IP Library Granted Patent US 11,962,591
Granted Patent B1
US 11,962,591 · App. 17/189,022 · Granted Apr 16, 2024

Operational support for network infrastructures

Inventors: Lawrence T. Belton, Jr. (Charlotte, NC); Peter A. Makohon (Huntersville, NC); Scott A. Keoseyan (Matthews, NC); Jon Gabel (Charlotte, NC); Robert Glenn Yelton, Jr. (Mount Pleasant, SC); Ryan B. Benskin (Charlotte, NC)
Assignee: Wells Fargo Bank, N.A.
H04L63/0892H04M3/2263H04W12/06H04M3/42059
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,962,591
App. No.
17/189,022
Granted
Apr 16, 2024
Kind
B1
Abstract

Systems and methods that facilitate operational support for network infrastructures are discussed. The disclosed system and method facilitate a unified view of the current state of the network and networked devices including real-time log monitoring and for providing metrics for long term system planning. One such method can include the acts of automatically discovering a device deployed on a network, receiving device and network related data in real-time, determining whether a device is authorized, terminating device network access, filtering device data, validating device configuration, configuring a device and providing an output for use by a user. The disclosed system and method can be utilized, for example, to reduce the time involved in troubleshooting and resolving network issues, for establishing a baseline for network performance and for network capacity planning.

Claims (35)

1. A system, comprising:

a processor coupled to a memory that stores instructions that, when executed by the processor, cause the processor to:

create one or more evolving data structures based on stored data from input of observed source data, wherein the observed source data is associated with operation of a network;

generate one or more observed views of a network environment based on the stored data from the one or more evolving data structures;

produce a map of the network environment based on the stored data from the one or more evolving data structures;

wherein producing the map comprises producing at least one of a security data structure map or a system attack surface map, wherein the security data structure map indicates control density and coverage, and the system attack surface map identifies asset risk;

reallocating a workload process based at least in part on a system element characteristic and a velocity change of the system element characteristic that are based at least in part on one of the security data structure map or the system attack surface map; and

convey, for display on a display device, the one or more observed views and the map of the network environment.

2. The system of claim 1 , wherein the instructions further cause the processor to generate and convey a recommendation for workload reallocation based on at least one of a security control density and the system attack surface map.

3. The system of claim 1 , wherein the instructions further cause the processor to identify granularity of application layer data and application layer metadata and build an association between one or more functional aspects and one or more physical aspects into the one or more evolving data structures.

4. The system of claim 3 , wherein the application layer data and the application layer metadata include additional data and additional metadata across a plurality of applications or across multiple instances of a single application.

5. The system of claim 1 , wherein the instructions further cause the processor to build granularity of security control data and security control metadata into at least one of the one or more evolving data structures.

6. The system of claim 5 , wherein the security control data and the security control metadata cross security control applications or an instance of a single security control application.

7. The system of claim 5 , wherein the security control data comprises a ranked risk elimination plan.

8. The system of claim 1 , wherein the instructions further cause the processor to map a comparison source to at least one of the one or more evolving data structures;

determine one or more differences between the comparison source and the map of the network environment; and

update the comparison source with the one or more differences.

9. The system of claim 1 , wherein the observed source data comprises a network log, an authentication log, a vulnerability scan data, a security agent data and an enrichment source that augment at least one missing map location corresponding to a comparison source as captured in the system attack surface map.

10. A method, comprising:

creating one or more evolving data structures based on stored data from input of observed source data, wherein the observed source data is associated with operation of a network;

generating one or more observed views of a network environment based on the stored data from the one or more evolving data structures;

producing a map of the network environment based on the stored data from the one or more evolving data structures;

wherein producing the map comprises producing at least one of a security data structure map or a system attack surface map, wherein the security data structure map indicates control density and coverage, and the system attack surface map identifies asset risk;

reallocating a workload process based at least in part on a system element characteristic and a velocity change of the system element characteristic that are based at least in part on one of the security data structure map or the system attack surface map; and

conveying, for display on a display device, the one or more observed views and the map of the network environment.

11. The method of claim 10 , further comprising identifying an update associated with the network environment and reporting the update to a comparison source.

12. The method of claim 10 , wherein creation of the one or more evolving data structures captures a plurality of functional aspects to a plurality of physical aspects from at least identification of granularity of application layer data and application layer metadata determined based on at least one of associated data and associated metadata across multiple applications or multiple instances of a single application.

13. A method, comprising:

executing, on a processor, instructions that cause the processor to perform operations comprising:

creating an evolving data structure based on stored data and stored metadata from input of an observed source data associated with operation of a network;

generating one or more observed views of a network environment based on the stored data from the evolving data structure;

producing a map of the network environment based on at least one of the one or more observed views of the network environment;

wherein producing the map comprises producing at least one of a security data structure map or a system attack surface map, wherein the security data structure map indicates control density and coverage, and the system attack surface map identifies asset risk;

reallocating a workload process based at least in part on a system element characteristic and a velocity change of the system element characteristic that are based at least in part on one of the security data structure map or the system attack surface map; and

transmitting, for display on a display device, the map of the network environment.

Assignments (2)
ADDRESS CHANGE Recorded Jun 2, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071769/0143 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2021
From: BELTON, LAWRENCE T., JR.; MAKOHON, PETER A.; KEOSEYAN, SCOTT A.; GABEL, JON; YELTON, ROBERT G., JR.; BENSKIN, RYAN B.
To: WELLS FARGO BANK, N.A.
Reel/Frame 055505/0173 →
Continuity (3)
Continuation 16222743 · Dec 17, 2018
Continuation In Part 15629168 · Jun 21, 2017
Continuation 14145659 · Dec 31, 2013