US2022255958A1PendingUtilityA1

Systems and methods for dynamic zone protection of networks

Assignee: LOOKINGGLASS CYBER SOLUTIONS INCPriority: Feb 9, 2021Filed: Feb 14, 2022Published: Aug 11, 2022
Est. expiryFeb 9, 2041(~14.6 yrs left)· nominal 20-yr term from priority
H04L 41/14H04L 63/1425H04L 63/0218H04L 41/046H04L 63/0236H04L 43/026H04L 63/1416H04L 69/22
62
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Disclosed are systems and methods for securing a network using one or more controllers and one or more network nodes. A method may utilize a packet processing engine configured to process incoming network packets, a processing analysis engine configured to perform relatively more complex processing and analysis, and one or more controllers configured to coordinate one or more packet processing engines and one or more processing analysis engines across a network to perform endpoint threat detection and mitigation.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method comprising:
 forwarding, by a packet processing engine, a received data packet to a processing analysis engine;   performing a comparison, by the packet processing engine, of an attribute of the received data packet to an attribute associated with a predetermined data packet of interest;   processing, by the packet processing engine, the received data packet, a session associated with the received data packet, and/or a data flow associated with the received data packet based at least in part on the comparison; and   analyzing, by a processing analysis engine, the forwarded data packet, a session associated with the forwarded data packet, and/or a data flow associated with the forwarded data packet in parallel with the comparison by the packet processing engine.   
     
     
         22 . The method of  claim 21 , wherein the processing analysis engine includes a first processing analysis engine and a second processing analysis engine. 
     
     
         23 . The method of  claim 21 , wherein the processing the received data packet, the session associated with the received data packet, and/or the data flow associated with the received data packet based at least in part on the comparison comprises:
 responding to, copying, dropping, routing, and/or modifying, by the packet processing engine, the received data packet, the associated session, and/or the associated data flow based at least in part on the comparison;   executing a program, by the packet processing engine, based at least in part on the comparison; and/or   creating a new data packet, a new session, and/or a new data flow, by the packet processing engine, based at least in part on the comparison.   
     
     
         24 . The method of  claim 21 , further comprising:
 receiving, by the of the processing analysis engine, a message from an agent node.   
     
     
         25 . The method of  claim 24 , wherein the message describes information captured on a network connected device, a network associated with the network connected device, a file state associated with the network connected device, and/or user information associated with the network connected device. 
     
     
         26 . The method of  claim 24 , further comprising:
 transmitting, by the processing analysis engine, a result of the analyzing and the message to a controller,   wherein the controller is configured to (i) update the predetermined data packet of interest based on the result of the analyzing and the message, and (ii) transmit the attribute associated with the updated predetermined data packet of interest.   
     
     
         27 . The method of  claim 21 , further comprising:
 storing the attribute associated with the predetermined data packet of interest in a data store, and   updating the stored attribute associated with the predetermined data packet of interest based on the attribute associated with an updated predetermined data packet of interest.   
     
     
         28 . A system comprising:
 a first packet processing engine and a first processing analysis engine,   wherein the first packet processing engine is configured to:   forward a received data packet to the first processing analysis engine,   perform a comparison of an attribute of the received data packet to attribute associated with a predetermined data packet of interest, and   process the received data packet, a session associated with the received data packet, and/or a data flow associated with the received data packet based at least in part on the comparison, and   wherein the first processing analysis engine is configured to:   analyze the forwarded data packet, a session associated with the forwarded data packet, and/or a data flow associated with the forwarded data packet in parallel with the comparison performed by the first packet processing engine.   
     
     
         29 . The system of  claim 28 , further comprising a second packet processing engine and a second processing analysis engine,
 wherein the first packet processing engine is further configured to forward the received data packet to the second processing analysis engine, and   wherein the second processing analysis engine is configured to analyze the forwarded data packet, the associated session, and/or the associated data flow in parallel with the comparison performed by the first packet processing engine.   
     
