IP Library › Granted Patent US 10,111,208
Granted Patent B2
US 10,111,208 · App. 15/174,850 · Granted Oct 23, 2018

System and method for performing security management operations in network having non-static collection of nodes

Inventors: David Hindawi (Berkeley, CA); Orion Hindawi (Berkeley, CA); Lisa Lippincott (Berkeley, CA); Peter Lincroft (Albany, CA)
Assignee: TANIUM INC.
H04W72/0406H04L41/04H04L41/12H04L45/02H04L67/1072H04W8/005H04W24/02H04W48/16H04L41/044H04L41/082H04L43/0817H04L43/10H04L63/20H04W84/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,111,208
App. No.
15/174,850
Granted
Oct 23, 2018
Kind
B2
Abstract

Machines in a managed network implement a set of rules that cause individual machines to directly interact with only a small number of machines in the network. Independent local actions of the individual machines collectively cause the individual machines to be self-organized into one or more communication orbits without any global control or coordination by a server or an administrator. The communication orbits are used for supporting security management, including, at a first node of the network, receiving a security management message from an upstream neighbor through a respective receiving channel from the upstream neighbor to the first node; performing one or more security management operations in accordance with the security management message received from the upstream neighbor; and forwarding the security management message to a downstream neighbor through a respective propagation channel from the first node to the downstream neighbor.

Claims (68)

1. A method of managing a network comprising a non-static collection of machines, comprising:

at a first node coupled to the network, the first node being a first machine among the non-static collection of machines:

proactively constructing and maintaining a respective local segment of a linear communication orbit in the network, wherein the proactive constructing and maintaining comprises:

obtaining, from a server of the network, contact information of one or more potential neighbor nodes for the first node, wherein the one or more potential neighbor nodes are machines that are known to the server as being coupled to the network;

proactively establishing, in accordance with a respective network communication protocol, a respective propagation channel from the first node to a downstream neighbor upon detecting that said respective propagation channel to the downstream neighbor does not already exist, wherein the downstream neighbor comprises a live succeeding node among the one or more potential neighbor nodes;

allowing a respective collection channel from the downstream neighbor to the first node to be established in accordance with the respective network communication protocol upon a request by the downstream neighbor, wherein the request has been generated by the downstream neighbor to establish a respective reporting channel thereof in accordance with the respective network communication protocol;

proactively establishing, in accordance with the respective network communication protocol, a respective reporting channel from the first node to an upstream neighbor upon detecting that said respective reporting channel to the upstream neighbor does not already exist, wherein the upstream neighbor comprises a live preceding node among the one or more potential neighbor nodes; and

allowing a respective receiving channel from the upstream neighbor to the first node to be established in accordance with the respective network communication protocol upon a request by the upstream neighbor, wherein the request has been generated by the upstream neighbor to establish a respective propagation channel thereof in accordance with the respective network communication protocol;

receiving a security management message from the upstream neighbor through the respective receiving channel from the upstream neighbor to the first node;

performing one or more security management operations in accordance with the security management message received from the upstream neighbor; and

forwarding the security management message to the downstream neighbor through the respective propagation channel from the first node to the downstream neighbor.

2. The method of claim 1 , wherein performing one or more security management operations in accordance with the security management message received from the upstream neighbor includes updating the security management message based on local status information at the first node in response to a security management query specified in the security management message.

3. The method of claim 1 , wherein performing one or more security management operations in accordance with the security management message received from the upstream neighbor includes performing a security-related action at the first node in accordance with a security management command specified in the security management message.

4. The method of claim 1 , wherein performing one or more security management operations in accordance with the security management message received from the upstream neighbor includes detecting presence of malicious programs at the first node in accordance with the security management message.

5. The method of claim 1 , wherein performing one or more security management operations in accordance with the security management message received from the upstream neighbor includes disabling or suspending one or more suspicious operations at the first node in accordance with the security management message.

6. The method of claim 1 , comprising:

updating information in the security management message in accordance with a local state at the first node before forwarding the security management message to the downstream node.

7. The method of claim 1 , comprising:

receiving a status report message from the downstream neighbor through the respective collection channel from the downstream neighbor to the first node;

performing an aggregation of information in the status report message; and

after performing the aggregation of information, forwarding the status report message received from the downstream neighbor to the upstream neighbor through the respective reporting channel from the first node to the upstream neighbor.

8. The method of claim 1 , wherein the proactive constructing and maintaining further comprises:

upon establishing the respective propagation channel from the first node to the downstream neighbor, terminating a previous propagation channel from the first node to another succeeding node.

9. The method of claim 1 , wherein the proactive constructing and maintaining further comprises:

upon establishing the respective reporting channel from the first node to the upstream neighbor, terminating a previous reporting channel from the first node to another preceding node.

10. A system, the system serving as a first node coupled to a network comprising a non-static collection of machines, the first node being a first machine among the non-static collection of machines and the system comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the processors to perform operations including:

proactively constructing and maintaining a respective local segment of a linear communication orbit in the network, wherein the proactive constructing and maintaining comprises:

obtaining, from a server of the network, contact information of one or more potential neighbor nodes for the first node, wherein the one or more potential neighbor nodes are machines that are known to the server as being coupled to the network;

proactively establishing, in accordance with a respective network communication protocol, a respective propagation channel from the first node to a downstream neighbor upon detecting that said respective propagation channel to the downstream neighbor does not already exist, wherein the downstream neighbor comprises a live succeeding node among the one or more potential neighbor nodes;

allowing a respective collection channel from the downstream neighbor to the first node to be established in accordance with the respective network communication protocol upon a request by the downstream neighbor, wherein the request has been generated by the downstream neighbor to establish a respective reporting channel thereof in accordance with the respective network communication protocol;

proactively establishing, in accordance with the respective network communication protocol, a respective reporting channel from the first node to an upstream neighbor upon detecting that said respective reporting channel to the upstream neighbor does not already exist, wherein the upstream neighbor comprises a live preceding node among the one or more potential neighbor nodes; and

allowing a respective receiving channel from the upstream neighbor to the first node to be established in accordance with the respective network communication protocol upon a request by the upstream neighbor, wherein the request has been generated by the upstream neighbor to establish a respective propagation channel thereof in accordance with the respective network communication protocol;

receiving a security management message from the upstream neighbor through the respective receiving channel from the upstream neighbor to the first node;

performing one or more security management operations in accordance with the security management message received from the upstream neighbor; and

forwarding the security management message to the downstream neighbor through the respective propagation channel from the first node to the downstream neighbor.

