IP Library Granted Patent US 12,712,887
Granted Patent B2
US 12,712,887 · App. 18/795,717 · Granted Aug 18, 2026

Visualization tool for real-time network risk assessment

Inventors: F. William Conner (Dallas, TX); MinhDung Joe NguyenLe (San Ramon, CA); Atul Dhablania (San Jose, CA); Richard Chio (Union City, CA); Justin Jose (San Jose, CA); Lalith Kumar Dampanaboina (Milpitas, CA)
Assignee: SONICWALL INC.
H04L63/1408H04L43/028H04L43/045H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,712,887
App. No.
18/795,717
Granted
Aug 18, 2026
Kind
B2
Abstract

The present disclosure relates to methods and apparatus that collect data regarding malware threats, that organizes this collected malware threat data, and that provides this data to computers or people such that damage associated with these software threats can be quantified and reduced. The present disclosure is also directed to preventing the spread of malware before that malware can damage computers or steal computer data. Methods consistent with the present disclosure may optimize tests performed at different levels of a multi-level threat detection and prevention system. As such, methods consistent with the present disclosure may collect data from various sources that may include endpoint computing devices, firewalls/gateways, or isolated (e.g. “sandbox”) computers. Once this information is collected, it may then be organized, displayed, and analyzed in ways that were not previously possible.

Claims (30)

1 . A method for visualizing a spread of malware, the method comprising:

receiving information regarding at least one type of malware threat targeting a computer network that is protected by a plurality of different malware protection layers corresponding to different types of malware threats;

performing a first set of malware tests associated with a first protection layer of the plurality of malware protection layers and a second set of malware tests associated with a second protection layer of the plurality of malware protection layers in response to the at least one type of malware threat, wherein the first set of malware tests includes one or more of content filtering using universal resource locators (URL), botnet filtering, firewall or gateway virus inspection scanning, or intrusion prevention and the second set of malware test is different as compared to the first set of malware test:

generating a visualization that illustrates the computer network as being surrounded by the plurality of different malware protection layers and that illustrates a movement of the at least one type of malware threat moving toward, through, or stopping at the first protection layer and at the second protection layer based on results of the first set of malware tests and of the second set of malware tests; and

presenting the visualization of the movement of the at least one type of malware threat within a user interface on a display of an electronic device, wherein the user interface includes one or more options for enabling or disabling one or more of the different malware protection layers associated with the computer network.

2 . The method of claim 1 , wherein the visualization dynamically illustrates the at least one type of malware threat moving relative to the first protection layer.

3 . The method of claim 2 , wherein the at least one type of malware threat is illustrated in the dynamic illustration as moving toward, through, or stopping at one or more of the different malware protection layers.

4 . The method of claim 1 , wherein the at least one type of malware threat is a new malware type, and further comprising generating one or more deep packet inspection (DPI) signatures that are characteristic of the new malware type.

5 . The method of claim 4 , further comprising providing the DPI signatures to an external computer for storage.

6 . The method of claim 1 , wherein the visualization includes one or more arrowed lines that represent the at least one type of a malware threat.

7 . The method of claim 1 , wherein the visualization includes one or more different colors for the different protection layers and the at least one type of malware threat.

8 . The method of claim 1 , wherein the visualization is generated in real-time or in near-real-time with receipt of test data from the first set of malware tests.

9 . A system for visualizing a spread of malware, the system comprising:

a communication interface that communicates over a communication network to receive information regarding at least one type of malware threat targeting a computer network that is protected by a plurality of different malware protection layers corresponding to different types of malware threats; and

a processor that executes instructions stored in memory, wherein the processor executes the instructions to:

perform a first set of malware tests associated with a first protection layer of the plurality of malware protection layers and a second set of malware tests associated with a second protection layer of the plurality of malware protection layers in response to the at least one type of malware threat, wherein the first set of malware tests includes one or more of content filtering using universal resource locators (URL), botnet filtering, firewall/gateway virus inspection scanning, or intrusion prevention and the second set of malware test is different as compared to the first set of malware test;

generate a visualization that illustrates the computer network as being surrounded by the plurality of different malware protection layers and that illustrates a movement of the at least one type of malware threat moving toward, through, or stopping at the first protection layer and at the second protection layer based on results of the first set of malware tests and of the second set of malware tests; and

add the visualization to a presentation of the movement of the at least one type of malware threat within a user interface on a display of an electronic device, wherein the user interface includes one or more options for enabling or disabling one or more of the different malware protection layers associated with the computer network.

