IP Library Granted Patent US 10,694,402
Granted Patent B2
US 10,694,402 · App. 16/008,673 · Granted Jun 23, 2020

Security orchestration and network immune system deployment framework

Inventor: Mark Cummings (Atherton, CA)
H04W24/02G06F9/4411G06F30/327H04L67/10H04L67/16H04L67/22H04W8/22H04W28/0215H04W48/16H04W24/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,694,402
App. No.
16/008,673
Granted
Jun 23, 2020
Kind
B2
Abstract

Image data of a node with which an orchestration module is associated is received. The node is an electronic device and the image data of the node is received in a language associated with the node. The image data of the node with which the orchestration module is associated is translated into a meta-language associated with an orchestrator network comprising the orchestration module and one or more other orchestration modules associated one or more corresponding nodes. A scope of information to provide from the orchestration module to the one or more other orchestration modules associated with one or more corresponding nodes is determined. The determined information is communicated to the one or more other orchestration modules in the meta-language understood by the orchestration module and the one or more other orchestration modules associated with one or more corresponding nodes.

Claims (40)

1. A system, comprising:

a processor; and

a memory coupled with the processor, wherein the memory is configured to provide the processor with instructions which when executed, cause the processor to:

receive image data of a node with which the system is associated, wherein the node is an electronic device, wherein the image data of the node is received in a language associated with the node;

translate the image data of the node with which the system is associated into a meta-language associated with an orchestrator network comprising an orchestration module hosted on the system and one or more other orchestration modules associated with one or more corresponding nodes;

determine a scope of information to provide from the orchestration module to the one or more other orchestration modules associated with the one or more corresponding nodes; and

communicate the determined scope of information to the other one or more orchestration modules in the meta-language understood by the orchestration module and the one or more other orchestration modules.

2. The system of claim 1 , wherein the system further comprises a conductor in communication with the orchestration module and the one or more other orchestration modules, wherein the conductor is configured to generate the orchestration module and deploy the orchestration module to the node with which the system is associated.

3. The system of claim 1 , wherein the image data of the node with which the system is associated includes behavioral data of the node with which the system is associated.

4. The system of claim 3 , wherein the orchestration module is further configured to apply a histogram behavioral analysis algorithm to the behavioral data of the node with which the system is associated to determine a normal behavior of the node with which the system is associated, wherein the orchestration module is configured to determine the normal behavior either by itself or in conjunction with the one or more other orchestration modules.

5. The system of claim 3 , wherein the orchestration module includes a local behavior analytic engine that is configured to analyze the behavioral data of the node with which the system is associated.

6. The system of claim 3 , wherein the orchestration module includes a collector configured to capture the behavioral data of the node with which the system is associated.

7. The system of claim 1 , wherein the determined scope of information includes information indicating that the node with which the system is associated has been compromised.

8. The system of claim 7 , wherein the orchestration module is configured to receive from one of the one or more other orchestration modules a message indicating a remediation for the node with which the system is associated.

9. The system of claim 8 , wherein the orchestration module is configured to cause the node with which the system is associated to implement the remediation.

10. The system of claim 8 , wherein the orchestration module is configured to cause the node with which the system is associated to implement the remediation based on the image data of the node.

11. The system of claim 1 , wherein the image data of the node with which the system is associated comprises one or more objectives associated with the node, one or more constraints associated with the node, one or more algorithms associated with the node, one or more capabilities associated with the node, one or more configurations associated with the node, and an environment associated with the node.

12. The system of claim 1 , wherein the orchestration module is configured to communicate the determined information to the one or more other orchestration modules via a network that is specific to the orchestration module and the one or more other orchestration modules.

13. The system of claim 1 , wherein the node with which the system is associated is a network element.

14. The system of claim 1 , wherein the node with which the system is associated is a base station or access point.

15. The system of claim 1 , wherein the node with which the system is associated is an application, and wherein the orchestration module and the application are located in a first cloud data center.

16. The system of claim 15 , wherein the orchestration module and its associated application are configured to move from the first cloud data center to a second cloud data center.

17. The system of claim 1 , wherein the node with which the system is associated is located in a central site computing center.

18. The system of claim 1 , wherein the node with which the system is associated is a component of a vehicle.

19. The system of claim 1 , wherein the node with which the system is associated is part of a semiconductor.

20. The system of claim 1 , wherein the orchestration module is associated with a component inside of at least one of a processor, a core, and/or a semiconductor.

21. The system of claim 1 , wherein the system and at least one of the one or more other orchestration modules are configured to negotiate with each other based on objectives, algorithms, and constraints to respond to one or more changes in an internal security environment and/or external security environment.

22. The system of claim 1 , wherein the orchestration module and the one or more other orchestration modules are associated with an umbrella model, wherein corresponding image data associated with a plurality of nodes is translated from a language associated with a corresponding node into the meta-language, wherein the umbrella model comprises a set of the corresponding image data associated with the plurality of nodes, wherein the umbrella model provides end-to-end orchestration throughout the orchestrator network.

23. The system of claim 22 , wherein the umbrella model is configured to change while the orchestration module and the one or more other orchestration modules are running.

24. The system of claim 1 , wherein the orchestration module is configured to subscribe to one or more changes to the image data of the node with which the system is associated.

25. A method, comprising:

receiving image data of a node with which an orchestration module is associated, wherein the node is an electronic device, wherein the image data of the node is received in a language associated with the node;

translating the image data of the node with which the orchestration module is associated into a meta-language associated with an orchestrator network comprising the orchestration module and one or more other orchestration modules associated with one or more corresponding nodes;

determining a scope of information to provide from the orchestration module to the one or more other orchestration modules associated with the one or more corresponding nodes; and

communicating the determined scope of information to the one or more other orchestration modules in the meta-language understood by the orchestration module and the one or more other orchestration modules associated with the one or more corresponding nodes.

26. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving image data of a node with which an orchestration module is associated, wherein the node is an electronic device, wherein the image data of the node is received in a language associated with the node;

translating the image data of the node with which the orchestration module is associated into a meta-language associated with an orchestrator network comprising the orchestration module and one or more other orchestration modules associated with one or more corresponding nodes;

determining a scope of information to provide from the orchestration module to the one or more other orchestration modules associated with the one or more corresponding nodes; and

communicating the determined scope of information to the one or more other orchestration modules in the meta-language understood by the orchestration module and the one or more other orchestration modules associated with the one or more corresponding nodes.

Continuity (11)
Continuation In Part 15060478 · Mar 3, 2016
Continuation 13290736 · Nov 7, 2011
Continuation In Part 15694072 · Sep 1, 2017
Continuation 13290767 · Nov 7, 2011
Continuation In Part 15411546 · Jan 20, 2017
Continuation In Part 14993641 · Jan 12, 2016
Continuation 13290760 · Nov 7, 2011
Provisional Application 62523636 · Jun 22, 2017
Provisional Application 61456385 · Nov 5, 2010
Provisional Application 62378449 · Aug 23, 2016
Related Publication 20180368007A1 · Dec 20, 2018