IP Library Granted Patent US 11,588,857
Granted Patent B2
US 11,588,857 · App. 17/037,107 · Granted Feb 21, 2023

Network asset lifecycle management

Inventors: Matthew Kraning (San Francisco, CA); Gregory Toto (Piedmont, CA); Gregory Heon (San Francisco, CA); Haley Sayres (Belvedere Tiburon, CA); Peter Sorrentino (Washington, DC)
Assignee: Palo Alto Networks, Inc.
H04L63/20G06F16/2379G06Q10/0635G06Q10/105G06Q10/20G06Q30/0185G06Q50/18G06Q50/28H04L41/50H04L43/12H04L63/0236H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,588,857
App. No.
17/037,107
Filed
Sep 29, 2020
Granted
Feb 21, 2023
Kind
B2
Examiner
KORSAK, OLEG
Art Unit
2492
USPC
726/1
Abstract

Systems and methods for network asset lifecycle management are described. Network assets may include ephemeral Internet-accessible assets such as IP addresses, domain names, digital certificates, and cloud infrastructure accounts. A set of addresses associated with a computer network such as the Internet are scanned. Response data is received from one or more network systems connected to the computer network and processed to identify one or more network assets associated with an entity such as an enterprise organization. Asset data indicative of the identified network assets are then stored to build a record of the network assets associated with the entity.

Claims (120)

1. A method comprising:

scanning a computer network that includes Internet-accessible systems by, for each Internet-accessible system:

providing a payload to all accessible network systems on all accessible ports of the Internet-accessible system;

scanning each accessible network system from which a response to the payload is received;

receiving response data from one or more of the accessible network systems based on the scanning;

processing the response data to identify a combined attack surface associated with a plurality of entities associated with a supply chain; and

enabling a first entity of the plurality of entities to access a first view of the combined attack surface.

2. The method of claim 1 , wherein the first view of the combined attack surface obfuscates the identities of any of the plurality of entities associated with the supply chain that do not have a contractual relationship with the first entity.

3. The method of claim 1 , further comprising:

receiving netflow data indicative of network traffic communicated over the computer network;

processing the response data with the netflow data to detect a security event associated with one or more of the plurality of entities; and

performing an automated action to mitigate a risk presented by the security event.

4. The method of claim 3 , wherein the detected security event includes any one or more of:

detection of a vulnerable network system residing on an internal computer network associated with any of the plurality of entities;

a communication by a network system residing on an internal computer network associated with any of the plurality of entities to a vulnerable network system that resides outside the internal computer network;

a communication by a network system residing on an internal computer network associated with any of the plurality of entities that has not been involved in any communications for a specified period of time; or

a communication by a network system residing on an internal computer network associated with any of the plurality of entities with a new and/or ephemeral service.

5. The method of claim 3 , wherein performing the automated action includes:

causing a network system associated with the detected security event to be reconfigured; and/or

transmitting a notification indicative of the security event for delivery to the first entity.

6. The method of claim 5 , further comprising:

determining that the security event is associated with a second entity of the plurality of entities, wherein the second entity is a supplier to the first entity and wherein the second entity has a contractual relationship with the first entity; and

configuring the notification to indicate that the security event is associated with the second entity.

7. The method of claim 5 , further comprising:

determining that the security event is associated with a second entity of the plurality of entities, wherein the second entity is a supplier to a third entity of the plurality of entities, wherein the third entity is a supplier to the first entity, wherein the third entity has a contractual relationship with the first entity, and wherein the second entity does not have a contractual relationship with the first entity; and

configuring the notification to indicate that the security event is associated with a supplier to the third entity while obfuscating the identity of the second entity.

8. The method of claim 1 , further comprising:

receiving contract data indicative of a contractual obligation of a second entity of the plurality of entities to the first entity, wherein the second entity is a supplier to the first entity;

detecting based on the combined attack surface and contract data, a breach of the contractual obligation; and

performing an automated action to remedy the breach of the contractual obligation.

9. The method of claim 8 , wherein detecting the breach of the contractual obligation includes:

detecting, based on the combined attack surface, a security event associated with the second entity or a third entity that supplies the second entity; and

determining, based on the contract data, that the detected security event represents a breach of the contractual obligation.

10. The method of claim 8 , wherein detecting the breach of the contractual obligation includes:

monitoring, based on the combined attack surface, a network system associated with the second entity;

comparing the activity of the network system to a condition specified by the contractual obligation; and

determining, based on the comparing, that the condition is satisfied;

wherein the breach is detected in response to determining that the condition is satisfied.

