IP Library Granted Patent US 11,438,299
Granted Patent B2
US 11,438,299 · App. 16/736,492 · Granted Sep 6, 2022

Reducing battery impact of network device ARP spoofing

Inventors: Wicher Thomas Maarseveen (Epe, NL); Lukás Karas (Prague, CZ)
Assignee: Avast Software s.r.o.
H04L61/103H04L61/2514H04L61/5014H04L63/0272H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,438,299
App. No.
16/736,492
Granted
Sep 6, 2022
Kind
B2
Abstract

A private network device such as a security device is inserted in a private network using ARP spoofing, which includes sending periodic ARP packets from the private network device to a router and to client devices to ensure the private network device spoofing remains intact. The private network device determines when at least one of the one or more private network devices is inactive, such as by monitoring the network for activity between the devices and a router, and suspends sending the periodic ARP packets to the client devices when they are inactive.

Claims (23)

1. A method of managing Address Resolution Protocol (ARP) spoofing to reduce battery power consumption in a private network client device, comprising:

inserting the private network device between a router or gateway and one or more private network client devices in a private network by using Address Resolution Protocol (ARP) spoofing;

sending periodic ARP packets from the private network device to at least one of the one or more private network client devices to ensure the private network device remains inserted;

determining when at least one of the one or more private network devices is inactive, wherein determining when at least one of the one or more private network devices is inactive comprises determining whether the at least one device has sent traffic to the router or received traffic from the router during a threshold time for the at least one device, wherein the threshold time is dependent on the type of traffic sent or received; and

suspending the sending of periodic ARP packets to at least one of the one or more private network devices when the at least one private network device is determined to be inactive.

2. The method of managing ARP spoofing to reduce battery power consumption in a private network client device of claim 1 , where inserting the private network device between a router or gateway and one or more private network client devices comprises sending an ARP packet to the router or gateway and the one or more private network client devices.

3. The method of managing ARP spoofing to reduce battery power consumption in a private network client device of claim 1 , wherein the traffic types comprise one or more of DHCP, IP broadcast, and IP unicast packets from either the client to the router or from the router to the client, and ARP broadcast queries.

4. The method of managing ARP spoofing to reduce battery power consumption in a private network client device of claim 1 , further comprising periodically sending ARP packets to the router or gateway when sending of periodic ARP packets to at least one of the one or more private network devices has been suspended.

5. The method of managing ARP spoofing to reduce battery power consumption in a private network client device of claim 1 , further comprising removing the one or more private network devices from a network device list after a period of inactivity.

6. The method of managing ARP spoofing to reduce battery power consumption in a private network client device of claim 1 , further comprising monitoring the private network for ARP packets from the one or more private network devices, and reinserting the private network device between the router or gateway and the one or more private network client devices using ARP spoofing in response to discovering an ARP packet from the router or gateway or one or more private network devices.

7. The method of managing ARP spoofing to reduce battery power consumption in a private network client device of claim 1 , wherein reinserting the private network device between the router or gateway and the one or more private network client devices using ARP spoofing in response to discovering an ARP packet from the router or gateway or one or more private network devices comprises delaying at least ten milliseconds between discovering an ARP packet from the router or gateway or one or more private network devices and sending ARP packets to reinsert the private network device between the router or gateway and the one or more private network client devices.

8. The method of managing ARP spoofing to reduce battery power consumption in a private network client device of claim 1 , wherein reinserting the private network device between the router or gateway and the one or more private network client devices using ARP spoofing in response to discovering an ARP packet from the router or gateway or one or more private network devices comprises sending ARP packets to reinsert the private network device between the router or gateway and the one or more private network client devices multiple times over the first five seconds after discovering the ARP packet from the router or gateway or one or more private network devices.

9. A network security device, comprising:

a processor and a memory;

a malware protection module operable when executed on the processor to detect a threat to one or more private network devices and take one or more actions in response to detecting the threat; and

an Address Resolution Protocol (ARP) spoofing module operable when executed on the processor to insert the network security device between a router or gateway and the one or more private network clients by using ARP spoofing, to send periodic ARP packets from the private network device to at least one of the one or more private network client devices to ensure the private network device remains inserted, to determine when at least one of the one or more private network devices is inactive, wherein determining when at least one of the one or more private network devices is inactive comprises determining whether the at least one device has sent qualifying traffic to the router or received qualifying traffic from the router during a threshold time for the at least one device, wherein the threshold time is dependent on the type of traffic sent or received, and to suspend the sending of periodic ARP packets to at least one of the one or more private network devices when the at least one private network device is determined to be inactive.

10. The network security device of claim 9 , where inserting the private network device between a router or gateway and one or more private network client devices comprises sending an ARP packet to the router or gateway and the one or more private network client devices.

11. The network security device of claim 9 , wherein the traffic types comprise one or more of DHCP, IP broadcast, and IP unicast packets from either the client to the router or from the router to the client, and ARP broadcast queries.

12. The network security device of claim 9 , the ARP spoofing module further operable to periodically sending ARP packets to the router or gateway when sending of periodic ARP packets to at least one of the one or more private network devices has been suspended.

13. The network security device of claim 9 , the ARP spoofing module further operable to remove the one or more private network devices from a network device list after a period of inactivity.

14. The network security device of claim 9 , the ARP spoofing module further operable to monitor the private network for ARP packets to and/or from the one or more private network devices, and to reinsert the private network device between the router or gateway and the one or more private network client devices using ARP spoofing in response to discovering an ARP packet from the router or gateway or one or more private network devices.

15. The network security device of claim 9 , wherein reinserting the private network device between the router or gateway and the one or more private network client devices using ARP spoofing in response to discovering an ARP packet from the router or gateway or one or more private network devices comprises delaying at least ten milliseconds between discovering an ARP broadcast packet from the router or gateway or one or more private network devices and sending ARP packets to reinsert the private network device between the router or gateway and the one or more private network client devices.

16. The network security device of claim 9 , wherein reinserting the private network device between the router or gateway and the one or more private network client devices using ARP spoofing in response to discovering an ARP packet from the router or gateway or one or more private network devices comprises sending ARP packets to reinsert the private network device between the router or gateway and the one or more private network client devices multiple times over the first five seconds after discovering the ARP packet from the router or gateway or one or more private network devices.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: GEN DIGITAL AMERICAS S.R.O.
To: GEN DIGITAL INC.
Reel/Frame 071771/0767 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: AVAST SOFTWARE S.R.O.
To: GEN DIGITAL AMERICAS S.R.O.
Reel/Frame 071777/0341 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2020
From: MAARSEVEEN, WICHER THOMAS; KARAS, LUKÁS
To: AVAST SOFTWARE S.R.O.
Reel/Frame 051487/0906 →
Continuity (1)
Related Publication 20210211402A1 · Jul 8, 2021