IP Library › Granted Patent US 11,985,109
Granted Patent B1
US 11,985,109 · App. 16/032,924 · Granted May 14, 2024

Systems, methods and apparatus for local area network isolation

Inventor: Donald Van Oort (West Okoboji, IA)
Assignee: R&D Industries, Inc.
H04L63/0227H04L12/4641H04L63/10H04L63/1408H04L65/102H04L67/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,985,109
App. No.
16/032,924
Filed
Jul 11, 2018
Granted
May 14, 2024
Kind
B1
Art Unit
2431
USPC
726/3
Abstract

The disclosed apparatus, systems and methods relate to methods, systems, and devices for the isolation of devices on a LAN network. Route poisoning, ARP poisoning null routing, blackhole and/or firewall blocking are employed to prevent peer-to-peer network communications within the local area network.

Claims (54)

1. A system for isolation of a LAN comprising:

a. a local area network comprising:

i. at least one default gateway;

ii. a set of devices, comprising:

A. a first host;

B. a second host;

C. a whitelist device; and

D. one or more additional devices,

wherein at least the first host and second host are connected to the internet via the default gateway; and

iii. an ARP table; and

b. a device comprising a hardware processor configured to execute a series of executable steps on the first host to allow communications with the whitelist device and to prevent communications with the second host via one or more rules,

wherein the series of executable steps comprises the establishment and enforcement of at least one endpoint rule including ARP poisoning and two or more of route poisoning rules, null routing, and blackhole routing rules on a data link layer or network layer of the set of devices,

wherein the ARP poisoning comprises:

clearing a host ARP table;

creating a routing blacklist comprising IP addresses for all hosts where peer-to-peer communication is to be prevented;

creating a routing whitelist comprising IP address for all whitelist devices; and

creating a false entry for each device on the routing blacklist, wherein the false entry is formatted as a MAC address that is not the MAC address of any of the set of devices in use within the local area network.

2. The system of claim 1 , wherein the device processor is configured to enforce firewall rules on the first host on at least one of a transport layer, a session layer, a presentation layer, or an application layer.

3. The system of claim 1 , wherein the first host is a virtualized server.

4. The system of claim 1 , wherein the device comprising a hardware processor is constructed and arranged to whitelist and blacklist network devices.

5. The system of claim 4 , wherein the device comprising a hardware processor is configured to establish and enforce additional endpoint rules preventing communications with the blacklisted network devices.

6. The system of claim 5 , wherein the device comprising a hardware processor is configured to whitelist a default gateway.

7. The system of claim 5 , wherein the device comprising a hardware processor is configured to whitelist a subset of necessary local area devices.

8. The system of claim 1 , wherein the device processor is configured to enforce firewall rules on the second host.

9. The system of claim 1 , wherein the false entry comprises a first portion and a second portion, wherein the first portion corresponds to a device manufacturer and the combination of the first portion and the second portion does not match the MAC address of any of the set of devices connected to the local area network.

10. A local area network host isolation system comprising:

a. a local area network comprising:

i. a set of devices comprising:

A. a first host;

B. a second host; and

C. one or more additional devices; and

ii. a network sensor; and

b. a hardware processor, the hardware processor constructed and arranged for executing a platform configured to establish and enforce rules on the first and second hosts in the local area network to prevent peer-to-peer communications within the local area network by implementing ARP poisoning and route poisoning on the first or second host,

wherein at least one of the ARP poisoning and the route poisoning comprises:

clearing a host ARP table;

creating a routing blacklist comprising IP addresses for all hosts where peer-to-peer communication is to be prevented;

creating a routing whitelist comprising IP addresses for all whitelist devices; and

creating a false entry for device on the routing blacklist, wherein the false entry is formatted as a MAC address with a first portion that corresponds to a valid device manufacturer, and the false entry is not the MAC address of any of the set of devices in use within the local area network.

11. The system of claim 10 , wherein the first host and second host are connected to the internet via a default gateway.

12. The system of claim 10 , wherein the platform is constructed and arranged for establishing and enforcing firewall rules on local area network hosts to prevent peer-to-peer communications between the hosts.

13. The system of claim 10 , wherein the platform is constructed and arranged to whitelist and blacklist devices.

14. The system of claim 13 , wherein the platform is configured to whitelist at least one of a default gateway, a server, a host, and a printer and blacklist the first host on the second host.

15. The system of claim 10 , wherein the platform is configured to establish and enforce rules applied to at least one of a data link layer or a network layer.

16. A method of isolating hosts on a local area network comprising:

executing a host- or cloud-based platform, wherein the platform is configured to establish and enforce rules on the hosts to allow communications with a whitelist device and to prevent peer-to-peer communications within the local area network, the rules comprising ARP poisoning and two or more of route poisoning rules, and null routing rules on a data link layer or network layer of the hosts,

wherein the platform is configured to establish and enforce a set of firewall rules on the hosts, the firewall rules applied to a transport layer, a session layer, a presentation layer, or an application layer of the hosts, and

wherein ARP poisoning comprises:

clearing a host ARP table;

creating a routing blacklist comprising IP addresses for all hosts where peer-to-peer communication is to be prevented;

creating a routing whitelist comprising IP addresses for all whitelist devices;

creating a false entry for each device on the routing blacklist, wherein the false entry comprises a MAC address with a first portion that corresponds to a valid device manufacturer, and the false entry is not the MAC address of any of the hosts in use within the local area network.

17. The method of claim 16 , comprising an ARP based intrusion detection system.

18. The method of claim 16 , comprising a route-based intrusion detection system.

19. The method of claim 16 , comprising a network sensor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2018
From: VAN OORT, DONALD
To: R&D INDUSTRIES, INC.
Reel/Frame 046740/0541 →
Continuity (1)
Provisional Application 62531231 · Jul 11, 2017
Cited By (1)
US 12,375,475