IP Library Granted Patent US 8,955,032
Granted Patent B2
US 8,955,032 · App. 11/776,721 · Granted Feb 10, 2015

Assessing network and device compliance with security policies

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,955,032
App. No.
11/776,721
Granted
Feb 10, 2015
Kind
B2
Abstract

All of the transit services that each device is expected to provide are determined and contrasted with the transit configuration of each device. Because the transit configuration of each device may be state-dependent, the service items within each application service are processed in sequential order. Sequences of service items are associated with connection groups, and each of the routes associated with each connection group is determined based on the sequential order of the service items. The configuration of each device along each route is processed to determine the services that will be permitted or denied, based on its current configuration. Each desired transit service item is compared to the transit configuration provided by each device to identify any inconsistencies and/or violations.

Claims (55)

1. A method comprising:

receiving, at a processing machine, a plurality of transit policies, each policy indicating whether a given service is to be allowed for two or more device groups of a network, a device group including one or more devices of the network,

determining, by the processing machine, a plurality of routes among the device groups in the network,

identifying, by the processing machine, interface check objects at each interface along each of the routes,

comparing, by the processing machine, configuration settings at each interface check object to a corresponding transit policy of the plurality of transit policies, and

identifying, by the processing machine, violations of the transit policies.

2. The method of claim 1 , wherein determining the plurality of routes includes: identifying each unique pair of source and destination nodes used within the services indicated by the plurality of transit policies, and determining each route between each unique pair of source and destination nodes.

3. The method of claim 2 , wherein each service includes one or more service items, each service item identifying a source node and a destination node associated with the service item.

4. The method of claim 2 , including processing the transit policy at each interface check object to identify one or more sets of address ranges having a common transit policy, and wherein comparing the configuration settings includes comparing the configuration settings for each of the sets of address ranges.

5. The method of claim 2 , including determining one or more transit configurations at each interface check object, each transit configuration indicating a configuration address range and a transit state that indicates whether traffic within the configuration address range is permitted or denied, and processing the one or more transit configurations to determine a resultant configuration setting for each configuration address range.

6. The method of claim 5 , including processing the transit policy at each interface check object to identify one or more sets of policy address ranges having a common transit policy, and wherein comparing the configuration settings includes comparing the configuration settings for each configuration address range with the transit policy of the one or more sets of policy address ranges.

7. The method of claim 6 , wherein comparing the configuration settings includes comparing permitted transit policies with denied configuration settings and comparing denied transit policies with permitted configuration settings to identify the violations of the transit policies.

8. The method of claim 4 , wherein determining the one or more transit configurations includes allowing a user to specify one or more transit configurations for one or more of the interface check objects.

9. The method of claim 1 , wherein each service includes one or more service items, each service item identifying a source node and a destination node associated with the service item.

10. The method of claim 1 , including processing the transit policy at each interface check object to identify one or more sets of address ranges having a common transit policy, and wherein comparing the configuration settings includes comparing the configuration settings for each of the sets of address ranges.

11. The method of claim 10 , including determining one or more transit configurations at each interface check object, each transit configuration indicating a configuration address range and a transit state that indicates whether traffic within the configuration address range is permitted or denied, and processing the one or more transit configurations to determine a resultant configuration setting for each configuration address range.

12. The method of claim 11 , including processing the transit policy at each interface check object to identify one or more sets of policy address ranges having a common transit policy, and wherein comparing the configuration settings includes comparing the configuration settings for each configuration address range with the transit policy of the one or more sets of policy address ranges.

13. The method of claim 12 , wherein comparing the configuration settings includes comparing permitted transit policies with denied configuration settings and comparing denied transit policies with permitted configuration settings to identify the violations of the transit policies.

14. The method of claim 1 , including providing a display of violations of the transit policies.

15. The method of claim 14 , including providing an identification of one or more devices corresponding to one or more of the violations.

16. A computer program on a non-transitory computer-readable media that, when executed, configures a processor to:

receive a plurality of transit policies, each policy indicating whether a given service is to be allowed for two or more device groups of a network, a device group including one or more devices of the network,

determine a plurality of routes among the device groups in the network,

identify interface check objects at each interface along each of the routes,

compare configuration settings at each interface check object to a corresponding transit policy of the plurality of transit policies, and

identify violations of the transit policies.

