IP Library Granted Patent US 8,639,800
Granted Patent B2
US 8,639,800 · App. 12/526,957 · Granted Jan 28, 2014

Method and device for determining network device status

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,639,800
App. No.
12/526,957
Granted
Jan 28, 2014
Kind
B2
Abstract

Disclosed is a method of transparently detecting authentication status of endpoint devices in a network. This method may be used for differentiating guest or rogue endpoints from enterprise endpoints.

Claims (14)

1. A method for determining network security status of a specific computational device connected to a data network, said method comprising:

monitoring, by a network monitoring device communicatively coupled to the data network, authentication attempt related data traffic between the specific computational device and an authentication server communicatively coupled to the data network;

wherein monitoring consists of sniffing data traffic to which the monitoring device is not a party;

updating, by the network monitoring device, at least one record associated with the specific computational device within a device status data table, based on the monitored authentication attempt related data traffic; and

factoring the at least one record associated with the specific computational device within the device status data table when determining access to network computational resources for the specific computational device.

2. The method according to claim 1 , wherein the record is updated, by the network monitoring device, to indicate that the specific computational device is a guest or a rogue device when authentication response related data traffic from the authentication server indicates a login failure.

3. The method according to claim 1 , wherein the record is updated, by the network monitoring device, to indicate that the specific computational device is a non-guest device when authentication response related data traffic from the authentication server indicates a successful login.

4. A network monitoring device for determining network security status of a specific computational device connected to a data network, said monitoring device comprising:

a network monitoring module including hardware, the network monitoring module being communicatively coupled to the data network and configured to:

(1) monitor authentication attempt related data traffic between the specific computational device and an authentication server communicatively coupled to the data network; wherein monitoring consists of sniffing data traffic to which the monitoring device is not a party; and

(2) update at least one record associated with the specific computational device within a device status data table, based on the monitored authentication attempt related data traffic;

wherein, the at least one record associated with the specific computational device within the device status data table is considered when determining access to network resources for the specific computational device.

5. The device according to claim 4 , wherein the record is updated to indicate that the specific computational device is a guest or a rogue device when authentication response related data traffic from the authentication server indicates a login failure.

6. The device according to claim 4 , wherein the record is updated to indicate that the specific computational device is a non-guest device when authentication response related data traffic from the authentication server indicates a successful login.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Aug 17, 2020
From: SILICON VALLEY BANK; GOLD HILL CAPITAL 2008, LP
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 053513/0791 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 17, 2020
From: FORESCOUT TECHNOLOGIES, INC.
To: OWL ROCK CAPITAL CORPORATION, AS ADMINISTRATIVE AGENT
Reel/Frame 053519/0982 →
SECURITY INTEREST Recorded Oct 25, 2012
From: FORESCOUT TECHNOLOGIES, INC.
To: GOLD HILL CAPITAL 2008, LP; SILICON VALLEY BANK
Reel/Frame 029210/0075 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 5, 2009
From: FRIEDRICH, GIL; ROTEM, ROY
To: FORESCOUT TECHNOLOGIES
Reel/Frame 023472/0938 →