IP Library › Granted Patent US 12,218,912
Granted Patent B2
US 12,218,912 · App. 16/854,616 · Granted Feb 4, 2025

Telemetry collection and policy enforcement using asset tagging

Inventors: Robert Edgar Barton (Richmond, CA); Thomas Szigeti (Vancouver, CA); Jerome Henry (Pittsboro, NC); Ruben Gerald Lobo (Raleigh, NC); Laurent Jean Charles Hausermann (Lyons, FR); Maik Guenter Seewald (Nuremberg, DE); Daniel R. Behrens (Chardon, OH)
Assignee: Cisco Technology, Inc.
H04L63/0263G05B19/05G06Q10/0875H04L12/4641H04L41/0803H04L41/0893H04L43/026H04L47/20H04L47/2441H04L47/323H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,218,912
App. No.
16/854,616
Granted
Feb 4, 2025
Kind
B2
Abstract

According to one or more embodiments of the disclosure, a networking device receives a policy for an endpoint in a network. The policy specifies one or more component tags and one or more activity tags that were assigned to the endpoint based on deep packet inspection of traffic associated with the endpoint. The networking device identifies a set of tags for a particular traffic flow in the network associated with the endpoint. The set of tags comprises one or more component tags or activity tags associated with the particular traffic flow. The networking device makes a determination that the particular traffic flow violates the policy based on the set of tags comprising a tag that is not in the policy. The networking device initiates, based on the determination that the particular traffic flow violates the policy, a corrective measure with respect to the particular traffic flow.

Claims (38)

1. A method comprising:

receiving, at a networking device in a network, a policy for an endpoint device in the network, the policy specifying one or more component tags and one or more activity tags that were assigned to the endpoint device based on deep packet inspection of traffic associated with the endpoint device, wherein the one or more component tags that were assigned to the endpoint device are indicative of at least one of: a device type of the endpoint device or software executed by the endpoint device;

identifying, by the networking device, a set of tags for a particular traffic flow in the network associated with the endpoint device based on receiving, from a telemetry exporter in the network, a traffic flow record for the particular traffic flow, wherein the set of tags are embedded in the traffic flow record, and wherein the set of tags comprises one or more component tags or activity tags associated with the particular traffic flow;

making, by the networking device, a determination that the particular traffic flow violates the policy based on the set of tags for the particular traffic flow comprising a tag that is not in the policy, wherein the determination that the particular traffic flow violates the policy is made by comparing the set of tags for the particular traffic flow with the one or more component tags and the one or more activity tags specified by the policy; and

initiating, by the networking device and based on the determination that the particular traffic flow violates the policy, a corrective measure with respect to the particular traffic flow.

2. The method as in claim 1 , wherein initiating the corrective measure comprises:

blocking, by the networking device, the particular traffic flow from being delivered to the endpoint device.

3. The method as in claim 1 , wherein the networking device comprises a router or network switch.

4. The method as in claim 1 , wherein the policy is indicative of a baseline behavioral profile for the endpoint device, and wherein making the determination that the particular traffic flow violates the policy comprises:

computing, based on the baseline behavioral profile for the endpoint device, a probability that the set of tags is indicative of an anomalous behavior of the endpoint device.

5. The method as in claim 4 , wherein the anomalous behavior of the endpoint device corresponds to the endpoint device attempting to install software to another endpoint device in the network.

6. The method as in claim 4 , wherein the probability is computed using a Naïve Bayes classifier.

7. The method as in claim 1 , wherein the one or more activity tags that were assigned to the endpoint device based on deep packet inspection of traffic associated with the endpoint device are indicative of a behavior of the endpoint device.

8. An apparatus, comprising:

one or more network interfaces to communicate with a network;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process when executed configured to:

receive a policy for an endpoint device in a network, the policy specifying one or more component tags and one or more activity tags that were assigned to the endpoint device based on deep packet inspection of traffic associated with the endpoint device, wherein the one or more component tags that were assigned to the endpoint device are indicative of at least one of: a device type of the endpoint device or software executed by the endpoint device;

identify a set of tags for a particular traffic flow in the network associated with the endpoint device based on receiving, from a telemetry exporter in the network, a traffic flow record for the particular traffic flow, wherein the set of tags are embedded in the traffic flow record, and wherein the set of tags comprises one or more component tags or activity tags associated with the particular traffic flow;

make a determination that the particular traffic flow violates the policy based on the set of tags for the particular traffic flow comprising a tag that is not in the policy, wherein the determination that the particular traffic flow violates the policy is made by comparing the set of tags for the particular traffic flow with the one or more component tags and the one or more activity tags specified by the policy; and

initiate, based on the determination that the particular traffic flow violates the policy, a corrective measure with respect to the particular traffic flow.

9. The apparatus as in claim 8 , wherein the apparatus initiates the corrective measure by:

blocking the particular traffic flow from being delivered to the endpoint device.

10. The apparatus as in claim 8 , wherein the apparatus comprises a router or network switch.

11. The apparatus as in claim 8 , wherein the policy is indicative of a baseline behavioral profile for the endpoint device, and wherein the apparatus makes the determination that the particular traffic flow violates the policy by:

computing, based on the baseline behavioral profile for the endpoint device, a probability that the set of tags is indicative of an anomalous behavior of the endpoint device.

