IP Library Granted Patent US 10,356,121
Granted Patent B2
US 10,356,121 · App. 15/677,954 · Granted Jul 16, 2019

Systems and methods for dynamic network security control and configuration

Inventors: Malcolm Rieke (Santa Cruz, CA); James Sebastian Dennis (Scotts Valley, CA); Michael Berman (Scotts Valley, CA)
Assignee: CATBIRD NETWORKS, INC.
H04L63/1433G06F9/45558G06F16/951H04L63/02H04L63/0227H04L63/0236H04L63/0263H04L63/20G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,356,121
App. No.
15/677,954
Filed
Aug 15, 2017
Granted
Jul 16, 2019
Kind
B2
Art Unit
2434
USPC
726/25
Abstract

A computer-implemented method according to one embodiment of the present disclosure includes identifying, by a computer system, an asset associated with a group; detecting a change in an attribute of the asset; and in response to detecting the change in the attribute of the asset, modifying, by the computer system, a configuration setting for a firewall. Among other things, the embodiments of the present disclosure can perform dynamically configure and control security features in response to changes in the computing environment, including asset attribute changes, security events, operational events, user input and environmental changes. Embodiments of the present disclosure thereby help to quickly maintain or change the security posture of a system and maintain the level of compliance with set of predefined security benchmarks or codified best practices.

Claims (31)

1. A method, comprising:

identifying virtual machines in a virtualized infrastructure, the virtual machines organized into groups, wherein each of the virtual machines is associated with a policy;

monitoring the virtual machines; and

in response to the monitoring, applying a first policy to a first virtual machine in a first group of the virtual machines, wherein applying the first policy comprises modifying a firewall configuration by changing an access control rule associated with the first virtual machine.

2. The method of claim 1 , wherein the first policy is associated with the first group.

3. The method of claim 1 , further comprising applying a second policy to the first virtual machine, wherein the second policy is associated with a second group of the virtual machines.

4. The method of claim 1 , further comprising:

associating compliance policies with the virtual machines;

validating a compliance control for the first virtual machine; and

in response to the validating, adjusting a compliance level for the first virtual machine.

5. The method of claim 4 , further comprising displaying the compliance level.

6. The method of claim 1 , wherein applying the first policy further comprises issuing directives and collecting events to and from a firewall management element.

7. The method of claim 1 , wherein applying the first policy comprises modifying a configuration of the first virtual machine.

8. The method of claim 1 , wherein the monitoring detects a security vulnerability of the first virtual machine, and the applying the first policy to the first virtual machine comprises changes the access control rule for the first virtual machine.

9. The method of claim 1 , wherein the monitoring is performed by a computing device, and the first policy is a policy associated with a control configured by the computing device for at least one of the virtual machines.

10. The method of claim 1 , wherein the applying the first policy comprises terminating network access by the first virtual machine to any other of the virtual machines.

11. The method of claim 1 , wherein the monitoring detects a change in an IP address of the first virtual machine.

12. The method of claim 1 , wherein the monitoring comprises receiving a unique identifier from each of the virtual machines.

13. The method of claim 1 , wherein the first policy comprises a plurality of access control rules, the first group is associated with other policies in addition to the first policy, and wherein the other policies are applied to each of the virtual machines in the first group.

14. The method of claim 1 , wherein the monitoring comprises collecting events originated from the first virtual machine.

15. A method, comprising:

associating a policy with a first group;

monitoring a plurality of virtual machines in a virtualized infrastructure, wherein the plurality of virtual machines includes a first virtual machine that is a member of the first group;

detecting, based on the monitoring, a modification associated with the first virtual machine;

in response to detecting the modification, changing the policy associated with the first group; and

applying the changed policy to the first virtual machine, wherein the modification comprises a change in an access control rule for the first virtual machine.

16. A method, comprising:

storing data regarding a plurality of groups, each group associated with a subset of a plurality of virtual machines, the data further regarding a first virtual machine associated with a first group of the virtual machines, and the data comprising attribute data for the first virtual machine;

monitoring the plurality of virtual machines; and

in response to the monitoring, changing a first policy for the first virtual machine that modifies the association of the virtual machine with the first group, including a change in an access control rule for the first virtual machine.

17. The method of claim 16 , further comprising updating an attribute of the first virtual machine so that a policy associated with a second group of the virtual machines is automatically applied to the first virtual machine.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0970 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: SIS HOLDINGS, L.P.
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068312/0011 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: APPGATE FUNDING, LLC
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0570 →
SECURITY INTEREST Recorded Aug 22, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: APPGATE FUNDING, LLC
Reel/Frame 064672/0383 →
SECURITY INTEREST Recorded Jul 6, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: SIS HOLDINGS, L.P.
Reel/Frame 064461/0539 →
SECURITY INTEREST Recorded Jun 10, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 063956/0470 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2017
From: RIEKE, MALCOLM; DENNIS, JAMES; BERMAN, MICHAEL
To: CATBIRD NETWORKS, INC.
Reel/Frame 043758/0627 →
Continuity (5)
Continuation 15336691 · Oct 27, 2016
Continuation 14727623 · Jun 1, 2015
Continuation 13918633 · Jun 14, 2013
Provisional Application 61830003 · May 31, 2013
Related Publication 20180020019A1 · Jan 18, 2018