IP Library Granted Patent US 11,431,602
Granted Patent B2
US 11,431,602 · App. 16/837,276 · Granted Aug 30, 2022

Network asset discovery

Inventors: Connor Leete Gilbert (Menlo Park, CA); Michael Haggblade (San Bruno, CA)
Assignee: Palo Alto Networks, Inc.
H04L43/10H04L63/20H04L67/16H04L29/06H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,431,602
App. No.
16/837,276
Granted
Aug 30, 2022
Kind
B2
Abstract

A system for detecting network assets or attributes related to a network entity includes an input interface and a processor. The input interface is to receive a seed. The seed is associated with the network entity. The processor is to determine a first set of network assets or attributes associated with the seed and to determine a second set of network assets or attributes based at least in part on the first set of assets or attributes.

Claims (109)

1. A system for describing target entities in a network, comprising:

an input interface configured to receive an initial descriptor associated with a network including target network entities, the initial descriptor indicative of a first feature of the network, wherein the input interface is configured as architecturally external to the network wherein the target network entities reside; and

a processor configured to:

identify additional features of the network, including a second feature, based on an outside view of the network using the first feature;

identify further additional features of the network, including a third feature, based on an outside view of the network using the second feature;

iterate a subsequent set of network features based on an outside view of the network using each additional feature of the network identified, including the second feature and the third feature, until a diminishing returns criterion is met, wherein each iteration uses an output of a previous iteration as input as a set of parameters in a current iteration; and

update a set of features for the network that describe the target network entities based on the first feature, the additional features, the further additional features, and the subsequent set of network features.

2. The system of claim 1 , wherein the processor is further configured to:

determine a security evaluation of the target network entities.

3. The system of claim 1 , wherein the processor is further configured to:

create a map of the target network entities, wherein the map of the target network entities describes relationships within the network as visible externally from the network.

4. The system of claim 1 , wherein the processor is further configured to:

compare the set of features for the network that describe the target network entities with an expected set of network assets or attributes based on internal network view.

5. The system of claim 4 , wherein the processor is further configured to:

evaluate the set of features for the network that describe the target network entities based at least in part on the set of expected network assets or attributes.

6. The system of claim 1 , wherein identification of additional features, further additional features, or the subsequent set of network features is based at least in part on any of:

a WHOIS service;

regional Internet registry information;

DNS information;

certificate information;

cryptographic information; or

autonomous system number information.

7. The system of claim 1 , wherein identification of additional features, further additional features, or the subsequent set of network features is based at least in part on software version, firmware version, or hardware version information.

8. The system of claim 4 , wherein identification of additional features, further additional features, or the subsequent set of network features is based at least in part on unique identifying attributes of the network asset's software, firmware, or hardware.

9. The system of claim 1 , wherein the processor is further configured to:

determine a relationship between the first feature and the second feature.

10. The system of claim 9 , wherein the relationship comprises any of:

an “is owned by” relationship;

an “was previously owned by” relationship;

an “is operated by” relationship;

an “was previously operated by” relationship;

an “is manufactured by” relationship;

an “is maintained by” relationship;

an “was previously maintained by” relationship;

an “is operated on behalf of’ relationship;

an “was previously operated on behalf of by” relationship;

an “is associated with” relationship;

an “was previously associated with” relationship;

an “has configuration parameters or software versions identical or similar to” relationship; or

an “has displayed configuration parameters or software versions identical or similar to” relationship.

11. A method for describing target entities in a network, comprising:

receiving an initial descriptor associated with a network including target network entities, the initial descriptor indicative of a first feature of the network;

identifying additional features of the network, including a second feature, based on an architecturally external view of the network using the first feature;

identifying further additional features of the network, including a third feature, based on an architecturally external view of the network using the second feature;

iterating a subsequent set of network features based on an architecturally external view of the network using each additional feature of the network identified, including the second feature and the third feature, until a diminishing returns criterion is met, wherein each iteration uses an output of a previous iteration as input as a set of parameters in a current iteration; and

updating a set of features for the network that describe the target network entities based on the first feature, the additional features, the further additional features, and the subsequent set of network features.