11. The method of claim 8 , wherein performing the automated action to remedy the breach of the contractual obligation includes:

causing a network system associated with second entity to be reconfigured to remedy the breach of the contractual obligation;

transmitting a first notification indicative of the detected breach for delivery to the first entity; and/or

transmitting a second notification indicative of the detected breach for delivery to the second entity.

12. The method of claim 1 , further comprising:

enabling a second entity of the plurality of entities to access a second view of the combined attack surface, the second view of the combined attack surface different than the first view of the combined attack surface.

13. One or more non-transitory machine-readable media having stored therein a program product comprising instructions to:

scan a computer network that includes Internet-accessible systems, wherein the instructions to scan the computer network comprise instructions to, for each Internet-accessible system:

provide a payload to all accessible network systems on all accessible ports of the Internet-accessible system;

scan each accessible network system from which a response to the payload is received;

receive response data from one or more of the accessible network systems based on the scanning;

process the response data to identify a combined attack surface associated with a plurality of entities associated with a supply chain; and

enable a first entity of the plurality of entities to access a first view of the combined attack surface.

14. The machine-readable media of claim 13 , wherein the first view of the combined attack surface obfuscates the identities of any of the plurality of entities associated with the supply chain that do not have a contractual relationship with the first entity.

15. The machine-readable media of claim 13 , wherein the program product further comprises instructions to:

receive netflow data indicative of network traffic communicated over the computer network;

process the response data with the netflow data to detect a security event associated with one or more of the plurality of entities; and

perform an automated action to mitigate a risk presented by the security event.

16. The machine-readable media of claim 15 , wherein the detected security event includes any one or more of:

detection of a vulnerable network system residing on an internal computer network associated with any of the plurality of entities;

a communication by a network system residing on an internal computer network associated with any of the plurality of entities to a vulnerable network system that resides outside the internal computer network;

a communication by a network system residing on an internal computer network associated with any of the plurality of entities that has not been involved in any communications for a specified period of time; or

a communication by a network system residing on an internal computer network associated with any of the plurality of entities with a new and/or ephemeral service.

17. The machine-readable media of claim 15 , wherein the instructions to perform the automated action comprise instructions to:

cause a network system associated with the detected security event to be reconfigured; and/or

transmit a notification indicative of the security event for delivery to the first entity.

18. The machine-readable media of claim 15 , wherein the program code further comprises instructions to:

determine that the security event is associated with a second entity of the plurality of entities, wherein the second entity is a supplier to the first entity and wherein the second entity has a contractual relationship with the first entity; and

configure the notification to indicate that the security event is associated with the second entity.

19. The machine-readable media of claim 15 , wherein the program code further comprises instructions to:

determine that the security event is associated with a second entity of the plurality of entities, wherein the second entity is a supplier to a third entity of the plurality of entities, wherein the third entity is a supplier to the first entity, wherein the third entity has a contractual relationship with the first entity, and wherein the second entity does not have a contractual relationship with the first entity; and

configure the notification to indicate that the security event is associated with a supplier to the third entity while obfuscating the identity of the second entity.

20. The machine-readable media of claim 13 , wherein the program product further comprises instructions to:

receive contract data indicative of a contractual obligation of a second entity of the plurality of entities to the first entity, wherein the second entity is a supplier to the first entity;

detect based on the combined attack surface and contract data, a breach of the contractual obligation; and

perform an automated action to remedy the breach of the contractual obligation.

21. The machine-readable media of claim 20 , wherein the instructions to detect the breach of the contractual obligation comprise instructions to:

detect, based on the combined attack surface, a security event associated with the second entity or a third entity that supplies the second entity; and

determine, based on the contract data, whether the detected security event represents a breach of the contractual obligation.

22. The machine-readable media of claim 20 , wherein the instructions to detect the breach of the contractual obligation comprise instructions to:

monitor, based on the combined attack surface, a network system associated with the second entity;

compare the activity of the network system to a condition specified by the contractual obligation; and

determine, based on the comparing, whether the condition is satisfied;

wherein the breach is detected in response to determining that the condition is satisfied.

23. The machine-readable media of claim 20 , wherein the instructions to perform the automated action to remedy the breach of the contractual obligation comprise instructions to:

cause a network system associated with second entity to be reconfigured to remedy the breach of the contractual obligation;

transmit a first notification indicative of the detected breach for delivery to the first entity; and/or

transmit a second notification indicative of the detected breach for delivery to the second entity.

