IP Library Granted Patent US 11,240,114
Granted Patent B2
US 11,240,114 · App. 16/728,808 · Granted Feb 1, 2022

Network visibility

Inventors: Ilya Fainberg (Tel Aviv, IL); Anderson Lam (Fremont, CA); Mihael Sudakovitch (San Jose, CA)
Assignee: FORESCOUT TECHNOLOGIES, INC.
H04L41/12H04L41/069H04L43/04H04L43/10H04L63/1408H04L67/10G06F2009/45591
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,240,114
App. No.
16/728,808
Granted
Feb 1, 2022
Kind
B2
Abstract

Systems, methods, and related technologies for device monitoring are described. In certain aspects, network traffic data is analyzed to determine one or more devices associated with a network. The network may be a remote network. The network traffic data may further be used to determine one or more non-active devices associated with the network.

Claims (35)

1. A method comprising:

receiving, at a first time interval, device data associated with one or more devices coupled to a first network, wherein the device data comprises data of one or more active devices coupled to the first network;

receiving, at a second time interval, network traffic data associated with the first network at a device coupled to a second network, wherein the first time interval and the second time interval are independent;

determining, by a processing device, based on the network traffic data associated with the first network, one or more devices coupled to the first network during the second time interval that were not identified as active devices by the device data at the first time interval; and

storing information comprising first data associated with the one or more devices coupled to the first network and a second data associated with the one or more devices coupled to the first network during the second time interval that were not identified as active devices by the device data at the first time interval.

2. The method of claim 1 , wherein the first network is a remote network from the processing device.

3. The method of claim 1 , wherein the one or more devices coupled to the first network during the second time interval that were not identified as active devices by the device data at the first time interval comprises a virtual machine.

4. The method of claim 1 , wherein the first network is a cloud computing network.

5. The method of claim 4 , wherein the device data associated with the one or more devices coupled to the first network is from a cloud management system.

6. The method of claim 1 , wherein the device data associated with the one or more devices coupled to the first network is from a hypervisor.

7. The method of claim 1 further comprising:

initiating an action based on the data of one or more active devices coupled to the first network and data associated with the one or more devices coupled to the first network during the second time interval that were not identified as active devices by the device data at the first time interval associated with the first network.

8. The method of claim 7 , wherein the action comprises changing network access of a non-active device.

9. A system comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

receive, at a first time interval, device data associated with one or more devices coupled to a first network, wherein the device data comprises data of one or more active devices coupled to the first network;

receive, at a second time interval, network traffic data associated with the first network;

determine, based on the network traffic data associated with the first network, one or more devices coupled to the first network, wherein the first time interval and the second time interval are independent;

determine, based on the network traffic data and the device data, one or more non-active devices associated with the first network during the second time interval that were not identified as active devices by the device data during the first time interval; and

store information comprising first data associated with the one or more devices coupled to the first network and a second data associated with the one or more non-active devices coupled to the first network during the second time interval that were not identified as active devices by the device data at the first time interval.

10. The system of claim 9 , wherein the processing device further to:

initiate an action based on the information comprising the data of one or more active devices coupled to the first network and data associated with the one or more non-active devices associated with the first network.

11. The system of claim 10 , wherein the action comprises sending a notification associated with the one or more non-active devices.

12. The system of claim 9 , wherein the determination of the one or more non-active devices associated with the first network is based on a comparison of the network traffic data and the device data.

13. The system of claim 9 , wherein the first network is a cloud computing network.

14. The system of claim 9 , wherein the processing device is part of a network access control (NAC) device.

15. A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device, cause the processing device to:

request, at a first time interval, device data associated with one or more devices coupled to a first network;

send, at a second time interval, a request for network traffic data to a remote network, wherein the first time interval and the second time interval are independent;

receive the network traffic data;

determine a set of one or more devices associated with the remote network based on the network traffic data, wherein the set of one or more devices comprises one or more active devices associated with the remote network and one or more devices associated with the remote network during the second time interval that were not identified as active devices by the device data at the first time interval; and

store information comprising first data associated with the one or more devices coupled to the first network and a second data associated with the one or more devices coupled to the first network during the second time interval that were not identified as active devices by the device data at the first time interval.

16. The non-transitory computer readable medium of claim 15 , wherein the processing device further to: store the set of one or more devices associated with the remote network.

17. The non-transitory computer readable medium of claim 15 , wherein the processing device further to: initiate an action based on the set of one or more devices associated with the remote network.

Assignments (2)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 17, 2020
From: FORESCOUT TECHNOLOGIES, INC.
To: OWL ROCK CAPITAL CORPORATION, AS ADMINISTRATIVE AGENT
Reel/Frame 053519/0982 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 27, 2019
From: FAINBERG, ILYA; LAM, ANDERSON; SUDAKOVITCH, MIHAEL
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 051380/0550 →
Continuity (2)
Continuation 15420471 · Jan 31, 2017
Related Publication 20200136919A1 · Apr 30, 2020