IP Library Granted Patent US 8,898,734
Granted Patent B2
US 8,898,734 · App. 11/505,171 · Granted Nov 25, 2014

Analyzing security compliance within a network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,898,734
App. No.
11/505,171
Granted
Nov 25, 2014
Kind
B2
Abstract

A security policy database identifies the intended security policies within a network, a traffic generator provides test traffic that is configured to test each defined security policy, and a simulator simulates the propagation of this traffic on a model of the network. The model of the network includes the configuration data associated with each device, and thus, if devices are properly configured to enforce the intended security policies, the success/failure of the simulated test traffic will conform to the intended permit/deny policy of each connection. Differences between the simulated message propagation and the intended security policies are reported to the user, and diagnostic tools are provided to facilitate identification of the device configuration data that accounts for the observed difference. Additionally, if a network's current security policy is unknown, test traffic is generated to reveal the actual policy in effect, to construct a baseline intended security policy.

Claims (25)

1. A method comprising:

identifying, on a security validation system, one or more pairs of zones of a network, each element of a first zone of each pair having a common security policy relative to each element of a second zone of the pair,

selecting, by the security validation system, at least one pair of the pairs of zones,

generating, by the security validation system, one or more messages for transmission between a source zone and a destination zone of the at least one pair, and

determining, by the security validation system, the security policy corresponding to the at least one pair of zones based on propagation of the one or more messages from the source zone toward the destination zone.

2. The method of claim 1 , wherein determining the security policy includes simulating the propagation of the one or more messages based on a model of the network.

3. The method of claim 2 , including determining whether the security policy corresponding to the at least one pair of zones is consistent with an expected security policy associated with the at least one pair, based on the propagation of the one or more messages.

4. The method of claim 3 , including facilitating diagnosis of violations of the expected security policy.

5. The method of claim 4 , including:

based on the propagation, identifying one of:

a path corresponding to the propagation of at least one of the one or more messages between the source and destination zones, and

one or more network devices that blocked the propagation of the at least one message to the destination zone.

6. The method of claim 1 , including determining whether the security policy corresponding to the at least one pair of zones based on the propagation of the one or more messages between the zones is consistent with an expected security policy for the at least one pair of zones.

7. The method of claim 6 , including facilitating diagnosis of violations of the expected security policy.

8. The method of claim 1 , including identifying a path corresponding to the propagation of at least one of the one or more messages between the source and destination zones.

9. The method of claim 1 , including identifying one or more network devices that blocked the propagation of the at least one message to the destination zone.

10. The method of claim 1 , including displaying information regarding the security policy corresponding to the at least one pair of zones.

11. The method of claim 1 , wherein the information includes an identification of whether a connection was permitted or denied between the first zone and the second zone of at least one pair, based on the propagation.

12. The method of claim 10 , wherein the information includes an identification of whether an expected security policy of the at least one pair of zones was violated, based on the propagation.

13. The method of claim 10 , wherein the information includes a path corresponding to the propagation of at least one of the one or more messages between the source and destination zones, based on the propagation.

14. The method of claim 10 , wherein the information includes a first report that identifies the security policy for a plurality of the one or more pairs, based on the propagation.

15. The method of claim 14 , wherein the information includes a second report that identifies each of the one or more pairs in which communication was denied between the first zone and the second zone, based on the propagation.

16. The method of claim 15 , wherein the information includes a third report that identifies each of the one or more pairs in which communication was permitted between the first zone and the second zone, based on the propagation.

17. The method of claim 16 , wherein the information includes a fourth report that identifies each of the one or more pairs in which an expected security policy was violated, based on the propagation.

18. The method of claim 10 , wherein the information includes a report that identifies each of the one or more pairs in which an expected security policy was violated, based on the propagation.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2013
From: OPNET TECHNOLOGIES LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 030462/0135 →
CHANGE OF NAME Recorded May 14, 2013
From: OPNET TECHNOLOGIES, INC.
To: OPNET TECHNOLOGIES LLC
Reel/Frame 030411/0234 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2006
From: SINGH, PRADEEP K.; COHEN, ALAIN J.; JEYACHANDRAN, VINOD; AGARWAL, ANKIT; BARATHAN, VENUPRAKASH
To: OPNET TECHNOLOGIES, INC.
Reel/Frame 018206/0472 →