Invention Grant
- Patent Title: Transparent inspection of traffic encrypted with perfect forward secrecy (PFS)
-
Application No.: US16990098Application Date: 2020-08-11
-
Publication No.: US11601456B2Publication Date: 2023-03-07
- Inventor: Sean O'Hara , Archana A. Rajaram
- Applicant: Arbor Networks, Inc.
- Applicant Address: US MA Westford
- Assignee: Arbor Networks, Inc.
- Current Assignee: Arbor Networks, Inc.
- Current Assignee Address: US MA Westford
- Agency: Locke Lord LLP
- Agent Scott D. Wofsy; Christopher J. Capelli
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/40

Abstract:
A method is provided for inspecting network traffic. The method, performed in a single contained device, includes receiving network traffic inbound from an external host that is external to the protected network flowing to a protected host of the protected network, wherein the network traffic is transported by a secure protocol that implements ephemeral keys that endure for a limited time. The method further includes performing a first transmission control protocol (TCP) handshake with the external host, obtaining source and destination data during the first TCP handshake, the source and destination data including source and destination link and internet addresses obtained, caching the source and destination data, and using the cached source and destination data to obtain a Layer-7 request from the external host to the protected host and to pass a Layer-7 response from the protected host to the external host.
Public/Granted literature
- US20210360011A1 TRANSPARENT INSPECTION OF TRAFFIC ENCRYPTED WITH PERFECT FORWARD SECRECY (PFS) Public/Granted day:2021-11-18
Information query