IP Library Granted Patent US 10,728,251
Granted Patent B2
US 10,728,251 · App. 15/707,989 · Granted Jul 28, 2020

Systems and methods for creating and modifying access control lists

Inventors: Malcolm Rieke (Santa Cruz, CA); James Sebastian Dennis (Scotts Valley, CA)
Assignee: Catbird Networks, Inc.
H04L63/101H04L41/22H04L41/5058H04L43/045H04L63/0209H04L63/1433H04L63/20H04L41/5009H04L43/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,728,251
App. No.
15/707,989
Filed
Sep 18, 2017
Granted
Jul 28, 2020
Kind
B2
Art Unit
2497
USPC
726/3
Abstract

Embodiments of the present disclosure can present information on services hosted and used by various assets on a network, and allow users to control access to such services. In particular, embodiments of the disclosure may be used to present one or more services hosted by a network asset, and control access to such services by other network assets based on user input.

Claims (40)

1. A computer-implemented method comprising:

collecting, by a computer system, data from a plurality of different types of sources on a network;

identifying, by the computer system based on the collected data, one or more services provided by a host network asset for use by a client network asset over the network into one or more respective logic zones for association with respective control policies; and

presenting to a user interface, a graphical representation that includes representations of: the host network asset, the client network asset, the one or more services, and a flow information graph visually indicating a security vulnerability associated with one or more of the host network asset and the client network asset and with the one or more respective logic zones.

2. The method of claim 1 , wherein presenting the graphical representation includes displaying which of the one or more services have been previously used by the client network asset and which of the one or more services have not been previously used by the client network asset.

3. The method of claim 1 , wherein presenting the graphical representation includes presenting a flow information graph that depicts the host network asset, the client network asset, connections between the host network asset and the client network asset, services that are permitted to be accessed between the host network asset and the client network asset, and services that are not permitted to be accessed between the host network asset and the client network asset.

4. The method of claim 3 , wherein the flow information graph visually indicates one or more of: an attribute of the host network asset, an attribute of the client network asset, and an attribute of a connection between the host network asset and the client network asset.

5. The method of claim 4 , wherein the flow information graph further depicts:

network data associated with one or more of host network asset and the client network asset; and

a system operational attribute associated with one or more of the host network asset and the client network asset.

6. The method of claim 3 , wherein the flow information graph depicts connections between the host network asset and the client network asset using selectable directional flow lines.

7. The method of claim 6 , wherein the flow lines indicate a type of the source of the collected data used to identify the connection.

8. The method of claim 3 , wherein presenting the flow information graph includes:

visually indicating the identified security vulnerability in the flow information graph.

9. The method of claim 1 , further comprising:

receiving, by the computer system via the user interface, input from a user that includes:

a selection of a service from the one or more services;

a selection permitting or rejecting access to the selected service by the client network asset; and

a selection of a second client network asset, wherein the second client network asset uses services from one of the host network asset and a second host network asset; and

in response to the input from the user, modifying access to the selected service by the client network asset over the network;

wherein the input from the user includes an annotation associated with the selected service, and wherein presenting the graphical representation includes displaying the annotation for the selected service.

10. The method of claim 9 , wherein modifying access to the selected service includes restricting access by the client network asset to all services provided by the host network asset.

11. The method of claim 9 , wherein modifying access to the selected service includes allowing access by the client network asset to all services provided by the host network asset.

12. The method of claim 9 , wherein modifying access to the selected service includes selectively restricting access by a plurality of client network assets to all services provided by the host network asset based on a common attribute of each of the plurality of client network assets.

13. The method of claim 9 , wherein modifying access to the selected service includes selectively allowing access by a plurality of client network assets to all services provided by the host network asset based on a common attribute of each of the plurality of client network assets.

14. The method of claim 1 , wherein the collected data is obtained from a source selected from the group consisting of: a NETFLOW IPFIX collector, a network tap, a router, a switch, a firewall, an intrusion detection system, an intrusion protection system, and combinations thereof.

15. A tangible, non-transitory computer-readable medium storing instructions that, when executed, cause a computer system to:

collect data from a plurality of different types of sources on a network;

identify, based on the collected data, one or more services provided by a host network asset for use by a client network asset over the network into one or more respective logic zones for association with respective control policies; and

present to a user interface, a graphical representation that includes representations of: the host network asset, the client network asset, the one or more services, and a flow information graph visually indicating a security vulnerability associated with one or more of the host network asset and the client network asset and with the one or more respective logic zones.

16. A computer system comprising:

a processor; and

memory in communication with the processor and storing instructions that, when executed by the processor, cause the computer system to:

collect data from a plurality of different types of sources on a network;

identify, based on the collected data, one or more services provided by a host network asset for use by a client network asset over the network into one or more respective logic zones for association with respective control policies;

present to a user interface, a graphical representation that includes representations of: the host network asset, the client network asset, the one or more services, and a flow information graph visually indicating a security vulnerability associated with one or more of the host network asset and the client network asset and with the one or more respective logic zones.

17. The method of claim 1 , wherein the input from the user includes a selection of one or more of: network flow associated with the host asset and an attribute associated with the host asset.

18. The method of claim 1 , wherein the control policies comprise a security technical control policy.

19. The method of claim 1 , wherein the control policies comprise a logic zone membership policy.

20. The method of claim 1 , wherein environmental events associated with one logic zone of the one or more respective logic zones are monitored in light of all of the control policies associated with the respective one or more logic zones.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0970 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: SIS HOLDINGS, L.P.
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068312/0011 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: APPGATE FUNDING, LLC
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0570 →
SECURITY INTEREST Recorded Aug 22, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: APPGATE FUNDING, LLC
Reel/Frame 064672/0383 →
SECURITY INTEREST Recorded Jul 6, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: SIS HOLDINGS, L.P.
Reel/Frame 064461/0539 →
SECURITY INTEREST Recorded Jun 10, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 063956/0470 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2018
From: RIEKE, MALCOLM; DENNIS, JAMES SEBASTIAN
To: CATBIRD NETWORKS, INC.
Reel/Frame 045192/0754 →
Continuity (6)
Continuation 14821103 · Aug 7, 2015
Provisional Application 62137590 · Mar 24, 2015
Provisional Application 62103496 · Jan 14, 2015
Provisional Application 62060433 · Oct 6, 2014
Provisional Application 62046807 · Sep 5, 2014
Related Publication 20180069865A1 · Mar 8, 2018