IP Library Granted Patent US 11,316,861
Granted Patent B2
US 11,316,861 · App. 16/455,480 · Granted Apr 26, 2022

Automatic device selection for private network security

Inventor: Rajarshi Gupta (Los Altos, CA)
Assignee: Avast Software s.r.o.
H04L63/102H04L63/1416H04L63/1433H04L63/1441H04L63/164H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,316,861
App. No.
16/455,480
Granted
Apr 26, 2022
Kind
B2
Abstract

A method of selecting devices on a private network for security protection via a network security device comprises classifying devices on the private network into devices that are sometimes protected and devices that are always either protected or not protected. Threats are monitored, the threats comprising at least one of a macro security event and a local security event, the macro security event detected by one or more external systems and the local security event detected by one or more devices local to the private network. When a threat is detected, it is determined whether the detected threat is a threat to one or more devices on the private network classified as devices that are sometimes protected, and if the detected threat is determined to be a threat to the one or more devices that are sometimes protected the one or more devices are protected.

Claims (28)

1. A method of selecting devices on a private network for security protection via a network security device, comprising:

classifying devices on the private network into devices that are sometimes protected and devices that are always either protected or not protected;

detecting a threat comprising at least one of a macro security event and a local security event, the macro security event detected by one or more external systems and the local security event detected by one or more devices local to the private network;

determining whether the detected threat is a threat to one or more devices on the private network classified as devices that are sometimes protected; and

selectively protecting the one or more devices that are sometimes protected if the detected threat is determined to be a threat to the one or more devices that are sometimes protected.

2. The method of selecting devices on a private network for security protection via a network security device of claim 1 , wherein devices that are always protected comprise devices that receive little network traffic from a public network.

3. The method of selecting devices on a private network for security protection via a network security device of claim 1 , wherein devices that are never protected comprise devices that have high computational capability or that are configured to execute their own security software.

4. The method of selecting devices on a private network for security protection via a network security device of claim 1 , wherein devices that are sometimes protected comprise devices that receive substantial network traffic from the public network at least periodically and that do not execute their own security software.

5. The method of selecting devices on a private network for security protection via a network security device of claim 1 , wherein detection of a threat further comprises knowledge of one or more security events provided via a threat feed.

6. The method of selecting devices on a private network for security protection via a network security device of claim 1 , wherein determining whether the detected threat is a threat to one or more devices on the private network classified as devices that are sometimes protected comprises evaluating at least one of: a physical geography of the detected threat, a network location of the detected threat, and a type of device or devices affected by the network threat.

7. The method of selecting devices on a private network for security protection via a network security device of claim 1 , wherein selectively protecting the one or more devices that are sometimes protected is further based on whether the detected threat is a local threat or macro threat, such that a local threat results in a greater likelihood of selectively protecting a device that is sometimes protected.

8. The method of selecting devices on a private network for security protection via a network security device of claim 1 , wherein selectively protecting the one or more devices that are sometimes protected is achieved by Address Resolution Protocol (ARP) spoofing to insert the network security device in the network path between the selectively protected device and one or more public network devices.

9. The method of selecting devices on a private network for security protection via a network security device of claim 1 , further comprising selectively removing protection from the one or more devices that are sometimes protected if the detected threat is determined to no longer be a threat to the one or more devices that are sometimes protected.

10. The method of selecting devices on a private network for security protection via a network security device of claim 1 , wherein the network security device is connected to the private network and configured to communicate with a public network (cloud) security provider.

11. A network security device, comprising:

a processor and a memory;

a malware protection module operable when executed on the processor to detect a threat comprising at least one of a macro security event and a local security event, the macro security event detected by one or more external systems and reported to the network security device and the local security event detected by the network security device or another device local to the private network and reported to the network security device;

a configuration module operable when executed on the processor to classify devices on a private network into devices that are sometimes protected and devices that are always either protected or not protected, and to determine whether the detected threat is a threat to one or more devices on the private network classified as devices that are sometimes protected;

a proxy module operable when executed on the processor to selectively protect the one or more devices that are sometimes protected if the detected threat is determined to be a threat to the one or more devices that are sometimes protected by configuring the network so that data flows between the selectively protected devices and the public network are routed through the network security device.

12. The network security device of claim 11 , wherein devices that are always protected comprise devices that receive little network traffic from a public network.

13. The network security device of claim 11 , wherein devices that are never protected comprise devices that have high computational capability or that are configured to execute their own security software.

14. The network security device of claim 11 , wherein devices that are sometimes protected comprise devices that receive substantial network traffic from the public network at least periodically and that do not execute their own security software.

15. The network security device of claim 11 , wherein detecting a threat further comprises receiving knowledge of one or more security events provided via a threat feed.

16. The network security device of claim 11 , wherein determining whether the detected threat is a threat to one or more devices on the private network classified as devices that are sometimes protected comprises evaluating at least one of: a physical geography of the detected threat, a network location of the detected threat, and a type of device or devices affected by the network threat.

17. The network security device of claim 11 , wherein selectively protecting the one or more devices that are sometimes protected is further based on whether the detected threat is a local threat or macro threat, such that a local threat results in a greater likelihood of selectively protecting a device that is sometimes protected.

18. The network security device of claim 11 , wherein selectively protecting the one or more devices that are sometimes protected is achieved by Address Resolution Protocol (ARP) spoofing to insert the network security device in the network path between the selectively protected device and one or more public network devices.

19. The network security device of claim 11 , the proxy module further operable to selectively remove protection from the one or more devices that are sometimes protected if the detected threat is determined to no longer be a threat to the one or more devices that are sometimes protected.

20. The network security device of claim 11 , wherein the network security device is connected to the private network and configured to communicate with a public network (cloud) security provider.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: GEN DIGITAL AMERICAS S.R.O.
To: GEN DIGITAL INC.
Reel/Frame 071771/0767 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: AVAST SOFTWARE S.R.O.
To: GEN DIGITAL AMERICAS S.R.O.
Reel/Frame 071777/0341 →
RELEASE OF SECURITY INTEREST Recorded Mar 26, 2021
From: CREDIT SUISSE INTERNATIONAL, AS COLLATERAL AGENT
To: AVAST SOFTWARE, S.R.O.
Reel/Frame 055726/0435 →
SECURITY INTEREST Recorded May 6, 2020
From: AVAST SOFTWARE S.R.O.
To: CREDIT SUISSE INTERNATIONAL, AS COLLATERAL AGENT
Reel/Frame 052582/0285 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: GUPTA, RAJARSHI
To: AVAST SOFTWARE S.R.O.
Reel/Frame 051073/0081 →