Method, system, and computer storage device for monitoring the life cycle of a computer network connection

By using security devices to monitor the time synchronization traffic between the network client device and the time server in the networked directory service environment, identify the true identity of the client device and monitor the connection life cycle, the security threat detection problem in the directory service environment is solved, and effective monitoring and detection of network security threats is achieved.

CN113079068BActive Publication Date: 2025-06-10MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110513008.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2015-08-26
Filing Date
2016-08-04
Publication Date
2025-06-10
Estimated Expiration
2036-08-04

AI Technical Summary

Technical Problem

There are security vulnerabilities in the networked directory service environment, which may cause legitimate clients to lose network resource access rights or disclose sensitive information, and it is difficult for existing technology to effectively monitor and detect these security threats.

Method used

An automated system and method is designed to monitor time synchronization traffic between network client devices and time servers through security devices, identify the true identity of client devices, monitor the connection life cycle, and detect abnormal and malicious patterns to provide network security threat detection.

Benefits of technology

The system can effectively monitor and detect security threats in the network, prevent unauthorized access and information leakage, and improve network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113079068B_ABST
    Figure CN113079068B_ABST
Patent Text Reader

Abstract

The present disclosure relates to methods, systems, and computer storage devices for monitoring the lifecycle of computer network connections. There is provided a method of monitoring the lifecycle of a connection of a network client device to a network by monitoring time synchronization traffic flowing between one or more network client devices and a time server in the network. A system for monitoring the lifecycle of a connection of a network client device to a network includes a security device operable to identify the true identity of one or more network client devices, identify the connection of the network client device to the network and disconnection from the network, determine which network client devices have been associated with a particular Internet Protocol (IP) address, and generate an output of connection and disconnection information associated with the network client device. In some examples, the security device is operable to detect anomalies and malicious patterns in the network.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of a patent application for invention with international application number PCT / US2016 / 045446, international filing date August 4, 2016, date of entry into the Chinese national phase February 7, 2018, and national application number 201680046601.3. Technical Field

[0002] The present disclosure generally relates to computer networks, and more particularly to methods, systems, and computer storage devices for monitoring the lifecycle of computer network connections. Background Art

[0003] In a networked directory service environment, various components are used to authenticate users and to generate authorization data for controlling access to network resources to provide secure network access to network data by authorized users and to deny access by unauthorized users. Security vulnerabilities in a networked directory service environment can result in loss of network resource access by legitimate clients or leakage of potentially sensitive information. Such information leakage can occur for data stored on network resources or from the networked directory service database itself. Anomaly detection of network traffic or malicious patterns can indicate security vulnerabilities in a networked directory service environment. Summary of the Invention

[0004] The Summary of the Invention is provided to introduce a selection of concepts in a simplified form that will be further described in the Detailed Description section below. The Summary of the Invention is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to assist in determining the scope of the claimed subject matter.

[0005] Aspects relate to automated systems and methods for monitoring the lifecycle of a connection of a network client device to a network. A computer network connection lifecycle monitoring system includes a security device operable to monitor time synchronization traffic flowing between one or more network client devices and a time server in the network. The security device is operable to identify the true identity of one or more network client devices, identify the connection of the network client device to the network and disconnection from the network, determine which network client devices have been associated with a particular Internet Protocol (IP) address, and generate an output including connection and disconnection information associated with one or more network client devices. According to one aspect, the security device is operable to detect anomalies and malicious patterns in the network.

[0006] Examples are implemented as computer processes, computing systems, or articles of manufacture such as computer program products or computer-readable media. According to one aspect, a computer program product is a computer storage medium readable by a computer system and encoding a computer program of instructions for performing a computer process.

[0007] Details of one or more aspects are set forth in the accompanying drawings and the description below. Other features and advantages will be apparent from the following detailed description and the related drawings. It is to be understood that the following detailed description is merely exemplary and is not restrictive of the claims. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] The accompanying drawings, which are incorporated in and constitute a part of this disclosure, illustrate various aspects. In the drawings:

[0009] Figure 1 is a simplified block diagram of a system for monitoring the lifecycle of a connection to a computer network;

[0010] Figure 2 is a simplified block diagram illustrating components of a security device for monitoring the lifecycle of a connection to a computer network;

[0011] Figure 3 is an example of a true identifier associated with a network client device;

[0012] Figure 4 is a flowchart showing the overall stages involved in an example method for monitoring the lifecycle of a connection to a computer network;

[0013] Figure 5 is a block diagram illustrating example physical components of a computing device;

[0014] Figure 6A and Figure 6B is a simplified block diagram of a mobile computing device; and

[0015] Figure 7 is a simplified block diagram of a distributed computing system. DETAILED DESCRIPTION

[0016] The following detailed description refers to the accompanying drawings. Whenever possible, the same reference numbers are used in the drawings and the following description to refer to the same or like elements. Although examples may be described, modifications, alterations, and other implementations are possible. For example, elements shown in the drawings may be replaced, added, or modified, and the methods described herein may be modified by replacing, reordering, or adding stages. Accordingly, the following detailed description is not restrictive, and rather, the appropriate scope is defined by the appended claims. Examples may take the form of a hardware implementation, or a fully software implementation, or an implementation combining software and hardware aspects. Accordingly, the following detailed description should not be considered restrictive.

[0017] Aspects of the present disclosure relate to monitoring the lifecycle of a connection to a computer network. Figure 1is a simplified block diagram of an example of a computer network connection lifecycle monitoring system 100. According to one aspect, the computer network connection lifecycle monitoring system 100 is adapted to be implemented in a networked directory service environment 110. An example of a networked directory service environment 110 is Active (AD) Domain Services, which provides a secure, structured, hierarchical data store for objects in the network 104 and support for locating and working with these objects. As Figure 1 shown, the system 100 includes one or more network client devices 102a-g (collectively 102). The one or more network client devices 102 are devices that are permitted to connect to the network 104 and can be assigned permissions. For example, the one or more network client devices 102 can include mainframe computers 102a, desktop computers 102b, printers 102c, laptop computers 102d, tablet devices 102e, telephones 102f, or other resources or security principal objects or entities in the network 104. As should be understood, the examples are not limited to these example network client device 102 types. According to one aspect, the network 104 is a cloud-based network or a local network.

