IP Library Granted Patent US 12,261,887
Granted Patent B2
US 12,261,887 · App. 15/920,049 · Granted Mar 25, 2025

Monitoring device data and gateway data

Inventors: Rhys McCaig (Portland, OR); Seetharaman Ramasubramani (Saratoga, CA); Gaurav Khandpur (Santa Clara, CA); Paddy Vishnubhatt (Los Altos, CA); Evan Kaverman (San Francisco, CA); Eric Bertrand (Montreal, CA); Andrea Peiro (Burlingame, CA); Jeffrey Barberio (San Jose, CA); Remko Vos (San Mateo, CA); Jeremy Clark (Mountain View, CA); Steven Leardi (New York, NY); Albert Ribe Costa (San Mateo, CA); Thomas Fad (Philadelphia, PA)
Assignee: Comcast Cable Communications, LLC
H04L63/20H04L63/0209H04L63/0227H04L63/1408H04L63/1441H04W12/122H04W84/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,261,887
App. No.
15/920,049
Filed
Mar 13, 2018
Granted
Mar 25, 2025
Kind
B2
Art Unit
2494
USPC
726/12
Abstract

Systems, apparatuses, and methods are described for monitoring device data and/or gateway data. Devices may be connected to a network via a gateway device. Data transmitted and/or received by one or more of the devices may be captured and monitored to determine various parameters associated with the one or more devices. Data associated with the gateway device may also be captured and monitored. Signal strengths, device statuses, network security, and/or other metrics may be determined based on monitored data.

Claims (65)

1. A method comprising:

sending, by a computing device, a request to activate a network security service, on a network security service entity external to a gateway device, for a first network associated with the gateway device;

sending, by the computing device to the gateway device, an instruction to activate a security agent configured to execute on the gateway device to support the network security service;

causing, after receiving an indication that the network security service has been activated, modification, of an application on a user device associated with the gateway device, with information indicative of activation of the network security service; and

receiving, by the computing device and from the network security service entity, an indication of one or more network security threats associated with one or more devices connected to the first network.

2. The method of claim 1 , further comprising:

monitoring, after activation of the network security service, data traffic associated with the one or more devices connected to the first network; and

blocking, based on the monitoring and the indication of the one or more network security threats, a device, of the one or more devices, from connecting to the gateway device.

3. The method of claim 1 , wherein the computing device is in a first cloud network in communication with the first network via the gateway device, and wherein the network security service entity is in a second cloud network linked to the first cloud network via the computing device.

4. The method of claim 1 , further comprising:

causing output, via the application on the user device, of data indicating:

a plurality of devices associated with the gateway device, and

a quantity of network security threats associated with each device of the plurality of devices.

5. The method of claim 1 , wherein the instruction comprises an instruction to deactivate a dynamic host configuration protocol service.

6. The method of claim 1 , wherein the sending the request to activate the network security service comprises requesting the network security service to block unauthorized access from an external network to one or more devices connected to the first network.

7. The method of claim 1 , further comprising causing output, via the application on the user device, of an interface indicating that a device, of the one or more devices, was disconnected from the first network.

8. The method of claim 1 , further comprising causing output, via the application on the user device, of an interface indicating that a device, of the one or more devices, was blocked from receiving a requested resource.

9. The method of claim 1 , further causing, based on the one or more network security threats, redirecting of a request, for a resource, from a device of the one or more devices to a proxy for the resource.

10. The method of claim 1 , further comprising causing output, via the user device, of an interface indicating an option to perform one or more of:

allow access to a blocked resource, or

download or update software on a device of the one or more devices.

11. The method of claim 1 , further comprising causing output, via the user device, of an interface indicating an option to view one or more of:

devices associated with a quantity of network security threats,

one or more locations of the one or more devices associated with the one or more network security threats, or

quantities of network security threat associated with similar premises to a premises associated with the gateway device.

12. The method of claim 1 , wherein the sending the request is based on receiving:

an indication of a one-touch selection, on an interface of the application on the user device, to activate the network security service.

13. The method of claim 1 , further comprising sending, by the computing device to the gateway device, information for determining whether a request, from a second computing device to the gateway device, for a resource, should be:

directed to the resource,

redirected to a proxy of the resource; or

blocked.

14. The method of claim 1 , wherein the network security service is configured to, based on being activated for the first network, perform one or of more of:

content access control;

intrusion detection;

intrusion prevention;

devices fingerprinting; or

device intelligence.

15. A method comprising:

sending, by a gateway device, a request to activate a network security service at a security device, wherein the activated network security service protects a network associated with the gateway device;

activating, on the gateway device, a network security agent for communication with the security device;

receiving, by the gateway device and from the network security service, an indication of one or more network security threats associated with one or more devices associated with the gateway device; and

based on the received indication of the one or more network security threats, redirecting a request, for a resource, from a device of the one or more devices to a proxy for the resource.

