IP Library › Granted Patent US 12,732,506
Granted Patent B2
US 12,732,506 · App. 18/638,424 · Granted Sep 8, 2026

Segmentation management including visualization, configuration, simulation, or a combination thereof

Inventors: Ilya Fainberg (Tel Aviv, IL); Yafit Maor (Even-Yehuda, IL); Amir Olswang (Kidron, IL)
Assignee: FORESCOUT TECHNOLOGIES, INC.
H04L63/104H04L41/0894H04L41/0895H04L41/145H04L43/045H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,506
App. No.
18/638,424
Granted
Sep 8, 2026
Kind
B2
Abstract

Technology for segmentation management is described. The segmentation management may include visualization, configuration, simulation, or a combination thereof, of segmentation policies. Segmentation management may include tagging entities communicatively coupled to a network, grouping the entities communicatively coupled to the network into a plurality of groups based at least on one or more tags that are associated with each of the entities, and displaying a user interface for selecting a first group and a second group from the plurality of groups. In response to receiving an input through the user interface, an indication of network traffic is displayed between the first group and the second group, where the network traffic is associated with one or more segmentation rules. In response to receiving additional input through the user interface, segmentation management configures an enforcement point with the segmentation rules.

Claims (37)

1 . A method comprising:

tagging a plurality of entities communicatively coupled to a network;

grouping the plurality of entities communicatively coupled to the network into a plurality of groups based at least on one or more tags that are associated with each of the plurality of entities;

monitoring and storing network traffic;

displaying one or more controls for selecting a first group and a second group from the plurality of groups;

in response to receiving an input associated with the one or more controls, displaying, by a processing device, an indication of network traffic between the first group and the second group, the network traffic being associated with one or more segmentation rules received through the input or obtained from storage, wherein displaying the indication of the network traffic comprises performing a simulation with the stored network traffic in view of the one or more segmentation rules, and displaying network traffic resulting from the simulation; and

in response to receiving a second input through the one or more controls, configuring an enforcement point with the one or more segmentation rules, the enforcement point being associated with the first group and the second group.

2 . The method of claim 1 , wherein the one or more controls comprises a first control configured to apply the one or more segmentation rules to an entire group, and a second control to apply the one or more segmentation rules to a single entity of the plurality of entities.

3 . The method of claim 1 , further comprising, in response to receiving, through the one or more controls, a selection of a service that is configured on an entity of the first group or the second group, displaying a subset of the network traffic resulting from the simulation, wherein the subset of the network traffic is associated with the service.

4 . The method of claim 1 , wherein tagging the plurality of entities includes generating one or more tags for each of the plurality of entities wherein at least one of the one or more tags are determined based on a characteristic of an entity that is independent of internet protocol (IP) address.

5 . The method of claim 4 , wherein grouping the plurality of entities is performed based on commonality of the one or more tags among the plurality of entities.

6 . The method of claim 1 , wherein displaying the indication of the network traffic comprises displaying an indication comprising at least one of a first visual indication associated in response to allowed communication between a first entity of the first group and a second entity of the second group, a second visual indication in response to partial allowed communication between the first entity of the first group and the second entity of the second group, and a third visual indication in response to blocked communication between the first entity of the first group and the second entity of the second group.

7 . The method of claim 1 , further comprising, in response to receiving a third input associated with the one or more controls, displaying a subset of the network traffic resulting from the simulation, wherein the subset of the network traffic is authorized, and in response to receiving a fourth input associated with the one or more controls, displaying a second subset of the network traffic resulting from the simulation, wherein the second subset of the network traffic is unauthorized.

8 . A system comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

tag a plurality of entities communicatively coupled to a network;

group the plurality of entities communicatively coupled to the network into a plurality of groups based at least on one or more tags that are associated with each of the plurality of entities;

monitor and store traffic of the network;

display one or more controls for selecting a first group and a second group from the plurality of groups;

in response to receiving an input associated with the one or more controls, display an indication of network traffic between the first group and the second group, the network traffic being associated with one or more segmentation rules received through the input or obtained from storage, wherein to display the indication of the network traffic comprises to perform a simulation with the stored network traffic in view of the one or more segmentation rules, and to display network traffic resulting from the simulation; and

in response to receiving a second input through the one or more controls, configure an enforcement point with the one or more segmentation rules, the enforcement point being associated with the first group and the second group.

9 . The system of claim 8 , wherein the one or more controls comprise a first control configured to apply the one or more segmentation rules to an entire group, and a second control to apply the one or more segmentation rules to a single entity of the plurality of entities.

10 . The system of claim 8 , wherein the processing device is further to, in response to receiving, through the one or more controls, a selection of a service that is configured on an entity of the first group or the second group, display a subset of the network traffic resulting from the simulation, wherein the subset of the network traffic is associated with the service.