12. The apparatus as in claim 11 , wherein the anomalous behavior of the endpoint device corresponds to the endpoint device attempting to install software to another endpoint device in the network.

13. The apparatus as in claim 11 , wherein the probability is computed using a Naïve Bayes classifier.

14. The apparatus as in claim 8 , wherein the one or more activity tags that were assigned to the endpoint device based on deep packet inspection of traffic associated with the endpoint device are indicative of a behavior of the endpoint device.

15. A tangible, non-transitory, computer-readable medium storing program instructions that cause a device in a network to execute a process comprising:

receiving a policy for an endpoint device in the network, the policy specifying one or more component tags and one or more activity tags that were assigned to the endpoint device based on deep packet inspection of traffic associated with the endpoint device, wherein the one or more component tags that were assigned to the endpoint device are indicative of at least one of: a device type of the endpoint device or software executed by the endpoint device;

identifying a set of tags for a particular traffic flow in the network associated with the endpoint device based on receiving, from a telemetry exporter in the network, a traffic flow record for the particular traffic flow, wherein the set of tags are embedded in the traffic flow record, and wherein the set of tags comprises one or more component tags or activity tags associated with the particular traffic flow;

making a determination that the particular traffic flow violates the policy based on the set of tags for the particular traffic flow comprising a tag that is not in the policy, wherein the determination that the particular traffic flow violates the policy is made by comparing the set of tags for the particular traffic flow with the one or more component tags and the one or more activity tags specified by the policy; and

initiating, based on the determination that the particular traffic flow violates the policy, a corrective measure with respect to the particular traffic flow.

16. The medium as in claim 15 , wherein initiating the corrective measure comprises:

blocking the particular traffic flow from being delivered to the endpoint device.

17. The medium as in claim 15 , wherein the policy is indicative of a baseline behavioral profile for the endpoint device, and wherein making the determination that the particular traffic flow violates the policy comprises:

computing, based on the baseline behavioral profile for the endpoint device, a probability that the set of tags is indicative of an anomalous behavior of the endpoint device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2020
From: BARTON, ROBERT EDGAR; SZIGETI, THOMAS; HENRY, JEROME; LOBO, RUBEN GERALD; HAUSERMANN, LAURENT JEAN CHARLES; SEEWALD, MAIK GUENTER; BEHRENS, DANIEL R.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 052456/0475 →
Continuity (2)
Provisional Application 62951645 · Dec 20, 2019
Related Publication 20210194815A1 · Jun 24, 2021
References Cited (29)
US 8682812B1 · Ranjan · 2014 [cited by examiner]
US 9143563B2 · Pingel et al. · 2015 [cited by applicant]
US 10389550B1 · Bharadwaj · 2019 [cited by examiner]
US 10432669B1 · Badhwar · 2019 [cited by examiner]
US 10447540B2 · Yang et al. · 2019 [cited by applicant]
US 10530749B1 · Park et al. · 2020 [cited by applicant]
US 20120023217A1 · Wakumoto · 2012 [cited by examiner]
US 20130054601A1 · Whitlock · 2013 [cited by examiner]
US 20140137257A1 · Martinez et al. · 2014 [cited by applicant]
US 20150326528A1 · Murthy · 2015 [cited by examiner]
US 20160359897A1 · Yadav · 2016 [cited by examiner]
US 20180276254A1 · Whitlock et al. · 2018 [cited by applicant]
US 20190014137A1 · Du et al. · 2019 [cited by applicant]
US 20200007360A1 · Turner · 2020 [cited by examiner]
US 20200162391A1 · Savalle · 2020 [cited by examiner]
US 20200296139A1 · Fainberg · 2020 [cited by examiner]
US 20200358794A1 · Vasseur et al. · 2020 [cited by applicant]
US 20200366578A1 · Punj · 2020 [cited by examiner]
“Asset Intelligence: Focus on the OT and IoT Incidents that Matter”, Data Sheet, 2020, 4 pages, Nozomi Networks, Inc. [cited by applicant]
“Create a Tag”, Jan. 2020, 1 page, ExtraHop Networks, Inc. [cited by applicant]
“Devices”, Jan. 2020, 8 pages, ExtraHop. [cited by applicant]
“Extreme Visibility: Why Extreme Visibility in Industrial Networks is no Longer just a Nice-to-Have”, White Paper, Dec. 2018, 5 pages, Claroty, Clarity for OT Networks. [cited by applicant]
“Find a Device”, Jan. 2020, 8 pages, ExtraHop. [cited by applicant]
“ForeScout for Operational Technology (OT)”, Datasheet,2018, 4 pages, ForeScout Technologies, Inc. [cited by applicant]
“Introduction to the ExtraHop System”, Jan. 2020, 7 pages, ExtraHop. [cited by applicant]
“OT and IoT Security and Visibility”, Solution Brief, 2020, 12 pages, Nozomi Networks, Inc. [cited by applicant]
“Overview of Cisco TrustSec”, Jul. 2019, 6 pages, Cisco.com. [cited by applicant]
“Threat Intelligence”, Data Sheet, 2020, 4 pages, Nozomi Networks, Inc. [cited by applicant]
“What is Network Segmentation?”, online: https://www.cisco.com/c/en/us/products/security/what-is-network-segmentation.html, printed Apr. 2020, 3 pages, Cisco.com. [cited by applicant]