IP Library Granted Patent US 10,009,240
Granted Patent B2
US 10,009,240 · App. 15/172,274 · Granted Jun 26, 2018

System and method of recommending policies that result in particular reputation scores for hosts

Inventors: Supreeth Hosur Nagesh Rao (Cupertino, CA); Ashutosh Kulshreshtha (Fremont, CA); Omid Madani (San Jose, CA); Jackson Ngoc Ki Pang (Sunnyvale, CA); Navindra Yadav (Cupertino, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L43/045G06F3/0482G06F3/04842G06F3/04847G06F9/45558G06F17/3053G06F17/30241G06F17/30554G06F17/30598G06F17/30604G06F17/30867G06F21/53G06N99/005G06T11/206H04J3/0661H04J3/14H04L1/242H04L9/0866H04L9/3239H04L9/3242H04L41/046H04L41/0668H04L41/0803H04L41/0806H04L41/0816H04L41/0893H04L41/12H04L41/16H04L41/22H04L43/02H04L43/04H04L43/062H04L43/08H04L43/0805H04L43/0811H04L43/0829H04L43/0841H04L43/0858H04L43/0864H04L43/0876H04L43/0882H04L43/0888H04L43/10H04L43/106H04L43/12H04L43/16H04L45/306H04L45/38H04L45/46H04L45/507H04L45/66H04L45/74H04L47/11H04L47/20H04L47/2441H04L47/2483H04L47/28H04L47/31H04L47/32H04L61/2007H04L63/0227H04L63/0263H04L63/06H04L63/0876H04L63/145H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/1458H04L63/1466H04L63/16H04L63/20H04L67/10H04L67/1002H04L67/12H04L67/16H04L67/36H04L67/42H04L69/16H04L69/22H04W72/08H04W84/18G06F2009/4557G06F2009/45587G06F2009/45591G06F2009/45595H04L67/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,009,240
App. No.
15/172,274
Filed
Jun 3, 2016
Granted
Jun 26, 2018
Kind
B2
Art Unit
2436
USPC
726/1
Abstract

A method provides for associating reputation scores with policies, stacks and hosts within a network and upon receiving information about a newly provisioned entity (such as a host or a stack), recommending a policy scheme for the newly provisioned entity that will result in a particular reputation score of the reputation scores. The method further includes implementing the policy scheme for the newly provisioned entity.

Claims (36)

1. A method comprising:

associating reputation scores with policies, stacks and hosts within a network, wherein the reputation scores are based at least in part on data received from a first capturing agent at a physical layer in a network, a second capturing agent at a hypervisor layer in the network, and a third capturing agent at a virtual layer of the network;

upon receiving information about a newly provisioned entity, recommending a policy scheme for the newly provisioned entity that will result in a particular reputation score of the reputation scores; and

implementing the policy scheme for the newly provisioned entity.

2. The method of claim 1 , further comprising, when the particular reputation score of the newly provisioned entity falls below a threshold amount, isolating the newly provisioned entity from the network.

3. The method of claim 1 , further comprising:

after isolating the newly provisioned entity from the network, analyzing traffic from other hosts similar to the newly provisioned entity with increased scrutiny.

4. The method of claim 1 , wherein isolating the newly provisioned entity from the network further comprises removing the newly provisioned entity from the network.

5. The method of claim 1 , wherein multiple policies result in the particular reputation score.

6. The method of claim 5 , wherein, when the multiple policies result in the particular reputation score, the policy scheme that is recommended comprises a least restrictive policy of the multiply policies.

7. The method of claim 1 , wherein the newly provisioned entity comprises one of a host and a stack.

8. A system comprising:

a processor; and

a computer-readable storage medium storing instructions which, when executed by the processor, cause the processor to perform operations comprising:

associating reputation scores with policies, stacks and hosts within a network, wherein the reputation scores are based at least in part on data received from a first capturing agent at a physical layer in a network, a second capturing agent at a hypervisor layer in the network, and a third capturing device at a virtual layer of the network;

upon receiving information about a newly provisioned entity, recommending a policy scheme for the newly provisioned entity that will result in a particular reputation score of the reputation scores; and

implementing the policy scheme for the newly provisioned entity.

9. The system of claim 8 , wherein the computer-readable storage medium stores further instructions which, when executed by the processor, cause the processor to perform operations comprising further comprising:

when the particular reputation score of the newly provisioned entity falls below a threshold amount, isolating the newly provisioned entity from the network.

10. The system of claim 8 , wherein the computer-readable storage medium stores further instructions which, when executed by the processor, cause the processor to perform operations comprising further comprising:

after isolating the newly provisioned entity from the network, analyzing traffic from other hosts similar to the newly provisioned entity with increased scrutiny.

11. The system of claim 8 , wherein isolating the newly provisioned entity from the network further comprises removing the newly provisioned entity from the network.

12. The system of claim 8 , wherein multiple policies result in the particular reputation score.

13. The system of claim 12 , wherein, when the multiple policies result in the particular reputation score, the policy scheme that is recommended comprises a least restrictive policy of the multiply policies.

14. The system of claim 8 , wherein the newly provisioned entity comprises one of a host and a stack.

15. A computer-readable storage device storing instructions which, when executed by a processor, cause the processor to perform operations comprising:

associating reputation scores with policies, stacks and hosts within a network, wherein the reputation scores are based at least in part on data received from a first capturing agent at a physical layer in a network, a second capturing agent at a hypervisor layer in the network, and a third capturing device at a virtual layer of the network;

upon receiving information about a newly provisioned entity, recommending a policy scheme for the newly provisioned entity that will result in a particular reputation score of the reputation scores; and

implementing the policy scheme for the newly provisioned entity.

16. The computer-readable storage device of claim 15 , wherein the computer-readable storage device stores further instructions which, when executed by the processor, cause the processor to perform operations comprising further comprising:

when the particular reputation score of the newly provisioned entity falls below a threshold amount, isolating the newly provisioned entity from the network.

17. The computer-readable storage device of claim 15 , wherein the computer-readable storage device stores further instructions which, when executed by the processor, cause the processor to perform operations comprising further comprising:

after isolating the newly provisioned entity from the network, analyzing traffic from other hosts similar to the newly provisioned entity with increased scrutiny.

18. The computer-readable storage device of claim 15 , wherein isolating the newly provisioned entity from the network further comprises removing the newly provisioned entity from the network.

19. The computer-readable storage device of claim 15 , wherein multiple policies result in the particular reputation score.

20. The computer-readable storage device of claim 19 , wherein, when the multiple policies result in the particular reputation score, the policy scheme that is recommended comprises a least restrictive policy of the multiply policies.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2016
From: RAO, SUPREETH HOSUR NAGESH; KULSHRESHTHA, ASHUTOSH; MADANI, OMID; PANG, JACKSON NGOC KI; YADAV, NAVINDRA
To: CISCO TECHNOLOGY, INC.
Reel/Frame 039825/0353 →
Continuity (2)
Provisional Application 62171899 · Jun 5, 2015
Related Publication 20160359917A1 · Dec 8, 2016
Cited By (11)
US 12,192,078 US 12,212,476 US 12,224,921 US 12,231,307 US 12,231,308 US 12,278,746 US 12,335,275 US 12,368,629 US 12,596,568 US 12,657,049 US 12,670,003