10 . The system of claim 9 , wherein the visualization dynamically illustrates the at least one type of malware threat moving relative to the first protection layer.

11 . The system of claim 10 , wherein the at least one type of malware threat is illustrated in the dynamic illustration as moving toward, through, or stopping at one or more of the different malware protection layers.

12 . The system of claim 9 , wherein the at least one type of malware threat is a new malware type, and further comprising generating one or more deep packet inspection (DPI) signatures that are characteristic of the new malware type.

13 . The system of claim 12 , wherein the communication interface further provides the DPI signatures to an external computer for storage.

14 . The system of claim 9 , wherein the visualization includes one or more arrowed lines that represent the at least one type of a malware threat.

15 . The system of claim 9 , wherein the visualization includes one or more different colors for the different protection layers and the at least one type of malware threat.

16 . The system of claim 9 , wherein the visualization is generated in real-time or in near-real-time with receipt of test data from the first set of malware tests.

17 . A non-transitory, computer-readable storage medium, having embodied thereon a program executable by a processor to perform a method for visualizing a spread of malware, the method comprising:

receiving information regarding at least one type of malware threat targeting a computer network that is protected by a plurality of different malware protection layers corresponding to different types of malware threats;

performing a first set of malware tests associated with a first protection layer of the plurality of malware protection layers and a second set of malware tests associated with a second protection layer of the plurality of malware protection layers in response to the at least one type of malware threat, wherein the first set of malware tests includes one or more of content filtering using universal resource locators (URL), botnet filtering, firewall/gateway virus inspection scanning, or intrusion prevention and the second set of malware test is different as compared to the first set of malware test;

generating a visualization that illustrates the computer network as being surrounded by the plurality of different malware protection layers and that illustrates a movement of the at least one type of malware threat moving toward, through, or stopping at the first protection layer and at the second protection layer based on results of the first set of malware tests and of the second set of malware tests; and

presenting the visualization of the movement of the at least one type of malware threat within a user interface on a display of an electronic device, wherein the user interface includes one or more options for enabling or disabling one or more of the different malware protection layers associated with the computer network.

