IP Library Granted Patent US 10,237,351
Granted Patent B2
US 10,237,351 · App. 14/949,292 · Granted Mar 19, 2019

Sub-networks based security method, apparatus and product

Inventors: Shmulik Bachar (Herzliya, IL); Yossi Atias (Kfar-Saba, IL)
Assignee: DOJO-LABS LTD
H04L67/12H04L63/102H04L67/10H04L67/22H04L67/303H04L61/2015
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,237,351
App. No.
14/949,292
Granted
Mar 19, 2019
Kind
B2
Abstract

A method, apparatus and product for sub-networks based cyber security. One method comprises detecting a device connecting to a local network which is divided into subnets; determining a usage profile of the device; automatically selecting a subnet to connect the device based on the usage profile; and connecting the device to the selected subnet in the local network. Another method comprises monitoring communication traffic of devices in each of the subnets of a local network; performing anomaly detection to detect an abnormal communication of a device connected to a subnet; blocking the abnormal communication of the device; and removing the device from the subnet and connecting the device to a quarantine subnet of the local network, whereby reducing connectivity of the device with other devices connected to the local network.

Claims (20)

1. A device having a hardware processor coupled to memory, wherein the device is connectable to a local network that is connected to an external network, wherein at least a particular user device and a particular Internet of Things (IoT) device are connected to the local network on a same subnet, wherein the device being configured to perform:

detecting being connected to a networking device of the local network, wherein the networking device is a Dynamic Host Configuration Protocol (DHCP) server of the local network;

in response to being connected to the networking device,

becoming the DHCP server of the local network instead of the networking device, wherein said becoming the DHCP server of the local network instead of the networking device comprises the device shutting down a DHCP functionality of the networking device;

creating at least three subnets for the local network, wherein the at least three subnets comprise: a guest subnet, a user device subnet and an IoT subnet, wherein the user device subnet excludes IoT devices, wherein the IoT subnet excludes user devices;

adding each device connected to the local network to one of the at least three subnets, wherein guest devices are connected to the guest subnet; wherein non-guest user devices are connected to the user device subnet and IoT devices are connected to the IoT subnet, whereby dividing the local network into three or more sub-networks, whereby separating the particular user device and the particular IoT device to be on different subnets in the local network; and

monitoring communication traffic in the local network, wherein said monitoring comprises applying a first set of security rules on the guest subnet, applying a second set of security rules on the user device subnet, and applying a third set of security rules on the IoT subnet, wherein at least part of at least one of the first, second and third sets of security rules are related to inter-subnet communication.

2. The device of claim 1 , wherein the communication traffic in the local network is selected from the group consisting of:

communication between two devices that are connected to the local network; and

communication between a local device and an external device, wherein the local device is connected to the local network, wherein the external device is not connected to the local network and is connected, directly or indirectly, to the external network, wherein the communication between the local device and the external device is routed via the external network.

3. A device having a hardware processor coupled to memory, wherein the device is connectable to a local network that is connected to an external network, wherein at least a particular user device and a particular Internet of Things (IoT) device are connected to the local network on a same subnet, wherein the device being configured to perform:

detecting being connected to a networking device of the local network, wherein the networking device is a Dynamic Host Configuration Protocol (DHCP) server of the local network;

in response to being connected to the networking device,

becoming the DHCP server of the local network instead of the networking device, wherein the networking device is a router, wherein said becoming the DHCP server of the local network instead of the networking device comprises automatically shutting down a DHCP functionality of the router, whereby the router subsequently functions as a network bridge between the local network and the external network;

creating at least three subnets for the local network, wherein the at least three subnets comprise: a guest subnet, a user device subnet and an IoT subnet, wherein the user device subnet excludes IoT devices, wherein the IoT subnet excludes user devices;

adding each device connected to the local network to one of the at least three subnets, wherein guest devices are connected to the guest subnet; wherein non-guest user devices are connected to the user device subnet and IoT devices are connected to the IoT subnet, whereby dividing the local network into three or more sub-networks, whereby separating the particular user device and the particular IoT device to be on different subnets in the local network; and

monitoring communication traffic in the local network, wherein said monitoring comprises applying a first set of security rules on the guest subnet, applying a second set of security rules on the user device subnet, and applying a third set of security rules on the IoT subnet, wherein at least part of at least one of the first, second and third sets of security rules are related to inter-subnet communication.

4. The device of claim 3 , wherein the communication traffic in the local network is selected from the group consisting of:

communication between two devices that are connected to the local network; and

communication between a local device and an external device, wherein the local device is connected to the local network, wherein the external device is not connected to the local network and is connected, directly or indirectly, to the external network, wherein the communication between the local device and the external device is routed via the external network.

Assignments (5)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 17, 2020
From: FORESCOUT TECHNOLOGIES, INC.
To: OWL ROCK CAPITAL CORPORATION, AS ADMINISTRATIVE AGENT
Reel/Frame 053519/0982 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2020
From: BULLGUARD ISRAEL LTD.
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 051586/0962 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2019
From: BULLGUARD LIMITED
To: BULLGUARD ISRAEL LIMITED
Reel/Frame 050429/0711 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2019
From: DOJO LABS LIMITED
To: BULLGUARD LIMITED
Reel/Frame 050431/0957 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 23, 2015
From: BACHAR, SHMULIK; ATIAS, YOSSI
To: DOJO-LABS LTD
Reel/Frame 037121/0475 →
Continuity (1)
Related Publication 20170149775A1 · May 25, 2017