[0018] Within the networked directory service environment 110, the clocks of the network client devices 102 in the network 104 are synchronized within a given accuracy range. According to one aspect, the clocks are synchronized to ensure consistent time across the enterprise. According to another aspect, time synchronization supports computer network authentication. For example, computer network authentication protocols (such as Kerberos) that use tickets to verify a client's access to a service are time-sensitive to a given clock deviation. By using encrypted tickets, secure authentication occurs when the client attempting to access the service knows the key. Timestamp information is included in the ticket to prevent replay attacks (i.e., fraudulent presentation of a previously issued ticket for unauthorized access). According to one example, due to a time difference with the authentication server, a network client device 102 with an inaccurate clock attempting authentication will fail the authentication attempt.

[0019] In some examples, the networked directory service environment 110 uses a network protocol (e.g., Network Time Protocol (NTP) or other similar implementations) for time synchronization between computer systems over a packet-switched, variable-latency data network. According to one aspect, the time synchronization protocol used in the networked directory service environment 110 synchronizes the clocks of network client devices 102 by using one or more specified time references (referred to herein as time servers 108). In some examples, domain controller machines that are part of the networked directory service environment 110 domain are automatically configured to act as time servers 108. In other examples, the time servers 108 are manually specified time sources.

[0020] Still referring to Figure 1 , the computer network connection lifecycle monitoring system 100 further includes a security device 106 operable to monitor time synchronization traffic flowing between one or more network client devices 102 and the time servers 108. According to one aspect, the security device 106 is a collection of systems, devices, or components or modules that operate on a system or device operable to monitor time synchronization traffic flowing between one or more network client devices 102 and the time servers 108. According to one aspect, as will be described in detail below, by monitoring the time synchronization traffic, the security device 106 is also operable to determine the identity of the network client devices. According to another aspect, the security device 106 is also operable to identify the connection of the network client devices to the network 104 and the disconnection from the network 104. According to another aspect, the security device 106 is also operable to determine which network client devices 102 have been associated with a particular Internet Protocol (IP) address.

[0021] By monitoring the time synchronization traffic flowing between one or more network client devices 102 and the time servers 108 and by monitoring the lifecycle of the connection of the network client devices 102 to the network 104, the security device 106 is enabled to detect network behavior anomalies and malicious patterns in the network 104, thereby providing network security threat detection. According to some aspects, the time synchronization traffic monitoring for network security threat detection includes the identity of the network client devices and is thus not easily spoofed by attackers.

[0022] The components of one or more network client devices 102, time servers 108, and security device 106 are examples of multiple computing systems, including but not limited to desktop computer systems, wired and wireless computing systems, mobile computing systems (e.g., mobile phones, netbooks, tablet or slate computers, laptops, and notebooks), handheld devices, multiprocessor systems, microprocessor-based or programmable consumer electronics, minicomputers, and mainframe computers.

[0023] According to various aspects, reference is made to Figure 2 illustrate and describe the components of the security device 106. As used herein, the term "component" refers to a separate computing device having the processing, memory, and other computer operating components as described in the following reference Figures 5 - 7 wherein the operating instructions are hard-coded on the computing device, or computer-executable instruction sets for causing the component to perform the functions described herein are processed using the computing device. Alternatively, the term "component" refers to an instruction set executed by a computing device or system ( Figures 5 - 7 ) for causing the component to perform the functions described herein. Each of the components described below can operate independently, but can interact with other components, or each component can be integrated into a single operating module, device, or system (e.g., the security device 106 described herein).

[0024] As Figure 2 shown, the security device 106 includes a network traffic listener 202, a data extractor 204, a connection type identifier 206, a network client device identification engine 208, a connection monitor 210, an anomaly detection engine 212, a data repository 214, and a report generator 216. The data repository 214 is a general data storage unit or system for storing data received, accessed, identified, or determined by the network traffic listener 202, data extractor 204, connection type identifier 206, network client device identification engine 208, connection monitor 210, anomaly detection engine 212, and report generator 216 associated with the security device 106.

[0025] The network traffic listener 202 is an illustration of a software module, system, or device operable to access and monitor time synchronization traffic flowing between one or more network client devices 102 and a time server 108. Some implementations of network protocols for time synchronization include: a network client device 102 that sends a request with its current time and additional information to the time server 108, the additional information including the date and time of the last clock adjustment; a time server 108 that replies with the time sent by the network client device 102, the time at which the request was received according to the time server's clock, and the time at which the time server 108 sent its response; a network client device 102 that calculates the time of the time server by estimating the round-trip time; and a network client device 102 that adjusts its clock accordingly. According to one example, the network traffic listener 202 passively monitors time synchronization traffic (i.e., requests and responses) in a non-intrusive manner. According to another example, the network traffic listener 202 actively requests time synchronization traffic from the network client device 102 to the time server 108 as needed.

[0026] According to various aspects, the reliability of time synchronization network protocol message exchanges is protected using signatures based on a shared secret between the network client device 102 and the time server 108. For the network client device 102 to be identified, it sends a unique identifier to the time server 108 using a request. In some examples, such as in an environment, the unique identifier is a relative identifier (RID) value, where the RID value is an unsigned integer assigned to each security principal object (i.e., user, computer, and group) in a domain within a networked directory service environment 110 at creation and uniquely identifies each object in the domain. When the time server 108 sends a response, it signs the response using the shared secret associated with the unique identifier of the network client device, such that the network client device 102 can use the shared secret to verify the reliability of the response.