Assignments (2)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071758/0159 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2024
From: CONNER, F. WILLIAM; NGUYENLE, MINHDUNG JOE; DHABLANIA, ATUL; CHIO, RICHARD; JOSE, JUSTIN; DAMPANABOINA, LALITH KUMAR
To: SONICWALL INC.
Reel/Frame 068960/0842 →
Continuity (4)
Continuation 17862948 · Jul 12, 2022
Continuation 16863933 · Apr 30, 2020
Provisional Application 62943122 · Dec 3, 2019
Related Publication 20250039191A1 · Jan 30, 2025
References Cited (66)
US 5948104A · Gluck et al. · 1999 [cited by applicant]
US 7743419B1 · Mashevsky et al. · 2010 [cited by applicant]
US 7823205B1 · Isenberg et al. · 2010 [cited by applicant]
US 8875292B1 · Bogorad et al. · 2014 [cited by applicant]
US 8904535B2 · Liu et al. · 2014 [cited by applicant]
US 8990723B1 · Lymer et al. · 2015 [cited by applicant]
US 9009827B1 · Albertson et al. · 2015 [cited by applicant]
US 10104101B1 · Thakar et al. · 2018 [cited by applicant]
US 10250623B1 · Patton et al. · 2019 [cited by applicant]
US 10333898B1 · Moore · 2019 [cited by examiner]
US 10607011B1 · Orhan · 2020 [cited by applicant]
US 10701086B1 · Mushtaq · 2020 [cited by applicant]
US 10805340B1 · Goradia · 2020 [cited by examiner]
US 10893059B1 · Aziz et al. · 2021 [cited by applicant]
US 11003773B1 · Fang et al. · 2021 [cited by applicant]
US 11102223B2 · Kraemer et al. · 2021 [cited by applicant]
US 11388176B2 · Conner · 2022 [cited by applicant]
US 11588832B2 · Brown · 2023 [cited by examiner]
US 11693961B2 · Duo et al. · 2023 [cited by applicant]
US 12056237B2 · Duo · 2024 [cited by applicant]
US 12058147B2 · Conner · 2024 [cited by applicant]
US 20060031933A1 · Costa et al. · 2006 [cited by applicant]
US 20070016955A1 · Goldberg et al. · 2007 [cited by applicant]
US 20080295153A1 · Cheng et al. · 2008 [cited by applicant]
US 20090070873A1 · McAfee et al. · 2009 [cited by applicant]
US 20090083852A1 · Kuo et al. · 2009 [cited by applicant]
US 20100115620A1 · Alme · 2010 [cited by applicant]
US 20110016525A1 · Jeong · 2011 [cited by applicant]
US 20120260343A1 · Sun et al. · 2012 [cited by applicant]
US 20150058976A1 · Carney · 2015 [cited by examiner]
US 20160048681A1 · Fang · 2016 [cited by applicant]
US 20160149943A1 · Kaloroumakis · 2016 [cited by examiner]
US 20160205120A1 · Marck · 2016 [cited by applicant]
US 20160232358A1 · Grieco et al. · 2016 [cited by applicant]
US 20160308905A1 · Stiekes et al. · 2016 [cited by applicant]
US 20170019415A1 · Takano · 2017 [cited by applicant]
US 20170063912A1 · Muddu · 2017 [cited by examiner]
US 20170083703A1 · Abbasi et al. · 2017 [cited by applicant]
US 20170171170A1 · Sun · 2017 [cited by examiner]
US 20180124098A1 · Carver et al. · 2018 [cited by applicant]
US 20180139235A1 · Desai et al. · 2018 [cited by applicant]
US 20180144139A1 · Cheng et al. · 2018 [cited by applicant]
US 20180191771A1 · Newman et al. · 2018 [cited by applicant]
US 20180288087A1 · Hittel · 2018 [cited by applicant]
US 20190007436A1 · Dods · 2019 [cited by applicant]
US 20190081970A1 · Teramoto · 2019 [cited by applicant]
US 20190132358A1 · Divalentin · 2019 [cited by applicant]
US 20190297097A1 · Gong et al. · 2019 [cited by applicant]
US 20200153863A1 · Wiener et al. · 2020 [cited by applicant]
US 20200304462A1 · Kopp · 2020 [cited by applicant]
US 20210165879A1 · Duo · 2021 [cited by applicant]
US 20210168157A1 · Conner · 2021 [cited by applicant]
US 20210194915A1 · Duo · 2021 [cited by applicant]
US 20230007013A1 · Conner · 2023 [cited by applicant]
US 20240045954A1 · Duo et al. · 2024 [cited by applicant]
US 20240419792A1 · Duo et al. · 2024 [cited by applicant]
US 20250039191A1 · Conner et al. · 2025 [cited by applicant]
U.S. Appl. No. 17/111,398 Final Office Action mailed Mar. 7, 2023. [cited by applicant]
U.S. Appl. No. 17/111,398 Office Action mailed Aug. 16, 2023. [cited by applicant]
U.S. Appl. No. 17/111,398 Final Office Action mailed Mar. 20, 2023. [cited by applicant]
U.S. Appl. No. 17/111,398 Office Action mailed Jun. 24, 2022. [cited by applicant]
U.S. Appl. No. 17/111,414 Office Action mailed Sep. 15, 2022. [cited by applicant]
U.S. Appl. No. 17/111,398, Final Office Action dated Mar. 7, 2024. [cited by applicant]
U.S. Appl. No. 17/111,398, Office Action dated Jul. 24, 2024. [cited by applicant]
U.S. Appl. No. 17/111,398, Final Office Action dated Nov. 1, 2024. [cited by applicant]
U.S. Appl. No. 17/111,398, Office Action dated Feb. 27, 2025. [cited by applicant]