IP Library Granted Patent US 10,659,498
Granted Patent B2
US 10,659,498 · App. 15/994,655 · Granted May 19, 2020

Systems and methods for security configuration

Inventors: Ross R. Kinder (Ann Arbor, MI); Jon R. Ramsey (Atlanta, GA); Timothy M. Vidas (Omaha, NE); Robert Danford (Boulder, CO)
Assignee: SecureWorks Corp.
H04L63/20H04L41/0813H04L41/145H04L41/147H04L63/0227H04L41/22H04L43/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,659,498
App. No.
15/994,655
Granted
May 19, 2020
Kind
B2
Abstract

A method of configuring a network security device includes receiving a changed set of network rules to replace a current set of network rules; using a plurality of network traffic events to perform a first simulation of according to the current set of network rules and a second simulation according to the changed set of network rules; comparing the results of the first and second simulation to identify changes in network traffic allowed and denied between the current set and the changed set of network rules; displaying the changes in allowed and denied traffic for review of the changed set of network rules; receiving an instruction to implement the changed set of network rules based on the review; and filtering network traffic according to the changed set of network rules.

Claims (52)

1. A network security device comprising:

a memory configured to:

store a plurality of network events; and

store a set of network filter rules; and

a hardware processor connected to the memory, the hardware processor configured to:

receive a change to a set of network rules;

perform a first simulation of network traffic allowed and denied according to the current set of network rules and a second simulation of network traffic allowed and denied according to the changed set of network rules, the first simulation and second simulation utilizing at least a portion of the network events;

evaluate the use of computational resources during the first and second simulation;

calculate an entropy of strings matching a wildcard of a new network rule of the changed set of network rules to determine if the changed network rule is too broad;

provide an indication of the changes in allowed and denied traffic and the entropy of the new network rule for review of the changed set of network rules;

provide an indication of a performance impact of the changed set of network rules or rejecting the changed set of rules if the performance impact crosses a threshold;

receive an instruction to implement the changed set of network rules based on the review; and

filter network traffic according to the changed set of network rules.

2. The network security device of claim 1 , wherein the network events are stored in a first-in-first out buffer.

3. The network security device of claim 1 , wherein the hardware processor is further configured to group and display the plurality of network events.

4. The network security device of claim 1 , wherein the hardware processor is further configured to display a performance impact of the changed set of network rules.

5. The network security device of claim 4 , wherein the performance impact includes a change in CPU utilization between the first simulation and the second simulation.

6. The network security device of claim 1 , wherein the hardware processor is further configured to:

calculate a ratio of allowed traffic between the current set of network rules and the changed set of network rules; and

reject the changed set of network rules if the ratio crosses a threshold.

7. The network security device of claim 1 , wherein the hardware processor is further configured to log a set of alerts generated by the changed set of network rules but not by the current set of network rules.

8. The network security device of claim 1 , wherein the hardware processor is further configured to:

calculate a rule quality score for the changed set of network rules; and

display the rule quality score or reject the changed set of rules if the rule quality score crosses a threshold.

9. A method for network security configuration, comprising:

receiving a changed set of network rules to replace a current set of network rules;

using a plurality of network traffic events to perform a first simulation of network traffic allowed and denied according to the current set of network rules and a second simulation of network traffic allowed and denied according to the changed set of network rules;

evaluating the use of computational resources during the first and second simulation;

calculating an entropy of strings matching a wildcard of a new network rule of the changed set of network rules to determine if the changed network rule is too broad;

displaying the changes in allowed and denied traffic for review of the changed set of network rules;

displaying an indication of a performance impact of the changed set of network rules or rejecting the changed set of rules if the performance impact crosses a threshold;

receiving an instruction to implement the changed set of network rules based on the review; and

filtering network traffic according to the changed set of network rules.

10. The method of claim 9 , wherein the network events are stored in a first-in-first-out buffer.

11. The method of claim 9 , further comprising calculating a ratio of allowed traffic between the current set of network rules and the changed set of network rules, and reject the changed set of network rules if the ratio crosses a threshold.

12. The method of claim 9 , further comprising logging a set of alerts generated by the changed set of network rules but not by the current set of network rules.

13. The method of claim 9 , further comprising:

calculating a rule quality score for the changed set of network rules; and

displaying the rule quality score or rejecting the changed set of rules if the rule quality score crosses a threshold.

14. A method for network security configuration, comprising:

retrieving a plurality of network events;

grouping and displaying the plurality of network events;

receiving a changed network rule;

simulating the effect of the changed network rule on the network events;

using a processor to evaluate computational resources used by the changed network rule during the simulation and to reject the changed network rule if a performance impact crosses a threshold;

calculating an entropy of strings matching a wildcard of the changed network rule to determine if the changed network rule is too broad;

using a processor to evaluate the changed network rule based on a rule quality score crossing a threshold and to reject the changed network rule if the rule quality score crosses the threshold, the rule quality based at least in part on the calculated entropy; and

filtering network traffic according to the changed network rule if the changed network rule is not rejected.

15. The method of claim 14 , wherein the plurality of network events are stored in a first-in-first-out buffer.

16. The method of claim 14 , further comprising evaluating the performance impact by comparing a processor usage of a current network rule and the changed network rule.

17. The method of claim 14 , further comprising evaluating the performance impact by comparing a memory usage of a current network rule and the changed network rule.

18. The method of claim 14 , further comprising calculating a ratio of allowed traffic between a current network rule and the changed network rule.

Assignments (3)
SECURITY INTEREST Recorded May 2, 2025
From: SECUREWORKS CORP.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 071156/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2025
From: KINDER, ROSS R.; RAMSEY, JON R.; VIDAS, TIMOTHY M.; DANFORD, ROBERT
To: SECUREWORKS HOLDING CORPORATION
Reel/Frame 070562/0754 →
CHANGE OF NAME Recorded Mar 19, 2025
From: SECUREWORKS HOLDING CORPORATION
To: SECUREWORKS CORP.
Reel/Frame 070566/0631 →
Continuity (2)
Continuation 14991646 · Jan 8, 2016
Related Publication 20180288100A1 · Oct 4, 2018