IP Library Patent Application 18129902
Patent Application
App. No. 18/129,902

SECURITY POSTURE VISUALIZATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/129,902
Abstract

The disclosure provides an approach for visualizing a security posture of a network entity. Embodiments include a method including displaying, on a display of a computing device, a security posture summary screen of a network entity. The method further includes receiving a first input on a first connection depicted in the security posture summary screen, the first connection between the network entity and a first entity of one or more source entities or one or more destination entities. The method further includes in response to the first input, displaying, on the display, a drill down view screen of first security rules applicable to communication between the network entity and the first entity.

Claims (69)

1 . A method of visualizing a security posture of a network entity, comprising:

displaying, on a display of a computing device, a security posture summary screen of a network entity, the security posture summary screen comprising:

a depiction of the network entity;

a depiction of one or more source entities or one or more destination entities;

a depiction of one or more connections between the one or more source entities or one or more destination entities and the network entity;

for each of the one or more connections, a depiction of a number of security rules, for each of one or more types of rules, applicable to communication between the network entity and the corresponding source entity or destination entity;

receiving a first input on a first connection of the one or more connections, the first connection between the network entity and a first entity of the one or more source entities or one or more destination entities; and

in response to the first input, displaying, on the display, a drill down view screen of first security rules applicable to communication between the network entity and the first entity, the drill down view screen comprising:

a list of the first security rules arranged in priority order; and

one or more details about each security rule of the first security rules.

2 . The method of claim 1 , further comprising:

receiving a filter parameter in a filter field of the security posture summary screen; and

in response to the receiving the filter parameter, displaying a filtered security posture summary screen of the network entity, the filtered security posture summary screen comprising:

a depiction of the network entity; and

a depiction of a subset of the one or more source entities or one or more destination entities, wherein the subset includes any of the one or more source entities or one or more destination entities that have a same parameter as the filter parameter;

3 . The method of claim 2 , wherein the filter parameter specifies one or more of a policy name, a policy status, a rule comment, a rule identifier, a rule name, a second comment, a source entity name, a source IP address, or a source group.

4 . The method of claim 1 , wherein for at least one security rule of the first security rules, the one or more details comprises an insights item indicating one or more of whether the rule is possibly a dead rule or a duplicate rule.

5 . The method of claim 1 , wherein the security posture summary screen comprises a toggle for toggling between depicting entities as services and depicting entities as groups or static IP addresses.

6 . The method of claim 1 , wherein the network entity comprises a virtual computing instance, and wherein each of the one or more source entities or one or more destination entities comprise at least one of a static IP address, a security group, or a service application.

7 . The method of claim 1 , further comprising:

receiving a second input on the first connection of the one or more connections; and

in response to the second input, displaying, on the display, a quick view screen of the first security rules, the quick view screen comprising:

a depiction of the number of security rules, for each of the one or more types of rules, applicable to communication between the network entity and the first entity; and

for each of the one or more types of rules, a depiction of one or more services to which a security rule of the number of security rules applies.

8 . A computing system comprising:

memory; and

at least one processor coupled to the memory, the at least one processor configured to:

display, on a display, a security posture summary screen of a network entity, the security posture summary screen comprising:

a depiction of the network entity;

a depiction of one or more source entities or one or more destination entities;

a depiction of one or more connections between the one or more source entities or one or more destination entities and the network entity;

for each of the one or more connections, a depiction of a number of security rules, for each of one or more types of rules, applicable to communication between the network entity and the corresponding source entity or destination entity;

receive a first input on a first connection of the one or more connections, the first connection between the network entity and a first entity of the one or more source entities or one or more destination entities; and

in response to the first input, display, on the display, a drill down view screen of first security rules applicable to communication between the network entity and the first entity, the drill down view screen comprising:

a list of the first security rules arranged in priority order; and

one or more details about each security rule of the first security rules.