[0027] Data extractor 204 is an illustration of a software module, system, or device operable to parse time synchronization network protocol messages to extract useful information. For example, data extractor 204 extracts various values from time synchronization network protocol messages, including but not limited to: a source address value (e.g., the Internet Protocol (IP) address of network client device 102); an identifier uniquely identifying network client device 102 (e.g., the RID value); a domain identifier uniquely identifying the domain of network client device 102 (e.g., a domain security identifier (SID) value); a value indicating the tier of time server 108 in the time server hierarchy; an original timestamp value; and a received timestamp value. According to one aspect, data extractor 204 stores the extracted information in data repository 214.

[0028] Connection type identifier 206 is an illustration of a software module, system, or device operable to determine whether a time synchronization network protocol request message is an initial request (e.g., a request generated at a start / restart event, a connect / reconnect event, or other specific event (e.g., a domain connection)). According to one aspect, when the reference clock identifier value (i.e., a code identifying a specific reference clock) is set to "empty", when the peer clock layer value is set to unspecified, invalid, or 0, and when the original timestamp value (i.e., a timestamp established by network client device 102 specifying the time the request for time server 108 left) and the received timestamp value (i.e., a timestamp established by time server 108 specifying the time the request arrived from network client device 102) are set to 0 (Unix Time 1.1.1970), connection type identifier 206 identifies the request as being associated with an initial connection event. According to one aspect, connection type identifier 206 stores connection time information in data repository 214.

[0029] The Network Client Device Identity Engine 208 is an illustration of a software module, system, or device operable to determine the true identity of the network client device 102. According to one example, the Network Client Device Identity Engine 208 extracts the RID value from the time synchronization networking protocol message and extracts the domain SID value from the destination of the time synchronization networking protocol message. The Network Client Device Identity Engine 208 is operable to determine the true identity of the network client device 102 (which is the permanent identity of the device). According to one example, the true identity of the network client device 102 is the complete security ID (SID) associated with the device. Figure 3 An example of the complete SID 302 of the network client device 102 is shown in Figure 3 . According to one example, the complete SID 302 of the network client device 102 includes the domain SID value 304 and the RID value 306 of the network client device 102. The Network Client Device Identity Engine 208 is also operable to associate the determined true identity of the network client device 102 with the identified IP address. According to one aspect, the Network Client Device Identity Engine 208 stores the true identity of the network client device 102 and the associated IP address in the data repository 214.

[0030] According to one aspect, the network client device 102 continuously polls the time server 108 for time synchronization according to a polling interval. The Connection Monitor 210 is an illustration of a software module, system, or device operable to monitor the time synchronization traffic flowing between the network client device 102 and the time server 108 for time synchronization polling transactions. For example, the network client device 102 periodically sends time synchronization networking protocol messages to the time server 108, and the time server 108 then responds within a certain time interval (i.e., the polling interval). According to one example, the polling interval is included in the message transaction monitored by the Connection Monitor 210.

[0031] The Connection Monitor 210 is further operable to determine when the network client device 102 disconnects from the network 104. For example, when the polling interval has passed and the Connection Monitor 210 does not detect a time synchronization networking protocol message sent from the network client device 102 to the time server 108, the Connection Monitor 210 determines that the network client device 102 has disconnected from the network 104. The Connection Monitor 210 is also operable to determine the time when the network client device 102 disconnects from the network 104. In some examples, the disconnection time is an estimate based on the range within the polling interval. According to one aspect, the Connection Monitor 210 stores the disconnection time information in the data repository 214.

[0032] According to one aspect, when the network client device 102 reconnects to the network 104, the network client device 102 sends a time synchronization networking protocol message to the time server 108, where the time synchronization networking protocol message includes a timestamp of the time most recently used by the time server 108 to update the clock of the network client device 102. In some examples, the timestamp value is included in the reference timestamp field in the time synchronization networking protocol message. Using this timestamp value, the connection monitor 210 determines the most recent time the network client device 102 was connected to the network 104. According to one aspect, the connection monitor 210 stores the reconnect time information in the data repository 214.

[0033] The anomaly detection engine 212 is an illustration of a software module, system, or device operable to detect anomalies in network traffic. According to one example, the anomaly detection engine 212 views connection, disconnection, and reconnection information associated with the network client device 102 based on the true identity of the network client device 102, and detects anomalous traffic behavior, such as when a second network client device uses the same security token as the one used on the first network client device 102, when the same network client device 102 connects too quickly (e.g., below a predetermined time threshold) on geographically distant networks, the number or frequency of anomalous connections, disconnections, and reconnections, a network client device 102 that frequently changes its IP address, etc. According to another example, the anomaly detection engine 212 views connection, disconnection, and reconnection information associated with an IP address and detects anomalous traffic behavior associated with the IP address. According to one aspect, the anomalous behavior may indicate a network security attack (e.g., fraud). According to one aspect, the anomaly detection engine 212 stores the anomalous traffic behavior information in the data repository 214.

[0034] The report generator 216 is an illustration of a software module, system, or device operable to generate output of the network client device 102 or network traffic information. According to one example, the report generator 216 is operable to generate a report of connection, disconnection, and reconnection information. For example, the report generator 216 is operable to generate a report including records of connections and disconnections from the network 104. As another example, the report generator 216 is operable to generate a report including records of the network client device 102 associated with a specific IP address.

[0035] According to one aspect, the report generator 216 generates a report in response to receiving a query. For example, the report generator 216 may receive a query regarding a particular network client device 102, and the report generator 216 generates a report that includes a list of connections and disconnections associated with the network client device 102. As another example, the report generator 216 may receive a query regarding a particular IP address, and the report generator 216 generates a report that includes a list of network client devices 102 associated with the IP address. According to one aspect, the report generator 216 is also operable to generate a report of anomalous traffic activity determined by the anomaly detection engine 212.

