Selectively applying internet protocol security (ipsec) encryption based on application layer information
Abstract
A network device may receive a packet flow, and may identify an application associated with the packet flow. The network device may determine that packets associated with the application are not to be encrypted using a security protocol. The network device may store a rule that indicates that the packets are not to be encrypted using the security protocol based on determining that the packets are not to be encrypted using the security protocol. The rule may include network layer information or transport layer information associated with the packet flow, and may exclude application layer information associated with the packet flow. The network device may transmit, based on the rule, the packets without using the security protocol to encrypt the packets.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A device, comprising:
one or more memories; and one or more processors to:
receive one or more packets associated with a network traffic flow,
the network traffic flow including parameters related to at least one of:
network layer information, or
transport layer information;
determine to protect the one or more packets, associated with the network traffic flow, using a security protocol based upon the parameters related to the at least one of the network layer information or the transport layer information;
identify an application associated with the network traffic flow;
compare information identifying the application to a list of stored applications to determine whether the application is not required to be protected using the security protocol; and
determine to continue to protect network traffic, associated with the application, using the security protocol based upon the application not being on the list of stored applications.
22 . The device of claim 21 , where the security protocol is Internet protocol security (IPsec).
23 . The device of claim 21 , where the one or more processors, when identifying the application, are to:
determine an application identifier that identifies the application; where the one or more processors, when comparing the information identifying the application to the list of stored applications, are to:
compare the application identifier and a list of stored application identifiers,
the list of stored application identifiers including one or more application identifiers corresponding to one or more applications for which network traffic is not to be encrypted using the security protocol; and
where the one or more processors, when determining to continue to protect the network traffic, are to:
determine that packets, associated with the application, are to be encrypted using the security protocol based on comparing the application identifier and the list of stored application identifiers.
24 . The device of claim 21 , where the one or more processors are further to:
determine application layer information included in the one or more packets, and where the one or more processors, when identifying the application associated with the network traffic flow, are to:
identify the application based upon the application layer information.
25 . The device of claim 24 , where the one or more processors, when determining the application layer information, are to:
copy a quantity of the one or more packets to create one or more copied packets; analyze the one or more copied packets; and determine the application layer information, included in the one or more packets, based on analyzing the one or more copied packets.
26 . The device of claim 21 , where the one or more processors are further to:
receive one or more packets associated with an additional network traffic flow,
the additional network traffic flow being associated with another application;
compare information identifying the other application to the list of stored applications to determine whether the other application is not required to be protected using the security protocol; and determine to not protect network traffic, associated with the other application, using the security protocol based upon the other application being on the list of stored applications.
27 . The device of claim 26 , where the one or more processors are further to:
store a rule that indicates that the network traffic, associated with the additional network traffic flow, is not to be protected using the security protocol based on determining that the network traffic, associated with the other application, is not to be protected using the security protocol; transmit, to another device, a message indicating that the network traffic, associated with the additional network traffic flow, is not to be protected using the security protocol based on determining that the network traffic, associated with the other application, is not to be protected using the security protocol; and transmit, to the other device, the network traffic, associated with the additional network traffic flow, without using the security protocol.
28 . A non-transitory computer-readable medium storing instructions, the instructions comprising:
one or more instructions that, when executed by one or more processors, cause the one or more processors to:
receive one or more packets associated with a network traffic flow;
determine to protect the one or more packets, associated with the network traffic flow, using a security protocol;
identify an application associated with the network traffic flow;
compare information identifying the application to a list of stored applications to determine whether the application is not required to be protected using the security protocol; and
determine to continue to protect network traffic, associated with the application, using the security protocol based upon the application not being on the list of stored applications,
the security protocol using network layer information or transport layer information to determine whether to encrypt the one or more packets.
