EP4274166A2

Methods and systems for protecting a secured network

Abstract

Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at least one of multiple packet transformation functions specified by the dynamic security policy may be performed on the packets.

EP4274166A2, drawing sheet 1
Sheet 1 of 14

Term

8.5 yearsto projected expiry

Projected expiry 7 April 2035, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

15 claims: 12 independent, 3 dependent

  1. 1
    A method of filtering packets at a packet security gateway (112) configured for protection of a network, wherein the packet security gateway is capable of receiving a plurality of dynamic security policies and is associated with a security policy management server (120) external from the network, the method comprising:receiving (1302), by the packet security gateway and from the security policy management server, a dynamic security policy comprising rules, wherein one or both of the dynamic security policy or one or more of the rules of the dynamic security policy were automatically created or altered (1304), by the security policy management server, based on network addresses received from a plurality of malicious host tracker services, wherein at least two of the network addresses are received from two different malicious host tracker services of the plurality of malicious host tracker services, wherein one or more of the rules were updated by the security policy management server based on a correlation between two different portions of the network addresses that were provided by the two different malicious host tracker services of the plurality of malicious host tracker services, and wherein a first rule of the rules comprises: at least one packet matching criteria, and a corresponding packet transformation function comprising a packet digest logging function, and performing, based on the rules, packet filtering on individual packets of a plurality of packets associated with the network protected by the packet security gateway, wherein the packet filtering comprises: examining individual packets;filtering each packet based on content of that individual packet;and performing, based on comparing a first packet of the plurality of packets to the at least one packet matching criteria, the packet digest logging function on the first packet.
  2. 4
    The method of any one of claims 1-3, wherein the dynamic security policy specifies that a first plurality of packets should be placed in a first forwarding queue and a second plurality of packets should be placed in a second forwarding queue, wherein the first forwarding queue has a higher forwarding rate than the second forwarding queue, and wherein the method further comprises:sending, by the packet security gateway, the first plurality of packets in the first forwarding queue;and sending, by the packet security gateway, the second plurality of packets in the second forwarding queue.
  3. 5
    The method of any one of claims 1-4, further comprising:receiving, by the packet security gateway and using an interface that is not addressed at the network layer, packets in a network layer transparent manner;and performing at least one packet transformation function at the network layer.
  4. 6
    The method of any one of claims 1-5, wherein the packet security gateway is a LAN switch.
  5. 7
    The method of any one of claims 1-6, wherein the filtering each packet comprises:filtering one packet at a time.
  6. 9
    The method of any one of claims 1-8, wherein the first rule comprises a logging rule.
  7. 10
    The method of any one of claims 1-9, wherein the corresponding packet transformation function is configured to drop network traffic matching the at least one packet matching criteria.
  8. 11
    The method of any one of claims 1-10, wherein the at least one packet matching criteria comprises a range of network addresses that includes network addresses specified by at least two different malicious host tracker services of the plurality of malicious host tracker services.
  9. 12
    The method of any one of claims 1-11, wherein the packet security gateway provides an interface across a boundary of the network protected by the packet security gateway and one or more networks other than the network protected by the packet security gateway.
  10. 13
    A packet security gateway comprising:one or more processors;and memory storing instructions that, when executed by the one or more processors, cause the packet security gateway to perform the method of any one of claims 1-12.
  11. 14
    One or more non-transitory computer-readable media storing instructions that, when executed by one or more processors of a packet security gateway, cause the packet security gateway to perform the method of any one of claims 1-12.
  12. 15
    A system comprising:a packet security gateway configured to perform the method of any one of claims 1-12;and the security policy management server, wherein the security policy management server is configured to send the dynamic security policy.