IP Library Granted Patent US 8,584,195
Granted Patent B2
US 8,584,195 · App. 11/854,392 · Granted Nov 12, 2013

Identities correlation infrastructure for passive network monitoring

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,584,195
App. No.
11/854,392
Granted
Nov 12, 2013
Kind
B2
Abstract

User names and user groups serve as the basis of a formal policy in a network. A passive monitor examines network traffic in near real time and indicates: which network traffic is flowing on the network as before; which users or user groups were logged into workstations initiating this network traffic; and which of this traffic conforms to the formal policy definition. In one embodiment of the invention, users and user groups are determined by querying Microsoft® Active Directory and Microsoft® Windows servers, to determine who is logged onto the Microsoft® network. Other sources of identity information are also possible. The identity information is then correlated with the network traffic, so that even traffic that does not bear on the Microsoft® networking scheme is still tagged with identity

Claims (100)

1. An identity enabled policy monitoring system, comprising:

a network monitor device for receiving network traffic from a network under observation;

an Identity Acquisition Manager (IAM), executing on a hardware processor communicatively connected to said network monitor, enabling said network monitor to perform a correlation analysis of user identities and said network traffic to infer which users and user groups are responsible for generating said network traffic and enabling said network monitor to store an Internet Protocol (IP) address of the network traffic in a cache of IP addresses when the correlation analysis performed at the network monitor indicates that there is no identity associated with the IP address, the IAM further configured to determine current login information, the current login information determined from login events and synthesized logout information, the synthesized logout information derived using a combination of timeouts and remote probing information, wherein the IAM distributes the current login information to one or more remote network monitors, wherein the remote probing is performed over the network, and wherein probing techniques include both identity aware and non-identity aware techniques, the identity aware techniques accessing an identity infrastructure associated with a device being probed to determine which users are currently logged into the device being probed, and the non-identity aware techniques analyzing network traffic indicated to have no identity associated with the IP address;

an identity-enhanced policy having a priority ranking system for relationships based upon identities, said ranking based upon any of user identity, authenticated computer identity, group identity, and IP address; and

a mechanism for connecting actively into the identity infrastructure of the network under observation to get information regarding identities and for passing said information regarding identities back to the IAM;

wherein an identity-enhanced view of traffic is compared against a formal specification in said identity-enhanced policy; and

wherein a human-readable report is generated indicating which traffic met and did not meet said identity-enhanced policy.

2. The identity enabled policy monitoring system of claim 1 , wherein said mechanism for connecting actively comprises:

a distributed logon collector (DLC).

3. The identity enabled policy monitoring system of claim 1 , wherein an identity which served as a basis for authentication is carried forward during a session for purposes of policy enforcement.

4. A computer implemented distributed network monitoring method, the method comprising:

providing a mapping from an Internet Protocol (IP) address to an identity;

storing the IP address in a cache of IP addresses stored in a memory when the mapping indicates that there is no identity for the IP address;

providing a formal policy definition based, at least in part, upon any of user names, authenticated computer names, user groups, and computer groups;

examining network traffic, using a processor, in near real time with a passive network monitor to determine conformance with said formal policy definition; and

providing an identity acquisition manager (IAM) module for determining which users are currently logged into computers on the network from login events and synthesized logout information, the synthesized logout information derived using a combination of timeouts and remote probing information, wherein the IAM distributes current login information to one or more remote network monitors, wherein the remote probing is performed over a network, and wherein remote probing techniques include both identity aware and non-identity aware techniques, the identity aware techniques accessing an identity infrastructure associated with a device being probed to determine which users are currently logged into the device being probed, and the non-identity aware techniques analyzing network traffic indicated to have no identity associated with the IP address;

said passive network monitor indicating which network traffic is flowing on the network, and at least one of:

which users were logged into workstations initiating the network traffic, the identity of computers initiating said network traffic, to which groups said users and/or computers belong and where said users and/or computers have previously authenticated to a network authentication infrastructure;

which of said authenticated computers is receiving the network traffic; and

which of the network traffic conforms to the formal policy definition.