[0036] has been described with respect to Figures 1 - 3 the operating environment and various aspects Figure 4 FIG. illustrates a flow chart showing the overall stages involved in an example method for monitoring the life cycle of connections to a computer network. The method 400 begins at start operation 405 and proceeds to operation 410, where the network traffic listener 202 listens for network traffic in the networked directory service environment 110. For example, the network traffic listener 202 accesses and monitors time synchronization traffic flowing between one or more network client devices 102 and the time server 108.

[0037] The method 400 continues to operation 415, where the data extractor 204 parses the time synchronization network protocol messages and extracts useful information such as, for example, a source address value (the Internet Protocol (IP) address of the network client device 102); an identifier that uniquely identifies the network client device 102 (e.g., a RID value); a domain identifier that uniquely identifies the domain of the network client device 102 (e.g., a domain security identifier (SID) value); a peer clock layer value; an original timestamp value; and a received timestamp value). Also at operation 415, the data extractor 204 stores the extracted information in the data repository 214.

[0038] Method 400 proceeds to operation 420, where connection type identifier 206 identifies the time synchronization networking protocol request message as an initial request (e.g., a request generated at a start / restart event, a connect / reconnect event, a domain connection event, etc.). As described above, when the reference clock identifier value (i.e., the code identifying a specific reference clock) is set to "null", when the peer clock layer value is set to unspecified, invalid, or 0, and when the original timestamp value (i.e., the timestamp established by network client device 102 that specifies the time when the request for time server 108 left) and the receive timestamp value (i.e., the timestamp established by time server 108 that specifies the time when the request arrived from network client device 102) are set to 0 (UnixTime 1.1.1970), connection type identifier 206 identifies the request as an initial request. According to one aspect, when network client device 102 reconnects to network 104, the timestamp of the most recent time used by time server 108 to update the clock of network client device 102 is included in the time synchronization networking protocol request message. Using this timestamp value, connection monitor 210 determines the most recent time that network client device 102 was connected to network 104 and stores the reconnect time information in data repository 214.

[0039] Method 400 proceeds to operation 425, where network client device identity engine 208 determines the true identity of network client device 102. According to one example, network client device identity engine 208 extracts the RID value from the time synchronization networking protocol message and extracts the domain SID value from the destination of the time synchronization networking protocol message, determines the complete SID (i.e., the true identity) of network client device 102, and associates the determined true identity of network client device 102 with the identified IP address. Also at operation 425, network client device identity engine 208 stores the true identity of network client device 102 and the associated IP address in data repository 214.

[0040] Method 400 proceeds to operation 430, where connection monitor 210 monitors the time synchronization traffic flowing between network client device 102 and time server 108 according to the polling interval specified in the time synchronization networking protocol message for time synchronization polling transactions.

[0041] At decision operation 435, connection monitor 210 monitors the time synchronization traffic to identify when network client device 102 disconnects from network 104. For example, at decision operation 435, it is determined whether the polling interval associated with network client device 102 has passed and whether connection monitor 210 has not detected a time synchronization networking protocol message sent from network client device 102 to time server 108.

[0042] If it is determined that the network client device 102 has been disconnected from the network, method 400 proceeds to operation 440, where the connection monitor 210 determines the time at which the network client device 102 was disconnected from the network 104 based on an estimate made according to the most recent polling request sent by the network client device 102 to the time server 108 and the polling interval. For example, if the most recent request sent by the network client device 102 occurred at 12:01:02.763054000 UTC and the polling interval is 1024 seconds, the connection monitor 210 may estimate the disconnection time to be within the range of 12:01:02.763054000 UTC to 12:18:06.763054000 UTC. The connection monitor 210 stores the disconnection time information in the data repository 214.

[0043] Method 400 optionally proceeds to decision operation 445, where the anomaly detection engine 212 examines connection, disconnection, and reconnection information associated with the IP address or with the network client device 102 based on the true identity of the network client device 102 and determines whether there is anomalous traffic behavior, such as when a second network client device uses the same security token as the one used on the first network client device 102, when the same network client device 102 connects too quickly (e.g., below a predetermined time threshold) on networks that are geographically far apart, the number or frequency of anomalies in the connection, disconnection, and reconnection of the network client device 102, the network client device 102 that frequently changes its IP address, anomalous traffic behavior associated with the IP address, etc. If it is determined that there is anomalous traffic behavior, the method proceeds from decision operation 445 to operation 450, where the anomaly detection engine 212 stores the anomalous traffic behavior information in the data repository 214.

[0044] If method 400 does not proceed from operation 440 to decision operation 445, method 400 continues to operation 455, where the report generator 216 receives a query. For example, the report generator 216 may receive a query about a specific network client device 102, a query about a specific IP address, etc.

[0045] Method 400 continues to operation 460 where the report generator 216 generates a report. If the method continues from operation 450, the report generator 216 generates a report that includes the abnormal traffic activity determined by the anomaly detection engine 212. If the method continues from operation 455, the report generator 216 generates a report that includes information associated with the received query. For example, if the report generator 216 receives a query regarding connection information associated with a particular network client device 102, the report generator 216 generates a report that includes a list of connections and disconnections associated with the particular network client device 102. As another example, if the report generator 216 receives a query regarding connection information associated with a particular IP address, the report generator 216 generates a report that includes a list of the true identities of the network client devices 102 associated with the IP address. Method 400 ends at operation 495.

[0046] Although implementations have been described in the general context of program modules that execute in conjunction with an application program running on an operating system on a computer, those skilled in the art will recognize that various aspects can also be implemented in conjunction with other program modules. Generally, program modules include routines, programs, components, data structures, and other types of structures that perform particular tasks or implement particular abstract data types.