29 . The non-transitory computer-readable medium of claim 28 , where the one or more instructions, that cause the one or more processors to identify the application, cause the one or more processors to:
determine an application identifier that identifies the application; where the one or more instructions, that cause the one or more processors to compare the information identifying the application to the list of stored applications, cause the one or more processors to:
compare the application identifier and a list of stored application identifiers,
the list of stored application identifiers including one or more application identifiers corresponding to one or more applications for which network traffic is not to be encrypted using the security protocol; and
where the one or more instructions, that cause the one or more processors to determine to continue to protect the network traffic, cause the one or more processors to:
determine that packets, associated with the application, are to be encrypted using the security protocol based on comparing the application identifier and the list of stored application identifiers.
30 . The non-transitory computer-readable medium of claim 28 , where the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:
determine application layer information included in the one or more packets, and where the one or more instructions, that cause the one or more processors to identify the application associated with the network traffic flow, cause the one or more processors to:
identify the application based upon the application layer information.
31 . The non-transitory computer-readable medium of claim 28 , where the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:
receive one or more packets associated with an additional network traffic flow,
the additional network traffic flow being associated with another application;
compare information identifying the other application to the list of stored applications to determine whether the other application is not required to be protected using the security protocol; and determine to not protect network traffic, associated with the other application, using the security protocol based upon the other application being on the list of stored applications.
32 . The non-transitory computer-readable medium of claim 31 , where the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:
store a rule that indicates that the network traffic, associated with the additional network traffic flow, is not to be protected using the security protocol based on determining that the network traffic, associated with the other application, is not to be protected using the security protocol; transmit, to another device, a message indicating that the network traffic, associated with the additional network traffic flow, is not to be protected using the security protocol based on determining that the network traffic, associated with the other application, is not to be protected using the security protocol; and transmit, to the other device, the network traffic, associated with the additional network traffic flow, without using the security protocol.
33 . The non-transitory computer-readable medium of claim 32 , where the one or more instructions, that cause the one or more processors to store the rule, cause the one or more processors to:
store the rule in a security policy database that stores Internet protocol security (IPsec) policies.
34 . The non-transitory computer-readable medium of claim 32 , where the network layer information or the transport layer information is included in the rule.
35 . A method, comprising:
receiving, by a device, one or more packets associated with a network traffic flow,
the network traffic flow including parameters related to at least one of:
network layer information, or
transport layer information;
determining, by the device, to protect the one or more packets, associated with the network traffic flow, using a security protocol based upon the parameters related to the at least one of the network layer information or the transport layer information; identifying, by the device, an application associated with the network traffic flow; comparing, by the device, information identifying the application to a list of stored applications to determine whether the application is not required to be protected using the security protocol; and selectively determining, by the device, whether or not to continue to protect the network traffic flow associated with the application using the security protocol,
the network traffic flow associated with the application is to be protected when the information identifying the application is not on the list of stored applications, and
the network traffic flow associated with the application is not to be protected when the information identifying the application is on the list of stored applications.
36 . The method of claim 35 , further comprising:
determining that the network traffic flow is to be transmitted unencrypted when the information identifying the application is on the list of stored applications.
37 . The method of claim 35 , further comprising:
storing a rule that indicates that the network traffic flow is not to be protected using the security protocol when the information identifying the application is on the list of stored applications.
38 . The method of claim 37 , further comprising:
transmitting, to another device, a message indicating that the network traffic flow is not to be protected using the security protocol based on determining that the network traffic flow is not to be protected using the security protocol; and transmitting, to the other device, the network traffic flow without using the security protocol.
39 . The method of claim 35 , further comprising:
determining application layer information included in the one or more packets, and where identifying the application associated with the network traffic flow comprises:
identifying the application based upon the application layer information.
40 . The method of claim 39 , where determining the application layer information comprises:
copying a quantity of the one or more packets to create one or more copied packets; analyzing the one or more copied packets; and determining the application layer information, included in the one or more packets, based on analyzing the one or more copied packets.Join the waitlist — get patent alerts
Track US2018191783A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.