17. The program of claim 16 , wherein the processor is configured to determine the plurality of routes by:

identifying each unique pair of source and destination nodes used within the services indicated by the plurality of transit policies, and

determining each route between each unique pair of source and destination nodes.

18. The program of claim 17 , wherein each service includes one or more service items, each service item identifying a source node and a destination node associated with the service item.

19. The program of claim 17 , wherein the processor is configured to: process the transit policy at each interface check object to identify one or more sets of address ranges having a common transit policy, and compare the configuration settings by comparing the configuration settings for each of the sets of address ranges.

20. The program of claim 17 , wherein the processor is configured to: determine one or more transit configurations at each interface check object, each transit configuration indicating a configuration address range and a transit state that indicates whether traffic within the configuration address range is permitted or denied, and process the one or more transit configurations to determine a resultant configuration setting for each configuration address range.

21. The program of claim 20 , wherein the processor is configured to: process the transit policy at each interface check object to identify one or more sets of policy address ranges having a common transit policy, and compare the configuration settings by comparing the configuration settings for each configuration address range with the transit policy of the one or more sets of policy address ranges.

22. The program of claim 21 , wherein the processor is configured to compare the configuration settings by comparing permitted transit policies with denied configuration settings and comparing denied transit policies with permitted configuration settings to identify the violations of the transit policies.

23. The program of claim 19 , wherein the processor is configured to determine the one or more transit configurations by allowing a user to specify one or more transit configurations for one or more of the interface check objects.

24. The program of claim 16 , wherein each service includes one or more service items, each service item identifying a source node and a destination node associated with the service item.

25. The program of claim 16 , wherein the processor is configured to: process the transit policy at each interface check object to identify one or more sets of address ranges having a common transit policy, and compare the configuration settings by comparing the configuration settings for each of the sets of address ranges.

26. The program of claim 16 , wherein the processor is configured to: determine one or more transit configurations at each interface check object, each transit configuration indicating a configuration address range and a transit state that indicates whether traffic within the configuration address range is permitted or denied, and process the one or more transit configurations to determine a resultant configuration setting for each configuration address range.

27. The program of claim 26 , wherein the processor is configured to: process the transit policy at each interface check object to identify one or more sets of policy address ranges having a common transit policy, and compare the configuration settings by comparing the configuration settings for each configuration address range with the transit policy of the one or more sets of policy address ranges.

28. The program of claim 27 , wherein the processor is configured to compare the configuration settings includes comparing permitted transit policies with denied configuration settings and compare denied transit policies with permitted configuration settings to identify the violations of the transit policies.

29. The program of claim 16 , wherein the processor is configured to provide a display of violations of the transit policies.

30. The program of claim 29 , wherein the processor is configured to provide an identification of one or more devices corresponding to one or more of the violations.

31. A system comprising:

a display device,

a processor, and

a memory that is configured to store a network analysis program that configures the processor to:

receive a plurality of transit policies, each policy indicating whether a given service is to be allowed for two or more device groups of a network, a device group including one or more devices of the network,

determine a plurality of routes among the device groups in the network,

identify interface check objects at each interface along each of the routes,

compare configuration settings at each interface check object to a corresponding transit policy of the plurality of transit policies, and

display violations of the transit policies on the display device.

32. The system of claim 31 , wherein the processor is configured to: determine one or more transit configurations at each interface check object, each transit configuration indicating a configuration address range and a transit state that indicates whether traffic within the configuration address range is permitted or denied, and process the one or more transit configurations to determine a resultant configuration setting for each configuration address range.

33. The system of claim 32 , wherein the processor is configured to: process the transit policy at each interface check object to identify one or more sets of policy address ranges having a common transit policy, and compare the configuration settings by comparing the configuration settings for each configuration address range with the transit policy of the one or more sets of policy address ranges.

34. The system of claim 33 , wherein the processor is configured to compare the configuration settings includes comparing permitted transit policies with denied configuration settings and compare denied transit policies with permitted configuration settings to identify the violations of the transit policies.

35. The program of claim 34 , wherein the processor is configured to display an identification of one or more devices corresponding to one or more of the violations.

Assignments (18)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →