IP Library › Granted Patent US 11,888,876
Granted Patent B2
US 11,888,876 · App. 18/171,322 · Granted Jan 30, 2024

Intelligent quarantine on switch fabric for physical and virtualized infrastructure

Inventors: Balaji Sundararajan (Fremont, CA); Gaurang Rajeev Mokashi (Sunnyvale, CA); Preety Mordani (Fremont, CA); Vivek Agarwal (Campbell, CA)
Assignee: Cisco Technology, Inc.
H04L63/1416G06F9/45558H04L43/08H04L47/20H04L49/25H04L63/20G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,888,876
App. No.
18/171,322
Granted
Jan 30, 2024
Kind
B2
Abstract

Systems, methods, and computer-readable media for performing threat remediation through a switch fabric of a virtualized network environment. Data traffic passing into a virtualized network environment including a plurality of virtual machines running on a switch fabric is monitored. A network threat introduced through at a least a portion of the data traffic is identified at the switch fabric. One or more remedial measures are performed in the network environment based on the identification of the network threat in the virtualized network environment.

Claims (47)

1. A method comprising:

monitoring data traffic passing into a virtualized network environment including a plurality of virtual machines;

identifying, at a first node, a network threat introduced into the virtualized network environment through at least a portion of the data traffic passing into the virtualized network environment, the first node receiving the at least a portion of the data traffic introducing the network threat, the first node locally identifying the network threat introduced through the at least a portion of the data traffic received at the first node; and

performing one or more remedial measures in the virtualized network environment based on the identification of the network threat in the virtualized network environment.

2. The method of claim 1 , further comprising:

intercepting the at least a portion of the data traffic introducing the network threat into the virtualized network environment; and

performing the one or more remedial measures while the at least a portion of the data traffic remains in the virtualized network environment.

3. The method of claim 2 , wherein the performing the one or more remedial measures includes quarantining, in the virtualized network environment, the at least a portion of the data traffic introducing the network threat in the virtualized network environment.

4. The method of claim 1 , wherein the performing the one or more remedial measures comprises preventing transmission of the at least a portion of the data traffic introducing the network threat to either or both the virtual machines and one or more hypervisors hosting the virtual machines in the virtualized network environment.

5. The method of claim 1 , further comprising:

generating threat information regarding the network threat introduced into the virtualized network environment; and

propagating the threat information to one or more additional nodes in the virtualized network environment distinct from the first node, wherein the one or more additional nodes are configured to identify one or more additional network threats introduced into the virtualized network environment based on the threat information.

6. The method of claim 5 , wherein the threat information includes one or a combination of an identification of a type of threat of the network threat, an identification of a source of the at least a portion of the data traffic introducing the network threat into the virtualized network environment, a signature of the at least a portion of the data traffic, and an identification of characteristics of the at least a portion of the data traffic.

7. The method of claim 1 , further comprising:

matching the at least a portion of the data traffic introducing the network threat to a known network threat based on a signature of the at least a portion of the data traffic and a signature of the known network threat; and

identifying the network threat in the at least a portion of the data traffic based on a matching of the at least a portion of the data traffic to the known network threat.

8. A system comprising:

one or more processors; and

at least one non-transitory computer-readable storage medium having stored therein instructions which, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

monitor data traffic passing into a virtualized network environment including a plurality of virtual machines;

identify, at a first node, a network threat introduced into the virtualized network environment through at least a portion of the data traffic passing into the virtualized network environment, the first node receiving the at least a portion of the data traffic introducing the network threat, the first node locally identifying the network threat introduced through the at least a portion of the data traffic received at the first node; and

perform one or more remedial measures in the virtualized network environment based on the identification of the network threat in the virtualized network environment.

9. The system of claim 8 , the operations further comprising:

intercept the at least a portion of the data traffic introducing the network threat into the virtualized network environment; and

perform the one or more remedial measures while the at least a portion of the data traffic remains in the virtualized network environment.

10. The system of claim 9 , wherein the perform the one or more remedial measures includes quarantine, in the virtualized network environment, the at least a portion of the data traffic introducing the network threat in the virtualized network environment.

11. The system of claim 8 , wherein the perform the one or more remedial measures comprises prevent transmission of the at least a portion of the data traffic introducing the network threat to either or both the virtual machines and one or more hypervisors hosting the virtual machines in the virtualized network environment.

12. The system of claim 8 , the operations further comprising:

generate threat information regarding the network threat introduced into the virtualized network environment; and

propagate the threat information to one or more additional nodes in the virtualized network environment distinct from the first node, wherein the one or more additional nodes are configured to identify one or more additional network threats introduced into the virtualized network environment based on the threat information.

13. The system of claim 12 , the operations wherein the threat information includes one or a combination of an identification of a type of threat of the network threat, an identification of a source of the at least a portion of the data traffic introducing the network threat into the virtualized network environment, a signature of the at least a portion of the data traffic, and an identification of characteristics of the at least a portion of the data traffic.

14. The system of claim 8 , the operations further comprising:

match the at least a portion of the data traffic introducing the network threat to a known network threat based on a signature of the at least a portion of the data traffic and a signature of the known network threat; and

identify the network threat in the at least a portion of the data traffic based on a matching of the at least a portion of the data traffic to the known network threat.

15. A non-transitory computer-readable storage medium having stored therein instructions which, when executed by a processor, cause the processor to perform operations comprising:

monitor data traffic passing into a virtualized network environment including a plurality of virtual machines;

identify, at a first node, a network threat introduced into the virtualized network environment through at least a portion of the data traffic passing into the virtualized network environment, the first node receiving the at least a portion of the data traffic introducing the network threat, the first node locally identifying the network threat introduced through the at least a portion of the data traffic received at the first node; and

perform one or more remedial measures in the virtualized network environment based on the identification of the network threat in the virtualized network environment.

16. The non-transitory computer-readable storage medium of claim 15 , the operations further comprising:

intercept the at least a portion of the data traffic introducing the network threat into the virtualized network environment; and

perform the one or more remedial measures while the at least a portion of the data traffic remains in the virtualized network environment.

17. The non-transitory computer-readable storage medium of claim 16 , wherein the perform the one or more remedial measures includes quarantine, in the virtualized network environment, the at least a portion of the data traffic introducing the network threat in the virtualized network environment.

18. The non-transitory computer-readable storage medium of claim 15 , wherein the perform the one or more remedial measures comprises prevent transmission of the at least a portion of the data traffic introducing the network threat to either or both the virtual machines and one or more hypervisors hosting the virtual machines in the virtualized network environment.

19. The non-transitory computer-readable storage medium of claim 15 , the operations further comprising:

generate threat information regarding the network threat introduced into the virtualized network environment; and

propagate the threat information to one or more additional nodes in the virtualized network environment distinct from the first node, wherein the one or more additional nodes are configured to identify one or more additional network threats introduced into the virtualized network environment based on the threat information.

20. The non-transitory computer-readable storage medium of claim 19 , the operations wherein the threat information includes one or a combination of an identification of a type of threat of the network threat, an identification of a source of the at least a portion of the data traffic introducing the network threat into the virtualized network environment, a signature of the at least a portion of the data traffic, and an identification of characteristics of the at least a portion of the data traffic.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2023
From: SUNDARARAJAN, BALAJI; MOKASHI, GAURANG RAJEEV MOKASHI; MORDANI, PREETY; AGARWAL, VIVEK
To: CISCO TECHNOLOGY, INC.
Reel/Frame 062737/0428 →
Continuity (2)
Continuation 16826082 · Mar 20, 2020
Related Publication 20230208863A1 · Jun 29, 2023