MANAGING DECRYPTION OF NETWORK FLOWS THROUGH A NETWORK APPLIANCE

    公开(公告)号:US20230084792A1

    公开(公告)日:2023-03-16

    申请号:US18051312

    申请日:2022-10-31

    申请人: Gigamon Inc.

    摘要: A network appliance receives a communication from a client device that includes a request to establish a network connection to a server. Prior to initiating a network connection between the network appliance and the server, the network appliance accesses a server certificate issued by the server. In response to a determination, based on application of a policy to the server certificate, not to decrypt data transmitted between the client device and the server, the network appliance establishes only a single connection between the network appliance and the server. The network appliance transmits encrypted data between the client device and the server over the single connection.

    CORRELATING NETWORK FLOWS THROUGH A PROXY DEVICE

    公开(公告)号:US20200287881A1

    公开(公告)日:2020-09-10

    申请号:US16297346

    申请日:2019-03-08

    申请人: Gigamon Inc.

    IPC分类号: H04L29/06 H04L9/08 H04L29/08

    摘要: A network appliance stores a session identifier that uniquely identifies a network communication session between a first device and the network appliance. A first communication is received from the first device over the network communication session. The network appliance also receives from a proxy tool, a second communication that includes a header specifying the session identifier and that includes data generated by the proxy in response to the first communication. The network appliance associates the first communication with the second communication using the session identifier. An encrypted representation of the data generated by the proxy is transmitted to a second device based on the association between the first communication and the second communication.

    Managing decryption of network flows through a network appliance

    公开(公告)号:US11516205B2

    公开(公告)日:2022-11-29

    申请号:US16352735

    申请日:2019-03-13

    申请人: Gigamon Inc.

    摘要: A network appliance receives a communication from a client device that includes a request to establish a network connection to a server. The network appliance establishes, in response to the communication, a single connection between the network appliance and the server based on application of a policy that causes the network appliance to determine not to decrypt data transmitted between the client device and the server. The network appliance transmits encrypted data between the client device and the server over the single connection.

    Correlating network flows through a proxy device

    公开(公告)号:US11019044B2

    公开(公告)日:2021-05-25

    申请号:US16297346

    申请日:2019-03-08

    申请人: Gigamon Inc.

    IPC分类号: H04L29/06 H04L29/08 H04L9/08

    摘要: A network appliance stores a session identifier that uniquely identifies a network communication session between a first device and the network appliance. A first communication is received from the first device over the network communication session. The network appliance also receives from a proxy tool, a second communication that includes a header specifying the session identifier and that includes data generated by the proxy in response to the first communication. The network appliance associates the first communication with the second communication using the session identifier. An encrypted representation of the data generated by the proxy is transmitted to a second device based on the association between the first communication and the second communication.

    Managing decryption of network flows through a network appliance

    公开(公告)号:US12028332B2

    公开(公告)日:2024-07-02

    申请号:US18051312

    申请日:2022-10-31

    申请人: Gigamon Inc.

    摘要: A network appliance receives a communication from a client device that includes a request to establish a network connection to a server. Prior to initiating a network connection between the network appliance and the server, the network appliance accesses a server certificate issued by the server. In response to a determination, based on application of a policy to the server certificate, not to decrypt data transmitted between the client device and the server, the network appliance establishes only a single connection between the network appliance and the server. The network appliance transmits encrypted data between the client device and the server over the single connection.

    Dynamic decryption of suspicious network traffic based on certificate validation

    公开(公告)号:US11032294B2

    公开(公告)日:2021-06-08

    申请号:US15845635

    申请日:2017-12-18

    申请人: Gigamon Inc.

    IPC分类号: G06F21/00 H04L29/06 H04L9/32

    摘要: A disclosed method performed by a network device can include intercepting cryptographic certificates of host servers received in response to requests for encrypted connections between host servers and user devices, and determining that each encrypted connection is a suspicious connection or a normal connection based on a certificate validation policy. The method can further include causing decryption or metadata analysis of any suspicious encrypted connection and bypassing decryption or metadata analysis of any normal encrypted connection.

    MANAGING DECRYPTION OF NETWORK FLOWS THROUGH A NETWORK APPLIANCE

    公开(公告)号:US20200296087A1

    公开(公告)日:2020-09-17

    申请号:US16352735

    申请日:2019-03-13

    申请人: Gigamon Inc.

    摘要: A network appliance receives a communication from a client device that includes a request to establish a network connection to a server. The network appliance establishes, in response to the communication, a single connection between the network appliance and the server based on application of a policy that causes the network appliance to determine not to decrypt data transmitted between the client device and the server. The network appliance transmits encrypted data between the client device and the server over the single connection.