IP Library Granted Patent US 9,560,077
Granted Patent B2
US 9,560,077 · App. 14/698,560 · Granted Jan 31, 2017

Methods and systems for protecting a secured network

Inventors: Steven Rogers (Leesburg, VA); Sean Moore (Hollis, NH)
Assignee: Centripetal Networks, Inc.
H04L63/20H04L63/0209H04L63/0218H04L63/0236H04L63/0263H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,560,077
App. No.
14/698,560
Granted
Jan 31, 2017
Kind
B2
Abstract

Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at least one of multiple packet transformation functions specified by the dynamic security policy may be performed on the packets. Performing the at least one of multiple packet transformation functions specified by the dynamic security policy on the packets may include performing at least one packet transformation function other than forwarding or dropping the packets.

Claims (62)

1. A method comprising:

provisioning, each device of a plurality of devices, with one or more rules generated based on a boundary of a network protected by the plurality of devices with one or more networks other than the network protected by the plurality of devices at which the device is configured to be located; and

configuring, each device of the plurality of devices, to:

receive packets via a communication interface that does not have a network-layer address;

responsive to a determination by the device that a portion of the packets received from or destined for a host located in the network protected by the plurality of devices corresponds to criteria specified by the one or more rules, drop the portion of the packets; and

modify a switching matrix of a local area network (LAN) switch associated with the device such that the LAN switch is configured to drop the portion of the packets responsive to the determination by the device.

2. The method of claim 1 , wherein:

the provisioning comprises, provisioning, each device of the plurality of devices, with at least one rule configured to identify spoofed source addresses; and

the configuring comprises, configuring, each device of the plurality of devices, to, responsive to a determination by the device that at least a portion of the packets comprise a source address corresponding to criteria specified by the at least one rule, drop the at least a portion of the packets.

3. The method of claim 1 , wherein:

the provisioning comprises, provisioning, each device of the plurality of devices, with at least one rule configured to identify malicious network traffic based on information received from a subscription service; and

the configuring comprises, configuring, each device of the plurality of devices, to, responsive to a determination by the device that at least a portion of the packets comprise data corresponding to criteria specified by the at least one rule and included in the information received from the subscription service, drop the at least a portion of the packets.

4. The method of claim 1 , wherein:

the provisioning comprises, provisioning, each device of the plurality of devices, with the one or more rules via a communication interface of the device having a network-layer address.

5. The method of claim 1 , comprising configuring, each device of the plurality of devices, to, responsive to a determination by the device that at least a portion of the packets correspond to criteria specified by the one or more rules, encapsulate, each packet of the at least a portion of the packets, with a header specifying a network address different from a destination network address specified by the packet.

6. The method of claim 1 , comprising configuring, each device of the plurality of devices, to, responsive to a determination by the device that at least a portion of the packets correspond to criteria specified by the one or more rules, route, each packet of the at least a portion of the packets, toward its destination network-layer address via a layer-2 virtual local area network (VLAN) such that the packet is routed differently than if it had been routed based on its destination network-layer address.

7. A system comprising:

at least one processor; and

a memory storing instructions that when executed by the at least one processor cause the system to:

provision, each device of a plurality of devices, with one or more rules generated based on a boundary of a network protected by the plurality of devices with one or more networks other than the network protected by the plurality of devices at which the device is configured to be located; and

configure, each device of the plurality of devices, to:

receive packets via a communication interface that does not have a network-layer address;

responsive to a determination by the device that a portion of the packets received from or destined for a host located in the network protected by the plurality of devices corresponds to criteria specified by the one or more rules, drop the portion of the packets; and

modify a switching matrix of a local area network (LAN) switch associated with the device such that the LAN switch is configured to drop the portion of the packets responsive to the determination by the device.

8. The system of claim 7 , wherein the instructions, when executed by the at least one processor, cause the system to:

provision, each device of the plurality of devices, with at least one rule configured to identify spoofed source addresses; and

configure, each device of the plurality of devices, to, responsive to a determination by the device that at least a portion of the packets comprise a source address corresponding to criteria specified by the at least one rule, drop the at least a portion of the packets.

9. The system of claim 7 , wherein the instructions, when executed by the at least one processor, cause the system to:

provision, each device of the plurality of devices, with at least one rule configured to identify malicious network traffic based on information received from a subscription service; and

configure, each device of the plurality of devices, to, responsive to a determination by the device that at least a portion of the packets comprise data corresponding to criteria specified by the at least one rule and included in the information received from the subscription service, drop the at least a portion of the packets.

10. The system of claim 7 , wherein the instructions, when executed by the at least one processor, cause the system to:

provision, each device of the plurality of devices, with the one or more rules via a communication interface of the device having a network-layer address.

11. The system of claim 7 , wherein the instructions, when executed by the at least one processor, cause the system to configure, each device of the plurality of devices, to, responsive to a determination by the device that at least a portion of the packets correspond to criteria specified by the one or more rules, encapsulate, each packet of the at least a portion of the packets, with a header specifying a network address different from a destination network address specified by the packet.

