IP Library › Granted Patent US 11,483,351
Granted Patent B2
US 11,483,351 · App. 17/003,364 · Granted Oct 25, 2022

Securing network resources from known threats

Inventors: Supreeth Hosur Nagesh Rao (Cupertino, CA); Navindra Yadav (Cupertino, CA); Tapan Shrikrishna Patwardhan (Mountain View, CA); Umamaheswaran Arumugam (San Jose, CA); Darshan Shrinath Purandare (Fremont, CA); Aiyesha Ma (San Francisco, CA); Hongyang Zhang (Mountain View, CA); Kai Zhu (San Jose, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/20H04L63/101H04L63/145H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,483,351
App. No.
17/003,364
Filed
Aug 26, 2020
Granted
Oct 25, 2022
Kind
B2
Examiner
DO, KHANG D
Art Unit
2492
USPC
726/1
Abstract

The present disclosure relates to securing workloads of a network by identifying compromised elements in communication with the network and preventing their access to network resources. In one aspect, a method includes monitoring network traffic at network elements of a network; detecting a compromised element in communication with one or more of the network elements, the compromised element being associated with at least one network threat; and based on a defined network policy, applying one of a number of different access prevention schemes to the compromised element to prevent access to the network by the compromised element.

Claims (49)

1. A method comprising:

inserting, by a server, a list of known network threats into existing data packs exchanged between the server and sensors of network elements via a communications link;

defining, by the servers, polices by creating tags for the known network threats;

deploying the policies and known network threats from the server to the sensors;

monitoring, by the server through the sensors, network traffic at network elements of a network;

detecting, from the monitoring and based on at least one of the tags, a compromised element in communication with one or more of the network elements, the compromised element being associated with at least one network threat; and

based on a defined network policy of the policies, applying by the server through the sensors one of a number of different access prevention schemes to the compromised element to prevent access to the network by the compromised element.

2. The method of claim 1 , wherein detecting the compromised element comprises:

identifying the at least one network threat in corresponding network traffic monitored with respect to at least one network element of the network elements; and

marking the at least one network element as the compromised element.

3. The method of claim 1 , wherein the number of different access prevention schemes include:

blocking the compromised element from accessing at least one network element of the network elements; or

quarantining the compromised element for a period of time, wherein the quarantining prevents any communication to and from the compromised element.

4. The method of claim 1 , wherein the one of the number of different access prevention schemes includes blocking the compromised element from accessing a first workload on one or more of the network elements while allowing the compromised element to access a second workload on the one or more of the network elements.

5. The method of claim 1 , wherein the network threat is one of a known network IP address or a malware category.

6. The method of claim 1 , wherein the compromised element is an endpoint registered with the network, the endpoint having accessed an external source having the at least one network threat.

7. A network element comprising:

one or more memories having computer-readable instructions stored therein; and

one or more processors configured to execute the computer-readable instructions to:

insert, by a server, a list of known network threats into existing data packs exchanged between the server and sensors of network elements via a communications link;

define, by the servers, polices by creating tags for the known network threats;

deploy the policies and known network threats from the server to the sensors;

monitor, by the server through the sensors, network traffic at network elements of a network;

detect, from the monitoring and based on at least one of the tags, a compromised element in communication with one or more of the network elements, the compromised element being associated with at least one network threat; and

based on a defined network policy of the policies, apply by the server through the sensors one of a number of different access prevention schemes to the compromised element to prevent access to the network by the compromised element.

8. The network element of claim 7 , wherein the one or more processors are configured to detect the compromised element by:

identifying the at least one network threat in corresponding network traffic monitored with respect to at least one network element of the network elements; and

marking the at least one network element as the compromised element.

9. The network element of claim 7 , wherein the number of different access prevention schemes include:

blocking the compromised element from accessing at least one network element of the network elements; or

quarantining the compromised element for a period of time, wherein the quarantining prevents any communication to and from the compromised element.

10. The network element of claim 7 , wherein the one of the number of different access prevention schemes includes blocking the compromised element from accessing a first workload on one or more of the network elements while allowing the compromised element to access a second workload on the one or more of the network elements.

11. The network element of claim 7 , wherein the network threat is one of a known network IP address or a malware category.

12. The network element of claim 7 , wherein the compromised element is an endpoint registered with the network, the endpoint having accessed an external source having the at least one network threat.

13. One or more non-transitory computer-readable media comprising computer-readable instructions, which when executed by one or more processors, cause the one or more processors to:

insert, by a server, a list of known network threats into existing data packs exchanged between the server and sensors of network elements via a communications link;

define, by the servers, polices by creating tags for the known network threats;

deploy the policies and known network threats from the server to the sensors;

monitor, by the server through the sensors, network traffic at network elements of a network;

detect, from the monitoring and based on at least one of the tags, a compromised element in communication with one or more of the network elements, the compromised element being associated with at least one network threat; and

based on a defined network policy of the policies, apply by the server through the sensors one of a number of different access prevention schemes to the compromised element to prevent access to the network by the compromised element.

14. The one or more non-transitory computer-readable media of claim 13 , wherein the execution of the computer-readable instructions cause the one or more processors to detect the compromised element by:

identifying the at least one network threat in corresponding network traffic monitored with respect to at least one network element of the network elements; and

marking the at least one network element as the compromised element.

15. The one or more non-transitory computer-readable media of claim 13 , wherein the number of different access prevention schemes include:

blocking the compromised element from accessing at least one network element of the network elements; or

quarantining the compromised element for a period of time, wherein the quarantining prevents any communication to and from the compromised element.

16. The one or more non-transitory computer-readable media of claim 13 , wherein the network threat is one of a known network IP address or a malware category.

17. The one or more non-transitory computer-readable media of claim 13 , wherein the compromised element is an endpoint registered with the network, the endpoint having accessed an external source having the at least one network threat.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2020
From: RAO, SUPREETH HOSUR NAGESH; YADAV, NAVINDRA; PATWARDHAN, TAPAN SHRIKRISHNA; ARUMUGAM, UMAMAHESWARAN; PURANDARE, DARSHAN SHRINATH; MA, AIYESHA; ZHANG, HONGYANG; ZHU, KAI
To: CISCO TECHNOLOGY, INC.
Reel/Frame 053604/0694 →
Continuity (1)
Related Publication 20220070222A1 · Mar 3, 2022