     
         30 . The system of  claim 28 , wherein the first packet processing engine is configured to:
 process the received data packet, the associated session, and/or the associated data flow by responding to, copying, dropping, routing, and/or modifying the received data packet, the associated session, and/or the associated data flow based at least in part on the comparison;   process the received data packet, the associated session, and/or the associated data flow by executing a program based at least in part on the comparison; and/or   process the received data packet, the associated session, and/or the associated data flow by creating a new data packet, a new session, and/or a new data flow based at least in part on the comparison.   
     
     
         31 . The system of  claim 28 , further comprising:
 an agent node configured to transmit a message, wherein the message describes information captured on a network connected device, a network associated with the network connected device, a file state associated with the network connected device, and/or user information associated with the network connected device.   
     
     
         32 . The system of  claim 31 , wherein the first processing analysis engine is configured to analyze the forwarded data packet at least based on the transmitted message regarding the network connected device in parallel with the comparison performed by the first packet processing engine. 
     
     
         33 . The system of  claim 31 , wherein the first processing analysis engine is further configured to transmit analysis result of the analyzing and the message to a controller, and
 wherein the controller is configured to (i) update the predetermined data packet of interest based on the result of the analyzing and the message, and (ii) transmit the attribute associated with the updated predetermined data packet of interest.   
     
     
         34 . The system of  claim 28 , further comprising:
 a data store configured to store the attribute associated with the predetermined data packet of interest,   wherein the stored attribute associated with the predetermined data packet of interest is updated based on the attribute associated with an updated predetermined data packet of interest.   
     
     
         35 . The system of  claim 28 , further comprising a controller. 
     
     
         36 . A system comprising:
 an agent node configured to transmit messages regarding a network connected device to a first processing analysis engine of a first network node and/or a controller, wherein the network connected device is connected to the first network node; and   the first network node comprises a first packet processing engine and a first processing analysis engine,   wherein the first packet processing engine is configured to:   forward a received data packet to the first processing analysis engine,   perform a comparison of an attribute of the received data packet to attribute associated with a predetermined data packet of interest, and   process the received data packet, a session associated with the received data packet, and/or a data flow associated with the received data packet based at least in part on the comparison, and   wherein the first processing analysis engine is configured to:   analyze the forwarded data packet, a session associated with the forwarded data packet, and/or a data flow associated with the forwarded data packet at least based on the received message regarding the network connected device in parallel with the comparison performed by the first packet processing engine.   
     
     
         37 . The system of  claim 36 , further comprising a second network node comprising a second packet processing engine and a second processing analysis engine,
 wherein the first packet processing engine is further configured to forward the received data packet to the second processing analysis engine, and   wherein the second processing analysis engine is configured to analyze the forwarded data packet, the associated session, and/or the associated data flow in parallel with the comparison performed by the first packet processing engine.   
     
     
         38 . The system of  claim 36 , wherein the first packet processing engine is configured to:
 process the received data packet, the associated session, and/or the associated data flow by responding to, copying, dropping, routing, and/or modifying the received data packet, the associated session, and/or the associated data flow based at least in part on the comparison;   process the received data packet, the associated session, and/or the associated data flow by executing a program based at least in part on the comparison; and/or   process the received data packet, the associated session, and/or the associated data flow by creating a new data packet, a new session, and/or a new data flow based at least in part on the comparison.   
     
     
         39 . The system of  claim 36 , wherein the message describes information captured on the network connected device, a network associated with the network connected device, a file state associated with the network connected device, and/or user information associated with the network connected device. 
     
     
         40 . The system of  claim 36 , further comprising:
 a data store configured to store the attribute associated with the predetermined data packet of interest,   wherein the controller and/or the first network node are configured to update the stored attribute associated with the predetermined data packet of interest based on the attribute associated with an updated predetermined data packet of interest.

Join the waitlist — get patent alerts

Track US2022255958A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.