IP Library › Granted Patent US 12,206,647
Granted Patent B2
US 12,206,647 · App. 17/824,054 · Granted Jan 21, 2025

Dynamic variance mechanism for securing enterprise resources using a virtual private network

Inventors: Arjun Kochhar (Bangalore, IN); Suman Aluvala (Bangalore, IN); Amit Yadav (Bangalore, IN); Aman Srivastava (Bangalore, IN)
Assignee: Omnissa, LLC
H04L63/0272G06N20/00H04W12/40
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,206,647
App. No.
17/824,054
Granted
Jan 21, 2025
Kind
B2
Abstract

Disclosed are various examples for securing enterprise resources using a virtual private network. At least one computing device that can authenticate a client device for a virtual private network (VPN) connection based on a first device identifier received from the client device and a second device identifier received from a remote management service. The at least one computing device can determine that a network event associated with the client device has been observed and execute a machine learning routine to identify a pattern of access for the client device. A network access anomaly is determined in response to a network interaction of the client device deviating from the pattern of access for the client device. A remedial action is performed based on an anomaly type associated with the network access anomaly.

Claims (39)

1. A system, comprising:

at least one computing device; and

program instructions stored in memory of the at least one computing device and executable by the at least one computing device that, when executed, direct the at least one computing device to at least:

authenticate a client device for using a virtual private network (VPN) for network communications, wherein the authentication is based on a first device identifier (ID) received from the client device and on a second device ID generated by a management service executing on the at least one computing device;

train a machine learning (ML) routine to identify a pattern from past network communications of the client device;

in response to observing a new network communication of the client device, determine, using the trained ML routine, that the new network communication is an anomaly;

in response to determining that the new network communication is an anomaly: pause the VPN from being used by the client device for the network communications, and instruct the client device to reauthenticate with the at least one computing device to resume using the VPN, wherein pausing the VPN includes sending a control message to pause network traffic, to a VPN application residing on the client device; and

in response to the client device reauthenticating with the at least one computing device: resume the network communications of the client device using the VPN, and further train the ML routine using the anomaly.

2. The system of claim 1 , wherein the ML routine is trained by inputting into the ML routine, historical data describing the past network communications of the client device.

3. The system of claim 1 , wherein authenticating the client device for using the VPN includes: receiving the first device ID and the second device ID from the client device, transmitting the first device ID to the management service, and receiving the second device ID from the management service.

4. The system of claim 1 , wherein pausing the VPN and instructing the client device to reauthenticate, include transmitting the control message to the VPN application executing on the client device, the control message directing the client device to pause a flow of network traffic and to reauthenticate.

5. The system of claim 1 , wherein resuming the network communications of the client device using the VPN includes notifying the VPN application executing on the client device, that the client device has been verified based on a hyperlink transmitted to the client device.

6. A computer-implemented method, comprising:

authenticating a client device for using a virtual private network (VPN) for network communications, wherein the authentication is based on a first device identifier (ID) received from the client device and on a second device ID generated by a management service executing on at least one computing device;

training a machine learning (ML) routine to identify a pattern from past network communications of the client device;

in response to observing a new network communication of the client device, determining, using the trained ML routine, that the new network communication is an anomaly;

in response to determining that the new network communication is an anomaly: pausing the VPN from being used by the client device for the network communications, and instructing the client device to reauthenticate with the at least one computing device to resume using the VPN, wherein pausing the VPN includes sending a control message to pause network traffic, to a VPN application residing on the client device; and

in response to the client device reauthenticating with the at least one computing device: resuming the network communications of the client device using the VPN, and further training the ML routine using the anomaly.

7. The computer-implemented method of claim 6 , wherein the ML routine is trained by inputting into the ML routine, historical data describing the past network communications of the client device.

8. The computer-implemented method of claim 6 , wherein authenticating the client device for using the VPN includes: receiving the first device ID and the second device ID from the client device, transmitting the first device ID to the management service, and receiving the second device ID from the management service.

9. The computer-implemented method of claim 6 , wherein pausing the VPN and instructing the client device to reauthenticate, include transmitting the control message to the VPN application executing on the client device, the control message directing the client device to pause a flow of network traffic and to reauthenticate.

