IP Library Granted Patent US 10,440,119
Granted Patent B2
US 10,440,119 · App. 15/693,674 · Granted Oct 8, 2019

Sub-networks based security method, apparatus and product

Inventors: Shmulik Bachar (Herzliya, IL); Yossi Atias (Kfar-Saba, IL)
Assignee: DOJO-LABS LTD.
H04L67/12H04L63/102H04L67/10H04L67/22H04L67/303H04L61/2015
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,440,119
App. No.
15/693,674
Granted
Oct 8, 2019
Kind
B2
Abstract

A method, apparatus and product for sub-networks based cyber security. One method for managing a local network, which is divided into subnets, comprises: monitoring communication traffic of devices in each of the subnets; performing anomaly detection to detect an abnormal communication of a device connected to a subnet; blocking the abnormal communication of the device; and removing the device from the subnet and connecting the device to a quarantine subnet of the local network, whereby reducing connectivity of the device with other devices connected to the local network.

Claims (49)

1. A method performed by a processor for managing a local network, wherein the method comprises:

dividing the local network into a plurality of subnets in accordance with an expected traffic pattern for devices connected to each subnet of the plurality of subnets, wherein the expected traffic pattern is indicative at least of one of content and target of packets, the plurality of subnets comprising at least one Internet of Things (loT) subnet to which only IoT devices are connected, said dividing comprising:

for each IoT device of the IoT devices within the local network:

determining usage profile of a member of the local network, comprising:

identifying the loT device based at least on: a name of the IoT device, an operating system of the IoT device, and a declared or actual protocol of the IoT device; and

determining a fingerprint of the IoT device; and

assigning the IoT device to one of the at least one IoT subnet in accordance with the usage profile;

monitoring communication traffic of the devices connected to each subnet of the plurality of subnets into which the local network is initially divided in accordance with the expected traffic pattern for the devices connected to each subnet of the plurality of subnets;

performing anomaly detection to detect an abnormal communication of a particular loT device of the IoT devices connected to a particular subnet of the at least one IoT subnet, wherein the anomaly detection is based on an identification of diversion from an expected traffic pattern of the particular subnet of the at least one loT subnet, wherein a communication of a first device connected to a first subnet of the plurality of subnets is compared to a different expected traffic pattern than a communication of a second device connected to a second subnet of the plurality of subnets;

blocking the abnormal communication of the particular IoT device; and

removing the particular loT device from the particular subnet of the at least one loT subnet and connecting the particular IoT device to a quarantine subnet of the local network, thereby reducing connectivity of the particular IoT device with other devices connected to the local network.

2. The method of claim 1 further comprising:

notifying a user of another device that the abnormal communication occurred, wherein the another device is a user device connected to a user device subnet of the plurality of subnets, wherein the user device subnet is a subnet to which only user devices are connected;

allowing the user to indicate that the abnormal communication is authorized; and

in response to the user not authorizing the abnormal communication, performing said blocking and said removing.

3. The method of claim 2 , wherein said notifying the user is performed in response to determining that the another device is connected to the user device subnet.

4. The method of claim 1 , wherein the expected traffic pattern of the particular subnet of the at least one IoT subnet is based on monitored traffic pattern of the particular IoT device and crowd-sourced data indicative of monitored traffic patterns of other devices similar to the particular IoT device, wherein the other devices are not connected to the local network.

5. A computerized apparatus having a hardware processor, the hardware processor being adapted to perform operations for managing a local network, wherein the operations comprise:

dividing the local network into a plurality of subnets in accordance with an expected traffic pattern for devices connected to each subnet of the plurality of subnets, wherein the expected traffic pattern is indicative at least of one of content and target of packets, the plurality of subnets comprising at least one Internet of Things (IoT) subnet to which only IoT devices are connected, said dividing comprising:

for each IoT device of the IoT devices within the local network:

determining usage profile of a member of the local network, comprising:

identifying the IoT device based at least on: a name of the IoT device, an operating system of the IoT device, and a declared or actual protocol of the IoT device; and

determining a fingerprint of the IoT device; and assigning the IoT device to one of the at least one ToT subnet in accordance with the usage profile;

monitoring communication traffic of the devices connected to each subnet of the plurality of subnets into which the local network is initially divided in accordance with the expected traffic pattern for the devices connected to each subnet of the plurality of subnets;

performing anomaly detection to detect an abnormal communication of a particular IoT device of the IoT devices connected to a particular subnet of the at least one IoT subnet, wherein the anomaly detection is based on an identification of diversion from an expected traffic pattern of the particular subnet of the at least one IoT subnet, wherein a communication of a first device connected to a first subnet of the plurality of subnets is compared to a different expected traffic pattern than a communication of a second device connected to a second subnet of the plurality of subnets;

blocking the abnormal communication of the particular loT device; and

removing the particular IoT device from the particular subnet of the at least one IoT subnet and connecting the particular IoT device to a quarantine subnet of the local network, thereby reducing connectivity of the particular IoT device with other devices connected to the local network.

