IP Library Granted Patent US 9,860,259
Granted Patent B2
US 9,860,259 · App. 14/965,866 · Granted Jan 2, 2018

Reassembly free deep packet inspection for peer to peer networks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,860,259
App. No.
14/965,866
Granted
Jan 2, 2018
Kind
B2
Abstract

The present disclosure relates to a system, a method, and a non-transitory computer readable storage medium for deep packet inspection scanning at an application layer of a computer. A method of the presently claimed invention may scan pieces of data received out of order without reassembly at an application layer from a first input state generating one or more output states for each piece of data. The method may then identify that the first input state includes one or more characters that are associated with malicious content. The method may then identify that the data set may include malicious content when the first input state combined with one or more output states matches a known piece of malicious content.

Claims (61)

1. A method for deep packet inspection scanning, the method comprising:

receiving a first portion of a data set at an application layer of a computer system in an out of order sequence;

identifying a first input state associated with the data set, wherein the first input state includes a portion of information included in a piece of malicious content identified by a rule;

scanning with the DPI scanner the first portion of the received data set at the application layer from at least the first input state;

generating a first output state based on the scan of the first portion, wherein the first output state corresponds to the malicious content;

identifying that a second portion of the data set follows the first portion of the data set;

scanning with the DPI scanner the second portion of the data set from the first output state;

generating a second output state based on the scan of the second portion;

identifying that a third portion of the data set precedes the first portion of the data set;

scanning the third portion of the data set from the first input state;

generating a third output state based on the scan of the third portion;

identifying that the third output state corresponds to the first input state; and

indicating that the data set contains the malicious content, wherein the first input state, the first output state, and the second output state corresponds to the rule.

2. The method of claim 1 , further comprising terminating the reception of the data set after identifying that the received data set includes malicious content.

3. The method of claim 1 , wherein information identifying that the data set includes malicious content is stored in a database.

4. The method of claim 3 , further comprising:

receiving a subsequent request to download the data set;

identifying that the data set is associated with malicious content; and

blocking the subsequent request to download the data set.

5. The method of claim 1 , wherein a first portion of the at least portion of the data set is received from a first peer computer of a peer to peer network, and a second portion of the at least portion of the data set is received from a second peer computer in the peer to peer network.

6. A non-transitory computer-readable storage medium having embodied thereon a program executable by a processor to perform a method for deep packet inspection scanning, the method comprising:

receiving a first portion of a data set at an application layer of a computer system in an out of order sequence;

identifying a first input state associated with the data set, wherein the first input state includes a portion of information included in a piece of malicious content identified by a rule;

scanning with the DPI scanner the first portion of the received data set at the application layer from at least the first input state;

generating a first output state based on the scan of the first portion, wherein the first output state corresponds to the malicious content;

identifying that a second portion of the data set follows the first portion of the data set;

scanning with the DPI scanner the second portion of the data set from the first output state;

generating a second output state based on the scan of the second portion;

identifying that a third portion of the data set precedes the first portion of the data set;

scanning the third portion of the data set from the first input state;

generating a third output state based on the scan of the third portion;

identifying that the third output state corresponds to the first input state; and

indicating that the data set contains the malicious content, wherein the first input state, the first output state, and the second output state corresponds to the rule.

7. The non-transitory computer readable-storage medium of claim 6 , wherein the program further comprises instructions executable to terminate the reception of the data set after identifying that the received data set includes malicious content.

8. The non-transitory computer-readable storage medium of claim 6 , wherein information identifying that the data set includes malicious content is stored in a database.

9. The non-transitory computer-readable storage medium of claim 8 , wherein the program further comprises instructions executable to:

receive a subsequent request to download the data set;

identify that the data set is associated with malicious content; and

block the subsequent request to download the data set.

10. The non-transitory computer-readable storage medium of claim 6 , wherein a first portion of the at least portion of the data set is received from a first peer computer of a peer to peer network, and a second portion of the at least portion of the data set is received from a second peer computer in the peer to peer network.

11. An apparatus for performing deep packet inspection scanning, the apparatus comprising:

a network interface that receives a first portion of a data set at an application layer of a computer system in an out of order sequence; and

a processor that executes instructions stored in memory, wherein execution of the instructions by the processor:

identifies a first input state associated with the data set, wherein the first input state includes a portion of information included in a piece of malicious content identified by a rule;

scans the first portion of the received data set at the application layer from the first input state;

generates a first output state based on the scan of the first portion, wherein the first output state corresponds to the malicious content;

identifies a second portion of the data set follows the first portion of the data set;

identifies that the first output state that corresponds to a rule describing malicious content;

scans with the DPI scanner the second portion of the data set from the first output state;

generates a second output state based on the scan of the second portion;

identifies that a third portion of the data set precedes the first portion of the data set;

scans the at least third portion of the data set from the first input state;

generates a third output state based on the scan of the third portion;

identifying that the third output state corresponds to the first input state; and

indicates that the data set contains the malicious content, wherein the first input state, the first output state, and the second output state corresponds to the rule.

12. The apparatus of claim 11 , wherein the processor terminates the reception of the data set after identifying that the received data set includes malicious content.

13. The apparatus of claim 11 , wherein information identifying that the data set includes malicious content is stored in a database.

14. The apparatus of claim 13 , wherein the network interface receives a subsequent request to download the data set; and wherein the processor:

identifies that the data set is associated with malicious content; and

blocks the subsequent request to download the data set.

15. The apparatus claim 11 , wherein a first portion of the at least portion of the data set is received from a first peer computer of a peer to peer network, and a second portion of the at least portion of the data set is received from a second peer computer in the peer to peer network.

Assignments (19)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2022
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 059912/0097 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2018
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 045828/0650 →
CHANGE OF NAME Recorded Apr 3, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 045830/0265 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF REEL 037848 FRAME 0001 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0152 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF REEL 037848 FRAME 0210 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040031/0725 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 037847 FRAME 0843 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040017/0366 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 037848/0210 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037848/0001 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 037847/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2015
From: LING, HUI; YU, CUIPING; CHEN, ZHONG
To: DELL SOFTWARE INC.
Reel/Frame 037379/0237 →