16. The method of claim 15 , wherein the activating comprises activating, using firmware of the gateway device, the network security agent.

17. The method of claim 15 , further comprising:

sending, to a mobile device associated with the gateway device, information to cause output of data indicating:

a plurality of devices associated with the gateway device, and

a quantity of network security threats associated with each device of the plurality of devices.

18. The method of claim 15 , further comprising:

causing output, via a user device associated with the gateway device, of data indicating one or more origination locations of the one or more network security threats.

19. The method of claim 15 , wherein receiving the indication of one or more network security threats comprises receiving, via the network security agent and from a security cloud network associated with the network security service, the indication of one or more network security threats.

20. The method of claim 15 , further comprising receiving, by the gateway device and via a selection of a single graphical user interface option to activate the network security service, a request to activate the network security service.

21. The method of claim 15 , further comprising:

sending, by the gateway device, data transmitted or received by the one or more devices associated with the gateway device, wherein the receiving the indication of the one or more network security threats is based on the data.

22. The method of claim 15 , further comprising receiving, via the activated network security agent, information for determining whether the request for the resource should be:

directed to the resource,

redirected to the proxy of the resource; or

blocked.

23. A method comprising:

storing, by a computing device, configuration parameters of a gateway device;

determining, by the computing device, that a security service is available, on an entity external to the gateway device, for protecting a network associated with the gateway device;

sending, by the computing device, to the gateway device, based on determining that the security service is available, and based on the configuration parameters indicating a network security agent is configured to execute on the gateway device to support the security service, an instruction to execute the network security agent;

modifying, based on the sending the instruction, the configuration parameter to indicate the network security agent is executing on the gateway device; and

receiving, by the computing device and from the entity, an indication of one or more network security threats associated with one or more devices connected to the network.

24. The method of claim 23 , further comprising receiving a request to activate the security service, wherein the request is based on a single selection of an option, to activate the security service, output by a second user device associated with the gateway device.

