IP Library Granted Patent US 11,689,573
Granted Patent B2
US 11,689,573 · App. 16/731,678 · Granted Jun 27, 2023

Multi-layered policy management

Inventor: Jun Du (Cupertino, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/20G16Y30/10H04L41/0631H04L41/22H04L63/104H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,689,573
App. No.
16/731,678
Granted
Jun 27, 2023
Kind
B2
Abstract

Techniques for enforcing policy on multiple levels, including context-based and/or packet-based, as well as one or more of event-based, activity-based, and behavior-based. Higher-level abstraction of policy enables IP endpoint discovery and classification for which predefined multi-level policy can be applied. Management of policy can abstract lower-level parameters in favor of a higher-level of abstraction, which enables integration with an asset management platform.

Claims (30)

1. A method comprising:

dynamically generating, in response to detecting a threshold number of anomalies, a multi-level policy for a set of Internet of Things (IoT) devices, the multi-level policy comprising a first policy at a low level of abstraction and a second policy at a high level of abstraction, wherein the first policy at the low level of abstraction is generated at least in part in response to a specification of the second policy at the high level of abstraction, and wherein the second policy references an action to take if a particular activity is attempted by a device included in the set of IoT devices;

discovering an Internet Protocol (IP) endpoint, the IP endpoint corresponding to an IoT device;

classifying the IP endpoint; and

applying the generated multi-level policy to the IP endpoint based on the classification of the IP endpoint.

2. The method of claim 1 , further comprising:

detecting a deviation from the multi-level policy in operation of the IoT device; and

generating and sending an alert to an administrator of a network.

3. The method of claim 1 , wherein the first policy at the low level of abstraction is one or more of context-based and packet-based.

4. The method of claim 1 , wherein the first policy at the low level of abstraction is at least context-based, and context includes one or more of background event context, identity-based context, and group-based context.

5. The method of claim 1 , wherein the first policy at the low level of abstraction is at least packet-based, and is based at least in part on patterns in packets that match regular expressions of policy rules.

6. The method of claim 1 , wherein the second policy at the high level of abstraction is one or more of event-based, activity-based, and behavior-based.

7. The method of claim 1 , wherein the second policy at the high level of abstraction is at least event-based, and is based at least in part on converting patterns to fields of an event.

8. The method of claim 1 , wherein an administrator of a network is permitted to modify the second policy at the high level of abstraction and the first policy at the low level of abstraction.

9. The method of claim 1 , wherein an administrator of a network is permitted to modify the second policy at the high level of abstraction and is not permitted to modify the first policy at the low level of abstraction.

10. The method of claim 1 , wherein one or more of generating the multi-level policy and classifying the IP endpoint is based at least in part on machine learning.

11. A system comprising:

a multi-level policy management engine configured to dynamically generate, in response to detecting a threshold number of anomalies, a multi-level policy for a set of Internet of Things (IoT) devices, the multi-level policy comprising a first policy at a low level of abstraction and a second policy at a high level of abstraction, wherein the first policy at the low level of abstraction is generated at least in part in response to a specification of the second policy at the high level of abstraction, and wherein the second policy references an action to take if a particular activity is attempted by a device included in the set of IoT devices;

an Internet Protocol (IP) endpoint discovery and classification engine configured to discover an IP endpoint, the IP endpoint corresponding to an IoT device;

classify the IP endpoint; and

a multi-level policy compliance detection engine configured to apply the generated multi-level policy to the IP endpoint based on the classification of the IP endpoint.

12. The system of claim 11 , wherein the multi-level policy compliance detection engine is further configured to detect a deviation from the multi-level policy in operation of the IoT device, and wherein the system further comprises a signal correlation engine configured to generate and send an alert to an administrator of a network.

13. The system of claim 11 , wherein the first policy at the low level of abstraction is one or more of context-based and packet-based.

14. The system of claim 11 , wherein the first policy at the low level of abstraction is at least context-based, and context includes one or more of background event context, identity-based context, and group-based context.

15. The system of claim 11 , wherein the first policy at the low level of abstraction is at least packet-based, and is based at least in part on patterns in packets that match regular expressions of policy rules.

16. The system of claim 11 , wherein the second policy at the high level of abstraction is one or more of event-based, activity-based, and behavior-based.

17. The system of claim 11 , wherein the second policy at the high level of abstraction is at least event-based, and is based at least in part on converting patterns to fields of an event.

18. The system of claim 11 , wherein an administrator of a network is permitted to modify the second policy at the high level of abstraction and the first policy at the low level of abstraction.

19. The system of claim 11 , wherein an administrator of a network is permitted to modify the second policy at the high level of abstraction and is not permitted to modify the first policy at the low level of abstraction.

20. The system of claim 11 , wherein one or more of generating the multi-level policy and classifying the IP endpoint is based at least in part on machine learning.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2020
From: DU, JUN
To: PALO ALTO NETWORKS, INC.
Reel/Frame 052653/0296 →
Continuity (2)
Provisional Application 62787190 · Dec 31, 2018
Related Publication 20200213361A1 · Jul 2, 2020