IP Library Granted Patent US 11,924,073
Granted Patent B2
US 11,924,073 · App. 17/403,026 · Granted Mar 5, 2024

System and method of assigning reputation scores to hosts

Inventors: Sunil Kumar Gupta (Milpitas, CA); Navindra Yadav (Cupertino, CA); Michael Standish Watts (Mill Valley, CA); Ali Parandehgheibi (Sunnyvale, CA); Shashidhar Gandham (Fremont, CA); Ashutosh Kulshreshtha (Cupertino, CA); Khawar Deen (Sunnyvale, CA)
Assignee: Cisco Technology, Inc.
H04L43/045G06F3/0482G06F3/04842G06F3/04847G06F9/45558G06F16/122G06F16/137G06F16/162G06F16/17G06F16/173G06F16/174G06F16/1744G06F16/1748G06F16/2322G06F16/235G06F16/2365G06F16/24578G06F16/248G06F16/285G06F16/288G06F16/29G06F16/9535G06F21/53G06F21/552G06F21/556G06F21/566G06N20/00G06N99/00G06T11/206H04J3/0661H04J3/14H04L1/242H04L9/0866H04L9/3239H04L9/3242H04L41/046H04L41/0668H04L41/0803H04L41/0806H04L41/0816H04L41/0893H04L41/12H04L41/16H04L41/22H04L43/02H04L43/026H04L43/04H04L43/062H04L43/08H04L43/0805H04L43/0811H04L43/0829H04L43/0841H04L43/0858H04L43/0864H04L43/0876H04L43/0882H04L43/0888H04L43/10H04L43/106H04L43/12H04L43/16H04L45/306H04L45/38H04L45/46H04L45/507H04L45/66H04L45/74H04L47/11H04L47/20H04L47/2441H04L47/2483H04L47/28H04L47/31H04L47/32H04L61/5007H04L63/0227H04L63/0263H04L63/06H04L63/0876H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/145H04L63/1458H04L63/1466H04L63/16H04L63/20H04L67/01H04L67/10H04L67/1001H04L67/12H04L67/51H04L67/75H04L69/16H04L69/22H04W72/54H04W84/18G06F2009/4557G06F2009/45587G06F2009/45591G06F2009/45595G06F2221/033G06F2221/2101G06F2221/2105G06F2221/2111G06F2221/2115G06F2221/2145H04L67/535
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,924,073
App. No.
17/403,026
Granted
Mar 5, 2024
Kind
B2
Abstract

A method provides for receiving network traffic from a host having a host IP address and operating in a data center, and analyzing a malware tracker for IP addresses of hosts having been infected by a malware to yield an analysis. When the analysis indicates that the host IP address has been used to communicate with an external host infected by the malware to yield an indication, the method includes assigning a reputation score, based on the indication, to the host. The method can further include applying a conditional policy associated with using the host based on the reputation score. The reputation score can include a reduced reputation score from a previous reputation score for the host.

Claims (44)

1. A method comprising:

assigning, to a device associated with an internet protocol (IP) address, one or more reputation scores associated with a communication policy, the one or more reputation scores being based on at least one of a determination that the device has been infected by malware, a determination that the IP address of the device has been used to communicate with a different device that is infected by malware, or network activity associated with the device, wherein the device comprises a host in a data center at one of a virtual layer, a hypervisor layer and a physical layer; and

based on the one or more reputation scores, modifying a group policy membership of the device from a policy group to an additional policy group associated with the one or more reputation scores and which governs packet flow to the host in the data center.

2. The method of claim 1 , wherein assigning one or more reputation scores comprises, after assigning a reputation score to the device, assigning a different reputation score to the device based on network activity associated with the device.

3. The method of claim 2 , wherein the different reputation score is a reduced reputation score relative to the reputation score.

4. The method of claim 1 , further comprising:

determining an effectiveness of the communication policy based on data from packet flows associated with devices assigned to at least one of the policy group or the additional policy group; and

determining an action based on the determined effectiveness of the communication policy.

5. The method of claim 1 , further comprising:

separating behavior identified as malicious from different behavior identified as non-malicious based on an indication from at least one of the determination that the device has been infected by malware or the determination that the IP address has been used to communicate with the different device that is infected by malware.

6. The method of claim 1 , further comprising identifying, based on a malware tracker, one or more IP addresses of devices that have been infected by malware, wherein the one or more reputation scores are further based on whether the one or more IP addresses include the IP address of the device or a different IP address of the different device.

7. The method of claim 6 , wherein identifying the one or more IP addresses of devices that have been infected by malware comprises crawling multiple malware trackers.

