IP Library Granted Patent US 12676893
Granted Patent B2
US 12676893 · App. 18/521,791 · Granted Jul 7, 2026

First-time user experience systems and methods for workload protection solutions

Inventors: Gabriel J. Fontenot (Richardson, TX); Paul Mach (San Jose, CA); Tony Lee (San Jose, CA); Jana Radhakrishnan (San Jose, CA); Apurva Chhajed (San Jose, CA); Amandeep Singh (Apex, NC); Brijeshkumar Shah (Cary, NC)
Assignee: Cisco Technology, Inc.
H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12676893
App. No.
18/521,791
Granted
Jul 7, 2026
Kind
B2
Abstract

Devices, systems, methods, and processes for facilitating a first-time user experience for a workload protection solution are described herein. This can be done through a segmentation setup assistant that can be configured to gather data related to a network and generate one or more prompts for a user to input data related to the network. This data can be associated with a network's organization, infrastructure, environment, and the like. For example, providing various internet protocol addresses and subnets related to different network devices, data centers, and applications can be utilized to generate an automated hierarchy and/or suggestions on how to properly segment and setup a network for workload protection. In this way, a user may be able to configure the system via the setup assistant and thus be more apt to correctly setup a network with a workload protection solution and provide a more optimal security outcome.

Claims (43)

1 . A device, comprising:

a processor;

at least one network interface controller configured to provide access to a network; and

a memory communicatively coupled to the processor, wherein the memory comprises a workload protection logic comprising instructions executable by the process that are configured to:

initiate a segmentation setup assistant;

deploy a plurality of agents;

receive user input data; and

transform the user input data into a recommended network policy hierarchy.

2 . The device of claim 1 , wherein the plurality of agents are deployed on the network.

3 . The device of claim 2 , wherein the workload protection logic is further configured to determine a desired type of agent to install.

4 . The device of claim 2 , wherein the workload protection logic is further configured to determine a desired version of agent to install.

5 . The device of claim 1 , wherein the user input data comprises at least groupings of workloads.

6 . The device of claim 1 , wherein the user input data comprises at least a definition of at least one internet protocol address associated with the network.

7 . The device of claim 1 , wherein the user input data comprises at least a definition of at least one subnet associated with the network.

8 . The device of claim 1 , wherein the user input data comprises at least a definition of both public and private internet protocol address ranges associated with the network.

9 . The device of claim 1 , wherein the recommended network policy comprises at least a label associated with each data center.

10 . The device of claim 9 , wherein each data center is assigned a key and value pair.

11 . The device of claim 1 , wherein the recommended network policy comprises a recommended scope design.

12 . The device of claim 1 , wherein the recommended network policy comprises a recommended label design.

13 . The device of claim 1 , wherein workload protection logic is further configured to generate a prompt or user input.

14 . The device of claim 13 , wherein the prompt is a graphical user interface configured to show a hierarchal structure of the network.

15 . The device of claim 14 , wherein the graphical user interface is further configured to receive scope data.

16 . The device of claim 1 , wherein the recommended network policy comprises at least a segmented network hierarchy.

17 . The device of claim 1 , wherein the recommended network policy is based on at least the user input data and data received from at least one of the plurality of agents.

18 . A device, comprising:

a processor;

at least one network interface controller configured to provide access to a network; and

a memory communicatively coupled to the processor, wherein the memory comprises a workload protection logic comprising instructions executable by the process that are configured to:

receive a request to initiate network segmentation;

determine one or more suitable agent types for the network;

deploy a plurality of the suitable agents;

generate a graphical user interface prompt configured to receive user input;

receive user input data from the prompt; and

transform the user input data from the prompt into at least one recommended network segmentation.

19 . The device of claim 18 , wherein the at least one recommended network segmentation is based on at least the user input data and data received from at least one of the deployed agents.

20 . A method generating an application dependency mapping, comprising:

receiving a request to initiate network segmentation;

determining one or more suitable agent types for the network;

deploying a plurality of the suitable agents;

generating a graphical user interface prompt configured to receive user input;

receiving user input data from the prompt; and

generating

transform the user input data from the prompt into at least one recommended network segmentation.