6. The computerized apparatus of claim 5 , wherein the operations further comprising:

notifying a user of another device that the abnormal communication occurred, wherein the another device is a user device connected to a user device subnet of the plurality of subnets, wherein the user device subnet is a subnet to which only user devices are connected;

allowing the user to indicate that the abnormal communication is authorized; and

in response to the user not authorizing the abnormal communication, performing said blocking and said removing.

7. The computerized apparatus of claim 6 , wherein said notifying the user is performed in response to determining that the another device is connected to the user device subnet.

8. The computerized apparatus of claim 5 , wherein the expected traffic pattern of the particular subnet of the at least one IoT subnet is based on monitored traffic pattern of the particular IoT device and crowd-sourced data indicative of monitored traffic patterns of other devices similar to the particular IoT device, wherein the other devices are not connected to the local network.

9. A computer program product comprising a computer readable storage medium retaining program instructions, which program instructions when read by a processor, cause the processor to perform operations for managing a local network, wherein the operations comprise:

dividing the local network into a plurality of subnets in accordance with an expected traffic pattern for devices connected to each subnet of the plurality of subnets, wherein the expected traffic pattern is indicative at least of one of content and target of packets, the plurality of subnets comprising at least one Internet of Things (IoT) subnet to which only loT devices are connected, said dividing comprising:

for each (loT) device of the IoT devices within the local network:

determining usage profile of a member of the local network, comprising:

identifying the loT device based at least on: a name of the IoT device, an operating system of the IoT device, and a declared or actual protocol of the IoT device; and

determining a fingerprint of the IoT device: and assigning the IoT device to one of the at least one IoT subnet in accordance with the usage profile;

monitoring communication traffic of the devices connected to each subnet of the plurality of subnets into which the local network is initially divided in accordance with the expected traffic pattern for the devices connected to each subnet of the plurality of subnets;

performing anomaly detection to detect an abnormal communication of a particular IoT device of the IoT devices connected to a particular subnet of the at least one IoT subnet, wherein the anomaly detection is based on an identification of diversion from an expected traffic pattern of the particular subnet of the at least one loT subnet, wherein a communication of a first device connected to a first subnet of the plurality of subnets is compared to a different expected traffic pattern than a communication of a second device connected to a second subnet of the plurality of subnets;

blocking the abnormal communication of the particular loT device; and

removing the particular loT device from the particular subnet of the at least one loT subnet and connecting the particular loT device to a quarantine subnet of the local network, thereby reducing connectivity of the particular IoT device with other devices connected to the local network.

10. The computer program product of claim 9 , wherein the operations further comprising:

notifying a user of another device that the abnormal communication occurred, wherein the another device is a user device connected to a user device subnet of the plurality of subnets, wherein the user device subnet is a subnet to which only user devices are connected;

allowing the user to indicate that the abnormal communication is authorized; and

in response to the user not authorizing the abnormal communication, performing said blocking and said removing.

11. The computer program product of claim 10 , wherein said notifying the user is performed in response to determining that the another device is connected to the user device subnet.

12. The computer program product of claim 9 , wherein the expected traffic pattern of the particular subnet of the at least one IoT subnet is based on monitored traffic pattern of the particular IoT device and crowd-sourced data indicative of monitored traffic patterns of other devices similar to the particular IoT device, wherein the other devices are not connected to the local network.

Assignments (5)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 17, 2020
From: FORESCOUT TECHNOLOGIES, INC.
To: OWL ROCK CAPITAL CORPORATION, AS ADMINISTRATIVE AGENT
Reel/Frame 053519/0982 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2020
From: BULLGUARD ISRAEL LTD.
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 051586/0962 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2019
From: BULLGUARD LIMITED
To: BULLGUARD ISRAEL LIMITED
Reel/Frame 050429/0711 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2019
From: DOJO LABS LIMITED
To: BULLGUARD LIMITED
Reel/Frame 050431/0957 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2017
From: BACHAR, SCHMULIK; ATIAS, YOSSI
To: DOJO-LABS LTD.
Reel/Frame 043470/0236 →
Continuity (2)
Division 14949292 · Nov 23, 2015
Related Publication 20180013761A1 · Jan 11, 2018