IP Library › Granted Patent US 11,503,048
Granted Patent B2
US 11,503,048 · App. 17/026,093 · Granted Nov 15, 2022

Prioritizing assets using security metrics

Inventors: Travis Nathan Sugarbaker (Seattle, WA); Srivatsa Shripathi Modambu (Karnataka, IN)
Assignee: Cisco Technology, Inc.
H04L63/1416H04L63/0236H04L63/105H04L63/1425H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,503,048
App. No.
17/026,093
Granted
Nov 15, 2022
Kind
B2
Abstract

This disclosure describes techniques for identifying the criticality of an asset in a network. In an example method, a first security metric of a first asset in a network, as well as network data that identifies data flows associated with a second asset in the network are identified. The second asset is a nearest neighbor of the first asset in the network. The method includes determining, based on the network data, a number of hosts in the network that exchanged data traffic with the second asset during a time period and generating a second security metric of the second asset based on the first security metric and the number of hosts. A security policy of the second asset is adjusted based on the security metric.

Claims (107)

1. A method, comprising:

identifying a first security metric of a first asset in a network;

identifying network data that identifies data flows associated with a second asset in the network, the second asset being a nearest neighbor of the first asset in the network;

determining, based on the network data, a number of hosts in the network that exchanged data traffic with the second asset during a time period;

generating a second security metric of the second asset based on the following equation:

S

+

∑

1

n

f

prop

(

n

)

,

wherein S is a third security metric of the second asset based on the number of hosts in the network that exchanged the data traffic with the second asset during the time period, and f prop (n) is a propagation factor contributed by the nth nearest neighbor of the asset, n is an integer that is greater than or equal to 1, and the first asset is among the n nearest neighbors; and

adjusting a security policy of the second asset based on the second security metric.

2. The method of claim 1 , wherein the second security metric is independent of vulnerabilities of the second asset.

3. The method of claim 1 , wherein the second asset comprises at least one of an application, a port, or a host.

4. The method of claim 1 , wherein the second security metric indicates at least one of a criticality of the second asset, an exposure of the second asset, a vulnerability exploit probability of the asset, or an application vulnerability risk of the asset.

5. The method of claim 1 , further comprising:

identifying a number of users associated with the hosts that exchanged data traffic with the second asset during the time period,

wherein the third security metric is based on the number of users.

6. The method of claim 1 , wherein determining the number of hosts comprises:

identifying, based on the network data, addresses of the hosts;

generating shortened addresses by extracting a subset of the most significant digits of the addresses, the shortened addresses being shorter than the addresses; and

determining the number of hosts based on a number of the shortened addresses.

7. The method of claim 1 , wherein adjusting the security policy comprises:

determining that the second security metric is above a threshold; and

based on determining that the second security metric is above the threshold, decreasing a multi-factor authentication (MFA) interval of the asset.

8. The method of claim 1 , wherein adjusting the security policy comprises:

determining that one or more packets directed to the second asset are blocked by a firewall associated with the second asset;

determining that the second security metric is above a threshold; and

based on determining that the second security metric is above the threshold, outputting an alert reporting the one or more packets blocked by the firewall.

9. A system, comprising

at least one processor; and

one or more non-transitory media storing instructions that, when executed by the system, cause the system to perform operations comprising:

identifying a first security metric of a first asset in a network;

identifying network data that identifies data flows associated with a second asset in the network, the second asset being located within a threshold distance of the first asset;

determining, based on the network data, a number of hosts in the network that exchanged data traffic with the second asset during a time period;

generating a second security metric of the second asset based on the following equation:

S

+

∑

1

n

f

prop

(

n

)

,

wherein S is a third security metric of the second asset based on the number of hosts in the network that exchanged the data traffic with the second asset during the time period, f prop (n) is a propagation factor contributed by the nth nearest neighbor of the asset, n is an integer that is greater than or equal to 1, and the first asset is among the n nearest neighbors; and

adjusting a security policy of the second asset based on the security metric.

10. The system of claim 9 , wherein the second security metric is independent of vulnerabilities of the second asset.

11. The system of claim 9 , wherein the second asset comprises at least one of an application, a port, or a host.

12. The system of claim 9 , wherein a length of the time period is greater than or equal to 1 day and less than or equal to 31 days.

13. The system of claim 9 , wherein the operations further comprise:

identifying a number of users associated with the hosts that exchanged data traffic with the second asset during the time period,

wherein the third security metric is based on the number of users.

14. The system of claim 9 , wherein determining the number of hosts comprises:

identifying, based on the network data, addresses of the hosts;

generating shortened addresses by extracting a subset of the most significant digits of the addresses, the shortened addresses being shorter than the addresses; and

determining the number of hosts based on a number of the shortened addresses.

15. The system of claim 9 , wherein adjusting the security policy comprises:

determining that the security metric is above a threshold; and

based on determining that the security metric is above the threshold, decreasing a multi-factor authentication (MFA) interval of the asset.

16. The system of claim 9 , wherein adjusting the security policy comprises:

determining that one or more packets directed to the second asset are blocked by a firewall associated with the second asset;

determining that the second security metric is above a threshold; and

based on determining that the second security metric is above the threshold, outputting an alert reporting the one or more packets blocked by the firewall.

17. A system, comprising

at least one processor; and

one or more non-transitory media storing instructions that, when executed by the system, cause the system to perform operations comprising:

identifying a first security metric of a first asset in a network;

identifying network data that identifies data flows associated with a second asset in the network, the second asset being a nearest neighbor of the first asset in the network;

determining, based on the network data, a number of hosts in the network that received data traffic from the second asset during a time period, the time period being greater than or equal to 1 day and less than or equal to 31 days;

determining, based on the network data, an amount of the data traffic;

generating a second security metric of the second asset based on the following equation:

S

r

=

S

+

∑

1

n

f

prop

(

n

)

,

wherein S r is the second security metric, S is a third security metric of the second asset based on the number of hosts in the network that exchanged the data traffic with the second asset during the time period and on the amount of the data traffic, f prop (n) is a propagation factor contributed by the nth nearest neighbor of the asset, n is an integer that is greater than or equal to 1, and the first asset is among the n nearest neighbors; and

determining that one or more packets directed to the second asset are blocked by a firewall associated with the second asset;

determining that the second security metric is above a threshold; and

based on determining that the second security metric is above the threshold, outputting an alert reporting the one or more packets blocked by the firewall.

18. The system of claim 17 , wherein the operations further comprise:

identifying a number of users associated with the hosts that exchanged data traffic with the second asset during the time period,

wherein the third second security metric is based on the number of users.

19. The system of claim 17 , wherein determining the number of hosts comprises:

identifying, based on the network data, addresses of the hosts;

generating shortened addresses by extracting a subset of the most significant digits of the addresses, the shortened addresses being shorter than the addresses; and

determining the number of hosts based on a number of the shortened addresses.

20. The system of claim 17 , wherein the operations further comprise:

causing a user device to output at least one of the first security metric or the second security metric.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2020
From: SUGARBAKER, TRAVIS NATHAN; MODAMBU, SRIVATSA SHRIPATHI
To: CISCO TECHNOLOGY, INC.
Reel/Frame 053823/0326 →
Priority Claims (1)
IN 202041032709 · Jul 30, 2020 · national
Continuity (1)
Related Publication 20220038471A1 · Feb 3, 2022