IP Library Granted Patent US 10,878,110
Granted Patent B2
US 10,878,110 · App. 15/795,791 · Granted Dec 29, 2020

Dashboard for managing enterprise network traffic

Inventor: Chris Douglas Kraft (Vancouver, CA)
Assignee: Sophos Limited
G06F21/606G06F12/0813G06F21/44G06F21/50G06F21/51G06F21/54G06F21/55G06F21/554G06F21/57G06F21/602H04L9/0891H04L9/321H04L9/3247H04L9/3268H04L43/028H04L43/045H04L43/062H04L47/2475H04L63/02H04L63/0218H04L63/0227H04L63/0236H04L63/0263H04L63/14H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/168H04L63/20H04L63/205G06F2212/1052G06F2212/60G06F2212/62H04L9/30H04L43/026H04L43/10H04L63/145H04L67/2842
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,878,110
App. No.
15/795,791
Granted
Dec 29, 2020
Kind
B2
Abstract

An enterprise security system is improved by managing network flows based on an application type. When a network message having an unknown application type is received at a gateway, firewall, or other network device/service from an endpoint, the endpoint that originated the network message may be queried for identifying information for the source of the network message and the application type may be determined, or the endpoint may periodically communicate application type information to the network device in a heartbeat or other periodic communication or the like. The network message may be managed along with other network traffic according to the application type.

Claims (29)

1. A method for visualizing network usage comprising:

providing a number of application types that characterize one or more applications sourcing network traffic within an enterprise network;

labeling each of a number of network traffic flows in the enterprise network with one of the application types by querying endpoints for application type information when each new one of the number of network traffic flows is initiated, wherein querying the endpoints includes querying an endpoint defense driver in a kernel space of one of the endpoints to retrieve information from a process cache in the kernel space that stores at least a process identifier and an associated one of the application types for one or more processes executing on the one of the endpoint and wherein the kernel space is protected against manipulation by processes executing in a user space;

aggregating a number of endpoints using each one of the application types on the enterprise network at a cloud-based enterprise management facility; and

configuring the cloud-based enterprise management facility to present the number of endpoints using each one of the application types to a user in a web-based dashboard.

2. The method of claim 1 wherein each of the number of application types includes an application name.

3. The method of claim 1 wherein the number of application types include electronic mail, word processing, spread sheet, and web browser.

4. The method of claim 1 wherein labeling includes labeling at one or more network devices within the enterprise network.

5. The method of claim 1 wherein labeling includes extracting an explicit application type label from a network message within one of the network traffic flows.

6. The method of claim 5 wherein the explicit application type label is cryptographically signed.

7. The method of claim 1 wherein labeling includes extracting an explicit application type label from information transmitted in a heartbeat from an endpoint that originated a network message within one of the network traffic flows.

8. The method of claim 7 wherein the heartbeat is a secure heartbeat.

9. The method of claim 7 wherein the heartbeat is a digitally signed heartbeat.

10. The method of claim 1 wherein aggregating the number of endpoints using each one of the application types includes aggregating only the application types used by one or more of the endpoints.

11. The method of claim 1 wherein the web-based dashboard provides interactive access to underlying data for one or more of network usage by each application type, number of endpoints using each application type, duration of usage, and bandwidth usage.

12. A computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, performs the steps of:

providing a number of application types;

labeling each of a number of network traffic flows in an enterprise network with one of the application types by querying endpoints for application type information when each new one of the number of network traffic flows is initiated, wherein querying the endpoints includes querying an endpoint defense driver in a kernel space of one of the endpoints to retrieve information from a process cache in the kernel space that stores at least a process identifier and an associated one of the application types for one or more processes executing on the one of the endpoint and wherein the kernel space is protected against manipulation by processes executing in a user space;

aggregating a number of endpoints using each one of the application types on the enterprise network; and

configuring a server to present the number of endpoints using each one of the application types to a user in a web-based dashboard.

13. The computer program product of claim 12 wherein each of the number of application types includes an application name.

14. The computer program product of claim 12 wherein the number of application types include electronic mail, word processing, spread sheet, and web browser.

15. The computer program product of claim 12 wherein labeling includes extracting an explicit application type label from a network message within one of the network traffic flows.

16. The computer program product of claim 12 wherein labeling includes extracting an explicit application type label from information transmitted in a heartbeat from an endpoint that originated a network message within one of the network traffic flows.

17. The computer program product of claim 12 wherein the web-based dashboard provides interactive access to underlying data for one or more of network usage by each application type, number of endpoints using each application type, duration of usage, and bandwidth usage.

18. A system comprising:

a plurality of security agents executing on a plurality of endpoints in an enterprise network;

one or more network device in the enterprise network, each one of the network devices configured to label each of a number of network traffic flows in the enterprise network with one of an application type by querying endpoints for application type information when each new one of the number of network traffic flows is initiated, wherein querying the endpoints includes querying an endpoint defense driver in a kernel space of one of the endpoints to retrieve information from a process cache in the kernel space that stores at least a process identifier and an associated one of the application types for one or more processes executing on the one of the endpoint and wherein the kernel space is protected against manipulation by processes executing in a user space, the application type selected from a predetermined group of application types; and

a server configured to aggregate usage data from each one of the network devices to determine a number of instances of each one of the predetermined group of application types associated with a network traffic flow within the enterprise network, and to present the usage data in a web-based interface.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2018
From: KRAFT, CHRIS DOUGLAS
To: SOPHOS LIMITED
Reel/Frame 044787/0080 →
Continuity (4)
Provisional Application 62572548 · Oct 15, 2017
Provisional Application 62571759 · Oct 12, 2017
Provisional Application 62557703 · Sep 12, 2017
Related Publication 20190081873A1 · Mar 14, 2019