IP Library Granted Patent US 11,522,894
Granted Patent B2
US 11,522,894 · App. 17/069,415 · Granted Dec 6, 2022

Methods, systems, and devices for dynamically modeling and grouping endpoints for edge networking

Inventors: Tomer Weingarten (Mountain View, CA); Almog Cohen (Tel Aviv, IL)
Assignee: Sentinel Labs Israel Ltd.
H04L63/1425G06F8/61G06F9/44526H04L41/046H04L41/0893H04L41/16H04L63/08H04L63/102H04L63/104H04L63/1416H04L63/1441H04L63/205H04L67/10H04L67/34H04L41/12H04L41/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,522,894
App. No.
17/069,415
Granted
Dec 6, 2022
Kind
B2
Abstract

Various embodiments described herein disclose an endpoint modeling and grouping management system that can collect data from endpoint computer devices in a network. In some embodiments, agents installed on the endpoints can collect real-time information at the kernel level providing the system with deep visibility. In some embodiments, the endpoint modeling and grouping management system can identify similarities in behavior in response to assessing the data collected by the agents. In some embodiments, the endpoint modeling and grouping management system can dynamically model groups such as logical groups, and cluster endpoints based on the similarities and/or differences in behavior of the endpoints. In some embodiments, the endpoint modeling and grouping management system transmits the behavioral models to the agents to allow the agents to identify anomalies and/or security threats autonomously.

Claims (19)

1. A computer-implemented method for mapping an elastic computer network, the method comprising:

collecting, by each autonomous software agent of a plurality of autonomous software agents installed on each of a plurality of endpoint devices forming the elastic computer network, device data of a corresponding endpoint device, wherein the elastic computer network comprises one or more sub-networks;

transmitting, by each autonomous software agent, the device data to a central server, wherein the device data is configured to allow the central server to identify the corresponding endpoint device;

aggregating, by the central server, the device data from each of the autonomous software agents;

generating, by the central server, a visualization of the elastic computer network, wherein the visualization comprises a mapping of the elastic computer network and the one or more sub-networks of the elastic computer network; and

updating the visualization of the elastic computer network based on device data received from the plurality of autonomous software agents.

2. The computer-implemented method of claim 1 , wherein at least one of the plurality of endpoint devices comprises an Internet of Things (IoT) device.

3. The computer-implemented method of claim 1 , further comprising grouping, by the central server, the plurality of endpoint devices into one or more endpoint groupings.

4. The computer-implemented method of claim 3 , further comprising:

deriving, from the mapping of the elastic computer network model for the plurality of endpoint devices, wherein the model establishes a baseline of behavior or access restrictions for the one or more endpoint groupings; and

transmitting the model from the central server to the plurality of autonomous software agents.

5. The computer-implemented method of claim 4 , further comprising assessing, by the plurality of autonomous software agents; the activity of the plurality of endpoint devices to identify an anomaly relative to the baseline.

6. The computer-implemented method of claim 3 , further comprising applying, by the central server or the plurality of autonomous software agents, one or more group access rules to each endpoint grouping of the one or more endpoint groupings.

7. The computer-implemented method of claim 1 , further comprising scanning, by the central server or by the plurality of autonomous software agents, network communications of the plurality of endpoint devices to discover one or more additional endpoint devices without a corresponding autonomous software agent.

8. The computer-implemented method of claim 7 , further comprising:

grouping, by the central server, the one or more additional endpoint devices into an endpoint grouping; and

limiting the ability of the one or more additional endpoint devices to communicate with the plurality of endpoint devices forming the elastic computer network.

9. The computer-implemented method of claim 1 , further comprising aggregating the device data from each of the autonomous software agents with additional device data from one or more data centers or third-party services.

10. The computer-implemented method of claim 1 , wherein the visualization of the elastic computer network is updated continuously in real-time based on device data received from the plurality of autonomous software agents.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2020
From: WEINGARTEN, TOMER; COHEN, ALMOG
To: SENTINEL LABS, INC.
Reel/Frame 054056/0525 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2020
From: SENTINEL LABS, INC.
To: SENTINEL LABS ISRAEL LTD.
Reel/Frame 054056/0570 →
Continuity (6)
Continuation 16525415 · Jul 29, 2019
Continuation 16058810 · Aug 8, 2018
Provisional Application 62550439 · Aug 25, 2017
Provisional Application 62545917 · Aug 15, 2017
Provisional Application 62542288 · Aug 8, 2017
Related Publication 20210152586A1 · May 20, 2021
Cited By (13)
US 12,206,698 US 12,235,962 US 12,244,626 US 12,259,967 US 12,363,151 US 12,418,565 US 12,423,078 US 12,432,253 US 12,450,351 US 12,452,273 US 12,468,810 US 12,579,268 US 12,664,258