IP Library Granted Patent US 10,659,324
Granted Patent B2
US 10,659,324 · App. 15/173,477 · Granted May 19, 2020

Application monitoring prioritization

Inventors: Jackson Ngoc Ki Pang (Sunnyvale, CA); Navindra Yadav (Cupertino, CA); Anubhav Gupta (Sunnyvale, CA); Shashidhar Gandham (Fremont, CA); Supreeth Hosur Nagesh Rao (Cupertino, CA); Sunil Kumar Gupta (Milpitas, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L43/045G06F3/0482G06F3/04842G06F3/04847G06F9/45558G06F16/122G06F16/137G06F16/162G06F16/17G06F16/173G06F16/174G06F16/1744G06F16/1748G06F16/235G06F16/2322G06F16/2365G06F16/248G06F16/24578G06F16/285G06F16/288G06F16/29G06F16/9535G06F21/53G06F21/552G06F21/566G06N20/00G06N99/00G06T11/206H04J3/0661H04J3/14H04L1/242H04L9/0866H04L9/3239H04L9/3242H04L41/046H04L41/0668H04L41/0803H04L41/0806H04L41/0816H04L41/0893H04L41/12H04L41/16H04L41/22H04L43/02H04L43/04H04L43/062H04L43/08H04L43/0805H04L43/0811H04L43/0829H04L43/0841H04L43/0858H04L43/0864H04L43/0876H04L43/0882H04L43/0888H04L43/10H04L43/106H04L43/12H04L43/16H04L45/306H04L45/38H04L45/46H04L45/507H04L45/66H04L45/74H04L47/11H04L47/20H04L47/2441H04L47/2483H04L47/28H04L47/31H04L47/32H04L61/2007H04L63/0227H04L63/0263H04L63/06H04L63/0876H04L63/145H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/1458H04L63/1466H04L63/16H04L63/20H04L67/10H04L67/1002H04L67/12H04L67/16H04L67/36H04L67/42H04L69/16H04L69/22H04W72/08H04W84/18G06F2009/4557G06F2009/45587G06F2009/45591G06F2009/45595G06F2221/033G06F2221/2101G06F2221/2105G06F2221/2111G06F2221/2115G06F2221/2145H04L67/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,659,324
App. No.
15/173,477
Granted
May 19, 2020
Kind
B2
Abstract

An approach for establishing a priority ranking for endpoints in a network. This can be useful when triaging endpoints after an endpoint becomes compromised. Ensuring that the most critical and vulnerable endpoints are triaged first can help maintain network stability and mitigate damage to endpoints in the network after an endpoint is compromised. The present technology involves determining a criticality ranking and a secondary value for a first endpoint in a datacenter. The criticality ranking and secondary value can be combined to form priority ranking for the first endpoint which can then be compared to a priority ranking for a second endpoint to determine if the first endpoint or the second endpoint should be triaged first.

Claims (85)

1. A computer-implemented method comprising:

determining a first criticality ranking for a first endpoint in a datacenter;

determining a second criticality ranking for a second endpoint; and

when the first criticality ranking and the second criticality ranking are determined to be a same criticality ranking, executing a tie-breaker process by:

determining a first secondary value for the first endpoint;

determining a second secondary value for the second endpoint;

determining, based on the first criticality ranking, the first secondary value, the second criticality ranking, and the second secondary value, that one of the first endpoint and the second endpoint is a higher priority endpoint; and

triaging the higher priority endpoint before the other of the first endpoint and the second endpoint to mitigate endpoint damage to the datacenter if the datacenter becomes compromised.

2. The computer-implemented method of claim 1 , further comprising:

determining a third endpoint is compromised, the first endpoint being the higher priority endpoint; and

determining a distance between the third endpoint and the first endpoint,

wherein,

the secondary value for the first endpoint is based on the distance.

3. The computer-implemented method of claim 1 , wherein the determining of the first secondary value for the first endpoint further comprises:

determining a third endpoint is compromised, the first endpoint being the higher priority endpoint;

determining a similarity between the first endpoint and the third endpoint; and

determining the similarity likely caused the third endpoint to become compromised.

4. The computer-implemented method of claim 1 , wherein determining the criticality ranking for the first endpoint comprises:

detecting, using a sensor installed on a computer hosting the first endpoint, a network flow associated with the first endpoint;

classifying the network flow to yield a classification; and

determining a criticality of the classification.

5. The computer-implemented method of claim 1 , wherein the determining of the second secondary value for the second endpoint is based on a redundancy of the first endpoint.

6. The computer-implemented method of claim 1 ,

wherein,

the first endpoint is the higher priority endpoint, and

the second endpoint is triaged after the first endpoint.

