IP Library Granted Patent US 10,439,985
Granted Patent B2
US 10,439,985 · App. 15/899,453 · Granted Oct 8, 2019

Network application security policy generation

Inventor: John O'Neil (Watertown, MA)
Assignee: Edgewise Networks, Inc.
H04L63/0227H04L41/0893H04L41/145H04L43/04H04L43/0817H04L47/2441H04L63/20G06N20/00H04L41/046H04L41/16H04L43/026
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,439,985
App. No.
15/899,453
Filed
Feb 20, 2018
Granted
Oct 8, 2019
Kind
B2
Art Unit
2491
USPC
726/1
Abstract

Embodiments of the present invention generate network communication policies by applying machine learning to existing network communications, and without using information that labels such communications as healthy or unhealthy. The resulting policies may be used to validate communication between applications (or services) over a network.

Claims (46)

1. A method performed by at least one computer processor executing computer program instructions stored in at least one non-transitory computer-readable medium, the method comprising:

(A) for each of a plurality of communications over a network between applications executing on a plurality of computer systems, collecting and storing data about the plurality of communications, including, for each of the plurality of communications:

(1) data representing a local Internet Protocol (IP) address, local port, and protocol of the communication;

(2) data representing a remote IP address and remote port of the communication;

(3) data, other than the local IP address, local port, and protocol of the communication, representing a source application of the communication; and

(4) data, other than the remote IP address and remote port of the communication, representing a destination application of the communication;

(B) generating flow data based on the data about the plurality of communications collected and stored in (A), wherein the flow data includes a plurality of flow objects, wherein each of the plurality of flow objects contains data representing communications involving a single corresponding application;

(C) producing match data containing a plurality of match objects, wherein each of the match objects represents a pair of flow objects, in the plurality of flow objects, representing a flow at a source end of a network communication and a flow at a destination end of the network communication wherein the plurality of match objects do not include labels labeling communications as healthy or unhealthy; and

(D) generating a network communication model based on the match data, the network communication model comprising a plurality of rules, each of which comprises at least one feature-value pair representing a network communication from the plurality of communications and a corresponding probability calculated as the occurrence of the network communication containing the at least one feature-value pair, wherein the at least one feature-value pair includes at least one feature from a set comprising a source host, a source application, a destination host, and a destination application.

2. The method of claim 1 , wherein (A) comprises:

(A) (1) at a first local network information collection agent at a first one of the plurality of computer systems, collecting and storing data about a plurality of communications involving the first one of the plurality of computer systems; and

(A) (2) at a second local network information collection agent at a second one of the plurality of computer systems, collecting and storing data about a plurality of communications involving the second one of the plurality of computer systems.

3. The method of claim 2 , wherein (A) further comprises:

(A) (3) at the first local network information collection agent, transmitting the data about the plurality of communications involving the first one of the plurality of computer systems to a remote server; and

(A) (4) at the second local network information collection agent, transmitting the data about the plurality of communications involving the second one of the plurality of computer systems to the remote server.

4. The method of claim 1 , wherein (C) comprises identifying a first flow object containing:

data representing a communication having a particular IP address as its local IP address and a particular port as its local port; and

data representing a communication having the particular IP address as its remote IP address and the particular port as its remote port.

5. The method of claim 1 , wherein (D) comprises generating the network communication model using a MapReduce algorithm.

6. The method of claim 1 , wherein (D) comprises generating the network communication model using an unsupervised decision tree.

7. The method of claim 1 , wherein (D) comprises generating the network communication model using frequent itemset discovery.

8. The method of claim 1 , wherein (D) comprises generating the network communication model using a greedy algorithm.

9. The method of claim 1 , wherein (D) comprises generating the network communication model using a stochastic optimization model.

10. A system comprising at least one non-transitory computer-readable medium containing instructions executable by at least one computer processor to perform a method, the method comprising:

(A) for each of a plurality of communications over a network between applications executing on a plurality of computer systems, collecting and storing data about the plurality of communications, including, for each of the plurality of communications:

(1) data representing a local Internet Protocol (IP) address, local port, and protocol of the communication;

(2) data representing a remote IP address and remote port of the communication;

(3) data, other than the local IP address, local port, and protocol of the communication, representing a source application of the communication; and

(4) data, other than the remote IP address and remote port of the communication, representing a destination application of the communication;

(B) generating flow data based on the data about the plurality of communications collected and stored in (A), wherein the flow data includes a plurality of flow objects, wherein each of the plurality of flow objects contains data representing communications involving a single corresponding application;

(C) producing match data containing a plurality of match objects, wherein each of the match objects represents a pair of flow objects, in the plurality of flow objects, representing a flow at a source end of a network communication and a flow at a destination end of the network communication wherein the plurality of match objects do not include labels labeling communications as healthy or unhealthy; and

(D) generating a network communication model based on the match data, the network communication model comprising a plurality of rules, each of which comprises at least one feature-value pair representing a network communication from the plurality of communications and a corresponding probability calculated as the occurrence of the network communication containing the at least one feature-value pair, wherein the at least one feature-value pair includes at least one feature from a set comprising a source host, a source application, a destination host, and a destination application.

11. The system of claim 10 , wherein (A) comprises:

(A) (1) at a first local network information collection agent at a first one of the plurality of computer systems, collecting and storing data about a plurality of communications involving the first one of the plurality of computer systems; and

(A) (2) at a second local network information collection agent at a second one of the plurality of computer systems, collecting and storing data about a plurality of communications involving the second one of the plurality of computer systems.

12. The system of claim 11 , wherein (A) further comprises:

(A) (3) at the first local network information collection agent, transmitting the data about the plurality of communications involving the first one of the plurality of computer systems to a remote server; and

(A) (4) at the second local network information collection agent, transmitting the data about the plurality of communications involving the second one of the plurality of computer systems to the remote server.

13. The system of claim 10 , wherein (C) comprises identifying a first flow object containing:

data representing a communication having a particular IP address as its local IP address and a particular port as its local port; and

data representing a communication having the particular IP address as its remote IP address and the particular port as its remote port.

14. The system of claim 10 , wherein (D) comprises generating the network communication model using a MapReduce algorithm.

15. The system of claim 10 , wherein (D) comprises generating the network communication model using an unsupervised decision tree.

16. The system of claim 10 , wherein (D) comprises generating the network communication model using frequent itemset discovery.

17. The system of claim 10 , wherein (D) comprises generating the network communication model using a greedy algorithm.

18. The system of claim 10 , wherein (D) comprises generating the network communication model using a stochastic optimization model.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2020
From: EDGEWISE NETWORKS, INC.
To: ZSCALER, INC.
Reel/Frame 052959/0532 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2020
From: EDGEWISE NETWORKS, INC.
To: ZSCALER, INC.
Reel/Frame 052823/0390 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2018
From: O'NEIL, JOHN
To: EDGEWISE NETWORKS, INC.
Reel/Frame 045062/0322 →
Continuity (3)
Continuation 15896786 · Feb 14, 2018
Provisional Application 62459248 · Feb 15, 2017
Related Publication 20180234385A1 · Aug 16, 2018
Cited By (12)
US 12,192,076 US 12,244,643 US 12,255,923 US 12,309,203 US 12,341,794 US 12,348,525 US 12,452,210 US 12,489,790 US 12,572,622 US 12,580,921 US 12,592,930 US 12,602,450