12. The system of claim 7 , wherein the instructions, when executed by the at least one processor, cause the system to configure, each device of the plurality of devices, to, responsive to a determination by the device that at least a portion of the packets correspond to criteria specified by the one or more rules, route, each packet of the at least a portion of the packets, toward its destination network-layer address via a layer-2 virtual local area network (VLAN) such that the packet is routed differently than if it had been routed based on its destination network-layer address.

13. One or more non-transitory computer-readable media comprising instructions that when executed by a computing system cause the computing system to:

provision, each device of a plurality of devices, with one or more rules generated based on a boundary of a network protected by the plurality of devices with one or more networks other than the network protected by the plurality of devices at which the device is configured to be located; and

configure, each device of the plurality of devices, to:

receive packets via a communication interface that does not have a network-layer address;

responsive to a determination by the device that a portion of the packets received from or destined for a host located in the network protected by the plurality of devices corresponds to criteria specified by the one or more rules, drop the portion of the packets; and

modify a switching matrix of a local area network (LAN) switch associated with the device such that the LAN switch is configured to drop the portion of the packets responsive to the determination by the device.

14. The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the computing system, cause the computing system to:

provision, each device of the plurality of devices, with at least one rule configured to identify spoofed source addresses; and

configure, each device of the plurality of devices, to, responsive to a determination by the device that at least a portion of the packets comprise a source address corresponding to criteria specified by the at least one rule, drop the at least a portion of the packets.

15. The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the computing system, cause the computing system to:

provision, each device of the plurality of devices, with at least one rule configured to identify malicious network traffic based on information received from a subscription service; and

configure, each device of the plurality of devices, to, responsive to a determination by the device that at least a portion of the packets comprise data corresponding to criteria specified by the at least one rule and included in the information received from the subscription service, drop the at least a portion of the packets.

16. The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the computing system, cause the computing system to:

provision, each device of the plurality of devices, with the one or more rules via a communication interface of the device having a network-layer address.

17. The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the computing system, cause the computing system to configure, each device of the plurality of devices, to, responsive to a determination by the device that at least a portion of the packets correspond to criteria specified by the one or more rules, encapsulate, each packet of the at least a portion of the packets, with a header specifying a network address different from a destination network address specified by the packet.

18. The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the computing system, cause the computing system to configure, each device of the plurality of devices, to, responsive to a determination by the device that at least a portion of the packets correspond to criteria specified by the one or more rules, route, each packet of the at least a portion of the packets, toward its destination network-layer address via a layer-2 virtual local area network (VLAN) such that the packet is routed differently than if it had been routed based on its destination network-layer address.

19. A method comprising:

provisioning, each device of a plurality of devices, with one or more rules generated based on a boundary of a network protected by the plurality of devices with one or more networks other than the network protected by the plurality of devices at which the device is configured to be located; and

configuring, each device of the plurality of devices, to:

receive packets via a communication interface that does not have a network-layer address;

responsive to a determination by the device that a first portion of the packets received from or destined for a host located in the network protected by the plurality of devices corresponds to criteria specified by the one or more rules, drop the first portion of the packets; and

responsive to a determination by the device that a second portion of the packets correspond to criteria specified by the one or more rules, encapsulate, each packet of the second portion of the packets, with a header specifying a network address different from a destination network address specified by the packet.

20. A method comprising:

provisioning, each device of a plurality of devices, with one or more rules generated based on a boundary of a network protected by the plurality of devices with one or more networks other than the network protected by the plurality of devices at which the device is configured to be located; and

configuring, each device of the plurality of devices, to:

receive packets via a communication interface that does not have a network-layer address;

responsive to a determination by the device that a first portion of the packets received from or destined for a host located in the network protected by the plurality of devices corresponds to criteria specified by the one or more rules, drop the first portion of the packets; and

responsive to a determination by the device that a second portion of the packets correspond to criteria specified by the one or more rules, route, each packet of the second portion of the packets, toward its destination network-layer address via a layer-2 virtual local area network (VLAN) such that the packet is routed differently than if it had been routed based on its destination network-layer address.

Assignments (4)
CHANGE OF NAME Recorded Jan 20, 2023
From: CENTRIPETAL NETWORKS, INC.
To: CENTRIPETAL NETWORKS, LLC
Reel/Frame 062446/0660 →
SECURITY INTEREST Recorded Mar 4, 2019
From: SMITH, DOUGLAS A
To: CENTRIPETAL NETWORKS, INC.
Reel/Frame 048492/0499 →
SECURITY INTEREST Recorded Apr 19, 2017
From: CENTRIPETAL NETWORKS, INC.
To: SMITH, DOUGLAS A.
Reel/Frame 042056/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2015
From: ROGERS, STEVEN; MOORE, SEAN
To: CENTRIPETAL NETWORKS, INC.
Reel/Frame 035519/0348 →
Continuity (2)
Continuation 13657010 · Oct 22, 2012
Related Publication 20150341388A1 · Nov 26, 2015