 4 , wherein the pre-selected address attributes correspond to banned MAC addresses and the method responds to banned Media access Control (MAC) addresses with a Negative Acknowledgement (NACK).

6. The computer-implemented method of claim 1 , wherein a client endpoint device requesting a renewal of an address is reassigned a different reserved address.

7. The computer-implemented method of claim 1 , wherein the IP address assignments include at least one of: 1) modifying ciaddr requested by an endpoint device in a DHCP DISCOVER/REQUEST, 2) modifying yiaddr assigned to an endpoint device in a DHCP OFFER, 3) generated a DHCP Negative Acknowledgement (NACK) in response to a client DHCP Discover or Request, 4) proactively drop a DHCP OFFER/Acknowledgement (ACK) packet being sent to a client; and 5) generate a DHCP decline to a DHCP Server in response to a DHCP OFFER.

8. The computer-implemented method of claim 1 , further comprising:

detecting, by the security appliance, lateral propagation of ransomware between endpoint devices via intra-VLAN communication in the VLAN network.

9. A system for ransomware protection in a Virtual Local Area Network (VLAN) network, comprising:

a security appliance acting as a Dynamic Host Configuration Protocol (DHCP) relay for a DHCP server in the VLAN network;

the security appliance serving as the default gateway for a plurality of endpoint devices of the shared VLAN network by the security appliance, overwriting a subnet mask to 255.255.255.255 of responses to the DHCP server to set the security appliance as a default gateway; and

the security appliance further policing DHCP Internet Protocol (IP) address assignments by intercepting, by the security appliance, DHCP packets between the DHCP server and endpoint devices and policing, by the security appliance, 1) IP addresses requested by client endpoint devices, and 2) IP addresses proposed by the DHCP server, wherein the policing of IP address assignments by the security appliance is selected to aid in protecting the security of the endpoint devices from ransomware.

10. The system of claim 9 , where the IP addresses of the DHCP server and the DHCP relay are configurable to include at least one of a dynamic IP pool, reserved addresses, Media Access Control (MAC) addresses, and static IP addresses.

11. The system of claim 9 , wherein an assignment of different types of IP addresses assigned to particular endpoint devices is implemented to enhance security against ransomware attacks by preventing malevolent entities from acquiring a valid client endpoint device via DHCP.

12. The system of claim 9 , wherein the policing of IP address assignments comprises performing at least one action to stop, reject, or decline accepting IP addresses with pre-selected address attributes.

13. The system of claim 12 , wherein the pre-selected address attributes correspond to banned MAC addresses and the system-responds to the banned MAC addresses with a Negative Acknowledgement (NACK).

14. The system of claim 9 , wherein an endpoint device requesting a renewal of an address is reassigned a different reserved address.

15. The system of claim 9 , wherein the policing includes examining DHCP protocol packets between the DHCP server and endpoint devices and performing at least one of: 1) modifying ciaddr requested by an endpoint device in a DHCP DISCOVER/REQUEST, 2) modifying yiaddr assigned to an endpoint device in a DHCP OFFER, 3) generated a DHCP Negative Acknowledgement (NACK) in response to an endpoint device DHCP Discover or Request, 4) proactively dropping a DHCP OFFER/Acknowledgement (ACK) packet being sent to an endpoint device; and 5) generating a DHCP decline to a DHCP Server in response to a DHCP OFFER.

16. A method for providing ransomware protection in a Virtual Local Area Network (VLAN) network, comprising:

relaying, by a security appliance having a Dynamic Host Configuration Protocol (DHCP) relay function, DHCP requests from a plurality of endpoint devices to a DHCP server, the security appliance further overwriting a subnet mask of responses to the DHCP server to 255.255.255.255 to set the security appliance as a default gateway for the plurality of endpoint devices of the VLAN network;

monitoring, by the security appliance, intra-VLAN communication between the plurality of endpoint devices of the VLAN network; and

policing, by the security appliance, DHCP address assignments of endpoint devices.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2025
From: AIRGAP NETWORKS INC.
To: ZSCALER, INC.
Reel/Frame 072048/0358 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2023
From: CHEH, RAYMOND WING CHON; CHENG, CHIA CHI; MOHAN, SATISH M.; AGRAWAL, RITESH R.; ADAVI, VINAY
To: AIRGAP NETWORKS INC.
Reel/Frame 062326/0079 →
Continuity (3)
Continuation In Part 17521092 · Nov 8, 2021
Continuation 17387615 · Jul 28, 2021
Continuation 17357757 · Jun 24, 2021
Cited By (3)
US 12,531,912 US 12,542,817 US 12,556,586