IP Library › Granted Patent US 11,336,555
Granted Patent B2
US 11,336,555 · App. 17/111,742 · Granted May 17, 2022

Network segmentation effectiveness system and method

Inventors: Jeremy Soh (Singapore, SG); Utsav Saraf (Singapore, SG)
Assignee: JPMORGAN CHASE BANK, N.A.
H04L43/50H04L43/065H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,336,555
App. No.
17/111,742
Filed
Dec 4, 2020
Granted
May 17, 2022
Kind
B2
Art Unit
2441
USPC
709/224
Abstract

The invention relates to a network segmentation effectiveness attestation system and method. The method may comprise receiving a list of internet protocol (IP) addresses for information technology (IT) assets within a defined scope, and executing a plurality of segmentation scans from outside a cardholder data environment (CDE) using a plurality of software agents. The software agents may be deployed and orchestrated across multiple network tiers. The method may also comprise receiving, automatically interpreting, and certifying results from the segmentation scan, automatically generating a report from the results of the segmentation scan, and automatically posting the report for authorized users to access.

Claims (43)

1. A network segmentation effectiveness system comprising:

an electronic memory;

an interactive user interface that receives user input via a communication network; and

a computer processor coupled to the electronic memory and the interactive user interface and further programmed to execute the following functions:

receive, by an electronic input, a list of internet protocol (IP) addresses in a classless inter-domain routing (CIDR) format corresponding to information technology (IT) assets within a defined scope;

receive a unique information technology service management (ITSM) identifier defining a requested network segmentation scan, the definition comprising one or more parameters detailing timing and scope;

verify, by the computer processor, correctness of the CIDR format associated with the list of IP addresses and the ISTM identifier by determining that the CIDR format and the one or more scope parameters of the ISTM refer to the same list of IT assets;

generate, by the computer processor, a notification of a segmentation scan based on the IP addresses and ITSM identifier;

execute, by the computer processor, a plurality of segmentation scans on the IT assets corresponding to the IP addresses from outside a cardholder data environment (CDE) using a plurality of software agents, wherein the computer processor is programmed to deploy and orchestrate the software agents across multiple network tiers;

receive, by the communication network, results from the plurality of segmentation scans;

transmit, by the communication network, the results of the plurality of segmentation scans to a penetration test reporting module;

automatically generate, by the computer processor, a report from the results of the segmentation scan; and

automatically post, by the user interface, the report for authorized users to access.

2. The system of claim 1 , wherein the function to receive results from the plurality of segmentation scans further comprises:

automatically interpret and certify the results of the plurality of segmentation scans.

3. The system of claim 1 , wherein the function to execute a plurality of segmentation scans further comprises: perform a collaborative gap analysis that identifies one or more external scan results gaps.

4. The system of claim 3 , wherein the function to execute a plurality of segmentation scans further comprises: perform orchestrated scanning that performs rapid scans on the one or more external scan results gaps.

5. The system of claim 1 , wherein the function to execute a plurality of segmentation scans further comprises: replicate one or more scans via one or more software agents from the plurality of software agents.

6. The system of claim 1 , wherein the plurality of software agents are deployed to one or more sub-networks comprising a demilitarized zone (DMZ) network.

7. The system of claim 1 , wherein the plurality of software agents are deployed to one or more sub-networks comprising a cloud network.

8. The system of claim 1 , wherein the plurality of software agents fetch instructions comprising one or more of: a request to perform a host discovery scan against a specific network, provide past scan results and perform a tear-down process to uninstall a software agent.

9. The system of claim 1 , wherein the notification is sent to a security operations center (SOC).

10. The system of claim 1 , wherein the defined scope relates to one or more Payment Card Information Data Security Standard (PCI DSS) requirements.

11. A method for providing network segmentation, the method comprising the steps of:

receiving, by an electronic input, a list of internet protocol (IP) addresses in a classless inter-domain routing (CIDR) format corresponding to information technology (IT) assets within a defined scope;

receiving a unique information technology service management (ITSM) identifier defining a requested network segmentation scan, the definition comprising one or more parameters detailing timing and scope;

verifying determining, by the computer processor, correctness of the CIDR format associated with the list of IP addresses and the ISTM identifier by determining that the CIDR format and the one or more scope parameters of the ISTM refer to the same list of IT assets;

generating, by the computer processor, a notification of a segmentation scan based on the IP addresses and ITSM identifier;

executing, by the computer processor, a plurality of segmentation scans on the IT assets corresponding to the IP addresses from outside a cardholder data environment (CDE) using a plurality of software agents, wherein the computer processor is programmed to deploy and orchestrate the software agents across multiple network tiers;

receiving, by a communication network, results from the plurality of segmentation scans;

transmitting, by the communication network, the results of the plurality of segmentation scans to a penetration test reporting module;

automatically generating, by the computer processor, a report from the results of the segmentation scan; and

automatically posting, by the user interface, the report for authorized users to access.

12. The method of claim 11 , further comprising the step of:

automatically interpreting and certifying the results of the plurality of segmentation scans.

13. The method of claim 11 , wherein executing a plurality of segmentation scans further comprises: performing a collaborative gap analysis identifies one or more external scan results gaps.

14. The method of claim 13 , wherein executing a plurality of segmentation scans further comprises: performing an orchestrated scanning that performs rapid scans on the one or more external scan results gaps.

15. The method of claim 11 , wherein executing a plurality of segmentation scans further comprises: replicating one or more scans via one or more software agents from the plurality of software agents.

16. The method of claim 11 , wherein the plurality of software agents are deployed to one or more sub-networks comprising a demilitarized zone (DMZ) network.

17. The method of claim 11 , wherein the plurality of software agents are deployed to one or more sub-networks comprising a cloud network.

18. The method of claim 11 , wherein the plurality of software agents fetch instructions comprising one or more of: a request to perform a host discovery scan against a specific network, provide past scan results and perform a tear-down process to uninstall a software agent.

19. The method of claim 11 , wherein the notification it sent to a security operations center (SOC).

20. The method of claim 11 , wherein the defined scope relates to one or more Payment Card Information Data Security Standard (PCI DSS) requirements.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2020
From: SOH, JEREMY; SARAF, UTSAV
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 054543/0810 →
Continuity (2)
Provisional Application 62944490 · Dec 6, 2019
Related Publication 20210176158A1 · Jun 10, 2021
Cited By (15)
US 12,395,488 US 12,411,937 US 12,411,957 US 12,443,720 US 12,489,781 US 12,495,049 US 12,505,200 US 12,506,755 US 12,524,550 US 12,531,881 US 12,547,765 US 12,579,251 US 12,645,785 US 12,688,277 US 12,739,106