5. The method of claim 4 , wherein said network traffic comprises information about a flow of events within a small delay of the real time of those events, labeled with their actual time, such that the flow of events is equivalent to a real-time event flow.

6. The method of claim 4 , wherein the mapping from IP address to identities is determined by querying a network authentication system for logon events, and by referencing a network directory to map logon information to user, computer, and group information.

7. The method of claim 6 , wherein authenticated computer identities are also represented as special user accounts associated with authenticated computers on the network.

8. The method of claim 7 , further comprising:

performing multiple logon disambiguation when multiple user or computer logons are detected.

9. The method of claim 4 , further comprising:

providing at least one distributed logon collector (DLC) for performing queries into network identities sources under control of the IAM.

10. The method of claim 4 , further comprising:

providing an identity-enhanced policy development tool for allowing an operator to describe formal policies about network connections between machines when described by any of:

machine IP address;

authenticated computer identity;

authenticated computer group identity;

user identity;

user group identity; and

combinations of the above.

11. The method of claim 10 , further comprising:

providing an identity-enhanced policy engine for reading a policy from said identity enhanced policy development tool and for using said policy to annotate a near real time description of traffic with policy results.

12. The method of claim 4 , further comprising:

providing a report showing traffic from groups to select computers which represent critical business systems, said report comprising a matrix display with larger and smaller bubbles and including colors for policy.

13. The method of claim 4 , further comprising:

providing for multi-user computers where an IP address is associated with more than one concurrent directory user, and wherein multi-user computers are considered to have no individually identifiable users logged on and, thus, no user groups beyond those of which the computers themselves are members and an authenticated users built-in group; and

flagging multi-user computers, wherein a so-specified machine is always considered as a multi-user computer regardless of the number of users that are logged on concurrently, to ensure that policy applied to multi-user computers is applied consistently and deterministically regardless of the number of users logged on at that computer at any point in time.

14. The method of claim 4 , further comprising:

ranking identity policy objects with respect to each other, as well as with respect to addressable network objects, to determine a relative priority of policy relationships and a network object's effective policy.

15. The method of claim 14 , wherein said ranking of identity policy objects comprises in decreasing rank order:

a user object or a computer object;

a group object representing a user group, a computer group, or a custom group;

a built-in authenticated users group;

a built-in authenticated computers group;

a built-in anonymous group; and

ranking identity policy objects higher than any addressable network object;

wherein identity policy overrides host-based policy except for a prescriptive policy.

16. The method of claim 4 further comprising:

filtering the selection of available policy relationships using a current mapping from IP address to identity.

17. The method of claim 16 , further comprising:

selecting a policy relationship based upon any of: whether said mapping has a single user identity, whether said mapping has multiple user identities, whether said mapping has a single authenticated computer identity, or whether said mapping has no identities.

18. The method of claim 4 , further comprising:

arranging identity policy objects in a containment hierarchy to determine how policy defined for an object that is a policy relationship target is inherited by other objects that it contains.

19. The method of claim 4 , further comprising:

delaying evaluation of network traffic from a particular IP address until such time as user-identities associated with source and destination IP addresses can be ascertained.

20. The method of claim 4 , further comprising either of:

saving network event information offline in a file; or

capturing a sequence of packets from traffic data in the file; and

further comprising:

evaluating policy on data in said file offline; and

processing identities offline.

21. The method of claim 4 , further comprising:

computing effective policy relationships for any given network object by:

determining a relative ranking of a relationships' services; wherein said ranking is based on said services' transport layer specifications;

for relationships that have identically ranked services, determining a ranking of said relationships' targets; and

for relationships that have identically ranked targets, determine a ranking of the relationships' initiators;

wherein a relationship with a higher ranking overrides a relationship with a lower ranking.

22. The method of claim 4 , further comprising:

binding identity policy objects to zero, one, or more addressable network objects;

wherein an addressable network object or host comprises, directly or indirectly, an IP address space; and wherein if an identity policy object does not specify a host binding, the identity policy object is implicitly bound to an entire identity address space.

