IP Library Granted Patent US 11,122,071
Granted Patent B2
US 11,122,071 · App. 16/023,553 · Granted Sep 14, 2021

Visibility and scanning of a variety of entities

Inventors: Anderson Lam (Fremont, CA); Sharad Singh (San Jose, CA); Mihael Sudakovitch (Seattle, WA)
Assignee: FORESCOUT TECHNOLOGIES, INC.
H04L63/1433H04L63/10H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,122,071
App. No.
16/023,553
Granted
Sep 14, 2021
Kind
B2
Abstract

Systems, methods, and related technologies for entity visibility are described. In certain aspects, information associated with a type of entity is accessed and a network is scanned for a plurality of entities. One or more entities are selected from plurality of entities based on the type of entity. Properties associated with the one or more selected entities are accessed. The information associated with the one or more selected entities and the one or more properties associated with the selected one or more entities are stored.

Claims (40)

1. A method comprising:

accessing information associated with a type of entity to be monitored on a network;

scanning the network for a plurality of entities;

selecting, by a processing device, one or more entities of the plurality of entities based on the type of entity to be monitored on the network, wherein one of the one or more entities is a new entity;

accessing one or more properties associated, respectively, with the selected one or more entities, including the new entity, of the plurality of entities based on the type of entity to be monitored on the network;

accessing information associated with the new entity from another source based on the type of entity to be monitored on the network;

storing information associated with the one or more selected entities, including the new entity, of the plurality of entities and the one or more properties associated with the selected one or more entities; and

performing an action on an entity of the one or more selected entities of the plurality of entities based on a policy, wherein the action comprises preventing an account associated with a misconfigured firewall or router from accessing network resources.

2. The method of claim 1 , wherein the type of entity is independent of at least one of an interne protocol (IP) address or a media access control (MAC) address.

3. The method of claim 1 , wherein the one or more entities comprises an account.

4. The method of claim 1 , wherein the one or more entities comprises a cloud based storage resource.

5. The method of claim 1 , wherein the one or more entities comprises an indicator of compromise (IOC).

6. The method of claim 1 , wherein the one or more entities comprises a network device configuration.

7. The method of claim 1 , wherein the scanning of the network for a plurality of entities comprises communication with a plurality of devices, wherein each of the plurality of devices is operable to have at least one entity matching the type of entity.

8. A system comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

access information associated with a type of entity to be monitored on a network;

scan the network for a plurality of entities;

select one or more entities of the plurality of entities based on the type of entity to be monitored on the network, wherein one of the one or more entities is a new entity;

access one or more properties associated, respectively, with the selected one or more entities of the plurality of entities based on the type of entity to be monitored on the network;

access information associated with the new entity from another source based on the type of entity to be monitored on the network;

store information associated with the one or more selected entities, including the new entity, of the plurality of entities and the one or more properties associated with the selected one or more entities; and

perform an action on an entity of the one or more selected entities of the plurality of entities based on a policy, wherein the action comprises a poll for virtualization system information to determine a type of remediation action to take after checking permissions.

9. The system of claim 8 , wherein the type of entity is independent of at least one of an interne protocol (IP) address or a media access control (MAC) address.

10. The system of claim 8 , wherein the one or more entities comprises an account.

11. The system of claim 8 , wherein the one or more entities comprises a cloud based storage resource.

12. The system of claim 8 , the one or more entities comprises is an indicator of compromise (IOC).

13. The system of claim 8 , wherein the one or more entities comprises a network device configuration.

14. The system of claim 8 , wherein the scan of the network for a plurality of entities comprises communication with a plurality of devices.

15. A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device, cause the processing device to:

access information associated with a type of entity to be monitored on a network;

scan the network for a plurality of entities;

select, using the processing device, one or more entities of the plurality of entities based on the type of entity to be monitored on the network, wherein one of the one or more entities is a new entity;

access one or more properties associated, respectively, with the selected one or more entities of the plurality of entities based on the type of entity to be monitored on the network;

access information associated with the new entity from another source based on the type of entity to be monitored on the network;

store information associated with the one or more selected entities, including the new entity, of the plurality of entities and the one or more properties associated with the selected one or more entities; and

perform an action on an entity of the one or more selected entities of the plurality of entities based on a policy, wherein the action comprises a poll for virtualization system information to determine a type of remediation action to take after checking permissions.

16. The non-transitory computer readable medium of claim 15 , wherein the type of entity is independent of at least one of an interne protocol (IP) address or a media access control (MAC) address.

17. The non-transitory computer readable medium of claim 15 , wherein the one or more entities comprises an account.

Assignments (2)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 17, 2020
From: FORESCOUT TECHNOLOGIES, INC.
To: OWL ROCK CAPITAL CORPORATION, AS ADMINISTRATIVE AGENT
Reel/Frame 053519/0982 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 4, 2019
From: LAM, ANDERSON; SINGH, SHARAD; SUDAKOVITCH, MIHAEL
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 049366/0103 →
Continuity (1)
Related Publication 20200007570A1 · Jan 2, 2020