[0047] Aspects and functions described herein can be operated via multiple computing systems, including but not limited to desktop computer systems, wired and wireless computing systems, mobile computing systems (e.g., mobile phones, netbooks, tablet or slate computers, notebook computers, and laptop computers), handheld devices, multiprocessor systems, microprocessor-based electronic products, or programmable consumer electronics, small computers, and large computers.

[0048] Additionally, according to one aspect, aspects and functions described herein operate on a distributed system (e.g., a cloud-based computing system) where application functions, memory, data storage and retrieval, and various processing functions operate remotely from each other over a distributed computing network such as the Internet or an intranet. According to one aspect, a user interface and various types of information are displayed via an on-board computing device display or via a remote display unit associated with one or more computing devices. For example, the user interface and various types of information are displayed and interacted with on a wall surface that projects the user interface and various types of information. Interaction with a large number of computing systems in practice includes keystroke input, touchscreen input, voice or other audio input, gesture input, etc., where the associated computing device is equipped with detection (e.g., camera) functions for capturing and interpreting user gestures for controlling the functions of the computing device.

[0049] Figures 5 - 7and the associated description provides a discussion of various operating environments in which the illustrative examples are practiced. However, with respect to Figures 5 - 7 the devices and systems illustrated and discussed are for example and illustration purposes and do not limit the numerous computing device configurations for practicing the aspects described herein.

[0050] Figure 5 is a block diagram of the physical components (i.e., hardware) of a computing device 500 that illustrates an example of practicing the present disclosure. In a basic configuration, computing device 500 includes at least one processing unit 502 and system memory 504. According to one aspect, depending on the configuration and type of the computing device, system memory 504 includes, but is not limited to, volatile storage (e.g., random access memory), non-volatile memory (e.g., read only memory), flash memory, or any combination of these memories. According to one aspect, system memory 504 includes an operating system 505 and one or more programming modules 506 suitable for running software applications 550. According to one aspect, system memory 504 includes a security device 106. Operating system 505 is suitable for controlling the operation of computing device 500, for example. Additionally, aspects are practiced in conjunction with a graphics library, other operating systems, or any other application, and are not limited to any particular application or system. This basic configuration is Figure 5 illustrated by those components within dashed line 508. According to one aspect, computing device 500 has additional features or functionality. For example, according to one aspect, computing device 500 includes additional data storage devices (removable and / or non-removable) such as, for example, magnetic disks, optical disks, or magnetic tapes. Figure 5 Such additional storage is illustrated in

[0051] by removable storage device 509 and non-removable storage device 510. As described above, according to one aspect, a number of program modules and data files are stored in system memory 504. When executed on processing unit 502, programming modules 506 (e.g., security device 106) perform processes including but not limited to Figure 4 one or more stages of method 400 as shown in

[0052] According to one aspect, aspects are practiced in a circuit including discrete electronic components, in a package or integrated electronic chip containing logic gates, in a circuit utilizing a microprocessor, or on a single chip or microprocessor containing electronic components. For example, aspects are practiced via a system on a chip (SOC), where Figure 5Each of the one or more components shown in the figure is integrated onto a single integrated circuit. According to one aspect, such an SOC device includes one or more processing units, a graphics unit, a communication unit, a system virtualization unit, and various application functions (all integrated (burned) onto the chip substrate as a single integrated circuit). When operating via the SOC, the functions described herein operate via dedicated logic integrated with other components of the computing device 500 on a single integrated circuit (chip). According to one aspect, aspects of the present disclosure are practiced using other technologies capable of performing logical operations (such as AND, OR, and NOT), including but not limited to mechanical, optical, fluidic, and quantum technologies. Additionally, aspects are practiced within a general-purpose computer or any other circuit or system.

[0053] According to one aspect, the computing device 500 has (multiple) input devices 512 such as a keyboard, a mouse, a pen, a voice input device, a touch input device, etc. According to one aspect, it also includes (multiple) output devices 514 such as a display, a speaker, a printer, etc. The above devices are examples, and other devices may be used. According to one aspect, the computing device 500 includes one or more communication connections 516 that allow communication with other computing devices 518. Examples of suitable communication connections 516 include but are not limited to radio frequency (RF) transmitter, receiver, and / or transceiver circuits, universal serial bus (USB), parallel, and / or serial ports.

[0054] As used herein, the term computer-readable medium includes computer storage media. Computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, or program modules). System memory 504, removable storage device 509, and non-removable storage device 510 are all examples of computer storage media (i.e., memory storage devices). According to one aspect, computer storage media includes RAM, ROM, electrically erasable programmable read-only memory (EEPROM), flash memory, or other memory technologies, CD-ROM, digital versatile disk (DVD), or other optical memory, cassette tapes, magnetic tapes, disk storage, or other magnetic storage devices, or any other article that can be used to store information and can be accessed by the computing device 500. According to one aspect, any such computer storage media is part of the computing device 500. Computer storage media does not include carrier waves or other propagated data signals.

[0055] According to one aspect, a communication medium is embodied by computer-readable instructions, data structures, program modules, or other data in a modulated data signal, such as a carrier wave or other transmission mechanism, and the communication medium includes any information delivery medium. According to one aspect, the term "modulated data signal" describes a signal having one or more characteristics set or changed in such a manner as to encode information in the signal. By way of example, and not limitation, communication media include wired media such as a wired network or direct-wired connection, and wireless media such as acoustic, radio frequency (RF), infrared, and other wireless media.

