US2014090060A1PendingUtilityA1

Trusted network interface

Assignee: VIASAT INCPriority: Apr 30, 2008Filed: Nov 27, 2013Published: Mar 27, 2014
Est. expiryApr 30, 2028(~1.7 yrs left)· nominal 20-yr term from priority
Inventors:Steven R. Hart
H04L 63/0218H04L 43/00H04L 2463/144H04L 63/123H04L 63/0428H04L 63/1441H04L 63/1416
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods for combating and thwarting attacks by cybercriminals are provided. Network security appliances interposed between computer systems and public networks, such as the Internet, are configured to perform defensive and/or offensive actions against botnets and/or other cyber threats. According to some embodiments, network security appliances may be configured to perform coordinated defensive and/or offensive actions with other network security appliances.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A network security appliance interposed between a computer system and a public network, comprising:
 a network interface, configured to receive digitally signed and encrypted threat information for identifying malicious content and activities;   a trusted component communicatively coupled to the network interface, the trusted component containing a security engine, a processor, and a secured memory, and being configured to prevent physical manipulation of the security engine, the processor, and the secured memory;   the processor being configured to:   validate the signature of the threat information;   decrypt the threat information;   update the secured memory with the threat information;   analyze data traffic between the computer system and the public network to identify malicious content using the threat information; and   cause the network security appliance to perform at least one proactive measure to prevent a malicious cyber-attack from occurring by identifying the cyber-attack would emanate from the computer system and by preventing the computer system from sending traffic associated with the cyber-attack to at least one other computer system in response to the identifying; and   the security engine being configured to:   determine whether the processor functions correctly, and   determine whether the contents of the secured memory have not been compromised.   
     
     
         2 . The network security appliance of  claim 1  wherein if malicious content is identified, blocking data traffic between the computer system and the public network. 
     
     
         3 . The network security appliance of  claim 1 , wherein the threat information is received from another network security appliance via a secure peer to peer connection over the public network. 
     
     
         4 . The network security appliance of  claim 1 , wherein the threat information is received from a management server, the management server being configured to provide threat information for identifying malicious content and activities to a plurality of network security appliance. 
     
     
         5 . The network security appliance of  claim 1 , wherein the network security appliance is configured to transmit, via a secure connection over the public network, security related information to at least one other network security appliance and a management server. 
     
     
         6 . The network security appliance of  claim 1 , further configured to pose as a botnet member while remaining under control of a security management server. 
     
     
         7 . The network security appliance of  claim 1 , wherein the trusted component further comprises a signature database storing signatures for identifying malicious content. 
     
     
         8 . The network security appliance of  claim 1 , wherein the processor is further configured to switch from any of a plurality of functional modes to any other of the plurality of functional modes, the plurality of functional modes including a security appliance mode, a standalone defender mode, a cooperative defender mode, and a controlled defender mode. 
     
     
         9 . The network security appliance of  claim 1 , wherein the processor is further configured to cause the network security appliance to perform at least one action in an orchestrated manner with other network security appliances in response to a malicious cyber-attack. 
     
     
         10 . A method of operating a network security appliance, the network security appliance being interposed between a computer system and a public network, the method comprising:
 receiving, at a network interface of the network security appliance, digitally signed and encrypted threat information for identifying malicious content and activities;   at a processor of the network security appliance:   validating the signature of the threat information;   decrypting the threat information;   updating a secured memory of the network security appliance with the threat information; and   analyzing data traffic between the computer system and the public network to identify malicious content using the threat information;   performing at least one proactive measure to prevent a malicious cyber-attack from occurring by identifying the cyber-attack would emanate from the computer system and by preventing the computer system from sending traffic associated with the cyber-attack to at least one other computer system in response to the identifying;   preventing, at a trusted component communicatively coupled to the network interface, physical manipulation of a security engine, the processor, and the secured memory; and   determining, at the security engine, whether the processor functions correctly, and determining whether the contents of the secured memory have not been compromised.   
     
     
         11 . The method of  claim 10  further comprising:
 performing one or more remedial measures if malicious content is detected. 
 
     
     
         12 . The method of  claim 11  wherein performing the one or more remedial measures further comprises:
 notifying a management system of a potential threat via a secure connection over the public network, the management system being configured to provide threat information to a plurality of network security appliances. 
 
     
     
         13 . The method of  claim 11  wherein performing the one or more remedial measures further comprises:
 executing one or more defensive actions. 
 
     
     
         14 . The method of  claim 13  wherein executing one or more defensive actions further comprises:
 blocking all data packets from a source of the malicious content. 
 
     
     
         15 . The method of  claim 13  wherein executing one or more defensive actions further comprises:
 blocking all data packets of a particular type associated with the malicious content. 
 
     
     
         16 . The method of  claim 13  wherein executing one or more defensive actions further comprises:
 performing pattern recognition functions in cooperation with a plurality of other network security devices to identify a source of a threat. 
 
     
     
         17 . The method of  claim 11  wherein performing the one or more remedial measures further comprises:
 executing one or more offensive actions. 
 
     
     
         18 . The method of  claim 17  wherein executing one or more offensive actions further comprises:
 participating in a denial of service attack against the source of the malicious content with a plurality of other network security appliances. 
 
     
     
         19 . The method of  claim 17  wherein executing one or more offensive actions further comprises:
 propagating friendly malicious content to the source of the malicious content, the friendly malicious content being configured to damage or disable the source of the malicious content. 
 
     
     
         20 . The method of  claim 10  wherein analyzing the data packet for malicious content further comprises:
 accumulating multiple packets of data at the network security application before analyzing the data packets using the network security appliance to determine whether a threat exists; and 
 blocking the multiple packets of data if malicious content is identified; and 
 transmitting the multiple packets of data to a target destination if no malicious content is identified. 
 
     
     
         21 . The method of  claim 10 , further comprising posing as a botnet member while remaining under control of a security management server. 
     
     
         22 . The method of  claim 10 , further comprising storing signatures for identifying malicious content. 
     
     
         23 . The method of  claim 10 , further comprising switching from any of a plurality of functional modes to any other of the plurality of functional modes, the plurality of functional modes including a security appliance mode, a standalone defender mode, a cooperative defender mode, and a controlled defender mode. 
     
     
         24 . The method of  claim 10 , further comprising performing at the processor at least one action in an orchestrated manner with other network security appliances in response to a malicious cyber-attack.

Join the waitlist — get patent alerts

Track US2014090060A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.