IP Library Granted Patent US 12,132,733
Granted Patent B2
US 12,132,733 · App. 17/497,686 · Granted Oct 29, 2024

Method and device for determining network device status

Inventors: Gil Friedrich (Tel Aviv, IL); Roy Rotem (Tel Aviv, NL)
Assignee: FORESCOUT TECHNOLOGIES, INC.
H04L63/10H04L63/08H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,132,733
App. No.
17/497,686
Granted
Oct 29, 2024
Kind
B2
Abstract

Disclosed is a method of transparently detecting authentication status of endpoint devices in a network. This method may be used for differentiating guest or rogue endpoints from enterprise endpoints.

Claims (60)

1. A method comprising:

monitoring network traffic between a source device and an authentication system;

inspecting a data packet from the source device of the network traffic;

determining, based on inspection of the data packet, whether the source device is included in a device status table;

in response to determining that the source device of the data packet is not included in the device status table, adding a record in the device status table corresponding to the source device;

identifying, based on monitoring the network traffic, one or more authentication attempts associated with the source device; and

updating, based on the one or more authentication attempts exceeding a threshold number of failed authentication attempts wherein the threshold number of failed authentication attempts is greater than one, the record in the device status table corresponding to the source device to indicate a status of the source device.

2. The method of claim 1 , wherein monitoring network traffic between the source device and the authentication system is performed by a monitoring device communicatively coupled to the source device and the authentication system.

3. The method of claim 1 , wherein monitoring network traffic between the source device and the authentication system comprises:

receiving replicated network traffic at a monitoring device, wherein the replicated network traffic is replicated and forwarded to the monitoring device from a network communication device.

4. The method of claim 1 , further comprising:

in response to adding the record in the device status table, marking the source device as guest in the device status table.

5. The method of claim 1 , wherein updating the record in the device status table comprises:

determining that the one or more authentication attempts were successful; and

marking the source device as authenticated in the device status table.

6. The method of claim 5 , further comprising:

in response to marking the source device as authenticated in the device status table, providing the source device with access permissions to one or more network resources.

7. The method of claim 1 , wherein updating the record in the device status table comprises:

determining that the threshold number of authentication attempts associated with the source device have failed; and

marking the source device as rogue in the device status table.

8. A system comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

monitor network traffic between a source device and an authentication system;

inspect a data packet from the source device of the network traffic;

determine, based on inspection of the data packet, whether the source device is included in a device status table;

in response to determining that the source device of the data packet is not included in the device status table, add a record in the device status table corresponding to the source device;

identify, based on monitoring the network traffic, one or more authentication attempts associated with the source device; and

update, based on the one or more authentication attempts exceeding a threshold number of failed authentication attempts wherein the threshold number of failed authentication attempts is greater than one, the record in the device status table corresponding to the source device to indicate a status of the source device.

9. The system of claim 8 , wherein monitoring network traffic between the source device and the authentication system is performed by a monitoring device communicatively coupled to the source device and the authentication system.

10. The system of claim 8 , wherein to monitor network traffic between the source device and the authentication system, the processing device is to:

receive replicated network traffic at a monitoring device, wherein the replicated network traffic is replicated and forwarded to the monitoring device from a network communication device.

11. The system of claim 8 , wherein the processing device is further to:

in response to adding the record in the device status table, mark the source device as guest in the device status table.

12. The system of claim 8 , wherein to update the record in the device status table, the processing device is to:

determine that the one or more authentication attempts were successful; and

mark the source device as authenticated in the device status table.

13. The system of claim 12 , wherein the processing device is further to:

in response to marking the source device as authenticated in the device status table, provide the source device with access permissions to one or more network resources.

14. The system of claim 8 , wherein to update the record in the device status table, the processing device is to:

determine that the threshold number of authentication attempts associated with the source device have failed; and

mark the source device as rogue in the device status table.

15. A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device, cause the processing device to:

monitor network traffic between a source device and an authentication system;

inspect a data packet from the source device of the network traffic;

determine, based on inspection of the data packet, whether the source device is included in a device status table;

in response to determining that the source device of the data packet is not included in the device status table, add a record in the device status table corresponding to the source device;

identify, based on monitoring the network traffic, one or more authentication attempts associated with the source device; and

update, based on the one or more authentication attempts exceeding a threshold number of failed authentication attempts wherein the threshold number of failed authentication attempts is greater than one, the record in the device status table corresponding to the source device to indicate a status of the source device.

16. The non-transitory computer readable medium of claim 15 , wherein monitoring network traffic between the source device and the authentication system is performed by a monitoring device communicatively coupled to the source device and the authentication system.

17. The non-transitory computer readable medium of claim 15 , wherein the processing device is further to:

in response to adding the record in the device status table, mark the source device as guest in the device status table.

18. The non-transitory computer readable medium of claim 15 , wherein to update the record in the device status table, the processing device is to:

determine that the one or more authentication attempts were successful; and

mark the source device as authenticated in the device status table.

19. The non-transitory computer readable medium of claim 18 , wherein the processing device is further to:

in response to marking the source device as authenticated in the device status table, provide the source device with access permissions to one or more network resources.

20. The non-transitory computer readable medium of claim 15 , wherein to update the record in the device status table, the processing device is to:

determine that the threshold number of authentication attempts associated with the source device have failed; and

mark the source device as rogue in the device status table.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2021
From: FRIEDRICH, GIL; ROTEM, ROY
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 057767/0721 →
Continuity (4)
Continuation 14153110 · Jan 13, 2014
Continuation 12526957
Provisional Application 60890195 · Feb 16, 2007
Related Publication 20220200991A1 · Jun 23, 2022