IP Library Patent Application 16166906
Patent Application
App. No. 16/166,906

DISCOVERING INTERNET PROTOCOL (IP) ADDRESSES INVOLVED IN FLOWS TRAVERSING THE INTERNET

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/166,906
Abstract

Introduced here are security management platforms configured to discover traffic flows that involve one or more internal Internet Protocol (IP) addresses that reside on an internal network. By monitoring netflow data regarding the traffic traversing the Internet, a security management platform can identify each internal IP address that was involved in a public communication activity over an interval of time. A public communication activity normally involves an exchange of data packets between an internal IP address that resides on the internal network and an external IP address that does not reside on the internal network. Moreover, the security management platform may create a list that includes at least some of the internal IP addresses that have been involved in public communication activities. The list may enable the security management platform to more easily discover security threats that might otherwise go undetected.

Claims (64)

1 . A computer-implemented method for discovering traffic flows that involve one or more internal Internet Protocol (IP) addresses that reside on an internal network associated with an organization, the method comprising:

acquiring global netflow that includes all traffic having a certain characteristic that traversed the Internet during a certain time interval;

filtering the global netflow to obtain first data indicative of local netflow,

wherein the local netflow includes all traffic having the certain characteristic that crossed a perimeter of the internal network during the certain time interval;

parsing the first data to identify each internal IP address that was involved in a public communication activity during the certain time interval,

wherein the public communication activity involves an exchange of a data packet between an internal IP address that resides on the internal network and an external IP address that does not reside on the internal network; and

creating, based on said parsing, a first list that includes all internal IP addresses that were involved in public communication activities during the certain time interval.

2 . The computer-implemented method of claim 1 , further comprising:

acquiring second data indicative of the local netflow from one or more flow collectors instrumented along the perimeter of the internal network; and

combining the first data and the second data into a single dataset to be parsed.

3 . The computer-implemented method of claim 1 , wherein the local netflow includes data packets transmitted by external IP addresses to internal IP addresses, data packets transmitted by internal IP addresses to external IP addresses, or any combination thereof.

4 . The computer-implemented method of claim 1 , further comprising:

acquiring a second list that includes all internal IP addresses that are presently being monitored by the organization;

comparing the first list to the second list to identify any discrepancies; and

determining, based on said comparing, that at least one internal IP address included in the first is not included in the second list.

5 . The computer-implemented method of claim 4 , further comprising:

generating a notification that identifies the at least one internal IP address; and

transmitting the notification to a computing device associated with an administrator responsible for managing the internal network.

6 . The computer-implemented method of claim 1 , wherein the global netflow is acquired from one or more Internet service Providers (ISPs), one or more content delivery networks (CDNs), or any combination thereof.

7 . The computer-implemented method of claim 1 , further comprising:

retrieving map data from the Internet on a periodic basis; and

generating a model of the internal network based on the map data.

8 . The computer-implemented of claim 7 , further comprising:

probing each internal IP address included in the first list by transmitting a query designed to elicit a response; and

creating probe data from any responses received from the internal IP addresses included in the first list,

wherein the probe data specifies a class, a type, or a version of at least some computer programs residing on the internal network.

9 . A non-transitory computer-readable medium with instructions stored thereon that, when executed by a processor, cause the processor to perform operations comprising:

acquiring, by a security management platform, multiple unclassified data streams from at least two different sources,

wherein each unclassified data stream of the multiple unclassified data streams includes information regarding traffic that traversed a perimeter of an internal network associated with an organization;

fusing, by the security management platform, the multiple unclassified data streams together to form a unified workflow;

identifying, by the security management platform, a vector of attack against a cyber asset residing on the internal network by examining the unified workflow; and

causing a remediation action to be performed to deny the vector of attack.

10 . The non-transitory computer-readable medium of claim 9 , wherein said causing comprises:

generating, by the security management platform, a notification that identifies the remediation action; and

transmitting, by the security management platform, the notification to a computing device associated with an administrator responsible for managing the internal network.

11 . The non-transitory computer-readable medium of claim 9 , wherein the multiple unclassified data streams include:

map data characterizing an attack surface of IP addresses, computing devices, or services that reside on the internal network,

netflow data characterizing communication activities involving exchanges of data packets across the perimeter of the internal network, and

probe data characterizing a class, a type, or a version of at least one computer program that resides on the internal network.

12 . The non-transitory computer-readable medium of claim 9 , wherein the operations further comprise:

probing, by the security management platform, each internal IP address that resides on the internal network by transmitting a query designed to elicit a response; and

determining, by the security management platform, a status of each Internet-connected computing device that resides on the internal network by examining any responses received from the corresponding internal IP address.

13 . The non-transitory computer-readable medium of claim 12 , wherein said probing is performed on a periodic basis so that the status of each Internet-connected computing device can be monitored over a certain time interval.

14 . The non-transitory computer-readable medium of claim 13 , wherein the time interval is a day, a month, a year, or an indefinite period of time.

15 . The non-transitory computer-readable medium of claim 12 , wherein the operations further comprise:

storing, by the security management platform, data indicative of all responses for further analysis.

16 . An electronic device comprising:

a memory that includes instructions for discovering internal Internet Protocol (IP) addresses that communicate with external IP addresses via the Internet,

wherein the instructions, when executed by a processor, cause the processor to:

acquire global netflow that includes all traffic having a certain characteristic that traversed the Internet during a certain time interval;

filter the global netflow to obtain local netflow corresponding to an internal network on which the internal IP addresses resided during at least a portion of the certain time interval,

wherein the local netflow includes all traffic having the certain characteristic that crossed a perimeter of the internal network during the certain time interval;

parse the local netflow to identify each internal IP address that was involved in a public communication activity during the certain time interval;

create a first list that includes all internal IP addresses that were involved in public communication activities during the certain time interval;

compare the first list to a second list that includes all internal IP addresses that are presently being monitored; and

determine a risk posed by the public communication activities.

17 . The electronic device of claim 16 , wherein the instructions further cause the processor to:

determine that at least one internal IP address included in the first list is not included in the second list.

18 . The electronic device of claim 17 , wherein the instructions further cause the processor to:

generate a notification that identifies the at least one internal IP address; and

transmit the notification to a computing device associated with an administrator responsible for managing the internal network.

19 . The electronic device of claim 16 , wherein the instructions further cause the processor to:

retrieve the second list from a storage maintained by an organization associated with the internal network.

20 . The electronic device of claim 16 , wherein the global netflow is acquired from one or more scanning mechanisms deployed on the Internet.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2021
From: EXPANSE, LLC
To: PALO ALTO NETWORKS, INC.
Reel/Frame 056379/0222 →
CHANGE OF NAME Recorded May 24, 2021
From: EXPANSE, INC.
To: EXPANSE, LLC.
Reel/Frame 056355/0769 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2019
From: KRANING, MATTHEW; HEON, GREGORY; TOMAN, PAMELA
To: QADIUM, INC.
Reel/Frame 049408/0177 →
CHANGE OF NAME Recorded May 29, 2019
From: QADIUM, INC.
To: EXPANSE, INC.
Reel/Frame 049314/0179 →