7. A non-transitory computer-readable medium having computer readable instructions that, when executed by a processor of a computer, cause the computer to:

determine a first criticality ranking for a first endpoint in a datacenter;

determine a second criticality ranking for a second endpoint; and

when the first criticality ranking and the second criticality ranking are determined to be a same criticality ranking, execute a tie-breaker process by:

determining a first secondary value for the first endpoint;

determining a second secondary value for the second endpoint;

determining, based on the first criticality ranking, the first secondary value, the first criticality ranking, and the second secondary value, that one of the first endpoint and the second endpoint is a higher priority endpoint; and

triaging the higher priority endpoint before the other of the first endpoint and the second endpoint to mitigate endpoint damage to the datacenter if the datacenter becomes compromised.

8. The non-transitory computer-readable medium of claim 7 , wherein the instructions further cause the computer to:

determine a third endpoint is compromised, the first endpoint being the higher priority endpoint; and

determine a distance between the third endpoint and the first endpoint,

wherein,

the secondary value for the first endpoint is based on the distance.

9. The non-transitory computer-readable medium of claim 7 , wherein the instructions that cause the computer to determine the first secondary value for the first endpoint further cause the computer to:

determine a third endpoint is compromised, the first endpoint being the higher priority endpoint;

determine a similarity between the first endpoint and the third endpoint; and

determine the similarity likely caused the third endpoint to become compromised.

10. The non-transitory computer-readable medium of claim 7 , wherein the instructions that cause the computer to determine the criticality ranking for the first endpoint further cause the computer to:

detect, using a sensor, a network flow associated with the first endpoint;

classify the network flow to yield a classification; and

determine a criticality of the classification.

11. The non-transitory computer-readable medium of claim 7 , wherein the second secondary value for the second endpoint is determined based on a redundancy of the first endpoint.

12. The non-transitory computer-readable medium of claim 7 ,

wherein,

the first endpoint is the higher priority endpoint, and

the second endpoint is triaged after the first endpoint.

13. A system comprising:

a processor;

memory including instructions that when executed by the processor, cause the system to:

determine a first criticality ranking for a first endpoint in a datacenter;

determine a second criticality ranking for a second endpoint; and

when the first criticality ranking and the second criticality ranking are determined to be a same criticality ranking, execute a tie-breaker process by:

determining a first secondary value for the first endpoint;

determining a second secondary value for the second endpoint;

determining, based on the first criticality ranking, the first secondary value, the second criticality ranking, and the second secondary value, that one of the first endpoint and the second endpoint is a higher priority endpoint; and

triaging the higher priority endpoint before the other of the first endpoint and the second endpoint to mitigate endpoint damage to the datacenter if the datacenter becomes compromised.

14. The system of claim 13 , wherein the instructions further cause the system to:

determine a third endpoint is compromised, the first endpoint being the higher priority endpoint; and

determine a distance between the third endpoint and the first endpoint,

wherein,

the secondary value for the first endpoint is based on the distance.

15. The system of claim 13 , wherein the instructions that cause the system to determine the first secondary value for the first endpoint further cause the system to:

determine a third endpoint is compromised, the first endpoint being the higher priority endpoint;

determine a similarity between the first endpoint and the third endpoint; and

determine the similarity likely caused the third endpoint to become compromised.

16. The system of claim 13 , wherein the instructions that cause the system to determine the criticality ranking for the first endpoint further cause the system to:

detect, using a sensor installed on a computer hosting the first endpoint, a network flow associated with the first endpoint;

classify the network flow to yield a classification; and

determine a criticality of the classification.

17. The system of claim 13 , wherein the second secondary value for the second endpoint is determined based on a redundancy of the first endpoint.

18. The computer-implemented method of claim 1 ,

wherein,

the first endpoint is determined to be the higher priority endpoint when the first criticality ranking equals the second criticality ranking and a first value associated with the first secondary value has a higher ranking than a second value associated with the second secondary value.

19. The non-transitory computer-readable medium of claim 7 ,

wherein,

the first endpoint is determined to be the higher priority endpoint when the first criticality ranking equals the second criticality ranking and a first value associated with the first secondary value has a higher ranking than a second value associated with the second secondary value.

20. The system of claim 13 ,

wherein,

the first endpoint is determined to be the higher priority endpoint when the first criticality ranking equals the second criticality ranking and a first value associated with the first secondary value has a higher ranking than a second value associated with the second secondary value.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2016
From: PANG, JACKSON NGOC KI; YADAV, NAVINDRA; GUPTA, ANUBHAV; GANDHAM, SHASHIDHAR; RAO, SUPREETH HOSUR NAGESH; GUPTA, SUNIL KUMAR
To: CISCO TECHNOLOGY, INC.
Reel/Frame 039591/0230 →
Continuity (2)
Provisional Application 62171899 · Jun 5, 2015
Related Publication 20160359891A1 · Dec 8, 2016