11. The system of claim 10 , wherein performing one or more security management operations in accordance with the security management message received from the upstream neighbor includes updating the security management message based on local status information at the first node in response to a security management query specified in the security management message.

12. The system of claim 10 , wherein performing one or more security management operations in accordance with the security management message received from the upstream neighbor includes performing a security-related action at the first node in accordance with a security management command specified in the security management message.

13. The system of claim 10 , wherein performing one or more security management operations in accordance with the security management message received from the upstream neighbor includes detecting presence of malicious programs at the first node in accordance with the security management message.

14. The system of claim 10 , wherein performing one or more security management operations in accordance with the security management message received from the upstream neighbor includes disabling or suspending one or more suspicious operations at the first node in accordance with the security management message.

15. The system of claim 10 , wherein the operations further include:

updating information in the security management message in accordance with a local state at the first node before forwarding the security management message to the downstream node.

16. The system of claim 10 , wherein the operations further include:

receiving a status report message from the downstream neighbor through the respective collection channel from the downstream neighbor to the first node;

performing an aggregation of information in the status report message; and

after performing the aggregation of information, forwarding the status report message received from the downstream neighbor to the upstream neighbor through the respective reporting channel from the first node to the upstream neighbor.

17. A non-transitory computer-readable storage medium storing instructions that when executed by one or more processors, cause the processors to perform operations comprising:

at a first node coupled to a network comprising a non-static collection of machines, the first node being a first machine among the non-static collection of machines:

proactively constructing and maintaining a respective local segment of a linear communication orbit in the network, wherein the proactive constructing and maintaining comprises:

obtaining, from a server of the network, contact information of one or more potential neighbor nodes for the first node, wherein the one or more potential neighbor nodes are machines that are known to the server as being coupled to the network;

proactively establishing in accordance with a respective network communication protocol, a respective propagation channel from the first node to a downstream neighbor upon detecting that said respective propagation channel to the downstream neighbor does not already exist, wherein the downstream neighbor comprises a live succeeding node among the one or more potential neighbor nodes;

allowing a respective collection channel from the downstream neighbor to the first node to be established in accordance with the respective network communication protocol upon a request by the downstream neighbor, wherein the request has been generated by the downstream neighbor to establish a respective reporting channel thereof in accordance with the respective network communication protocol;

proactively establishing, in accordance with the respective network communication protocol, a respective reporting channel from the first node to an upstream neighbor upon detecting that said respective reporting channel to the upstream neighbor does not already exist, wherein the upstream neighbor comprises a live preceding node among the one or more potential neighbor nodes; and

allowing a respective receiving channel from the upstream neighbor to the first node to be established in accordance with the respective network communication protocol upon a request by the upstream neighbor, wherein the request has been generated by the upstream neighbor to establish a respective propagation channel thereof in accordance with the respective network communication protocol;

receiving a security management message from the upstream neighbor through the respective receiving channel from the upstream neighbor to the first node;

performing one or more security management operations in accordance with the security management message received from the upstream neighbor; and

forwarding the security management message to the downstream neighbor through the respective propagation channel from the first node to the downstream neighbor.

18. The computer-readable storage medium of claim 17 , wherein performing one or more security management operations in accordance with the security management message received from the upstream neighbor includes updating the security management message based on local status information at the first node in response to a security management query specified in the security management message.

19. The computer-readable storage medium of claim 17 , wherein performing one or more security management operations in accordance with the security management message received from the upstream neighbor includes performing a security-related action at the first node in accordance with a security management command specified in the security management message.

20. The computer-readable storage medium of claim 17 , wherein performing one or more security management operations in accordance with the security management message received from the upstream neighbor includes detecting presence of malicious programs at the first node in accordance with the security management message.

21. The computer-readable storage medium of claim 17 , wherein performing one or more security management operations in accordance with the security management message received from the upstream neighbor includes disabling or suspending one or more suspicious operations at the first node in accordance with the security management message.

22. The computer-readable storage medium of claim 17 , wherein the operations further include:

updating information in the security management message in accordance with a local state at the first node before forwarding the security management message to the downstream node.

23. The computer-readable storage medium of claim 17 , wherein the operations further include:

receiving a status report message from the downstream neighbor through the respective collection channel from the downstream neighbor to the first node;

performing an aggregation of information in the status report message; and

after performing the aggregation of information, forwarding the status report message received from the downstream neighbor to the upstream neighbor through the respective reporting channel from the first node to the upstream neighbor.

Continuity (5)
Continuation 15004757 · Jan 22, 2016
Continuation 13797946 · Mar 12, 2013
Provisional Application 61774106 · Mar 7, 2013
Provisional Application 61745236 · Dec 21, 2012
Related Publication 20160286540A1 · Sep 29, 2016
Cited By (9)
US 12,229,032 US 12,231,457 US 12,231,467 US 12,284,204 US 12,309,239 US 12,316,486 US 12,556,623 US 12,632,357 US 12,719,916