IP Library Granted Patent US 11,902,332
Granted Patent B2
US 11,902,332 · App. 18/097,357 · Granted Feb 13, 2024

Semi-automatic communication network microsegmentation

Inventors: Peter Smith (Acton, MA); Aparna Ayikkara (Brookline, NH); Omar Baba (Winchester, MA); Daniel Einspanjer (Salem, NH); Anthony Gelsomini (Westwood, MA); Thomas C. Hickman (Hollis, NH); Peter Kahn (Southborough, MA); Thomas Evan Keiser, Jr. (Boston, MA); Andriy Kochura (North Andover, MA); Nikitha Koppu (Shrewsbury, MA); Scott Laplante (Bedford, NH); Xing Li (Burlington, MA); Raymond Brian Liu (Lexington, MA); Sean Lutner (Norfolk, MA); Michael J. Melson (Arlington, MA); Peter Nahas (Watertown, MA); John O'Neil (Watertown, MA); Herman Parfenov (Andover, MA); Joseph Riopel (Worcester, MA); Suji Suresh (Westford, MA); Harry Sverdlove (North Reading, MA)
Assignee: Zscaler, Inc.
H04L63/20H04L41/0893H04L63/0227H04L67/10H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,902,332
App. No.
18/097,357
Granted
Feb 13, 2024
Kind
B2
Abstract

A technique for microsegmentation includes receiving information related to hosts and applications operating in a network where the information was obtained based on a survey of the network; identifying a plurality of microsegments utilizing the information, each microsegment includes a set of hosts similar to one another; for each of the plurality of microsegments, identifying security policies that control access to hosts in each microsegment; and providing the plurality of microsegments and corresponding security policies for approval thereof.

Claims (35)

1. A method comprising steps of:

collecting network information associated with a plurality of hosts;

measuring a similarity for each of the plurality of hosts;

identifying, from the plurality of hosts, a group of hosts which are sufficiently similar to each other as measured by one or more criteria related to any of how the group of hosts communicate with other hosts and software installed thereon;

generating and storing data indicating that the identified group of hosts forms a particular microsegment: and

providing output representing each defined microsegment.

2. The method of claim 1 , wherein the steps are repeated for identifying or updating existing microsegments.

3. The method of claim 1 , wherein the group of hosts are considered sufficiently similar to one another based on the group of hosts communicating with each other more in comparison to how much the group of hosts communicate with other hosts.

4. The method of claim 1 , wherein the group of hosts are considered sufficiently similar to one another based on if hosts in a first group of hosts communicate with hosts in a second group of hosts.

5. The method of claim 1 , wherein the group of hosts are considered sufficiently similar to one another based on if each host in the group of hosts have the same set of software installed.

6. The method of claim 1 , wherein the steps include

for each identified microsegment, automatically identifying existing network application security policies that control access to hosts in that microsegment.

7. The method of claim 6 , wherein the security policies include any of allowing or disallowing inbound connections and outbound connections.

8. A non-transitory computer-readable medium storing computer program instructions that are executed by at least one computer processor to perform steps of:

collecting network information associated with a plurality of hosts;

measuring a similarity for each of the plurality of hosts;

identifying, from the plurality of hosts, a group of hosts which are sufficiently similar to each other as measured by one or more criteria related to any of how the group of hosts communicate with other hosts and software installed thereon;

generating and storing data indicating that the identified group of hosts forms a particular microsegment: and

providing output representing each defined microsegment.

9. The non-transitory computer-readable medium of claim 8 , wherein the steps are repeated for identifying or updating existing microsegments.

10. The non-transitory computer-readable medium of claim 8 , wherein the group of hosts are considered sufficiently similar to one another based on the group of hosts communicating with each other more in comparison to how much the group of hosts communicate with other hosts.

11. The non-transitory computer-readable medium of claim 8 , wherein the group of hosts are considered sufficiently similar to one another based on if hosts in a first group of hosts communicate with hosts in a second group of hosts.

12. The non-transitory computer-readable medium of claim 8 , wherein the group of hosts are considered sufficiently similar to one another based on if each host in the group of hosts have the same set of software installed.

13. The non-transitory computer-readable medium of claim 8 , wherein the steps include

for each identified microsegment, automatically identifying existing network application security policies that control access to hosts in that microsegment.

14. The non-transitory computer-readable medium of claim 13 , wherein the security policies include any of allowing or disallowing inbound connections and outbound connections.

15. A system comprising at least one computer processor executing computer program instructions stored on at least one non-transitory computer-readable medium to perform steps of:

collecting network information associated with a plurality of hosts;

measuring a similarity for each of the plurality of hosts;

identifying, from the plurality of hosts, a group of hosts which are sufficiently similar to each other as measured by one or more criteria related to any of how the group of hosts communicate with other hosts and software installed thereon;

generating and storing data indicating that the identified group of hosts forms a particular microsegment: and

providing output representing each defined microsegment.

16. The system of claim 15 , wherein the steps are repeated for identifying or updating existing microsegments.

17. The system of claim 15 , wherein the steps include

for each identified microsegment, automatically identifying existing network application security policies that control access to hosts in that microsegment.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 16, 2023
From: SMITH, PETER; AYIKKARA, APARNA; BABA, OMAR; EINSPANJER, DANIEL; GELSOMINI, ANTHONY; HICKMAN, THOMAS C.; KAHN, PETER; KEISER, THOMAS EVAN, JR.; KOCHURA, ANDRIY; KOPPU, NIKITHA; LAPLANTE, SCOTT; LI, XING; LIU, RAYMOND BRIAN; LUTNER, SEAN; MELSON, MICHAEL J.; NAHAS, PETER; O'NEIL, JOHN; PARFENOV, HERMAN; RIOPEL, JOSEPH; SURESH, SUJI; SVERDLOVE, HARRY
To: EDGEWISE NETWORKS, INC.
Reel/Frame 062383/0106 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 16, 2023
From: EDGEWISE NETWORKS, INC.
To: ZSCALER, INC.
Reel/Frame 062383/0192 →
Continuity (4)
Continuation 17513454 · Oct 28, 2021
Continuation 16898997 · Jun 11, 2020
Provisional Application 62859793 · Jun 11, 2019
Related Publication 20230156040A1 · May 18, 2023