IP Library Granted Patent US 11,632,401
Granted Patent B2
US 11,632,401 · App. 17/513,454 · Granted Apr 18, 2023

Semi-automatic communication network microsegmentation

Inventors: Peter Smith (Acton, MA); Aparna Ayikkara (Brookline, NH); Omar Baba (Winchester, MA); Daniel Einspanjer (Salem, NH); Anthony Gelsomini (Westwood, MA); Thomas C. Hickman (Hollis, NH); Peter Kahn (Southborough, MA); Thomas Evan Keiser, Jr. (Boston, MA); Andriy Kochura (North Andover, MA); Nikitha Koppu (Shrewsbury, MA); Scott Laplante (Bedford, NH); Xing Li (Burlington, MA); Raymond Brian Liu (Lexington, MA); Sean Lutner (Norfolk, MA); Michael J. Melson (Arlington, MA); Peter Nahas (Watertown, MA); John O'Neil (Watertown, MA); Herman Parfenov (Andover, MA); Joseph Riopel (Worcester, MA); Suji Suresh (Westford, MA); Harry Sverdlove (North Reading, MA)
Assignee: Zscaler, Inc.
H04L63/20H04L41/0893H04L63/0227H04L67/10H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,632,401
App. No.
17/513,454
Granted
Apr 18, 2023
Kind
B2
Abstract

A technique for microsegmentation includes receiving information related to hosts and applications operating in a network where the information was obtained based on a survey of the network; identifying a plurality of microsegments utilizing the information, each microsegment includes a set of hosts similar to one another; for each of the plurality of microsegments, identifying security policies that control access to hosts in each microsegment; and providing the plurality of microsegments and corresponding security policies for approval thereof.

Claims (44)

1. A method comprising steps of:

receiving information related to hosts and applications operating in a network where the information was obtained based on a survey of the network;

identifying a plurality of microsegments utilizing the information, each microsegment includes a set of hosts similar to one another;

for each of the plurality of microsegments, identifying security policies that control access to hosts in each microsegment; and

providing the plurality of microsegments and corresponding security policies for approval thereof.

2. The method of claim 1 , wherein the steps include

responsive to the approval, applying the plurality of microsegments and the corresponding security policies.

3. The method of claim 2 , wherein the approval is on a per microsegment basis.

4. The method of claim 1 , wherein the steps include

periodically repeating the receiving and the identifying steps to any of update existing microsegments and create new microsegments.

5. The method of claim 1 , wherein the set of hosts are similar to one another based on any of

their communication with one another,

communication with another set of hosts, and

software installed thereon.

6. The method of claim 1 , wherein the security policies include any of allowing or disallowing inbound connections and/or outbound connections.

7. The method of claim 6 , wherein the security policies are applied on a per application basis on each host.

8. The method of claim 1 , wherein the providing includes displaying an output including listing names and/or Internet Protocol addresses of the hosts in each of the plurality of microsegments.

9. A non-transitory computer-readable medium storing computer program instructions that are executed by at least one computer processor to perform steps of:

receiving information related to hosts and applications operating in a network where the information was obtained based on a survey of the network;

identifying a plurality of microsegments utilizing the information, each microsegment includes a set of hosts similar to one another;

for each of the plurality of microsegments, identifying security policies that control access to hosts in each microsegment; and

providing the plurality of microsegments and corresponding security policies for approval thereof.

10. The non-transitory computer-readable medium of claim 9 , wherein the steps include

responsive to the approval, applying the plurality of microsegments and the corresponding security policies.

11. The non-transitory computer-readable medium of claim 10 , wherein the approval is on a per microsegment basis.

12. The non-transitory computer-readable medium of claim 9 , wherein the steps include

periodically repeating the receiving and the identifying steps to any of update existing microsegments and create new microsegments.

13. The non-transitory computer-readable medium of claim 9 , wherein the set of hosts are similar to one another based on any of

their communication with one another,

communication with another set of hosts, and

software installed thereon.

14. The non-transitory computer-readable medium of claim 9 , wherein the security policies include any of allowing or disallowing inbound connections and/or outbound connections.

15. The non-transitory computer-readable medium of claim 14 , wherein the security policies are applied on a per application basis on each host.

16. The non-transitory computer-readable medium of claim 9 , wherein the providing includes displaying an output including listing names and/or Internet Protocol addresses of the hosts in each of the plurality of microsegments.

17. A system comprising at least one computer processor executing computer program instructions stored on at least one non-transitory computer-readable medium to perform steps of:

receiving information related to hosts and applications operating in a network where the information was obtained based on a survey of the network;

identifying a plurality of microsegments utilizing the information, each microsegment includes a set of hosts similar to one another;

for each of the plurality of microsegments, identifying security policies that control access to hosts in each microsegment; and

providing the plurality of microsegments and corresponding security policies for approval thereof.

18. The system of claim 17 , wherein the steps include

responsive to the approval, applying the plurality of microsegments and the corresponding security policies.

19. The system of claim 18 , wherein the approval is on a per microsegment basis.

20. The system of claim 17 , wherein the steps include

periodically repeating the receiving and the identifying steps to any of update existing microsegments and create new microsegments.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2021
From: SMITH, PETER; AYIKKARA, APARNA; BABA, OMAR; EINSPANJER, DANIEL; GELSOMINI, ANTHONY; HICKMAN, THOMAS C.; KAHN, PETER; KEISER, THOMAS EVAN, JR.; KOCHURA, ANDRIY; KOPPU, NIKITHA; LAPLANTE, SCOTT; LI, XING; LIU, RAYMOND BRIAN; LUTNER, SEAN; MELSON, MICHAEL J.; NAHAS, PETER; O'NEIL, JOHN; PARFENOV, HERMAN; RIOPEL, JOSEPH; SURESH, SUJI; SVERDLOVE, HARRY
To: EDGEWISE NETWORKS, INC.
Reel/Frame 057952/0542 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2021
From: EDGEWISE NETWORKS, INC.
To: ZSCALER, INC.
Reel/Frame 057952/0661 →
Continuity (3)
Continuation 16898997 · Jun 11, 2020
Provisional Application 62859793 · Jun 11, 2019
Related Publication 20220053026A1 · Feb 17, 2022
Cited By (1)
US 12,579,315