[0056] Figure 6A and Figure 6B Illustrated is a mobile computing device 600, e.g., a mobile phone, a smart phone, a tablet personal computer, a laptop computer, etc., with which aspects may be practiced. Refer to Figure 6A, an example of a mobile computing device 600 for implementing these aspects is illustrated. In a basic configuration, the mobile computing device 600 is a handheld computer with input and output components. The mobile computing device 600 generally includes a display 605 and one or more input buttons 610 that allow a user to input information into the mobile computing device 600. According to one aspect, the display 605 of the mobile computing device 600 serves as an input device (e.g., a touchscreen display). If an optional side input component 615 is included, the optional side input component 615 allows for further user input. According to one aspect, the side input component 615 is a rotary switch, a button, or any other type of manual input component. In alternative examples, the mobile computing device 600 incorporates more or fewer input components. For example, in some examples, the display 605 may not be a touchscreen. In alternative examples, the mobile computing device 600 is a portable telephone system (e.g., a cellular phone). According to one aspect, the mobile computing device 600 includes an optional mini keyboard 635. According to one aspect, the optional mini keyboard 635 is a physical mini keyboard. According to another aspect, the optional mini keyboard 635 is a "soft" keyboard generated on a touchscreen display. In various aspects, the output components include the display 605 for presenting a graphical user interface (GUI), visual indicators 620 (e.g., light-emitting diodes), and / or audio transducers 625 (e.g., speakers). In some examples, the mobile computing device 600 incorporates a vibration transducer for providing haptic feedback to the user. In yet another example, the mobile computing device 600 incorporates input and / or output ports such as an audio input (e.g., a microphone jack), an audio output (e.g., a headphone jack), and a video output (e.g., an HDMI port) for sending signals to or receiving signals from external devices. In yet another example, the mobile computing device 600 incorporates a peripheral device port 640 such as an audio input (e.g., a microphone jack), an audio output (e.g., a headphone jack), and a video output (e.g., an HDMI port) for sending signals to or receiving signals from external devices.

[0057] Figure 6B is a block diagram of an architecture that illustrates an example of a mobile computing device. That is, the mobile computing device 600 incorporates a system (i.e., an architecture) 602 to implement some examples. In one example, the system 602 is implemented as a "smartphone" capable of running one or more applications (e.g., a browser, email, calendar, contact manager, messaging client, game, and media client / player). In some examples, the system 602 is integrated as a computing device such as an integrated personal digital assistant (PDA) and a wireless phone.

[0058] According to one aspect, one or more applications 650 are loaded into the memory 662 and run on or in association with the operating system 664. Examples of application programs include a telephone dialer program, an e-mail program, a personal information management (PIM) program, a word processing program, a spreadsheet program, an Internet browser program, a messaging program, and the like. According to one aspect, the security device 106 is loaded into the memory 662. The system 602 also includes a non-volatile storage area 668 within the memory 662. The non-volatile storage area 668 is used to store persistent information that should not be lost in the event of a power-down of the system 602. The application programs 650 may use information (e.g., e-mail or other messages used by an e-mail application) and store the information in the non-volatile storage area 668. A synchronization application (not shown) also resides on the system 602 and is programmed to interact with a corresponding synchronization application residing on a host to keep the information stored in the non-volatile storage area 668 synchronized with the corresponding information stored at the host. It should be understood that other applications may be loaded into the memory 662 and run on the mobile computing device 600.

[0059] According to one aspect, the system 602 has a power supply 670, which is implemented as one or more batteries. According to one aspect, the power supply 670 further includes an external power supply (e.g., an AC adapter or an electric docking cradle that supplements or recharges the battery).

[0060] According to one aspect, the system 602 includes a radio 672 that performs the functions of transmitting and receiving radio frequency communications. The radio 672 facilitates a wireless connection between the system 602 and the "outside world" via a communication carrier or service provider. Transmissions to and from the radio 672 are under the control of the operating system 664. In other words, communications received by the radio 672 can be propagated to the application programs 650 via the operating system 664, and vice versa.

[0061] According to one aspect, a visual indicator 620 is used to provide visual notifications and / or an audio interface 674 is used to generate audio notifications via an audio transducer 625. In the illustrated example, the visual indicator 620 is a light-emitting diode (LED) and the audio transducer 625 is a speaker. These devices can be directly coupled to a power source 670 such that when activated, even if the processor 660 and other components may be turned off to conserve battery power, these devices remain on for a duration specified by the notification mechanism. The LED can be programmed to remain on indefinitely until the user takes an action to indicate the on state of the device. The audio interface 674 is used to provide audio signals to the user and receive audio signals from the user. For example, in addition to being coupled to the audio transducer 625, the audio interface 674 can also be coupled to a microphone to receive audio input, such as to facilitate a telephone conversation. According to one aspect, the system 602 further includes a video interface 676 that enables operation of an in-vehicle camera 630 to record still images, video streams, and the like.

[0062] According to one aspect, the mobile computing device 600 implementing the system 602 has additional features or functionality. For example, the mobile computing device 600 includes additional data storage devices (removable and / or non-removable) such as magnetic disks, optical disks, or magnetic tapes. Figure 6B Such additional storage means are illustrated by the non-volatile storage area 668.

[0063] According to one aspect, as described above, the data / information generated or captured by the mobile computing device 600 and stored via the system 602 is stored locally on the mobile computing device 600. According to another aspect, the data is stored on any number of storage media accessible to the device via a radio 672 or via a wired connection between the mobile computing device 600 and a separate computing device associated with the mobile computing device 600 (e.g., a server computer in a distributed computing network (e.g., the Internet)). It should be understood that such data / information can be accessed via the mobile computing device 600, via the radio 672, or via a distributed computing network. Similarly, according to one aspect, in accordance with well-known data / information transfer and storage components (including email and collaborative data / information sharing systems), this data / information is easily transferred between computing devices for storage and use.

