IP Library › Granted Patent US 10,476,912
Granted Patent B2
US 10,476,912 · App. 15/708,019 · Granted Nov 12, 2019

Creating, visualizing, and simulating a threat based whitelisting security policy and security zones for networks

Inventor: Roger Hill (Aliso Viejo, CA)
Assignee: VERACITY SECURITY INTELLIGENCE, INC.
H04L63/20G06F3/0482G06F3/0484G06F3/0486H04L41/0893H04L41/12H04L41/22H04L41/28H04L63/0209H04L63/101H04L63/104H04L63/105H04L63/1433H04L63/1441H04L67/12G06F21/552
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,476,912
App. No.
15/708,019
Granted
Nov 12, 2019
Kind
B2
Abstract

Techniques described herein are directed toward creating, visualizing, and simulating a threat based whitelisting security policy and security zones for networks. The disclosed technology may be implemented by providing a graphical user interface (GUI) on a network orchestration and security platform that facilitates creation and visualization of security zones and security policies for networks.

Claims (37)

1. A method comprising:

generating a plurality of security zones in a network comprising a plurality of assets, wherein each of the plurality of security zones comprises a respective set of assets of the plurality of assets, wherein the plurality of security zones are generated based at least in part on a regularity of communications between assets of the plurality of assets and a type of protocol communication between assets of the plurality of assets;

initializing an application comprising a graphical user interface for editing and visually representing the plurality of security zones of the network;

displaying, on the graphical user interface, a visual representation of a first security zone of the plurality of security zones of the network, wherein the first security zone comprises a first set of assets of the plurality of assets;

receiving data corresponding to user input at the graphical user interface editing the first security zone; and

in response to receiving the data, editing the first security zone.

2. The method of claim 1 wherein the visual representation of the first security zone is a logical container of at least two or more of the plurality of assets.

3. The method of claim 2 , wherein the network is an industrial network and wherein the plurality of assets comprises industrial devices.

4. The method of claim 3 , wherein the network comprises a controller communicatively coupled to a plurality of forwarding devices, wherein each of the plurality of assets is communicatively coupled to a port of one of the plurality of forwarding devices, wherein the controller is configured to generate the plurality of security zones.

5. The method of claim 2 , wherein the user input at the graphical user interface editing the first security zone comprises at least one of: moving a visual representation of one of the plurality of assets into the logical container of the first security zone or moving a visual representation of one of the assets from the logical container of the first security zone into a logical container of a second security zone of the network.

6. The method of claim 5 , wherein the user input at the graphical user interface editing the first security zone comprises dragging a visual representation of an asset not assigned to a security zone into the logical container of the first security zone.

7. The method of claim 5 , wherein the user input at the graphical user interface editing the first security zone comprises dragging a visual representation of one of the assets from the logical container of the first security zone into a logical container of a second security zone of the network.

8. A non-transitory computer-readable medium having instructions stored thereon that, when executed by a processor, causes a system to:

generate a plurality of security zones in a network comprising a plurality of assets, wherein each of the plurality of security zones comprises a respective set of assets of the plurality of assets, wherein the plurality of security zones are generated based at least in part on a regularity of communications between assets of the plurality of assets and a type of protocol communication between assets of the plurality of assets;

initialize an application comprising a graphical user interface for editing and visually representing the plurality of security zones of the network;

display, on the graphical user interface, a visual representation of a first security zone of the plurality of security zones of the network, wherein the first security zone comprises a first set of assets of the plurality of assets;

receive data corresponding to user input at the graphical user interface editing the first security zone; and

in response to receiving the data, editing the first security zone.

9. The non-transitory computer-readable medium of claim 8 , wherein the visual representation of the first security zone is a logical container of at least two or more of the plurality of assets.

10. The non-transitory computer-readable medium of claim 9 , wherein the network is an industrial network and wherein the plurality of assets comprises industrial devices.

11. The non-transitory computer-readable medium of claim 10 , wherein the network comprises a controller communicatively coupled to a plurality of forwarding devices, wherein each of the plurality of assets is communicatively coupled to a port of one of the plurality of forwarding devices.

12. The non-transitory computer-readable medium of claim 9 , wherein the user input at the graphical user interface editing the first security zone comprises at least one of: moving a visual representation of one of the plurality of assets into the logical container of the first security zone or moving a visual representation of one of the assets from the logical container of the first security zone into a logical container of a second security zone of the network.

13. The non-transitory computer-readable medium of claim 12 , wherein the user input at the graphical user interface editing the first security zone comprises dragging a visual representation of an asset not assigned to a security zone into the logical container of the first security zone.

14. The non-transitory computer-readable medium of claim 12 , wherein the user input at the graphical user interface editing the first security zone comprises dragging a visual representation of one of the assets from the logical container of the first security zone into a logical container of a second security zone of the network.

15. An industrial network system, comprising:

a controller;

a plurality of forwarding devices communicatively coupled to the controller over an industrial network;

a plurality of assets, wherein each of the plurality of assets is communicatively coupled to a port of one of the plurality of forwarding devices; and

a non-transitory computer-readable medium having instructions stored thereon that, when executed by a processor, causes the system to:

generate a plurality of security zones in the industrial network, wherein each of the plurality of security zones comprises a respective set of assets of the plurality of assets, wherein the plurality of security zones are generated based at least in part on a regularity of communications between assets of the plurality of assets and a type of protocol communication between assets of the plurality of assets;

initialize an application comprising a graphical user interface for editing and visually representing the plurality of the security zones of the industrial network;

display, on the graphical user interface, a visual representation of a first security zone of the plurality of security zones of the network, wherein the first security zone comprises a first set of assets of the plurality of assets;

receive data corresponding to user input at the graphical user interface editing the first security zone; and

in response to receiving the data, editing the first security zone.

16. The industrial network system of claim 15 , wherein the visual representation of the first security zone is a logical container of at least two or more of the plurality of assets.

17. The industrial network system of claim 16 , wherein the user input at the graphical user interface editing the first security zone comprises at least one of: moving a visual representation of one of the plurality of assets into the logical container of the first security zone or moving a visual representation of one of the assets from the logical container of the first security zone into a logical container of a second security zone of the network.

18. The industrial network system of claim 17 , wherein the user input at the graphical user interface editing the first security zone comprises dragging a visual representation of an asset not assigned to a security zone into the logical container of the first security zone.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2020
From: VERACITY SECURITY INTELLIGENCE, INC.
To: VERACITY INDUSTRIAL NETWORKS, INC.
Reel/Frame 052830/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2017
From: HILL, ROGER
To: VERACITY SECURITY INTELLIGENCE, INC.
Reel/Frame 044408/0650 →
Continuity (1)
Related Publication 20190089742A1 · Mar 21, 2019