IP Library Granted Patent US 12,395,514
Granted Patent B2
US 12,395,514 · App. 17/694,448 · Granted Aug 19, 2025

Network portion risk assessment

Inventors: Arun Raghuramu (Milpitas, CA); Aveek Kumar Das (Santa Clara, CA); Yang Zhang (Fremont, CA)
Assignee: Forescout Technologies, Inc.
H04L63/1433H04L63/0227H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,395,514
App. No.
17/694,448
Granted
Aug 19, 2025
Kind
B2
Abstract

Systems, methods, and related technologies for determining a risk associated with a network portion are described. The determination of risk associated with a network portion may include accessing network traffic from a network and determining an entity type associated with at least one entity communicatively coupled to the network. A network portion associated with the at least one entity can be determined. A risk associated with the at least one entity can be determined. A risk associated with the network portion associated with the at least one entity can be determined based on the risk associated with the at least one entity. The risk associated with the network portion can then be stored.

Claims (43)

1. A method comprising:

accessing network traffic from a network;

determining an entity type associated with at least one entity communicatively coupled to the network;

determining a network portion including the at least one entity;

determining a risk associated with the at least one entity based on an impact of a potential attack on the at least one entity and a probability of the potential attack occurring with respect to the at least one entity;

determining, by a processing device and after determining the risk associated with the at least one entity, a risk associated with the network portion including the at least one entity based on the risk associated with the at least one entity;

storing the risk associated with the network portion; and

performing an action to reduce an attack surface of the network portion for the potential attack based on the risk associated with the network portion.

2. The method of claim 1 , wherein the risk associated with the at least one entity is based on at least one of a Common Vulnerabilities and Exposures (CVE) associated with the at least one entity, patch version, software version, security posture, or credentials.

3. The method of claim 1 wherein the action comprises at least one of changing a VLAN associated with the at least one entity, quarantining the at least one entity, initiating an update, tracking traffic of the at least one entity, or sending a notification associated with the at least one entity.

4. The method of claim 1 , wherein determining the risk associated with the at least one entity is based on the entity type associated with the at least one entity.

5. The method of claim 1 , wherein the at least one entity comprises a plurality of entities and wherein the risk associated with the network portion including the plurality of entities is based on the risk for each of the plurality of entities.

6. The method of claim 1 , wherein the risk associated with the at least one entity is based on a sensitivity associated with the at least one entity.

7. The method of claim 1 , wherein the risk associated with the at least one entity is based on an objective associated with at least one of entity risk, entity sensitivity, or entity types in the network portion.

8. The method of claim 1 , wherein the risk associated with the network portion is based on a sensitivity associated with the at least one entity.

9. A system comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

access network traffic from a network;

determine an entity type associated with at least one entity communicatively coupled to the network;

determine a network portion including the at least one entity;

determine a risk associated with the at least one entity based on an impact of a potential attack on the at least one entity and a probability of the potential attack occurring with respect to the at least one entity;

determine, after the determination of the risk associated with the at least one entity, a risk associated with the network portion including the at least one entity based on the risk associated with the at least one entity;

store the risk associated with the network portion; and

perform an action to reduce an attack surface of the network portion for the potential attack based on the risk associated with the network portion.

10. The system of claim 9 , wherein the risk associated with the at least one entity is based on at least one of a Common Vulnerabilities and Exposures (CVE) associated with the at least one entity, patch version, software version, security posture, or credentials.

11. The system of claim 9 , wherein the action comprises at least one of changing a VLAN associated with the at least one entity, quarantining the at least one entity, initiating an update, tracking traffic of the at least one entity, or sending a notification associated with the at least one entity.

12. The system of claim 9 , wherein determining the risk associated with the at least one entity is based on the entity type associated with the at least one entity.

13. The system of claim 9 , wherein the at least one entity comprises a plurality of entities and wherein the risk associated with the network portion including the plurality of entities is based on the risk for each of the plurality of entities.

14. The system of claim 9 , wherein the risk associated with the at least one entity is based on a sensitivity associated with the at least one entity.

15. The system of claim 9 , wherein the risk associated with the at least one entity is based on an objective associated with at least one of entity risk, entity sensitivity, or entity types in the network portion.

16. The system of claim 9 , wherein the risk associated with the network portion is based on a sensitivity associated with the at least one entity.

17. A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device, cause the processing device to:

access network traffic from a network;

determine an entity type associated with at least one entity communicatively coupled to the network;

determine a network portion including the at least one entity;

determine a risk associated with the at least one entity based on an impact of a potential attack on the at least one entity and a probability of the potential attack occurring with respect to the at least one entity;

determine, by the processing device and after the determination of the risk associated with the at least one entity, a risk associated with the network portion including the at least one entity based on the risk associated with the at least one entity;

store the risk associated with the network portion; and

perform an action to reduce an attack surface of the network portion for the potential attack based on the risk associated with the network portion.

18. The non-transitory computer readable medium of claim 17 , wherein the action comprises at least one of changing a VLAN associated with the at least one entity, quarantining the at least one entity, initiating an update, tracking traffic of the at least one entity, or sending a notification associated with the at least one entity.

19. The non-transitory computer readable medium of claim 17 , wherein the risk associated with the at least one entity is based on at least one of a Common Vulnerabilities and Exposures (CVE) associated with the at least one entity, patch version, software version, security posture, or credentials.

20. The non-transitory computer readable medium of claim 17 , wherein the risk associated with the network portion is based on a sensitivity associated with the at least one entity and wherein the risk associated with the at least one entity is based on the sensitivity associated with the at least one entity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2025
From: RAGHURAMU, ARUN; DAS, AVEEK KUMAR; ZHANG, YANG
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 071764/0316 →
Continuity (3)
Continuation 16583023 · Sep 25, 2019
Provisional Application 62831118 · Apr 8, 2019
Related Publication 20220201032A1 · Jun 23, 2022
References Cited (13)
US 6301668B1 · Gleichauf · 2001 [cited by examiner]
US 8181240B2 · Jonnala et al. · 2012 [cited by applicant]
US 11310258B2 · Raghuramu · 2022 [cited by examiner]
US 20060095961A1 · Govindarajan et al. · 2006 [cited by applicant]
US 20060101517A1 · Banzhof · 2006 [cited by examiner]
US 20170250823A1 · Glenn · 2017 [cited by applicant]
US 20180091540A1 · Solow et al. · 2018 [cited by applicant]
US 20180159890A1 · Warnick et al. · 2018 [cited by applicant]
US 20190394224A1 · Hamdi · 2019 [cited by applicant]
Transmittal of International Preliminary Report on Patentability mailed on Sep. 28, 2021, for International Application No. PCT/US2020/026850, filed Apr. 6, 2020, pp. 8. [cited by applicant]
Transmittal of the International Search Report and Written Opinion of the International Searching Authority mailed on Sep. 15, 2020, for International Application No. PCT/US2020/026850, filed Apr. 6, 2020, pp. 12. [cited by applicant]
Liang, L. et al. (2012). “Novel Method of Assessing Network Security Risks Based on Vulnerability Correlation Graph,” 2012 2nd International Conference on Computer Science and Network Technology, 1085-1090. [cited by applicant]
Ge, M. et al. (2017). “Security Modeling and Analysis of Cross-Protocol IoT Devices,” IEEE Computer Society, 1043-1048. [cited by applicant]