25. The method of claim 23 , further comprising sending, to the entity and based on an entitlement, an instruction to activate the security service such that the network security agent becomes configured to enable the entitlement.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE TWELFTH INVENTOR'S NAME PREVIOUSLY RECORDED ON REEL 045678 FRAME 0762. ASSIGNOR(S) HEREBY CONFIRMS THE TO READ AS RIBE COSTA, ALBERT. Recorded Oct 25, 2018
From: MCCAIG, RHYS; RAMASUBRAMANI, SEETHARAMAN; KHANDPUR, GAURAV; VISHNUBHATT, PADDY; KAVERMAN, EVAN; BERTRAND, ERIC; PEIRO, ANDREA; BARBERIO, JEFFREY; VOS, REMKO; CLARK, JEREMY; LEARDI, STEVEN; RIBE COSTA, ALBERT; FAD, THOMAS
To: COMCAST CABLE COMMUNICATIONS, LLC
Reel/Frame 047306/0095 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2018
From: MCCAIG, RHYS; RAMASUBRAMANI, SEETHARAMAN; KHANDPUR, GAURAV; VISHNUBHATT, PADDY; KAVERMAN, EVAN; BERTRAND, ERIC; PEIRO, ANDREA; BARBERIO, JEFFREY; VOS, REMKO; CLARK, JEREMY; LEARDI, STEVEN; COSTA, ALBERT RIBE; FAD, THOMAS
To: COMCAST CABLE COMMUNICATIONS, LLC
Reel/Frame 045678/0762 →
Continuity (3)
Provisional Application 62614926 · Jan 8, 2018
Provisional Application 62470818 · Mar 13, 2017
Related Publication 20180262533A1 · Sep 13, 2018
References Cited (43)
US 6629145B1 · Pham · 2003 [cited by examiner]
US 7316029B1 · Parker · 2008 [cited by examiner]
US 9716701B1 · Wang · 2017 [cited by examiner]
US 10320813B1 · Ahmed · 2019 [cited by examiner]
US 20050235360A1 · Pearson · 2005 [cited by examiner]
US 20060206940A1 · Strauss · 2006 [cited by examiner]
US 20070042769A1 · Thommana · 2007 [cited by examiner]
US 20110225647A1 · Dilley · 2011 [cited by examiner]
US 20120159572A1 · Patel · 2012 [cited by examiner]
US 20120306788A1 · Chen · 2012 [cited by examiner]
US 20140366118A1 · Yin · 2014 [cited by examiner]
US 20150087258A1 · Barnes · 2015 [cited by examiner]
US 20150089062A1 · Reiter · 2015 [cited by examiner]
US 20160127379A1 · Nayshtut · 2016 [cited by examiner]
US 20160248811A1 · Chen · 2016 [cited by examiner]
US 20190108470A1 · Jain · 2019 [cited by examiner]
W. Yassin, N. I. Udzir, Z. Muda, A. Abdullah and M. T. Abdullah, “A Cloud-based Intrusion Detection Service framework,” Proceedings Title: 2012 International Conference on Cyber Security, Cyber Warfare and Digital Foren… [cited by examiner]
D. H. Sharma, C. A. Dhote and M. M. Potey, “Implementing Intrusion Management as Security-as-a-service from cloud,” 2016 International Conference on Computation System and Information Technology for Sustainable Solution… [cited by examiner]
A. Meddahi, K. MaSmoudi, H. Afifi, A. M'Hamed and I. Hajeh, “Enabling secure third party control on wireless home networks,” 2004 4th Workshop on Applications and Services in Wireless Networks, 2004. ASWN 2004., Boston,… [cited by examiner]
RDK Central, “Reference Design Kit”, retrieved from http://RDKcentral.com/about-rdk/ on Feb. 28, 2017. [cited by applicant]
Amazon Web Services, “Amazon Kinesis”, retrieved from https://aws.amazon.com/kinesis/ on Mar. 12, 2017. [cited by applicant]
Amazon Web Services, “Amazon Simple Storage Service (S3)—Cloud Storage”, retrieved from https://aws.amazon.com/s3/ on Feb. 28, 2017. [cited by applicant]
Amazon Web Services, “Amazon Virtual Private Cloud (VPC)” retrieved from https://aws.amazon.com/vpc/ on Feb. 28, 2017. [cited by applicant]
Amazon Web Services, “Cloud Computing Services”, retrieved from https://aws.amazon.com/ on Feb. 28, 2017. [cited by applicant]
Anicas, Mitchell, “An Introduction to HAProxy and Load Balancing Concepts”, Digitial Ocean, May 13, 2014, retrieved from https://www.digitalocean.com/community/tutorials/an-introduction-to-haproxy-and-load-balancing-con… [cited by applicant]
Tableau Software, “Answer questions as fast as you can think of them with Tableau”, retrieved from https://www.tableau.com/trial/tableau-software on Feb. 28, 2017. [cited by applicant]
Wikipedia, “Apache Cassandra”, article retrieved Feb. 28, 2017. [cited by applicant]
Wikipedia, “Apache Spark”, article retrieved Feb. 28, 2017. [cited by applicant]
D3.js, “Data-Driven Documents”, retrieved from https://d3js.org/ on Feb. 28, 2017. [cited by applicant]
NGINX, “Deploying Global Server Load Balancing (GSLB)”, retrieved from https://www.nginx.com/resources/glossary/global-server-load-balancing/ on Feb. 28, 2017. [cited by applicant]
Wikipedia, “Django (web framework)”, article retrieved Feb. 28, 2017. [cited by applicant]
Fingerbank: Device Fingerprints, retrieved from https://fingerbank.org/learn_more.html on Mar. 9, 2017. [cited by applicant]
GitHub, “uber/ringpop-node: Scalable, fault-tolerant application-layer sharding for Node.js applications”, retrieved from https://github.com/uber/ringpop-node on Mar. 13, 2017. [cited by applicant]
IBM, “What is Avro?”, retrieved from https://www-01.ibm.com/software/data/infosphere/hadoop/avro on Feb. 28, 2017. [cited by applicant]
“Kafka in a Nutshell”, Sep. 25, 2015, retrieved from https://sookocheff.com/post/kafka/kafka-in-a-nutshell/. [cited by applicant]
Quantenna, “Unparalleled performance—at play or work”, retrieved from http://www.quantenna.com/products on Feb. 28, 2017. [cited by applicant]
RabbitMQ, “What can RabbitMQ do for you?”, retrieved from https://www.rabbitmq.com/features.html on Feb. 28, 2017. [cited by applicant]
Redis, retrieved from https://redis.io/ on Feb. 28, 2017. [cited by applicant]
S. Alexander and R. Droms, “DHCP Options and BOOTP Vendor Extensions”, IETF, Mar. 1997, retrieved from https://www.ietf.org/rfc/rfc2132.txt. [cited by applicant]
The Broadband Forum: Technical Report, “TR-181, Device Data Model for TR-069”, Issue 2, Amendment 2, Feb. 2011. [cited by applicant]
Cloudera, “Using Kafka with Flume”, retrieved from https://www.coudera.com/documentation/kafka/latest/topics/kafka_flume.html on Mar. 9, 2017. [cited by applicant]
Wikipedia, “Virtual private cloud”, article retrieved Mar. 9, 2017. [cited by applicant]
Apache Flume, “Welcome to Apache Flume”, retrieved from https://flume.apache.org on Mar. 12, 2017. [cited by applicant]
Cited By (2)
US 12,547,705 US 12,694,125