8. The method of claim 1 , wherein the assigning of the one or more reputation scores comprises:

obtaining data associated with the device based on a query to a whois database; and

determining whether a particular IP address has been allocated to an entity identified as real or legitimate based on the data obtained from the whois database.

9. A system comprising:

one or more processors; and

a computer-readable storage medium storing instructions which, when executed by the one or more processors, cause the one or more processors to:

assign, to a device associated with an internet protocol (IP) address, one or more reputation scores associated with a communication policy, the one or more reputation scores being based on at least one of a determination that the device has been infected by malware, a determination that the IP address of the device has been used to communicate with a different device that is infected by malware, or network activity associated with the device, wherein the device comprises a host in a data center at one of a virtual layer, a hypervisor layer and a physical layer; and

based on the one or more reputation scores, modify a group policy membership of the device from a policy group to an additional policy group associated with the one or more reputation scores and which governs packet flow to the host in the data center.

10. The system of claim 9 , wherein assigning one or more reputation scores comprises, after assigning a reputation score to the device, assigning a different reputation score to the device based on network activity associated with the device.

11. The system of claim 10 , wherein the different reputation score is a reduced reputation score relative to the reputation score.

12. The system of claim 9 , wherein the computer-readable storage medium store instructions which, when executed by the one or more processors, cause the one or more processors to:

determine an effectiveness of the communication policy based on data from packet flows associated with devices assigned to at least one of the policy group or the additional policy group; and

determine an action based on the determined effectiveness of the communication policy.

13. The system of claim 9 , wherein the computer-readable storage medium store instructions which, when executed by the one or more processors, cause the one or more processors to:

separate behavior identified as malicious from different behavior identified as non-malicious based on an indication from at least one of the determination that the device has been infected by malware or the determination that the IP address has been used to communicate with the different device that is infected by malware.

14. The system of claim 9 , wherein the computer-readable storage medium store instructions which, when executed by the one or more processors, cause the one or more processors to:

identify, based on a malware tracker, one or more IP addresses of devices that have been infected by malware, wherein the one or more reputation scores are further based on whether the one or more IP addresses include the IP address of the device or a different IP address of the different device.

15. The system of claim 14 , wherein identifying the one or more IP addresses of devices that have been infected by malware comprises crawling multiple malware trackers.

16. The system of claim 9 , wherein the assigning of the one or more reputation scores comprises:

obtaining data associated with the device based on a query to a whois database; and

determining whether a particular IP address has been allocated to an entity identified as real or legitimate based on the data obtained from the whois database.

17. A non-transitory computer-readable medium having stored thereon instructions which, when executed by one or more processors, cause the one or more processors to:

assign, to a device associated with an internet protocol (IP) address, one or more reputation scores associated with a communication policy, the one or more reputation scores being based on at least one of a determination that the device has been infected by malware, a determination that the IP address of the device has been used to communicate with a different device that is infected by malware, or network activity associated with the device, wherein the device comprises a host in a data center at one of a virtual layer, a hypervisor layer and a physical layer; and

based on the one or more reputation scores, modify a group policy membership of the device from a policy group to an additional policy group associated with the one or more reputation scores and which governs packet flow to the host in the data center.

18. The non-transitory computer-readable medium of claim 17 , storing instructions which, when executed by one or more processors, cause the one or more processors:

to analyze data from packet flows associated with devices assigned to at least one of the policy group and the additional policy group;

determine an effectiveness of the communication policy based on data from packet flows associated with devices assigned to at least one of the policy group or the additional policy group; and

determine an action based on the determined effectiveness of the communication policy.

19. The non-transitory computer-readable medium of claim 17 , storing instructions which, when executed by one or more processors, cause the one or more processors to:

separate behavior identified as malicious from different behavior identified as non-malicious based on an indication from at least one of the determination that the device has been infected by malware or the determination that the IP address has been used to communicate with the different device that is infected by malware.

20. The non-transitory computer-readable medium of claim 17 , storing instructions which, when executed by one or more processors, cause the one or more processors to:

identify, based on a malware tracker, one or more IP addresses of devices that have been infected by malware, wherein the one or more reputation scores are further based on whether the one or more IP addresses include the IP address of the device or a different IP address of the different device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2021
From: GUPTA, SUNIL KUMAR; YADAV, NAVINDRA; WATTS, MICHAEL STANDISH; PARANDEHGHEIBI, ALI; GANDHAM, SHASHIDHAR; KULSHRESHTHA, ASHUTOSH; DEEN, KHAWAR
To: CISCO TECHNOLOGY, INC.
Reel/Frame 057192/0172 →
Continuity (4)
Continuation 16280894 · Feb 20, 2019
Continuation 15171580 · Jun 2, 2016
Provisional Application 62171899 · Jun 5, 2015
Related Publication 20210377136A1 · Dec 2, 2021