24. The machine-readable media of claim 13 , wherein the program product further comprises instructions to:

enable a second entity of the plurality of entities to access a second view of the combined attack surface, the second view of the combined attack surface different than the first view of the combined attack surface.

25. An apparatus comprising:

a processor; and

a machine-readable medium having a program stored thereon, the program executable by the processor to cause the apparatus to,

scan a computer network that includes Internet-accessible systems, wherein the program executable to scan the computer network comprises the program being executable by the processor to cause the apparatus to, for each Internet-accessible system:

provide a payload to all accessible network systems on all accessible ports of the Internet-accessible system;

scan each accessible network system from which a response to the payload is received;

receive response data from one or more of the accessible network systems based on the scanning;

process the response data to identify a combined attack surface associated with a plurality of entities associated with a supply chain; and

enable a first entity of the plurality of entities to access a first view of the combined attack surface.

26. The apparatus of claim 25 , wherein the first view of the combined attack surface obfuscates the identities of any of the plurality of entities associated with the supply chain that do not have a contractual relationship with the first entity.

27. The apparatus of claim 25 , wherein the program is further executable by the processor to cause the apparatus to:

receive netflow data indicative of network traffic communicated over the computer network;

process the response data with the netflow data to detect a security event associated with one or more of the plurality of entities; and

perform an automated action to mitigate a risk presented by the security event.

28. The apparatus of claim 27 , wherein the detected security event includes any one or more of:

detection of a vulnerable network system residing on an internal computer network associated with any of the plurality of entities;

a communication by a network system residing on an internal computer network associated with any of the plurality of entities to a vulnerable network system that resides outside the internal computer network;

a communication by a network system residing on an internal computer network associated with any of the plurality of entities that has not been involved in any communications for a specified period of time; or

a communication by a network system residing on an internal computer network associated with any of the plurality of entities with a new and/or ephemeral service.

29. The apparatus of claim 27 , wherein the program executable to perform the automated action comprises the program executable by the processor to cause the apparatus to:

cause a network system associated with the detected security event to be reconfigured; and/or

transmit a notification indicative of the security event for delivery to the first entity.

30. The apparatus of claim 27 , wherein the program is further executable by the processor to cause the apparatus to:

determine that the security event is associated with a second entity of the plurality of entities, wherein the second entity is a supplier to the first entity and wherein the second entity has a contractual relationship with the first entity; and

configure the notification to indicate that the security event is associated with the second entity.

31. The apparatus of claim 27 , wherein the program is further executable by the processor to cause the apparatus to:

determine that the security event is associated with a second entity of the plurality of entities, wherein the second entity is a supplier to a third entity of the plurality of entities, wherein the third entity is a supplier to the first entity, wherein the third entity has a contractual relationship with the first entity, and wherein the second entity does not have a contractual relationship with the first entity; and

configure the notification to indicate that the security event is associated with a supplier to the third entity while obfuscating the identity of the second entity.

32. The apparatus of claim 25 , wherein the program is further executable by the processor to cause the apparatus to:

receive contract data indicative of a contractual obligation of a second entity of the plurality of entities to the first entity, wherein the second entity is a supplier to the first entity;

detect based on the combined attack surface and contract data, a breach of the contractual obligation; and

perform an automated action to remedy the breach of the contractual obligation.

Assignments (3)
NUNC PRO TUNC ASSIGNMENT Recorded Aug 3, 2021
From: KRANING, MATTHEW; TOTO, GREGORY; HEON, GREGORY; SAYRES, HALEY; SORRENTINO, PETER
To: EXPANSE, INC.
Reel/Frame 057066/0846 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2021
From: EXPANSE, LLC
To: PALO ALTO NETWORKS, INC.
Reel/Frame 056379/0222 →
CHANGE OF NAME Recorded May 24, 2021
From: EXPANSE, INC.
To: EXPANSE, LLC.
Reel/Frame 056355/0769 →
Continuity (4)
Provisional Application 62911078 · Oct 4, 2019
Provisional Application 62911077 · Oct 4, 2019
Provisional Application 62911076 · Oct 4, 2019
Related Publication 20210105304A1 · Apr 8, 2021
Cited By (3)
US 12,328,232 US 12,574,388 US 12,712,916