IP Library Granted Patent US 12,170,668
Granted Patent B2
US 12,170,668 · App. 17/689,820 · Granted Dec 17, 2024

Network security path identification and validation

Inventors: Michal Trembacz (Wexford, IE); Gianstefano Monni (Nuoro, IT)
Assignee: Salesforce, Inc.
H04L63/101H04L41/0893H04L41/12H04L63/18H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,170,668
App. No.
17/689,820
Granted
Dec 17, 2024
Kind
B2
Abstract

Embodiments herein may relate to a technique for identification and verification of compliance with one or more pre-defined security policy sets for a network. Specifically, embodiments may include generation of an access control graph (ACG) that relates to the network. One or more paths of the ACG may be identified, and then compared against the pre-defined security policy sets. Other embodiments may be described or claimed.

Claims (35)

1. A non-transitory machine-readable storage medium that provides instructions that, if executed by a set of one or more processors, are configurable to cause said set of one or more processors to perform operations comprising:

generating, based on node-related classification features of respective nodes of a plurality of nodes of a network and edge-related classification features of respective communicative couplings of a plurality of communicative couplings between respective nodes of the network, an access control graph (ACG) that relates to the network;

identifying, based on the ACG, one or more paths between a first node of the plurality of nodes and a second node of the plurality of nodes, wherein a path of the one or more paths includes one or more communicative couplings between the first node and the second node;

identifying whether respective paths of the one or more paths comply with a pre-defined security policy set related to the network, the identifying including comparing respective classifications of respective communicative couplings of the path with a class specified by the pre-defined security policy set; and

outputting an indication of compliance of the one or more paths.

2. The non-transitory machine-readable storage medium of claim 1 , wherein the ACG is a model of a network access control list (NACL) related to the network.

3. The non-transitory machine-readable storage medium of claim 2 , wherein identifying the one or more paths is based on identifying communication flows allowed by the NACL between the first node and the second node.

4. The non-transitory machine-readable storage medium of claim 1 , wherein the path of the one or more paths includes a third node communicatively coupled with the first node and the second node.

5. The non-transitory machine-readable storage medium of claim 1 , wherein identifying the one or more paths is based on a shortest-path algorithm and a depth-first search algorithm.

6. The non-transitory machine-readable storage medium of claim 5 , wherein the shortest-path algorithm is a Dijkstra algorithm or a Bellman-Ford algorithm.

7. The non-transitory machine-readable storage medium of claim 5 , wherein the depth-first algorithm is applied subsequent to the application of the shortest-path algorithm.

8. The non-transitory machine-readable storage medium of claim 1 , wherein the edge-related classification feature is a feature related to one or more of: an authentication-related feature, an authorization-related feature, and an encryption-related feature.

9. The non-transitory machine-readable storage medium of claim 1 , wherein the node-related classification feature is a feature related to an internet protocol (IP) address of a node of the network.

10. The non-transitory machine-readable storage medium of claim 1 , wherein identifying whether the path complies with the pre-defined security policy set includes comparing respective classifications of respective nodes of the path with classes specified by the pre-defined security policy set.

11. The non-transitory machine-readable storage medium of claim 1 , wherein a communicative coupling between two nodes of the plurality of nodes is an edge of the ACG.

12. An apparatus comprising:

a set of one or more processors;

a non-transitory machine-readable storage medium that provides instructions that, if executed by the set of one or more processors, are configurable to cause the apparatus to perform operations comprising,

generating, based on node-related classification features of respective nodes of a plurality of nodes of a network and edge-related classification features of respective communicative couplings of a plurality of communicative couplings between respective nodes of the network, an access control graph (ACG) that relates to the network;

identifying, based on the ACG, one or more paths between a first node of the plurality of nodes and a second node of the plurality of nodes, wherein a path of the one or more paths includes one or more communicative couplings between the first node and the second node;

identifying whether respective paths of the one or more paths comply with a pre-defined security policy set related to the network, the identifying including comparing the pre-defined security policy set with edge-related classification features of communicative couplings in the path; and

outputting an indication of compliance of the one or more paths.

13. The apparatus of claim 12 , wherein the edge-related classification feature is a feature related to one or more of: an authentication-related feature, an authorization-related feature, and an encryption-related feature.

14. The apparatus of claim 12 , wherein the node-related classification feature is a feature related to an internet protocol (IP) address of a node of the network.

15. The apparatus of claim 12 , wherein identifying whether the path complies with the pre-defined security policy set includes comparing the pre-defined security policy set with the node-related classification features of nodes in the path.

16. The apparatus of claim 12 , wherein the ACG is a model of a network access control list (NACL) related to the network, and wherein a communicative coupling between two nodes of the plurality of nodes is an edge of the ACG.

17. A method comprising:

generating, based on node-related classification features of respective nodes of a plurality of nodes of a network and edge-related classification features of respective communicative couplings of a plurality of communicative couplings between respective nodes of the network, an access control graph (ACG) that relates to the network;

identifying, based on the ACG, one or more paths between a first node of the plurality of nodes and a second node of the plurality of nodes, wherein a path of the one or more paths includes one or more communicative couplings between the first node and the second node;

identifying whether respective paths of the one or more paths comply with a pre-defined security policy set related to the network, the identifying including comparing the pre-defined security policy set with edge-related classification features of communicative couplings in the path; and

outputting an indication of compliance of the one or more paths.

18. The method of claim 17 , wherein the edge-related classification feature related to one or more of: an authentication-related feature, an authorization-related feature, and an encryption-related feature.

19. The method of claim 17 , wherein the node-related classification feature is a feature based on an internet protocol (IP) address of a node of the network.

20. The method of claim 17 , wherein identifying whether the path complies with the pre-defined security policy set includes comparing the pre-defined security policy set with the node-related classification features of nodes in the path.

21. The method of claim 17 , wherein the ACG is a model of a network access control list (NACL) related to the network, and wherein a communicative coupling between two nodes of the plurality of nodes is an edge of the ACG.

Assignments (2)
CHANGE OF NAME Recorded Oct 11, 2024
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 069166/0312 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2022
From: TREMBACZ, MICHAL; MONNI, GIANSTEFANO
To: SALESFORCE.COM, INC.
Reel/Frame 059215/0058 →
Continuity (1)
Related Publication 20230291736A1 · Sep 14, 2023