12. The method of claim 11 , further comprising:

determining a security evaluation of the target network entities.

13. The method of claim 11 , further comprising:

creating a map of the target network entities, wherein the map of the target network entities describes relationships within the network as visible externally from the network.

14. The method of claim 11 , further comprising:

comparing the set of features for the network that describe the target network entities with an expected set of network assets or attributes based on internal network view.

15. The method of claim 11 , wherein identification of additional features, further additional features, or the subsequent set of network features is based at least in part on any of:

a WHOIS service;

regional Internet registry information;

DNS information;

certificate information;

cryptographic information; or

autonomous system number information.

16. The method of claim 11 , further comprising:

determining a relationship between the first feature and the second feature.

17. The method of claim 16 , wherein the relationship comprises any of:

an “is owned by” relationship;

an “was previously owned by” relationship;

an “is operated by” relationship;

an “was previously operated by” relationship;

an “is manufactured by” relationship;

an “is maintained by” relationship;

an “was previously maintained by” relationship;

an “is operated on behalf of relationship;

an “was previously operated on behalf of by” relationship;

an “is associated with” relationship;

an “was previously associated with” relationship;

an “has configuration parameters or software versions identical or similar to” relationship; or an “has displayed configuration parameters or software versions identical or similar to” relationship.

18. A computer program product for describing target entities in a network, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving an initial descriptor associated with a network including target network entities, the initial descriptor indicative of a first feature of the network;

identifying additional features of the network, including a second feature, based on an architecturally external view of the network using the first feature;

identifying further additional features of the network, including a third feature, based on an architecturally external view of the network using the second feature;

iterating a subsequent set of network features based on an architecturally external view of the network using each additional feature of the network identified, including the second feature and the third feature, until a diminishing returns criterion is met, wherein each iteration uses an output of a previous iteration as input as a set of parameters in a current iteration; and

updating a set of features for the network that describe the target network entities based on the first feature, the additional features, the further additional features, and the subsequent set of network features.

19. The computer readable storage medium of claim 18 , further comprising computer instructions for:

determining a security evaluation of the target network entities.

20. The computer readable storage medium of claim 18 , further comprising computer instructions for:

creating a map of the target network entities, wherein the map of the target network entities describes relationships within the network as visible externally from the network.

21. The computer readable storage medium of claim 18 , further comprising computer instructions for:

comparing the set of features for the network that describe the target network entities with an expected set of network assets or attributes based on internal network view.

22. The computer readable storage medium of claim 18 , wherein identification of additional features, further additional features, or the subsequent set of network features is based at least in part on any of:

a WHOIS service;

regional Internet registry information;

DNS information;

certificate information;

cryptographic information; or

autonomous system number information.

23. The computer readable storage medium of claim 18 , further comprising computer instructions for:

determining a relationship between the first feature and the second feature.

24. The computer readable storage medium of claim 23 , wherein the relationship comprises any of:

an “is owned by” relationship;

an “was previously owned by” relationship;

an “is operated by” relationship;

an “was previously operated by” relationship;

an “is manufactured by” relationship;

an “is maintained by” relationship;

an “was previously maintained by” relationship;

an “is operated on behalf of’ relationship;

an “was previously operated on behalf of by” relationship;

an “is associated with” relationship;

an “was previously associated with” relationship;

an “has configuration parameters or software versions identical or similar to” relationship; or

an “has displayed configuration parameters or software versions identical or similar to” relationship.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2021
From: GILBERT, CONNOR LEETE; HAGGBLADE, MICHAEL
To: QADIUM, INC.
Reel/Frame 056499/0784 →
CHANGE OF NAME Recorded Jun 10, 2021
From: QADIUM, INC.
To: EXPANSE, INC.
Reel/Frame 056540/0543 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2021
From: EXPANSE, LLC
To: PALO ALTO NETWORKS, INC.
Reel/Frame 056379/0222 →
CHANGE OF NAME Recorded May 24, 2021
From: EXPANSE, INC.
To: EXPANSE, LLC.
Reel/Frame 056355/0769 →
Continuity (2)
Continuation 14966320 · Dec 11, 2015
Related Publication 20200228432A1 · Jul 16, 2020