IP Library Granted Patent US 10,986,092
Granted Patent B2
US 10,986,092 · App. 15/885,391 · Granted Apr 20, 2021

Managing claiming of unrecognized devices for admission to an enterprise network

Inventors: John Edward Tyrone Shaw (Oxford, GB); Ross McKerchar (Bristol, GB); Moritz Daniel Grimm (Bruchsal, DE); Jan Karl Heinrich Weber (Karlsruhe, DE); Shail R. Talati (Santa Clara, CA); Kenneth D. Ray (Seattle, WA); Andrew J. Thomas (Oxfordshire, GB)
Assignee: Sophos Limited
H04L63/0876H04L63/0227H04L63/0281H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,986,092
App. No.
15/885,391
Granted
Apr 20, 2021
Kind
B2
Abstract

A threat management facility detects a device on an enterprise network and determines whether the device is one of a set of managed devices for the enterprise network. When the device is not one of the set of managed devices, the threat management facility may determine whether the device is manageable. When the device is unrecognized and unmanageable, a portal may provide support to a user of the device by listing the device on an unclaimed device page published by the portal and accessible to authorized users of the enterprise network. An authorized user may claim the unrecognized device from the unclaimed device page and, in the process, may provide additional information regarding the unrecognized device. Once claimed, the previously unrecognized device may be permitted to communicate over the enterprise network.

Claims (28)

1. A method comprising:

detecting a device on an enterprise network managed by an administrator;

when the device provides, to a threat management facility, a heartbeat that identifies the device as one of a set of managed devices for the enterprise network, permitting the device to communicate over the enterprise network; and

when the device does not provide the heartbeat to the threat management facility, determining manageability of the device and, upon determining that the device is unmanageable by the threat management facility in a manner consistent with a security policy for the enterprise network, listing the device on an unclaimed device page accessible on the enterprise network and published by a portal for admission, by authorized users of the enterprise network in addition to the administrator, of unrecognized devices onto the enterprise network, and receiving information from an authorized user to associate the device with the authorized user.

2. The method of claim 1 , wherein listing the device includes displaying an association of the device with another device.

3. The method of claim 1 , further comprising receiving, from an authorized user of the enterprise network, a claim for the device from the unclaimed device page.

4. The method of claim 3 , wherein receiving the claim for the device includes registering the device in a database stored by the threat management facility.

5. The method of claim 3 , further comprising permitting the device to communicate over the enterprise network based on the claim for the device from the unclaimed device page.

6. The method of claim 1 , wherein determining manageability of the device includes obtaining a fingerprint of the device.

7. The method of claim 6 , wherein the fingerprint of the device is based on one or more of network traffic, packet header information, or status reports obtained from communications by the device.

8. The method of claim 1 , wherein determining manageability of the device includes testing ports of the device and assessing respective responses of the ports to the testing.

9. The method of claim 1 , wherein listing the device on the unclaimed device page includes performing a security scan of the device for compliance with a security policy.

10. A computer program product encoded on one or more non-transitory computer storage media, the computer program product comprising instructions that, when executed by one or more computing devices, cause the one or more computing devices to perform operations comprising:

detecting a device on an enterprise network managed by an administrator;

when the device provides, to a threat management facility, a heartbeat that identifies the device as one of a set of managed devices for the enterprise network, permitting the device to communicate over the enterprise network; and

when the device does not provide the heartbeat to the threat management facility that identifies the device as one of the set of managed devices, determining manageability of the device and, upon determining that the device is unmanageable by the threat management facility in a manner consistent with a security policy for the enterprise network, listing the device on an unclaimed device page accessible on the enterprise network and published by a portal for admission, by authorized users of the enterprise network in addition to the administrator, of unrecognized devices onto the enterprise network, and receiving information from an authorized user to associate the device with the authorized user.

11. The computer program product of claim 10 , the operations further comprising receiving, from an authorized user of the enterprise network, a claim for the device from the unclaimed device page.

12. The computer program product of claim 11 , wherein receiving the claim for the device includes registering the device in a database stored by the threat management facility.

13. The computer program product of claim 11 , the operations further comprising permitting the device to communicate over the enterprise network based on the claim for the device from the unclaimed device page.

14. The computer program product of claim 10 , wherein determining manageability of the device includes obtaining a fingerprint of the device.

15. The computer program product of claim 14 , wherein the fingerprint of the device is based on one or more of network traffic, packet header information, or status reports obtained from communications by the device.

16. The computer program product of claim 10 , wherein determining manageability of the device includes testing ports of the device and assessing respective responses of the ports to the testing.

17. The computer program product of claim 10 , wherein listing the device on the unclaimed device page includes performing a security scan of the device for compliance with a security policy.

18. A system comprising:

a portal for managing admission of unrecognized devices onto an enterprise network managed by an administrator, the portal including a first memory and a first processor, the first memory having stored thereon computer executable instructions for causing the first processor to publish an unclaimed device page accessible on the enterprise network; and

a threat management facility associated with the enterprise network and in communication with the portal, the threat management facility including a second memory and a second processor, the second memory having stored thereon computer executable instructions for causing the second processor to identify a device as one of a set of managed devices for the enterprise network, to permit the device to communicate over the enterprise network when the device is one of the set of managed devices, and, when the device is not one of the set of managed devices, to determine manageability of the device and, upon determining that the device is unmanageable by the threat management facility in a manner consistent with a security policy for the enterprise network, to list the device on the unclaimed device page published by the portal and accessible to authorized users of the enterprise network, in addition to the administrator, for admission of unrecognized devices onto the enterprise network, and to receive information from an authorized user to associate the device with the authorized user.

19. The system of claim 18 , wherein the first memory of the portal has further stored thereon instructions to further cause the first processor to receive, from one or more of the authorized users of the enterprise network, a claim for the device from the unclaimed device page.

20. The system of claim 19 , wherein the second memory of the threat management facility has further stored thereon instructions further cause the second processor to permit the device to communicate over the enterprise network based on the claim for the device from the unclaimed device page.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 8, 2019
From: SHAW, JOHN EDWARD TYRONE; MCKERCHAR, ROSS; GRIMM, MORITZ DANIEL; WEBER, JAN KARL HEINRICH; TALATI, SHAIL R.; RAY, KENNETH D.; THOMAS, ANDREW J.
To: SOPHOS LIMITED
Reel/Frame 049262/0121 →
Continuity (1)
Related Publication 20190238538A1 · Aug 1, 2019