IP Library Granted Patent US 11,563,776
Granted Patent B2
US 11,563,776 · App. 16/844,678 · Granted Jan 24, 2023

Compliance monitoring

Inventors: Anderson Lam (Fremont, CA); Kevin Benjamin Mayer (Tel Aviv, IL); Yuri Mikhel (Los Gatos, CA); Gilad Walden (Tel Aviv, IL)
Assignee: FORESCOUT TECHNOLOGIES, INC.
H04L63/20H04L63/102H04L63/105H04L63/1408H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,563,776
App. No.
16/844,678
Granted
Jan 24, 2023
Kind
B2
Abstract

Systems, methods, and related technologies for device compliance monitoring are described. In certain aspects, one or more compliance rules associated with a device classification are used to determine a compliance level of a device. The one or more compliance rules may be based on a standard. An action can be initiated based on the compliance level.

Claims (43)

1. A method comprising:

detecting, by a compliance monitoring device, a device coupled to a network;

determining a classification of the device based on traffic information associated with the device, wherein the traffic information comprises at least one of a port or a protocol being used by the device;

identifying a compliance policy comprising one or more compliance rules that are associated with the classification of the device;

accessing a compliance rule of the one or more compliance rules based on the classification of the device;

performing, by a processing device of the compliance monitoring device, a compliance scan on the device based on the compliance rule associated with the classification of the device;

determining a compliance level of the device based on a result of the compliance scan of the device; and

performing an action based on the compliance level.

2. The method of claim 1 , wherein the compliance scan of the device is performed periodically.

3. The method of claim 1 , wherein determining the classification of the device is based on a media access control (MAC) address of the device.

4. The method of claim 1 , wherein determining the classification of the device is based on traffic information associated with the device.

5. The method of claim 1 , further comprising:

performing another compliance scan of the device based on a security policy.

6. The method of claim 1 , wherein the action comprises changing network access of the device.

7. The method of claim 1 , wherein the compliance scan of the device is performed automatically according to a security policy.

8. The method of claim 1 , wherein the compliance rule is associated with a weight and the compliance level is based on the weight.

9. The method of claim 1 , wherein the action comprises automatically initiating an update service associated with the device.

10. The method of claim 1 , wherein the action comprises initiating a patch service associated with the device.

11. A compliance monitoring system comprising:

a memory; and

a processing device of the compliance monitoring system, operatively coupled to the memory, to:

determine a classification of a plurality of devices based on traffic information associated with the plurality of devices, wherein the traffic information comprises at least one of a port or a protocol being used by each of the plurality of devices;

access compliance data associated with the classification of the plurality of devices, wherein the compliance data comprises a plurality of compliance rules associated with the classification of the plurality of devices and a respective weight associated with each of the plurality of compliance rules;

perform a respective compliance scan of each of the plurality of devices based on the plurality of compliance rules associated with the classification of each respective device of the plurality of devices;

determine a respective compliance level for each of the plurality of devices, wherein the respective compliance level is determined based on the plurality of compliance rules and the respective weight associated with each compliance rule; and

initiate an action based on the compliance level for each device of the plurality of devices.

12. The system of claim 11 , wherein the respective compliance scan of each of the plurality of devices is performed periodically.

13. The system of claim 11 , wherein to determine the classification, the processing device is to determine the classification of each of the plurality of devices based on a respective media access control (MAC) address of each of the plurality of devices.

14. The system of claim 11 , wherein to determine the classification, the processing device is to determine the classification of each of the plurality of devices based on a respective traffic information associated with each of the plurality of devices.

15. The system of claim 11 , wherein the processing device is further to compare the compliance level of a device with a second threshold and the action is further based on the comparison of the compliance level of the device with the second threshold.

16. A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device of a compliance monitoring device, cause the processing device to:

detect, by the processing device of the compliance monitoring device, a device being coupled to a network;

determine a classification of the device based on traffic information associated with the device, wherein the traffic information comprises at least one of a port or a protocol being used by the device;

identifying a compliance policy comprising a plurality of compliance rules that are associated with the classification of the device;

access the plurality of compliance rules associated with the classification of the device, wherein the plurality of compliance rules are associated with a standard;

determine a compliance level of the device based on the plurality of compliance rules associated with the classification of the device;

compare, by the processing device, by the processing device of the compliance monitoring device, the compliance level to a threshold;

initiate a first action based on the compliance level being above the threshold; and

initiate a second action based on the compliance level being below the threshold.

17. The non-transitory computer readable medium of claim 16 , wherein the first action comprises granting substantially full network access to the device.

18. The non-transitory computer readable medium of claim 17 , wherein the processing device is further to perform an additional action based on the compliance level being above the threshold.

19. The non-transitory computer readable medium of claim 18 , wherein the additional action comprises at least one of a remediation action, logging information, or an information action.

20. The non-transitory computer readable medium of claim 16 , wherein the second action comprises granting limited network access to the device.

Assignments (2)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 17, 2020
From: FORESCOUT TECHNOLOGIES, INC.
To: OWL ROCK CAPITAL CORPORATION, AS ADMINISTRATIVE AGENT
Reel/Frame 053519/0982 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2020
From: LAM, ANDERSON; MAYER, KEVIN BENJAMIN; MIKHEL, YURI; WALDEN, GILAD
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 052362/0703 →
Continuity (2)
Continuation 15383137 · Dec 19, 2016
Related Publication 20200259867A1 · Aug 13, 2020