[0064] Figure 7Illustrated is an example of the architecture of a system for monitoring the lifecycle of a connection to a computer network 104 as described above. Content developed, interacted with, or edited in association with a security device 106 can be stored in different communication channels or other storage types. For example, directory services 722, web portals 724, mailbox services 726, instant message stores 728, or social networking sites 730 can be used to store various documents. The security device 106 is operable to use any of these types of systems for monitoring the lifecycle of a connection to the computer network 104 as described herein. According to one aspect, a server 715 provides the security device 106 to clients 705a, b, c. As an example, the server 715 is a web server that provides the security device 106 over a network. The server 715 provides the security device 106 on the network to the clients 705 over a network 710. As an example, client computing devices are implemented and embodied in a personal computer 705a, a tablet computing device 705b, or a mobile computing device 705c (e.g., a smart phone) or other computing devices. Any of these examples of client computing devices are operable to obtain content from a storage device 716.

[0065] Implementations have been described above with reference to block diagrams and / or operational descriptions of methods, systems, and computer program products according to various aspects. As shown in any flowchart, the functions / actions recorded in the blocks may not occur in the order presented. For example, depending on the functionality / action involved, two consecutive blocks shown may actually be executed substantially simultaneously, or the blocks may sometimes be executed in the reverse order.

[0066] The description and illustration of one or more examples provided in this application are not intended to limit or restrict the scope of what is claimed in any way. The aspects, examples, and details provided in this application are considered sufficient to convey ownership and enable others to make and use the best mode. Implementations should not be construed as limited to any aspect, example, or detail provided in this application. Whether shown and described in combination or separately, various features (structural and method features) are intended to be selectively included or omitted to produce examples with a particular set of features. Having provided the description and illustration of this application, those skilled in the art can envision variations, modifications, and alternative examples that fall within the spirit of the broader aspects embodied in this application and that do not depart from the broader scope.

Claims

1. A computer-implemented method for monitoring the lifecycle of a network client device on a computer network, the method comprising: by a computer device: monitoring time synchronization networking protocol messages associated with the computer network; determining whether a given time synchronization networking protocol message received by a time server of the computer network indicates an initial connection to the network client device of the computer network, including: extracting from the given time synchronization networking protocol message: a value of a level of a clock of the time server in a time server hierarchy; an original timestamp indicating a time at the network client device at which the network client device sent the given time synchronization networking protocol message to the time server; and a received timestamp indicating a time at the time server at which the given time synchronization networking protocol message was received by the time server; determining that the given time synchronization networking protocol message indicates the initial connection to the network client device of the computer network based on the level, the original timestamp, and the received timestamp having zero values; and determining that the given time synchronization networking protocol message does not indicate the initial connection to the network client device of the computer network based on at least one of the level, the original timestamp, and the received timestamp having a non-zero value; extracting information related to the network client device from a given time synchronization networking protocol request message; determining a true identity of the network client device connected to the computer network; associating the true identity of the network client device with an Internet Protocol (IP) address; determining when the network client disconnects from the computer network based on the time synchronization networking protocol message; and generating a report identifying the lifecycle of the network client device associated with the IP address based on connection and disconnection data associated with the network client device.

2. The method according to claim 1, wherein determining when the network client device disconnects from the computer network comprises: monitoring subsequent time synchronization networking protocol request messages sent from the network client device according to a defined polling interval; determining whether subsequent time synchronization networking protocol request messages are not sent from the network client device within the defined polling interval; and in response to making an affirmative determination, determining that the network client device has disconnected from the computer network.

3. The method according to claim 2, further comprising determining when the network client device reconnects to the network, wherein determining when the network client device reconnects to the network comprises: receiving a time synchronization networking protocol request message for the time server from the network client device; determining that the time synchronization networking protocol request message for the time server is associated with an initial connection event of the network client device; and Parse the time synchronization networking protocol request message for the time server and extract data from the time synchronization networking protocol request message for the time server, the data corresponding to a timestamp that indicates the time most recently used by the time server to update the internal clock of the network client device.

4. The method according to claim 1, further comprising estimating a disconnection time based on the time of the last subsequent time synchronization networking protocol request message for the time server sent by the network client device to the time server and a polling interval.

5. The method according to claim 1, wherein determining the true identity of the network client device connected to the computer network comprises: parsing the time synchronization networking protocol request message and extracting data corresponding to the following from the time synchronization networking protocol request message: a unique identifier identifying the network client device; and a unique identifier identifying the domain in which the network client device is grouped.

6. The method according to claim 5, wherein: the unique identifier identifying the network client device is a relative identifier that uniquely identifies the network client device within the domain in which the network client device is grouped; the unique identifier identifying the domain in which the network client device is grouped is a domain security identifier; and the true identity of the network client device is a network client device security identifier.

7. The method according to claim 1, wherein prior to generating the report: analyze at least one of the following: the true identity of the network client device; connection data associated with the network client device; and disconnection data associated with the network client device; and determine whether there is abnormal traffic behavior associated with the network client device.

8. The method according to claim 7, wherein determining whether there is abnormal traffic behavior associated with the network client device comprises at least one of the following: identifying whether a second network client device is connected to the computer network using a security token that is the same as the security token used by the network client device; identifying whether the network client device is connected to the computer network from multiple geographically remote networks based on connection times from the network client device to two of the multiple geographically remote networks that are below a predetermined minimum time threshold; identifying an abnormal number or frequency of connections or disconnections of the network client device to / from the computer network; identifying an abnormal number or frequency of changes in the IP address associated with the network client device; and identifying an abnormal number of network client devices associated with the IP address.

9. The method according to claim 1, wherein: prior to generating the report, receive a query associated with the network client device, the IP address, or the computer network; and generating the report comprises generating a report including at least one of the following: A connection associated with the network client device; A disconnection associated with the network client device; And An IP address associated with the network client device.

10. The method according to claim 1, wherein the values of the level, the original timestamp, and the received timestamp that are considered zero Include: Zero, Unspecified, Invalid, and January 1, 1970 of Unix Time.