23. The method of claim 22 , further comprising:

determining a relative ranking of two bound and otherwise identical identity objects; wherein said ranking is determined by the relative ranking of the addressable network objects to which they are bound.

24. A method comprising:

monitoring, in an identity acquisition manager, login state information of users logged into a network under observation, the login state information determined from login events and synthesized logout information, the synthesized logout information derived using a combination of timeouts and remote probing information, wherein the remote probing is performed over the network, and wherein remote probing techniques include both identity aware and non-identity aware techniques, the identity aware techniques accessing an identity infrastructure associated with a device being probed to determine which users are currently logged into the device being probed, and the non-identity aware techniques analyzing network traffic indicated to have no identity associated with the IP address;

receiving, in a passive network monitor, the login state information;

generating a local copy of the received login state information at the passive network monitor;

mapping, in accordance with the local copy of the login state information, an Internet Protocol (IP) address of the network under observation to an identity, wherein mapping an IP address of the network under observation includes storing the IP address in a cache of IP addresses stored in a memory when the mapping indicates that there is no identity associated with the IP address; and

examining network traffic, using a processor, in near real time with a passive network monitor to determine conformance with said formal policy definition, wherein conformance is based on the IP address mapping, and wherein the formal policy definition is based upon one or more of user names, authenticated computer names, user groups, and computer groups.

25. The method according to claim 24 , further comprising requesting updated login state information from the identity acquisition manager.

26. The method according to claim 24 , wherein monitoring includes periodically transmitting updated login state information to the passive network monitor, and wherein generating includes updating the local copy of the login state information in accordance with the updated login state information.

27. A system comprising:

an identity-enhanced policy having a priority ranking system for relationships based upon identities, said ranking based upon one or more of user identity, authenticated computer identity, group identity, and IP address;

a network monitor device; and

an identity acquisition manager (IAM), executing on a hardware processor communicatively connected to said network monitor, to:

determine which users are logged into a network under observation;

determine a current login state of the users using login state information determined from login events and synthesized logout information, the synthesized logout information derived using a combination of timeouts and remote probing information, wherein the remote probing is performed over the network, and wherein remote probing techniques include both identity aware and non-identity aware techniques, the identity aware techniques accessing an identity infrastructure associated with a device being probed to determine which users are currently logged into the device being probed, and the non-identity aware techniques analyzing network traffic indicated to have no identity associated with the IP address;

store the current login state as logon data; and

periodically transmit the logon data to the network monitor;

wherein the network monitor:

stores a local copy of the logon data received from the IAM;

updates the local copy of the data when updates of the logon data are received from the IAM;

receives network traffic from the network under observation;

performs a correlation analysis of user identities in the logon data and the network traffic to infer which users and user groups are responsible for generating the network traffic;

stores an Internet Protocol (IP)address of the network traffic in a cache of IP addresses when the correlation analysis indicates that there is no identity associated with the IP address; and

applies the identity-enhanced policy.

Assignments (25)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060561/0466 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
CHANGE OF NAME Recorded Sep 16, 2010
From: SECURE COMPUTING CORPORATION
To: SECURE COMPUTING, LLC
Reel/Frame 024990/0672 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2010
From: SECURE COMPUTING, LLC
To: MCAFEE, INC.
Reel/Frame 024990/0606 →
MERGER Recorded Sep 16, 2010
From: SECURIFY, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 024990/0603 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2009
From: SHERLOCK, KIERAN GERARD; COOPER, GEOFFREY HOWARD; GUZIK, JOHN R.; PEARCY, DEREK PATTON; VALENTE, FILIPE PEREIRA
To: MCAFEE, INC.
Reel/Frame 023524/0968 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2007
From: SHERLOCK, KIERAN GERARD; COOPER, GEOFFREY HOWARD; GUZIK, JOHN RICHARD; PEARCY, DEREK PATTON; PEREIRA VALENTE, LUIS FILIPE
To: SECURIFY, INC.
Reel/Frame 019827/0004 →