IP Library Granted Patent US 10,778,723
Granted Patent B2
US 10,778,723 · App. 15/936,180 · Granted Sep 15, 2020

Device visibility and scanning including network segments

Inventor: Siying Yang (Cupertino, CA)
Assignee: FORESCOUT TECHNOLOGIES, INC.
H04L63/20H04L41/0213H04L47/20H04L61/256H04L63/029H04L63/1408H04L63/1433H04L63/1466H04L61/2514H04L61/2535
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,778,723
App. No.
15/936,180
Granted
Sep 15, 2020
Kind
B2
Abstract

Systems, methods, and related technologies for device scanning are described. In certain aspects, a device is selected based on being a NAT device and information is accessed therefrom to determine a device communicatively coupled to the NAT device. The device communicatively coupled to the NAT device may then be scanned and the results stored.

Claims (49)

1. A method comprising:

selecting a first device, communicatively coupled to a network, based on the first device performing network address translation (NAT), wherein the first device is communicatively coupled to a second device, and wherein the second device is configured to communicate through the first device;

accessing network session information associated with the first device, wherein the network session information comprises an address associated with the second device;

determining, with a processing device, an identifier associated with the second device based on the network session information;

configuring a port forwarding policy on the first device based on the network session information;

performing a scan of the second device based on the port forwarding policy; and

storing the results of the scan.

2. The method of claim 1 further comprising:

performing an action based on the scan.

3. The method of claim 1 further comprising:

removing the port forwarding policy on the first device.

4. The method of claim 1 , wherein the second device is a NAT device, further comprising:

accessing network session information associated with the second device, wherein the network session information comprises an address associated with a third device;

determining, with the processing device, an identifier associated with the third device based on the network session information;

configuring a port forwarding policy on the second device based on the network session information associated with the second device;

performing a scan of the third device based on the port forwarding policy; and

storing the results of the scan.

5. The method of claim 1 , wherein the first device is at least one of a router, a firewall, a switch, or a carrier grade (CG) NAT device.

6. The method of claim 1 , wherein the port forwarding policy of the first device is configured using at least one of an application programming interface (API), command line interface (CLI), or a simple network management protocol (SNMP) interface.

7. The method of claim 1 further comprising:

determining an operating system (OS) of the second device based on the network session information.

8. The method of claim 1 , wherein the identifier of the second device comprises a unique identifier comprising an IP address associated with the second device and an IP address associated with the first device.

9. The method of claim 8 , wherein the unique identifier of the second device further comprises a media access control (MAC) address associated with the first device.

10. A system comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

select a first device, communicatively coupled to a network, based on the first device performing network address translation (NAT), wherein the first device is communicatively coupled to a second device, and wherein the second device is configured to communicate through the first device;

access network session information associated with the first device, wherein the network session information comprises an address associated with the second device;

determine an identifier associated with the second device based on the network session information;

configure a port forwarding policy on the first device based on the network session information;

perform a scan of the second device based on the port forwarding policy; and

store the results of the scan.

11. The system of claim 10 , wherein the processing device further to perform an action based on the scan.

12. The system of claim 10 , wherein the processing device further to remove the port forwarding policy on the first device.

13. The system of claim 11 , wherein the first device is at least one of a router, a firewall, a switch, or a carrier grade (CG) NAT device.

14. The system of claim 11 , wherein the port forwarding policy of the first device is configured using an application programming interface (API).

15. The system of claim 10 , wherein the processing device further to determine an operating system (OS) of the second device based on the network session information.

16. The system of claim 10 , wherein the identifier of the second device comprises a unique identifier comprising an IP address associated with the second device and an IP address associated with the first device.

17. The system of claim 10 , wherein the unique identifier of the second device further comprises a media access control (MAC) address associated with the first device.

18. A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device, cause the processing device to:

select a first device, communicatively coupled to a network, based on the first device performing network address translation (NAT), wherein the first device is communicatively coupled to a second device, and wherein the second device is configured to communicate through the first device;

access network session information associated with the first device, wherein the network session information comprises an address associated with the second device;

determine a unique identifier associated with the second device based on the network session information;

configure a port forwarding policy on the first device based on the network session information;

perform a scan of the second device based on the port forwarding policy; and

store the results of the scan.

19. The non-transitory computer readable medium of claim 18 , wherein the instructions further cause the processing device to perform an action based on the scan.

20. The non-transitory computer readable medium of claim 18 , wherein the instructions further cause the processing device to remove the port forwarding policy on the first device.

21. The non-transitory computer readable medium of claim 18 , wherein the first device is at least one of a router, a firewall, a switch, or a carrier grade (CG) NAT device.

Assignments (2)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 17, 2020
From: FORESCOUT TECHNOLOGIES, INC.
To: OWL ROCK CAPITAL CORPORATION, AS ADMINISTRATIVE AGENT
Reel/Frame 053519/0982 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2018
From: YANG, SIYING
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 045372/0351 →
Continuity (1)
Related Publication 20190297113A1 · Sep 26, 2019