IP Library Granted Patent US 11,716,343
Granted Patent B2
US 11,716,343 · App. 16/990,664 · Granted Aug 1, 2023

Secure neighborhoods assessment in enterprise networks

Inventors: Supreeth Rao (Cupertino, CA); Navindra Yadav (Cupertino, CA); Prasannakumar Jobigenahally Malleshaiah (Sunnyvale, CA); Hanlin He (San Jose, CA); Umamaheswaran Arumugam (San Jose, CA); Robert Bukofser (Mason, OH); Aiyesha Ma (San Francisco, CA); Kai Zhu (San Jose, CA); Ashok Kumar (Pleasanton, CA)
Assignee: Cisco Technology, Inc.
H04L63/1433G06F16/9024G06F16/9035H04L41/22H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,716,343
App. No.
16/990,664
Granted
Aug 1, 2023
Kind
B2
Abstract

Systems, methods, and computer-readable media for determine a neighborhood graph can include the following processes. A neighborhood graph system generates a neighborhood graph for a plurality of nodes in an enterprise network, the neighborhood graph representing a multi-hop connections between any two nodes of the plurality of nodes. A security score service determines a security score for each of the plurality of nodes to yield a plurality of scores. The neighborhood graph system updates the neighborhood graph of the plurality of nodes using the plurality of scores to provide a visual representation of securities of the plurality of nodes relative to each other.

Claims (43)

1. A method comprising:

generating a neighborhood graph for a plurality of nodes in an enterprise network, the neighborhood graph representing a multi-hop connection between any two nodes of the plurality of nodes;

determining a plurality of sub-scores for each of the plurality of nodes, each of the plurality of sub-scores including a corresponding vulnerability score, a corresponding process hash score, a corresponding attack surface score, a corresponding forensics score, a corresponding network anomaly score, and a corresponding segmentation compliance score for each of the plurality of nodes;

determining, based on the plurality of sub-scores, an overall security score for each of the plurality of nodes to yield a plurality of scores; and

updating the neighborhood graph of the plurality of nodes using the plurality of scores to provide a visual representation of securities of the plurality of nodes relative to each other.

2. The method of claim 1 , further comprising:

filtering the updated neighborhood graph.

3. The method of claim 2 , wherein the filtering is based on a filtering parameter associated with at least one of a number of source nodes and a number of destination nodes in the enterprise network.

4. The method of claim 3 , wherein the filtering parameter includes a threshold attack surface score of each of the number of source nodes, a threshold attack surface score of each of the number of destination nodes, a vulnerability score of each of the number of source nodes, or a vulnerability score of each of the number of destination nodes.

5. The method of claim 1 , further comprising:

receiving a request for generating the neighborhood graph.

6. The method of claim 1 , further comprising:

creating an alert for the updated neighborhood graph, the alert indicating presence of one or more new network connections between the plurality of nodes having a threshold security score.

7. The method of claim 1 , wherein the node is a scope, a cluster or an inventory filter.

8. A neighborhood graph system comprising:

one or more processors; and

at least one computer-readable storage medium having stored therein instructions which, when executed by the one or more processors, cause the one or more processors to:

generate a neighborhood graph for a plurality of nodes in an enterprise network, the neighborhood graph representing a multi-hop connection between any two nodes of the plurality of nodes;

determine a plurality of sub-scores for each of the plurality of nodes, each of the plurality of sub-scores including a corresponding vulnerability score, a corresponding process hash score, a corresponding attack surface score, a corresponding forensics score, a corresponding network anomaly score, and a corresponding segmentation compliance score for each of the plurality of nodes;

determine, based on the plurality of sub-scores, an overall security score for each of the plurality of nodes to yield a plurality of scores; and

update the neighborhood graph of the plurality of nodes using the plurality of scores to provide a visual representation of securities of the plurality of nodes relative to each other.

9. The neighborhood graph system of claim 8 , wherein the instructions which, when executed by the one or more processors, further cause the one or more processors to:

filter the updated neighborhood graph.

10. The neighborhood graph system of claim 9 , wherein the filtering is based on a filtering parameter associated with at least one of a number of source nodes and a number of destination nodes in the enterprise network.

11. The neighborhood graph system of claim 10 , wherein the filtering parameter includes a threshold attack surface score of each of the number of source nodes, a threshold attack surface score of each of the number of destination nodes, a vulnerability score of each of the number of source nodes, or a vulnerability score of each of the number of destination nodes.

12. The neighborhood graph system of claim 8 , wherein the instructions which, when executed by the one or more processors, further cause the one or more processors to:

receive a request for generating the neighborhood graph.

13. The neighborhood graph system of claim 8 , wherein the instructions which, when executed by the one or more processors, further cause the one or more processors to:

create an alert for the updated neighborhood graph, the alert indicating presence of one or more new network connections between the plurality of nodes having a threshold security score.

14. The neighborhood graph system of claim 8 , wherein the node is a scope, a cluster or an inventory filter.

15. A non-transitory computer-readable storage medium comprising instructions which, when executed by one or more processors of a neighborhood graph system, cause the neighborhood graph system to:

generate a neighborhood graph for a plurality of nodes in an enterprise network, the neighborhood graph representing a multi-hop connection between any two nodes of the plurality of nodes;

determine a plurality of sub-scores for each of the plurality of nodes, each of the plurality of sub-scores including a corresponding vulnerability score, a corresponding process hash score a corresponding attack surface score, a corresponding forensics score, a corresponding network anomaly score, and a corresponding segmentation compliance score for each of the plurality of nodes;

determine, based on the plurality of sub-scores, an overall security score for each of the plurality of nodes to yield a plurality of scores; and

update the neighborhood graph of the plurality of nodes using the plurality of scores to provide a visual representation of securities of the plurality of nodes relative to each other.

16. The non-transitory computer-readable storage medium of claim 15 , wherein execution of the instructions by the one or more processors further cause the neighborhood graph system to:

filter the updated neighborhood graph.

17. The non-transitory computer-readable storage medium of claim 16 , wherein the filtering is based on a filtering parameter associated with at least one of a number of source nodes and a number of destination nodes in the enterprise network.

18. The non-transitory computer-readable storage medium of claim 17 , wherein the filtering parameter includes a threshold attack surface score of each of the number of source nodes, a threshold attack surface score of each of the number of destination nodes, a vulnerability score of each of the number of source nodes, or a vulnerability score of each of the number of destination nodes.

19. The non-transitory computer-readable storage medium of claim 15 , wherein execution of the instructions by the one or more processors further cause the neighborhood graph system to:

receive a request for generating the neighborhood graph.

20. The non-transitory computer-readable storage medium of claim 15 , wherein execution of the instructions by the one or more processors further cause the neighborhood graph system to:

create an alert for the updated neighborhood graph, the alert indicating presence of one or more new network connections between the plurality of nodes having a threshold security score.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2020
From: RAO, SUPREETH; YADAV, NAVINDRA; MALLESHAIAH, PRASANNAKUMAR JOBIGENAHALLY; HE, HANLIN; ARUMUGAM, UMAMAHESWARAN; BUKOFSER, ROBERT; MA, AIYESHA; ZHU, KAI; KUMAR, ASHOK
To: CISCO TECHNOLOGY, INC.
Reel/Frame 053460/0888 →
Continuity (1)
Related Publication 20220053011A1 · Feb 17, 2022
Cited By (1)
US 12,212,594