11 . The system of claim 8 , wherein to tag the plurality of entities comprises to: generate one or more tags for each of the plurality of entities wherein at least one of the one or more tags are determined based on a characteristic of an entity that is independent of internet protocol (IP) address.

12 . The system of claim 11 , wherein to group the plurality of entities is performed based on commonality of the one or more tags among the plurality of entities.

13 . A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device, cause the processing device to:

tag a plurality of entities communicatively coupled to a network;

group the plurality of entities communicatively coupled to the network into a plurality of groups based at least on one or more tags that are associated with each of the plurality of entities;

monitor and store traffic of the network;

display one or more controls for selecting a first group and a second group from the plurality of groups;

in response to receiving an input associated with the one or more controls, display, by the processing device, an indication of network traffic between the first group and the second group, the network traffic being associated with one or more segmentation rules received through the input or obtained from storage, wherein to display the indication of the network traffic comprises to perform a simulation with the stored network traffic in view of the one or more segmentation rules, and to display network traffic resulting from the simulation; and

in response to receiving a second input through the one or more controls, configure an enforcement point with the one or more segmentation rules, the enforcement point being associated with the first group and the second group.

14 . The non-transitory computer readable medium of claim 13 , wherein the one or more controls comprise a first control configured to apply the one or more segmentation rules to an entire group, and a second control to apply the one or more segmentation rules to a single entity of the plurality of entities.

15 . The non-transitory computer readable medium of claim 13 , wherein the processing device is further to, in response to receiving, through the one or more controls, a selection of a service that is configured on an entity of the first group or the second group, display a subset of the network traffic resulting from the simulation, wherein the subset of the network traffic is associated with the service.

16 . The non-transitory computer readable medium of claim 13 , wherein to tag the plurality of entities comprises to: generate one or more tags for each of the plurality of entities wherein at least one of the one or more tags are determined based on a characteristic of an entity that is independent of internet protocol (IP) address.

17 . The non-transitory computer readable medium of claim 16 , wherein to group the plurality of entities is performed based on commonality of the one or more tags among the plurality of entities.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2024
From: FAINBERG, ILYA; MAOR, YAFIT; OLSWANG, AMIR
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 067404/0296 →
Continuity (4)
Continuation 17567100 · Dec 31, 2021
Continuation 16144051 · Sep 27, 2018
Continuation In Part 16023284 · Jun 29, 2018
Related Publication 20240267293A1 · Aug 8, 2024
References Cited (24)
US 7277931B1 · Booth et al. · 2007 [cited by applicant]
US 8341717B1 · Delker et al. · 2012 [cited by applicant]
US 10212191B2 · Kirner et al. · 2019 [cited by applicant]
US 10560452B2 · Osaki et al. · 2020 [cited by applicant]
US 20070157286A1 · Singh et al. · 2007 [cited by applicant]
US 20090198707A1 · Rohner · 2009 [cited by applicant]
US 20130275574A1 · Hugard IV et al. · 2013 [cited by applicant]
US 20150326528A1 · Murthy et al. · 2015 [cited by applicant]
US 20160301717A1 · Dotan et al. · 2016 [cited by applicant]
US 20170118173A1 · Arramreddy et al. · 2017 [cited by applicant]
US 20180159751A1 · Zhang et al. · 2018 [cited by applicant]
US 20180176185A1 · Kumar et al. · 2018 [cited by applicant]
US 20190306182A1 · Fry et al. · 2019 [cited by applicant]
CN 104580078A · 2015 [cited by applicant]
JP 2007243373A · 2007 [cited by applicant]
JP 2016540463A · 2016 [cited by applicant]
JP 2017147575A · 2017 [cited by applicant]
JP Decision to Grant a Patent dated Apr. 12, 2023, (received Apr. 17, 2023) from related JP Patent Application No. 2021-500065 filed Jan. 4, 2021; 4 pages. [cited by applicant]
International Preliminary Report on Patentability mailed on Jan. 7, 2021, for International Application No. PCT/US2019/036106, filed Jun. 7, 2019, p. 8. [cited by applicant]
International Preliminary Report on Patentability mailed on Apr. 8, 2021, for International Application No. PCT/US2019/052018, filed Sep. 7, 2019, p. 8. [cited by applicant]
International Preliminary Report on Patentability mailed on Apr. 8, 2021, for International Application No. PCT/US2019/052017, filed Sep. 19, 2019, p. 8. [cited by applicant]
International Search report for the International Application No. PCT/US2019/052018, mailed Nov. 12, 2019. [cited by applicant]
International Search report for the International Application No. PCT/US2019/052017, mailed Nov. 12, 2019. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2019/036106, mailed Sep. 8, 2019. [cited by applicant]