US2017048262A1PendingUtilityA1

Packet capture and network traffic replay

Assignee: PROTECTWISE INCPriority: Nov 13, 2013Filed: Oct 26, 2016Published: Feb 16, 2017
Est. expiryNov 13, 2033(~7.3 yrs left)· nominal 20-yr term from priority
H04L 63/1425H04L 63/1416
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Implementations disclosed herein provide a network agent embodied in firmware and/or software that replays network traffic of an enterprise network to an entity outside of the enterprise network. The network agent selects and processes the network traffic according to certain policies set by the enterprise network or a third party security management system. These policies allow for a capture and replay of high-integrity data that enables threat analysis.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . One or more tangible computer-readable storage media of a tangible article of manufacture encoding computer-executable instructions for executing on a computer system a computer process for threat detection within an enterprise network, wherein the process further comprises:
 intercepting a network traffic stream of the enterprise network directed to a target destination;   copying data packets of the network traffic stream concurrent with receipt of each of the packets within the intercepted network traffic stream;   replaying the copied packets to end destination outside of the enterprise network other than the target destination; and   analyzing the copied and replayed packets to determine whether the copied and replayed packets include a potential security threat to the enterprise network.   
     
     
         2 . The one or more computer-readable storage media of  claim 1 , wherein replaying the copied packets to the end destination further comprises:
 during a period of time that the network traffic stream is intercepted, continuously bundling groups of the packets, each bundle created responsive to receipt of a predetermined quantity of the packets; and   replaying each one of the bundled groups of the packets to the end destination.   
     
     
         3 . The one or more computer-readable storage media of  claim 1 , wherein the computer process further comprises:
 responsive to receipt of a predetermined number of packets of the network traffic stream, bundling the predetermined number of packets for the replay operation.   
     
     
         4 . The one or more computer-readable storage media of  claim 1 , wherein the computer process further comprises:
 replaying at least one packet per transmission at a rate of at least one transmission per second during a time period that the network traffic stream is intercepted.   
     
     
         5 . The one or more computer-readable storage media of  claim 1 , wherein the replay operation further comprises:
 replaying the packets in real-time as the packets are copied.   
     
     
         6 . The one or more computer-readable storage media of  claim 1 , wherein the process for high integrity threat analysis is a retrospective threat analysis. 
     
     
         7 . The one or more computer-readable storage media of  claim 1 , wherein the enterprise network is a network interconnecting various devices controlled by security policies of an enterprise. 
     
     
         8 . The one or more computer-readable storage media of  claim 1 , wherein the intercepting and copying of the network traffic occurs within a communication channel of the enterprise network. 
     
     
         9 . The one or more computer-readable storage media of  claim 1 , wherein the computer process further comprises:
 selecting the network traffic for replay based on policies specified by an entity external to the enterprise network.   
     
     
         10 . The one or more computer-readable storage media of  claim 1 , wherein the computer process further comprises:
 processing the network traffic based on policies specified by an entity external to the enterprise network.   
     
     
         11 . The one or more computer-readable storage media of  claim 1 , wherein the computer process further comprises:
 adaptively altering a data selection policy based on collective network intelligence of a third-party security service external to the enterprise network.   
     
     
         12 . The one or more computer-readable storage media of  claim 1 , wherein the computer process further comprises:
 adaptively altering a data transmission preparation policy based on collective network intelligence of a third-party security service.   
     
     
         13 . The one or more computer-readable storage media of  claim 1 , wherein the computer process further comprises:
 taking a remediative action responsive to a notification based on collective network intelligence of a security service external to the enterprise network.   
     
     
         14 . The one or more computer-readable storage media of  claim 1 , wherein the computer process further comprises:
 transmitting a communication to a first agent of an enterprise network, the communication instructing the first agent to perform a first part of a replay task; and   performing, at a second agent of the enterprise network, a different part of the replay task.   
     
     
         15 . A system comprising:
 a network agent stored in at least one memory and executable by at least one processor, the network agent configured to:
 utilize the processor to intercept a network traffic stream of an enterprise network directed to a target destination; 
 copy data packets of the network traffic stream concurrent with interception of each of the packets within the network traffic stream; 
 replay the copied packets to end destination outside of the enterprise network other than the target destination; and 
   a security management module of a managed security service, the security management module stored in memory and executable by at least one processor, wherein the security management module is configured to analyze the copied, replayed packets to assess whether one or more of the copied, replayed packets includes a potential security threat to the enterprise network.   
     
     
         16 . The system of  claim 15 , wherein the network agent is further configured to:
 bundle a predetermined number of packets for the replay operation responsive to receipt of the predetermined number of packets.   
     
     
         17 . The system of  claim 15 , wherein the network agent is further configured to:
 continuously bundle groups of the packets during a period of time that the network traffic stream is intercepted, each bundle created responsive to receipt of a predetermined quantity of the packets; and   replaying each one of the bundled groups of the packets to the end destination.   
     
     
         18 . The system of  claim 15 , wherein the network agent is further configured to replay the copied packets in individual transmissions that each include at least one of the packets and wherein the transmissions are sent at a rate of at least one transmission per second 
     
     
         19 . The system of  claim 15 , wherein the network agent is further configured to replay the packets in real-time as the packets are copied. 
     
     
         20 . The system of  claim 15 , wherein the network agent is configured to replay a filtered subset of all network traffic on the enterprise network. 
     
     
         21 . The system of  claim 15 , wherein the network agent selects packets for the replay based on policies specified by an entity external to the enterprise network. 
     
     
         22 . The system of  claim 15 , wherein the network agent processes the network traffic based on policies specified by an entity external to the enterprise network. 
     
     
         23 . The system of  claim 15 , further comprising:
 a managed security service external to the enterprise network, the managed security service configured to adaptively alter a data selection policy of the network agent based on collective network intelligence.   
     
     
         24 . The system of  claim 15 , wherein the network agent is further configured to take remediative action responsive to notification of a security threat, the notification based on collective network intelligence of a security service external to the enterprise network. 
     
     
         25 . The system of  claim 15 , wherein the network agent is configured to perform a first part of a replay task and transmit a communication instructing another network agent to perform a second part of the replay task. 
     
     
         26 . The system of  claim 15 , wherein the network agent replays a bundle of data packets within one second of receiving the data packets.

Join the waitlist — get patent alerts

Track US2017048262A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.