IP Library Granted Patent US 10,212,182
Granted Patent B2
US 10,212,182 · App. 15/485,680 · Granted Feb 19, 2019

Device profiling for isolation networks

Inventors: Patrick Wetterwald (Mouans Sartoux, FR); Pascal Thubert (La Colle sur Loup, FR); Jean-Philippe Vasseur (Saint Martin d'uriage, FR); Eric Levy-Abegnoli (Valbonne, FR)
Assignee: Cisco Technology, Inc.
H04L63/1425G06N99/005H04L12/4641H04L63/029H04L63/0227H04L63/0272H04L63/1458
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,212,182
App. No.
15/485,680
Granted
Feb 19, 2019
Kind
B2
Abstract

In one embodiment, a server instructs one or more networking devices in a local area network (LAN) to form virtual network overlay in the LAN that redirects traffic associated with a particular node in the LAN to the server. The server receives the redirected traffic associated with the particular node. The server determines a node profile for the particular node based in part on an analysis of the redirected traffic. The server configures the particular node based on the determined node profile for the particular node.

Claims (57)

1. A method comprising:

instructing, by a server, one or more networking devices in a local area network (LAN) to form a virtual network overlay in the LAN that redirects traffic associated with a particular node in the LAN to the server;

receiving, at the server, the redirected traffic associated with the particular node;

determining, by the server, a node profile for the particular node based in part on an analysis of the redirected traffic; and

configuring, by the server, the particular node based on the determined node profile for the particular node.

2. The method of claim 1 , further comprising:

receiving, at the server, a set of node behavioral rules; and

applying, by the server, the set of node behavioral rules to the redirected traffic from the particular node, to determine the node profile for the particular node.

3. The method of claim 1 further comprising:

receiving, at the server, a machine learning-based node behavioral model; and

applying, by the server, behavioral model to the redirected traffic from the particular node, to determine the node profile for the particular node.

4. The method of claim 3 , wherein the machine learning-based node behavioral model comprises a traffic classifier.

5. The method of claim 1 , wherein determining the node profile for the particular node based in part on the analysis of the redirected traffic comprises:

training, by the server, a machine learning-based node behavioral model using traffic from one or more other nodes; and

analyzing, by the server, the redirected traffic from the particular node using the trained node behavioral model.

6. The method of claim 5 , wherein the node behavioral model is trained using the traffic from the one or more other nodes after boot of the one or more other nodes.

7. The method of claim 1 , wherein analyzing the redirected traffic from the particular node using the trained node behavioral model comprises:

deploying, by the server, a node behavioral model to a networking device in the LAN, wherein the networking device uses the node behavioral model to analyze traffic associated with the particular node that is not redirected to the server.

8. An apparatus comprising:

one or more network interfaces to communicate with a network;

a processor coupled to the network interfaces and configured to execute one or more processes; and

a memory configured to store a process executable by the processor, the process when executed configured to:

instruct one or more networking devices in a local area network (LAN) to form a virtual network overlay in the LAN that redirects traffic associated with a particular node in the LAN to the apparatus;

receive the redirected traffic associated with the particular node;

determine a node profile for the particular node based in part on an analysis of the redirected traffic; and

configure the particular node based on the determined node profile for the particular node.

9. The apparatus as in claim 8 , wherein the process when executed is further configured to:

receive a set of node behavioral rules; and

apply the set of node behavioral rules to the redirected traffic from the particular node, to determine the node profile for the particular node.

10. The apparatus as in claim 8 , wherein the process when executed is further configured to:

receive a machine learning-based node behavioral model; and

applying, by the server, behavioral model to the redirected traffic from the particular node, to determine the node profile for the particular node.

11. The apparatus as in claim 10 , wherein the process when executed is further configured to:

detect a deviation in a behavior of the node based on the redirected traffic and on the determined node profile for the node.

12. The apparatus as in claim 10 , wherein the apparatus determines the node profile for the particular node based in part on the analysis of the redirected traffic by:

training a machine learning-based node behavioral model using traffic from one or more other nodes; and

analyzing the redirected traffic from the particular node using the trained node behavioral model.

13. The apparatus as in claim 12 , wherein the node behavioral model is trained using the traffic from the one or more other nodes after boot of the one or more other nodes.

14. The apparatus as in claim 10 , wherein the apparatus analyzes the redirected traffic from the particular node using the trained node behavioral model by:

deploying a node behavioral model to a networking device in the LAN, wherein the networking device uses the node behavioral model to analyze traffic associated with the particular node that is not redirected to the apparatus.

15. A tangible, non-transitory, computer-readable medium storing program instructions that, when executed by a device in a network, cause a server to perform a process comprising:

instructing, by the server, one or more networking devices in a local area network (LAN) to form a virtual network overlay in the LAN that redirects traffic associated with a particular node in the LAN to the server;

receiving, at the server, the redirected traffic associated with the particular node;

determining, by the server, a node profile for the particular node based in part on an analysis of the redirected traffic; and

configuring, by the server, the particular node based on the determined node profile for the particular node.

16. The computer-readable medium as in claim 15 , wherein the process further comprises:

receiving, at the server, a set of node behavioral rules; and

applying, by the server, the set of node behavioral rules to the redirected traffic from the particular node, to determine the node profile for the particular node.

17. The computer-readable medium as in claim 15 , wherein the process further comprises:

receiving, at the server, a machine learning-based node behavioral model; and

applying, by the server, behavioral model to the redirected traffic from the particular node, to determine the node profile for the particular node.

18. The computer-readable medium as in claim 15 , wherein analyzing the redirected traffic from the particular node using the trained node behavioral model comprises:

deploying, by the server, a node behavioral model to a networking device in the LAN, wherein the networking device uses the node behavioral model to analyze traffic associated with the particular node that is not redirected to the server.

19. The computer-readable medium as in claim 15 , wherein determining the node profile for the particular node based in part on the analysis of the redirected traffic comprises:

training, by the server, a machine learning-based node behavioral model using traffic from one or more other nodes; and

analyzing, by the server, the redirected traffic from the particular node using the trained node behavioral model.

20. The computer-readable medium as in claim 19 , wherein the node behavioral model is trained using the traffic from the one or more other nodes after boot of the one or more other nodes.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2017
From: WETTERWALD, PATRICK; THUBERT, PASCAL; VASSEUR, JEAN-PHILIPPE; LEVY-ABEGNOLI, ERIC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 042234/0653 →
Continuity (2)
Provisional Application 62408423 · Oct 14, 2016
Related Publication 20180109551A1 · Apr 19, 2018
Cited By (1)
US 12,192,175