11. A system for monitoring the life cycle of a network client device on a computer network, Comprising: One or more processors for executing programmed instructions; A memory coupled to the one or more processors for storing program instruction steps executed by the one or more processors; A security device, comprising: A network traffic listener program configured to: Monitor time synchronization networking protocol messages associated with the computer network; and Determine whether a given time synchronization networking protocol message received by a time server of the computer network indicates an initial connection to the network client device of the computer network, wherein the network traffic listener program is configured to extract from the given time synchronization networking protocol message: The value of the level of the clock of the time server in the time server hierarchy; An original timestamp that indicates the time at the network client device at which the network client device sent the given time synchronization networking protocol message to the time server; and A received timestamp that indicates the time at the time server at which the given time synchronization networking protocol message was received by the time server; Wherein, based on the level, the original timestamp, and the received timestamp having zero values, it is determined that the given time synchronization networking protocol message indicates the initial connection to the network client device of the computer network; and Wherein, based on at least one of the level, the original timestamp, and the received timestamp having a non-zero value, it is determined that the given time synchronization networking protocol message does not indicate the initial connection to the network client device of the computer network; a data extractor program configured to extract information related to the network client device from a time synchronization networking protocol request message; A network client device identification engine configured to: Determine the true identity of the network client device connected to the computer network based on the information extracted from the time synchronization networking protocol request message information; Associate the true identity of the network client device with an Internet Protocol (IP) address; A connection monitor program configured to determine when the network client disconnects from the computer network based on the time synchronization networking protocol message; and A report generator program configured to generate a report identifying the life cycle of the network client device associated with the IP address based on connection and disconnection data associated with the network client device.

12. The system according to claim 11, wherein in determining when the network client device disconnects from the computer network, the connection monitor program is further configured to: Monitor subsequent time synchronization networking protocol request messages sent from the network client device according to a defined polling interval; Determine whether a subsequent time synchronization networking protocol request message is not sent from the network client device within the defined polling interval; and In response to making an affirmative determination, determine that the network client device has disconnected from the network.

13. The system according to claim 11, wherein in determining the true identity of the network client device connected to the computer network, the network client device identification engine is further configured to: Receive data corresponding to: A unique identifier identifying the network client device ; And A unique identifier identifying the domain to which the network client device is grouped, wherein: The unique identifier identifying the network client device is a relative identifier; The unique identifier identifying the domain to which the network client device is grouped is a domain security identifier; and The true identity of the network client device is a network client device security identifier.

14. The system according to claim 11, further comprising an anomaly detection engine, the anomaly detection engine being further configured to: Analyze the connection and disconnection data; and Determine whether there is abnormal traffic behavior associated with the connection and disconnection data.

15. The system according to claim 14, wherein in determining whether there is abnormal traffic behavior associated with the connection and disconnection data, the anomaly detection engine is further configured to identify at least one of the following: Whether a second network client device is connected to the computer network using a security token that is the same as the security token used by the network client device; Based on the connection time from the network client device to two of a plurality of geographically remote networks being lower than a predetermined minimum time threshold, whether the network client device connects to the computer network from a plurality of geographically remote networks; The abnormal number or frequency of connections or disconnections of the network client device to the computer network; The abnormal number or frequency of changes in the IP address associated with the network client device; and The abnormal number of network client devices associated with the IP address.

16. The system according to claim 11, wherein before generating a report including connection information associated with the network client device, the report generator program is further configured to receive a query associated with the network client device, the IP address, or the computer network.

17. The values of the level, the original timestamp, and the received timestamp that are regarded as zero Include: Zero, Not specified, Invalid, and January 1, 1970 of Unix Time.

18. A computer-readable storage device storing computer-usable instructions that, when used by one or more computing devices, cause the one or more computing devices to perform a method for monitoring the lifecycle of network client devices on a computer network, the method comprises: monitoring time synchronization networking protocol messages associated with the computer network; determining whether a given time synchronization networking protocol message received by a time server of the computer network indicates an initial connection to the network client device of the computer network, including: extracting from the given time synchronization networking protocol message: a value of the level of the clock of the time server in the time server hierarchy; an original timestamp indicating the time at the network client device at which the network client device sent the given time synchronization networking protocol message to the time server; and a received timestamp indicating the time at the time server at which the given time synchronization networking protocol message was received by the time server; determining that the given time synchronization networking protocol message indicates the initial connection to the network client device of the computer network based on the level, the original timestamp, and the received timestamp having zero values; and determining that the given time synchronization networking protocol message does not indicate the initial connection to the network client device of the computer network based on at least one of the level, the original timestamp, and the received timestamp having a non-zero value; extracting information related to the network client device from a given time synchronization networking protocol request message; determining the true identity of the network client device connected to the computer network; associating the true identity of the network client device with an Internet Protocol (IP) address; determining when the network client disconnects from the computer network based on the time synchronization networking protocol message; and generating a report identifying the lifecycle of the network client device associated with the IP address based on connection and disconnection data associated with the network client device.

19. The computer-readable storage device according to claim 18, wherein the values of the level, the original timestamp, and the received timestamp that are considered to be zero comprise: zero, unspecified, invalid, and January 1, 1970 of Unix Time.

20. The computer-readable storage device according to claim 18, wherein determining the true identity of the network client device connected to the computer network further comprises: parsing the time synchronization networking protocol request message and extracting data corresponding to the following items from the time synchronization networking protocol request message: a domain security identifier that uniquely identifies the domain in which the network client device is grouped; and a relative identifier that uniquely identifies the network client device in the domain in which the network client device is grouped; and Wherein the true identity of the network client device is the security identifier of the network client device.

Citation Information

Patent Citations

  • Protecting against distributed network flood attacks

    CN102014116A

  • System and method for network security including detection of man-in-the-browser attacks

    US20110185421A1