IP Library Granted Patent US 11,522,775
Granted Patent B2
US 11,522,775 · App. 16/867,791 · Granted Dec 6, 2022

Application monitoring prioritization

Inventors: Jackson Ngoc Ki Pang (Sunnyvale, CA); Navindra Yadav (Cupertino, CA); Anubhav Gupta (Fremont, CA); Shashidhar Gandham (Fremont, CA); Supreeth Hosur Nagesh Rao (Cupertino, CA); Sunil Kumar Gupta (Milpitas, CA)
Assignee: Cisco Technology, Inc.
H04L43/045G06F3/0482G06F3/04842G06F3/04847G06F9/45558G06F16/122G06F16/137G06F16/162G06F16/17G06F16/173G06F16/174G06F16/1744G06F16/1748G06F16/235G06F16/2322G06F16/2365G06F16/248G06F16/24578G06F16/285G06F16/288G06F16/29G06F16/9535G06F21/53G06F21/552G06F21/556G06F21/566G06N20/00G06N99/00G06T11/206H04J3/0661H04J3/14H04L1/242H04L9/0866H04L9/3239H04L9/3242H04L41/046H04L41/0668H04L41/0803H04L41/0806H04L41/0816H04L41/0893H04L41/12H04L41/16H04L41/22H04L43/02H04L43/026H04L43/04H04L43/062H04L43/08H04L43/0805H04L43/0811H04L43/0829H04L43/0841H04L43/0858H04L43/0864H04L43/0876H04L43/0882H04L43/0888H04L43/10H04L43/106H04L43/12H04L43/16H04L45/306H04L45/38H04L45/46H04L45/507H04L45/66H04L45/74H04L47/11H04L47/20H04L47/2441H04L47/2483H04L47/28H04L47/31H04L47/32H04L61/5007H04L63/0227H04L63/0263H04L63/06H04L63/0876H04L63/145H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/1458H04L63/1466H04L63/16H04L63/20H04L67/01H04L67/10H04L67/1001H04L67/12H04L67/51H04L67/75H04L69/16H04L69/22H04W72/08H04W84/18G06F2009/4557G06F2009/45587G06F2009/45591G06F2009/45595G06F2221/033G06F2221/2101G06F2221/2105G06F2221/2111G06F2221/2115G06F2221/2145H04L67/535
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,522,775
App. No.
16/867,791
Granted
Dec 6, 2022
Kind
B2
Abstract

An approach for establishing a priority ranking for endpoints in a network. This can be useful when triaging endpoints after an endpoint becomes compromised. Ensuring that the most critical and vulnerable endpoints are triaged first can help maintain network stability and mitigate damage to endpoints in the network after an endpoint is compromised. The present technology involves determining a criticality ranking and a secondary value for a first endpoint in a datacenter. The criticality ranking and secondary value can be combined to form priority ranking for the first endpoint which can then be compared to a priority ranking for a second endpoint to determine if the first endpoint or the second endpoint should be triaged first.

Claims (53)

1. A computer-implemented method comprising:

determining a first plurality of values for a first endpoint;

determining a first priority ranking of the first endpoint based on the first plurality of values;

determining a second plurality of values for a second endpoint;

determining a second priority ranking of the second endpoint based on the second plurality of values;

comparing the first priority ranking and the second priority ranking;

when the first priority ranking is higher than the second priority ranking, triaging the first endpoint;

when the second priority ranking is higher than the first priority ranking, triaging the second endpoint; and

when the first priority ranking and the second priority ranking are determined to be a same priority ranking, execute a tie-breaker process including:

determining a first secondary value for the first endpoint;

determining a second value for the second endpoint;

determining, based on the first priority ranking, the first secondary value, the second priority ranking, and the second secondary value, that one of the first endpoint and the second endpoint is a higher priority endpoint; and

triaging the higher priority endpoint to mitigate endpoint damage.

2. The computer-implemented method of claim 1 , further comprising:

detecting a compromised endpoint.

3. The computer-implemented method of claim 2 , wherein the detecting of the compromised endpoint includes analyzing flow data from a plurality of sensors associated with the compromised endpoint.

4. The computer-implemented method of claim 1 , further comprising:

labeling the first endpoint with a criticality ranking via a prioritization list of labels.

5. The computer-implemented method of claim 1 , wherein the determining of the first priority ranking is based on a prioritization list of labels.

6. A non-transitory computer-readable medium having computer readable instructions that, when executed by a processor of a computer, cause the computer to:

determine a first plurality of values for a first endpoint;

determine a first priority ranking of the first endpoint based on the first plurality of values;

determine a second plurality of values for a second endpoint;

determine a second priority ranking of the second endpoint based on the second plurality of values;

compare the first priority ranking and the second priority ranking;

when the first priority ranking is higher than the second priority ranking, triaging the first endpoint;

when the second priority ranking is higher than the first priority ranking, triaging the second endpoint; and

when the first priority ranking and the second priority ranking are determined to be a same criticality ranking, execute a tie-breaker process including:

determine a first secondary value for the first endpoint;

determine a second secondary value for the second endpoint;

determine, based on the first priority ranking, the first secondary value, the second priority ranking, and the second secondary value, that one of the first endpoint and the second endpoint is a higher priority endpoint; and

triage the higher priority endpoint.

7. The non-transitory computer-readable medium of claim 6 , comprising further instructions, which when executed, cause the computer to detect a compromised endpoint.

8. The non-transitory computer-readable medium of claim 7 , wherein detecting the compromised endpoint includes analyzing flow data from a plurality of sensors associated with the compromised endpoint.

9. The non-transitory computer-readable medium of claim 6 , comprising further instructions, which when executed cause the computer to label the first endpoint with a criticality ranking via a prioritization list of labels.

10. The non-transitory computer-readable medium of claim 6 , wherein determining the first priority ranking is based on a prioritization list of labels.

11. A system comprising:

a processor;

a memory including instructions that when executed by the processor, cause the system to:

determine a first plurality of values for a first endpoint;

determine a first priority ranking of the first endpoint based on the first plurality of values;

determine a second plurality of values for a second endpoint;

determine a second priority ranking of the second endpoint based on the second plurality of values;

compare the first priority ranking and the second priority ranking;

when the first priority ranking is higher than the second priority ranking, triaging the first endpoint;

when the second priority ranking is higher than the first priority ranking, triaging the second endpoint; and

when first priority ranking and the second priority ranking are determined to be a same criticality ranking, execute a tie-breaker process including:

determine a first secondary value for the first endpoint; determine a second secondary value for the second endpoint;

determine, based on the first priority ranking, the first secondary value, the second priority ranking, and the second secondary value, that one of the first endpoint and the second endpoint is a higher priority endpoint and

triage the higher priority endpoint.

12. The system of claim 11 , comprising further instructions which when executed cause the system to detect a compromised endpoint.

13. The system of claim 12 , wherein detecting the compromised endpoint includes analyzing flow data from a plurality of sensors associated with the compromised endpoint.

14. The system of claim 11 , comprising further instructions which when executed cause the system to label the first endpoint with a criticality ranking via a prioritization list of labels.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2020
From: PANG, JACKSON NGOC KI; YADAV, NAVINDRA; GUPTA, ANUBHAV; GANDHAM, SHASHIDHAR; RAO, SUPREETH HOSUR NAGESH; GUPTA, SUNIL KUMAR
To: CISCO TECHNOLOGY, INC.
Reel/Frame 052585/0408 →
Continuity (3)
Continuation 15173477 · Jun 3, 2016
Provisional Application 62171899 · Jun 5, 2015
Related Publication 20200267066A1 · Aug 20, 2020