10. The computer-implemented method of claim 6 , wherein resuming the network communications of the client device using the VPN includes notifying the VPN application executing on the client device, that the client device has been verified based on a hyperlink transmitted to the client device.

11. A non-transitory computer-readable medium comprising program instructions stored thereon executable in a computing device that, when executed, direct the computing device to at least:

authenticate a client device for using a virtual private network (VPN) for network communications, wherein the authentication is based on a first device identifier (ID) received from the client device and on a second device ID generated by a management service executing on the computing device;

train a machine learning (ML) routine to identify a pattern from past network communications of the client device;

in response to observing a new network communication of the client device, determine, using the trained ML routine, that the new network communication is an anomaly;

in response to determining that the new network communication is an anomaly: pause the VPN from being used by the client device for the network communications, and instruct the client device to reauthenticate with the computing device to resume using the VPN, wherein pausing the VPN includes sending a control message to pause network traffic, to a VPN application residing on the client device; and

in response to the client device reauthenticating with the computing device: resume the network communications of the client device using the VPN, and further train the ML routine using the anomaly.

12. The non-transitory computer-readable medium of claim 11 , wherein the ML routine is trained by inputting into the ML routine, historical data describing the past network communications of the client device.

13. The non-transitory computer-readable medium of claim 11 , wherein authenticating the client device for using the VPN includes: receiving the first device ID and the second device ID from the client device, transmitting the first device ID to the management service, and receiving the second device ID from the management service.

14. The non-transitory computer-readable medium of claim 11 , wherein pausing the VPN and instructing the client device to reauthenticate, include transmitting the control message to the VPN application executing on the client device, the control message directing the client device to pause a flow of network traffic and to reauthenticate.

15. The non-transitory computer-readable medium of claim 11 , wherein resuming the network communications of the client device using the VPN includes notifying the VPN application executing on the client device, that the client device has been verified based on a hyperlink transmitted to the client device.

16. The system of claim 3 , wherein authenticating the client device for using the VPN further includes determining that the second device ID received from the client device matches the second device ID received from the management service.

17. The system of claim 1 , wherein the program instructions, when executed, further direct the at least one computing device to at least:

upon authenticating the client device for using the VPN, encrypt data and transmit the encrypted data to the client device using the VPN.

18. The computer-implemented method of claim 8 , wherein authenticating the client device for using the VPN further includes determining that the second device ID received from the client device matches the second device ID received from the management service.

19. The computer-implemented method of claim 6 , further comprising:

upon authenticating the client device for using the VPN, encrypting data and transmitting the encrypted data to the client device using the VPN.

