IP Library Granted Patent US 8,479,257
Granted Patent B1
US 8,479,257 · App. 12/537,790 · Granted Jul 2, 2013

Method and apparatus for assessing policy compliance of as-built data networks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,479,257
App. No.
12/537,790
Granted
Jul 2, 2013
Kind
B1
Abstract

An as-built network is evaluated by analyzing a model of the network by the steps of determining zones within the network, computing the access between zones, summarizing the access between zones to produce a dataset, then inputting a policy set comprising a collection of approvals, typically in the form of simple white-lists of approvals, then comparing the dataset and particularly the access between zones with the policy set of approvals (white-lists) to determine which access fall outside the approvals, and producing therefrom as an output to an end user a report of compliance and noncompliance, and then repeating the steps of determining, computing, and summarizing, and then the comparing step, after a period or after the network has changed. Thus a network operator or auditor can readily and interactively assess whether the infrastructure is in compliance with regulatory or other design requirements.

Claims (41)

1. A computer-implemented method, comprising:

duplicating, on a computing device, a pre-existing network environment by segmenting a pre-existing network into a plurality of defined zones, wherein a zone is defined by data elements and data associated with the data elements, and wherein interrelationships between zones are determined between two or more defined zones;

querying the pre-existing network for all packet access, wherein packet access includes inter-zone packet access;

summarizing inter-zone packet access;

generating an access dataset using the summarized inter-zone packet access, wherein summarizing includes generating a summary including a list of one or more protocol and destination port combinations found directionally between zone accesses;

receiving a policy set including a collection of approvals indicating whether a broad or narrow set of access is permissible;

computing the status of the pre-existing network by comparing the access dataset with the policy set; and

generating a compliance report using the computed status, wherein the compliance report is automatically re-generated and the status is automatically re-computed when a change to the pre-existing network environment is detected.

2. The method of claim 1 , wherein duplicating the pre-existing network environment facilitates the execution of testing and analysis of the pre-existing network environment without disrupting the pre-existing network environment.

3. The method of claim 1 , wherein the pre-existing network environment is in compliance with the policy set when the access data set is approved.

4. The method of claim 1 , wherein the compliance report is a Payment Card Industry compliance report.

5. The method of claim 1 , wherein the policy set includes a collection of negative rules.

6. The method of claim 1 , wherein the policy set includes a collection of exclusive rules.

7. A computer-implemented system, comprising:

one or more processors;

one or more non-transitory computer-readable storage mediums containing instructions configured to cause the one or more processors to perform operations including:

duplicating a pre-existing network environment by segmenting a pre-existing network into a plurality of defined zones, wherein a zone is defined by data elements and data associated with the data elements, and wherein interrelationships between zones are determined between two or more defined zones;

querying the pre-existing network for all packet access, wherein packet access includes inter-zone packet access;

summarizing inter-zone packet access;

generating an access dataset using the summarized inter-zone packet access, wherein summarizing includes generating a summary including a list of one or more protocol and destination port combinations found directionally between zone accesses;

receiving a policy set including a collection of approvals indicating whether a broad or narrow set of access is permissible;

computing the status of the pre-existing network by comparing the access dataset with the policy set; and

generating a compliance report using the computed status, wherein the compliance report is automatically re-generated and the status is automatically re-computed when a change to the pre-existing network environment is detected.

8. The system of claim 7 , wherein duplicating the pre-existing network environment facilitates the execution of testing and analysis of the pre-existing network environment without disrupting the pre-existing network environment.

9. The system of claim 7 , wherein the pre-existing network environment is in compliance with the policy set when the access data set is approved.

10. The system of claim 7 , wherein the compliance report is a Payment Card Industry compliance report.

11. The system of claim 7 , wherein the policy set includes a collection of negative rules.

12. The system of claim 7 , wherein the policy set includes a collection of exclusive rules.

13. A computer-program product, tangibly embodied in a machine-readable non-transitory storage medium, including instructions configured to cause a data processing apparatus to:

duplicate a pre-existing network environment by segmenting a pre-existing network into a plurality of defined zones, wherein a zone is defined by data elements and data associated with the data elements, and wherein interrelationships between zones are determined between two or more defined zones;

query the pre-existing network for all packet access, wherein packet access includes inter-zone packet access;

summarize inter-zone packet access;

generate an access dataset using the summarized inter-zone packet access, wherein summarizing includes generating a summary including a list of one or more protocol and destination port combinations found directionally between zone accesses;

receive a policy set including a collection of approvals indicating whether a broad or narrow set of access is permissible;

compute the status of the pre-existing network by comparing the access dataset with the policy set; and

generate a compliance report using the computed status, wherein the compliance report is automatically re-generated and the status is automatically re-computed when a change to the pre-existing network environment is detected.

14. The computer-program product of claim 13 , wherein duplicating the pre-existing network environment facilitates the execution of testing and analysis of the pre-existing network environment without disrupting the pre-existing network environment.

15. The computer-program product of claim 13 , wherein the pre-existing network environment is in compliance with the policy set when the access data set is approved.

16. The computer-program product of claim 13 , wherein the compliance report is based upon external regulatory standards, guidelines, and procedures for the collection, transmittal, and storage of credit card information.

17. The computer-program product of claim 13 , wherein the policy set includes a collection of negative rules.

18. The computer-program product of claim 13 , wherein the policy set includes a collection of exclusive rules.

Assignments (9)
SECURITY INTEREST Recorded Apr 17, 2019
From: REDSEAL, INC.
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 048902/0969 →
SECURITY INTEREST Recorded May 4, 2018
From: REDSEAL, INC.
To: SILICON VALLEY BANK
Reel/Frame 045720/0306 →
SECURITY INTEREST Recorded Dec 18, 2017
From: REDSEAL, INC.
To: RUNWAY GROWTH CREDIT FUND INC.
Reel/Frame 044425/0799 →
CORRECTIVE ASSIGNMENT TO CORRECT THE INCORRECT PATENT NO. 8707444 PREVIOUSLY RECORDED AT REEL: 036100 FRAME: 0642. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jun 22, 2017
From: REDSEAL NETWORKS, INC.
To: REDSEAL, INC.
Reel/Frame 042961/0821 →
CHANGE OF NAME Recorded Jul 13, 2015
From: REDSEAL NETWORKS, INC.
To: REDSEAL, INC.
Reel/Frame 036100/0642 →
RELEASE OF SECURITY INTEREST Recorded Jun 24, 2015
From: SILICON VALLEY BANK
To: REDSEAL, INC., FORMERLY KNOWN AS REDSEAL NETWORKS, INC.
Reel/Frame 035900/0037 →
SECURITY INTEREST Recorded May 21, 2014
From: REDSEAL NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 032938/0774 →
CHANGE OF NAME Recorded Apr 3, 2012
From: REDSEAL SYSTEMS, INC.
To: REDSEAL NETWORKS, INC.
Reel/Frame 027983/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2009
From: LLOYD, MICHAEL A.; JACKSON, CARY D.; BRENNER, RALPH T.; DURHAM, JENNIFER GATES
To: REDSEAL SYSTEMS, INC.
Reel/Frame 023070/0081 →