IP Library › Patent Application 18478722
Patent Application
App. No. 18/478,722

AUTOMATIC REMEDIATION OF A NETWORK COMPONENT CONFIGURATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/478,722
Abstract

A computer program product includes program instructions configured to be executable by a processor to cause the processor to perform various operations. The operations include identifying a network component within a network infrastructure, wherein the network component operates with a current configuration of network security parameters. The operations further include periodically accessing the current configuration of network security parameters for the network component, accessing a most-recent authenticated configuration of network security parameters for the network component, identifying that the current configuration of the network component differs from the most-recent authenticated configuration of the network component, and automatically remediating the current configuration of the network component. A corresponding method may include the steps implementing the operations.

Claims (43)

1 . A computer program product comprising a non-volatile computer readable medium and non-transitory program instructions embodied therein, the program instructions being configured to be executable by a processor to cause the processor to perform operations comprising:

identifying a network component within a network infrastructure, wherein the network component operates with a current configuration of network security parameters;

periodically accessing the current configuration of network security parameters for the network component;

accessing a most-recent authenticated configuration of network security parameters for the network component;

identifying that the current configuration of the network component differs from the most-recent authenticated configuration of the network component; and

automatically remediating the current configuration of the network component.

2 . The computer program product of claim 1 , wherein automatically remediating the current configuration of the network component includes automatically causing the network component to revert to the most-recent authenticated configuration.

3 . The computer program product of claim 1 , wherein identifying that the current configuration of the network component differs from the most-recent authenticated configuration of the network component includes identifying, for one or more of the network security parameters, that the network security parameter has a current value that differs from an authenticated value of the network security parameter in the most-recent authenticated configuration, and wherein automatically remediating the current configuration of the network component includes automatically remediating the identified network security parameter.

4 . The computer program product of claim 3 , wherein automatically remediating the identified network security parameter includes automatically replacing the current value of the identified network security parameter with the authenticated value of the identified network security parameter.

5 . The computer program product of claim 1 , the operations further comprising:

determining whether the current configuration of the network component causes a network security vulnerability, wherein automatically remediating the current configuration of the network component includes initiating a software upgrade of the network component in response to determining that the current configuration of the network component causes a network security vulnerability.

6 . The computer program product of claim 1 , wherein identifying that the current configuration of the network component differs from the most-recent authenticated configuration of the network component includes identifying that the current configuration includes a new firewall rule that is not included in the most-recent authenticated configuration, and wherein the new firewall rule accepts network traffic that is rejected by firewall rules set out in the most-recent authenticated configuration of the network component.

7 . The computer program product of claim 6 , wherein automatically remediating the current configuration of the network component includes deleting the new firewall rule.

8 . The computer program product of claim 6 , the operations further comprising:

monitoring a volume of the network traffic that is accepted only as a result of the new firewall rule; and

throttling, filtering or blocking the network traffic in response to detecting a sudden burst in the volume of the network traffic.

9 . The computer program product of claim 8 , the operations further comprising:

prioritizing network traffic that is accepted under a firewall rule included in the most-recent authenticated configuration of the network component.

10 . The computer program product of claim 6 , the operations further comprising:

monitoring a volume of the network traffic that is accepted only as a result of the new firewall rule;

searching a security advisory database to determine whether there is a security advisory record identifying a vulnerability associated with the new firewall rule and suggesting a software upgrade; and

initiating the suggested software upgrade of the network component in response to determining that the security advisory database includes a security advisory record identifying a vulnerability associated with the new firewall rule.

11 . The computer program product of claim 10 , the operations further comprising:

initiating the suggested software upgrade to a plurality of network components within the network infrastructure.

12 . The computer program product of claim 1 , wherein identifying that the current configuration of the network component differs from the most-recent authenticated configuration of the network component includes:

accessing a change management record including a history of configuration changes entered by an authorized user; and

determining that at least one of the network security parameters of the current configuration for the network component are not included the change management record.

13 . The computer program product of claim 1 , the operations further comprising:

updating the most-recent authenticated configuration of the network component in response to detecting that the current configuration of the network component has been changed by an authorized user.

14 . The computer program product of claim 13 , wherein the most-recent authenticated configuration of the network component is stored by the network component and/or a computing system that includes the processor.

15 . The computer program product of claim 1 , wherein the identified difference between the current configuration and the most-recent authenticated configuration of the network component is a rule that allows use of an insecure protocol of communication with network component.

16 . The computer program product of claim 1 , wherein the identified difference between the current configuration and the most-recent authenticated configuration of the network component is an elevated user privilege, a sudden DNS server change, or enabling a rule allowing an external Remote Desktop Protocol connection.

17 . The computer program product of claim 1 , further comprising:

automatically generating and sending an alert in response to identifying that the current configuration of the network component differs from the most-recent authenticated configuration of the network component, wherein the alert is an email message directed to an administrative person, an Short Message Service message directed to the administrative person, or a work ticket entry in a ticketing system.

18 . The computer program product of claim 1 , wherein the network component is a firewall selected from a perimeter network firewall, software defined firewall, application layer firewall, operating system layer firewall, and hypervisor firewall.

19 . The computer program product of claim 1 , the operations further comprising:

storing, for each of a plurality of network components in the network infrastructure, a record including an Internet Protocol Address, DNS name, component type, operating system type and operating system version.

20 . A method, comprising:

identifying a network component within a network infrastructure, wherein the network component operates with a current configuration of network security parameters;

periodically accessing the current configuration of network security parameters for the network component;

accessing a most-recent authenticated configuration of network security parameters for the network component;

identifying that the current configuration of the network component differs from the most-recent authenticated configuration of the network component; and

automatically remediating the current configuration of the network component.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2024
From: LENOVO GLOBAL TECHNOLOGY (UNITED STATES) INC.
To: LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD.
Reel/Frame 067929/0952 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2023
From: HASAN, MD KAMRUL; KERN, ERIC R; BHARADWAJ, MAHESH; SELTZER, DAVID D; FURDA, ROBERT
To: LENOVO GLOBAL TECHNOLOGY (UNITED STATES) INC.
Reel/Frame 065301/0285 →