20. The non-transitory computer-readable medium of claim 13 , wherein authenticating the client device for using the VPN further includes determining that the second device ID received from the client device matches the second device ID received from the management service.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0242 →
Priority Claims (1)
IN 201941051804 · Dec 13, 2019 · national
Continuity (2)
Continuation 16788325 · Feb 12, 2020
Related Publication 20220286435A1 · Sep 8, 2022
References Cited (39)
US 8649768B1 · Gaddam · 2014 [cited by examiner]
US 9843934B1 · Jiang · 2017 [cited by examiner]
US 9942200B1 · Tan · 2018 [cited by examiner]
US 10064055B2 · Raleigh et al. · 2018 [cited by applicant]
US 10129269B1 · Ford · 2018 [cited by examiner]
US 11297078B2 · Johnson · 2022 [cited by examiner]
US 20040022245A1 · Forbes et al. · 2004 [cited by applicant]
US 20040022257A1 · Green et al. · 2004 [cited by applicant]
US 20040148326A1 · Nadgir et al. · 2004 [cited by applicant]
US 20090292816A1 · Etchegoyen et al. · 2009 [cited by applicant]
US 20100325711A1 · Etchegoyen · 2010 [cited by applicant]
US 20120209951A1 · Enns et al. · 2012 [cited by applicant]
US 20130097674A1 · Jindal · 2013 [cited by examiner]
US 20170109840A1 · Lu · 2017 [cited by examiner]
US 20170201531A1 · Kim · 2017 [cited by examiner]
US 20170289134A1 · Bradley · 2017 [cited by examiner]
US 20180212930A1 · Cammisa · 2018 [cited by examiner]
US 20190356650A1 · Leavy · 2019 [cited by examiner]
US 20210144780A1 · Hao · 2021 [cited by examiner]
CA 2759732A1 · 2010 [cited by applicant]
CN 108293046A · 2018 [cited by applicant]
JP 4713186B2 · 2006 [cited by applicant]
WO WO02073877A2 · 2002 [cited by examiner]
WO WO2022027048A1 · 2022 [cited by examiner]
Priya, “Behavioral Biometrics based Authentication System using MLP-NN and MVPA,” 2021 IEEE International Power and Renewable Energy Conference (IPRECON), Kollam, India, 2021, pp. 1-6, doi: 10.1109/IPRECON52453.2021.964… [cited by examiner]
Sharghi et al.i, “A User Behavior-Based Approach to Detect the Insider Threat in Distributed Diagnostic Imaging Systems,” 2016 IEEE 29th International Symposium on Computer-Based Medical Systems (CBMS), Belfast and Dubl… [cited by examiner]
Ashibani et al., “A Behavior Profiling Model for User Authentication in IoT Networks based on App Usage Patterns,” IECON 2018—44th Annual Conference of the IEEE Industrial Electronics Society, Washington, DC, USA, 2018,… [cited by examiner]
Lu et al., “An user behavior credibility authentication model in cloud computing environment,” Proceedings of 2nd International Conference on Information Technology and Electronic Commerce, Dalian, China, 2014, pp. 271-… [cited by examiner]
Salunke et al., “Transfer Learning for Behavioral Biometrics-based Continuous User Authentication,” 2022 International Symposium on Networks, Computers and Communications (ISNCC), Shenzhen, China, 2022, pp. 1-6, doi: 10… [cited by examiner]
Zhao et al., “Bayesian Statistical Inference in Machine Learning Anomaly Detection,” 2010 International Conference on Communications and Intelligence Information Security, Xi'an, China, 2010, pp. 113-116, doi: 10.1109/I… [cited by examiner]
Mihailescu et al., “Unveiling Threats: Leveraging User Behavior Analysis for Enhanced Cybersecurity,” 2023 15th International Conference on Electronics, Computers and Artificial Intelligence (ECAI), Bucharest, Romania, … [cited by examiner]
Ding et al., “Detection of Anomaly User Behaviors Based on Deep Neural Networks,” 2021 IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), Shenyang, China, 2021,… [cited by examiner]
Khan et al., “Using Ensemble Learning for Securing Public Area Networks from VPN Malicious Transmissions,” IEEE, Chennai, India, 2023, pp. 1-6, doi: 10.1109/RMKMATE59243.2023.10368897. (Year: 2023). [cited by examiner]
Yanqin et al., “Design and Optimization of VPN Security Gateway,” 2006 First International Conference on Communications and Networking in China, Beijing, China, 2006, pp. 1-4, doi: 10.1109/CHINACOM.2006.344676. (Year: 2… [cited by examiner]
Mimura et al., “Behavior Shaver: An Application Based Layer 3 VPN that Conceals Traffic Patterns Using SCTP,” 2010 International Conference on Broadband, Wireless Computing, Communication and Applications, Fukuoka, Japa… [cited by examiner]
Katulanda et al., “Machine Learning Based Web Application Plugin for Threat Detection and IP Analysis,” 2023 5th International Conference on Advancements in Computing (ICAC), Colombo, Sri Lanka, 2023, pp. 17-22, doi: 10… [cited by examiner]
Rogers, Dean. “Orthus authentication protocol: Background services.” 2016 IEEE Symposium Series on Computational Intelligence (SSCI). IEEE, 2016. [cited by applicant]
Small, S., et al. “Scalable VPNs for the global information grid.” MILCOM 2005-2005 IEEE Military Communications Conference. IEEE, 2005. [cited by applicant]
Wangensteen, Audun, Lars Lunde, and Ivar Jorstad. “Secured enterprise access with strong SIM authentication.” 2006 10th IEEE International Enterprise Distributed Object Computing Conference (EDOC'06). IEEE, 2006. [cited by applicant]