9 . The computing system of claim 8 , wherein the at least one processor is further configured to:

receive a filter parameter in a filter field of the security posture summary screen; and

in response to the receiving the filter parameter, display a filtered security posture summary screen of the network entity, the filtered security posture summary screen comprising:

a depiction of the network entity; and

a depiction of a subset of the one or more source entities or one or more destination entities, wherein the subset includes any of the one or more source entities or one or more destination entities that have a same parameter as the filter parameter;

10 . The computing system of claim 9 , wherein the filter parameter specifies one or more of a policy name, a policy status, a rule comment, a rule identifier, a rule name, a second comment, a source entity name, a source IP address, or a source group.

11 . The computing system of claim 8 , wherein for at least one security rule of the first security rules, the one or more details comprises an insights item indicating one or more of whether the rule is possibly a dead rule or a duplicate rule.

12 . The computing system of claim 8 , wherein the security posture summary screen comprises a toggle for toggling between depicting entities as services and depicting entities as groups or static IP addresses.

13 . The computing system of claim 8 , wherein the network entity comprises a virtual computing instance, and wherein each of the one or more source entities or one or more destination entities comprise at least one of a static IP address, a security group, or a service application.

14 . The computing system of claim 8 , wherein the at least one processor is further configured to:

receive a second input on the first connection of the one or more connections; and

in response to the second input, display, on the display, a quick view screen of the first security rules, the quick view screen comprising:

a depiction of the number of security rules, for each of the one or more types of rules, applicable to communication between the network entity and the first entity; and

for each of the one or more types of rules, a depiction of one or more services to which a security rule of the number of security rules applies.

15 . A non-transitory computer readable media storing instructions, that when executed by a computer system, causes the computer system to perform operations for visualizing a security posture of a network entity, the operations comprising:

displaying, on a display, a security posture summary screen of a network entity, the security posture summary screen comprising:

a depiction of the network entity;

a depiction of one or more source entities or one or more destination entities;

a depiction of one or more connections between the one or more source entities or one or more destination entities and the network entity;

for each of the one or more connections, a depiction of a number of security rules, for each of one or more types of rules, applicable to communication between the network entity and the corresponding source entity or destination entity;

receiving a first input on a first connection of the one or more connections, the first connection between the network entity and a first entity of the one or more source entities or one or more destination entities; and

in response to the first input, displaying, on the display, a drill down view screen of first security rules applicable to communication between the network entity and the first entity, the drill down view screen comprising:

a list of the first security rules arranged in priority order; and

one or more details about each security rule of the first security rules.

16 . The non-transitory computer readable media of claim 15 , wherein the operations further comprise:

receiving a filter parameter in a filter field of the security posture summary screen; and

in response to the receiving the filter parameter, displaying a filtered security posture summary screen of the network entity, the filtered security posture summary screen comprising:

a depiction of the network entity; and

a depiction of a subset of the one or more source entities or one or more destination entities, wherein the subset includes any of the one or more source entities or one or more destination entities that have a same parameter as the filter parameter;

17 . The non-transitory computer readable media of claim 16 , wherein the filter parameter specifies one or more of a policy name, a policy status, a rule comment, a rule identifier, a rule name, a second comment, a source entity name, a source IP address, or a source group.

18 . The non-transitory computer readable media of claim 15 , wherein for at least one security rule of the first security rules, the one or more details comprises an insights item indicating one or more of whether the rule is possibly a dead rule or a duplicate rule.

19 . The non-transitory computer readable media of claim 15 , wherein the security posture summary screen comprises a toggle for toggling between depicting entities as services and depicting entities as groups or static IP addresses.

20 . The non-transitory computer readable media of claim 15 , wherein the network entity comprises a virtual computing instance, and wherein each of the one or more source entities or one or more destination entities comprise at least one of a static IP address, a security group, or a service application.

Assignments (2)
CHANGE OF NAME Recorded May 8, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067355/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2023
From: PARASHAR, SHRINIVAS SHARAD; PATEL, KALPESH; KHANDELWAL, TARANG; BALI, PRIYANKA; VAIDYULA, KRISHNA PAVAN
To: VMWARE, INC.
Reel/Frame 063199/0721 →