IP Library Granted Patent US 10,839,084
Granted Patent B2
US 10,839,084 · App. 15/841,956 · Granted Nov 17, 2020

Contextual risk monitoring

Inventors: Tal Peled (Tel Aviv, IL); Shlomit Tassa (Tel Aviv, IL); Oren Nechushtan (Tel Aviv, IL); Ariel Biton (Tzur Moshe, IL)
Assignee: FORESCOUT TECHNOLOGIES, INC.
G06F21/577G06F3/147G06F21/552H04L63/105H04L63/1408H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,839,084
App. No.
15/841,956
Granted
Nov 17, 2020
Kind
B2
Abstract

Systems, methods, and related technologies for device monitoring and device risk monitoring are described. In certain aspects, an indicator associated with a security risk is set based on communication between a first device having an associated elevated security risk and a second device. The indicator can be stored and may be used as a basis for performing a security action.

Claims (40)

1. A method comprising:

displaying a network graph comprising a first device and a second device;

accessing a first indicator associated with the first device, wherein the first indicator indicates a security risk level that the first device has been in communication with a risk device, wherein the security risk level is based on a number of degrees of separation of the first device from the risk device;

accessing communication information associated with the first device;

determining, by a processing device, the second device being in communication with the first device based on the communication information;

setting a second indicator associated with the second device based on information associated with the first device, wherein the second indicator is set based on a bandwidth usage associated with communication between the first device and the second device; and

storing the second indicator associated with the second device.

2. The method of claim 1 further comprising:

performing an action on the second device based on the second indicator.

3. The method of claim 1 , wherein the communication of the second device with the first device comprises a communication sent from the first device to the second device.

4. The method of claim 1 , wherein the communication of the second device with the first device comprises a communication sent from the second device to the first device.

5. The method of claim 1 , wherein the communication of the second device with the first device comprises an attempted communication from the first device to the second device.

6. The method of claim 1 , wherein the second indicator associated with the second device indicates a medium risk level.

7. The method of claim 1 further comprising:

displaying the second indicator associated with the second device.

8. The method of claim 1 , wherein the communication of the first and second device is associated with a protocol.

9. A system comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

display a network graph comprising a first device and a second device;

access a first indicator associated with the first device, wherein the first indicator indicates an elevated security risk that the first device has been in communication with a risk device;

access communication information associated with the first device;

determine, by a processing device, the second device being in communication with the first device based on the communication information, wherein the communication information comprises information associated with a communication from the first device to the second device;

set a second indicator associated with the second device based on information associated with the first device, wherein the second indicator is set based on a bandwidth usage associated with communication between the first device and the second device; and

store the second indicator associated with the second device.

10. The system of claim 9 , wherein the processing device further to perform a security action based on the second indicator.

11. The system of claim 9 , wherein the communication from the first device to a second device comprises an attempted communication from the first device to the second device.

12. The system of claim 9 , wherein the second indicator associated with the second device indicates a medium risk level.

13. The system of claim 9 , wherein the processing device further to display the first indicator associated with a first color and the second indicator associated with a second color.

14. The system of claim 9 , wherein the second indicator is determined based on communication associated with a protocol.

15. A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device, cause the processing device to:

display a network graph comprising a first device and a second device;

access a first indicator associated with the first device, wherein the first indicator indicates an elevated security risk that the first device has been in communication with a risk device;

access communication information associated with the first device;

determine, by the processing device, the second device in communication with the first device based on the communication information, wherein the communication information comprises information associated with a communication from the second device to the first device;

set a second indicator associated with the second device based on information associated with the first device, wherein the second indicator is set based on a bandwidth usage associated with communication between the first device and the second device; and

store the second indicator associated with the second device.

16. The non-transitory computer readable medium of claim 15 , wherein the processing device further to perform a security action based on the second indicator.

17. The non-transitory computer readable medium of claim 15 , wherein the communication from the second device to the first device comprises an attempted communication from the second device to the first device.

18. The non-transitory computer readable medium of claim 15 , wherein the second indicator is determined based on communication associated with a selected protocol.

Assignments (2)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 17, 2020
From: FORESCOUT TECHNOLOGIES, INC.
To: OWL ROCK CAPITAL CORPORATION, AS ADMINISTRATIVE AGENT
Reel/Frame 053519/0982 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 14, 2017
From: PELED, TAL; TASSA, SHLOMIT; NECHUSHTAN, OREN; BITON, ARIEL
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 044398/0671 →
Continuity (1)
Related Publication 20190188389A1 · Jun 20, 2019