IP Library › Granted Patent US 11,570,193
Granted Patent B2
US 11,570,193 · App. 16/698,989 · Granted Jan 31, 2023

Malware propagation risk assessment in software defined networks

Inventors: Anand Jaysingh Bhalerao (Pune, IN); Aneri Rajiv Desai (Pune, IN); Dashmeet Kaur Ajmani (Pune, IN)
Assignee: VMware, Inc.
H04L63/1433G06F9/45558H04L45/48H04L63/1425G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,570,193
App. No.
16/698,989
Granted
Jan 31, 2023
Kind
B2
Abstract

Described herein are systems, methods, and software to identify propagation risk of threats in a computing environment. In one implementation, a management service may identify a connection tree for a computing environment based on forwarding rules for virtual nodes in the computing environment. The management service may further, for each connection in the connection tree, determine a threat value based at least on a protocol associated with the connection. The management service may also identify a threat to a virtual node of the virtual nodes and generate a threat propagation summary for the threat based on the one or more minimum or maximum spanning trees.

Claims (57)

1. A method comprising:

identifying a connection tree for a computing environment based on forwarding rules for packets associated with virtual nodes in the computing environment, wherein the connection tree indicates at least a plurality of connections between the virtual nodes;

for each connection in the connection tree, determining a threat value based at least on a protocol associated with the connection;

calculating one or more minimum or maximum spanning trees for the virtual nodes based on the threat values and the connection tree; and

generating a threat propagation summary based on the one or more minimum or maximum spanning trees.

2. The method of claim 1 , wherein determining the threat value based at least on the protocol associated with the connection comprises determining the threat value based at least on packet size associated with the protocol and security measures implemented by the protocol.

3. The method of claim 1 further comprising:

obtaining a request for the threat propagation summary; and

wherein generating the threat propagation summary occurs in response to the request.

4. The method of claim 1 further comprising:

identifying a virtual node of the virtual nodes associated with a threat; and

wherein the threat propagation summary indicates one or more virtual nodes of the virtual nodes with connections to the virtual node.

5. The method of claim 4 , wherein the threat comprises malware executing on the virtual node.

6. The method of claim 1 further comprising:

identifying a virtual node of the virtual nodes associated with a threat; and

identifying one or more virtual nodes of the virtual nodes that satisfy propagation criteria based on the one or more minimum or maximum spanning trees; and

wherein the threat propagation summary indicates the one or more virtual nodes of the virtual nodes with connections to the virtual node.

7. The method of claim 1 , wherein determining the threat value is further based on data stored on virtual nodes associated with the connection or applications executing on virtual nodes associated with the connection.

8. The method of claim 1 further comprising:

identifying a virtual node of the virtual nodes associated with a threat; and

wherein generating the threat propagation summary comprises generating an interface that indicates a propagation threat hierarchy to one or more other virtual nodes of the virtual nodes in the computing environment.

9. A computing system comprising:

a storage system;

a processing system operatively coupled to the storage system; and

program instructions stored on the storage system that, when executed by the processing, direct the processing system to:

identify a connection tree for a computing environment based on forwarding rules for packets associated with virtual nodes in the computing environment, wherein the connection tree indicates at least a plurality of connections between the virtual nodes;

for each connection in the connection tree, determine a threat value based at least on a protocol associated with the connection;

calculate one or more minimum or maximum spanning trees for the virtual nodes based on the threat values and the connection tree; and

generate a threat propagation summary based on the one or more minimum or maximum spanning trees.

10. The computing system of claim 9 , wherein determining the threat value based at least on the protocol associated with the connection comprises determining the threat value based at least on packet size associated with the protocol and security measures implemented by the protocol.

11. The computing system of claim 9 , wherein the program instructions further direct the processing system to:

obtain a request for the threat propagation summary; and

wherein generating the threat propagation summary occurs in response to the request.

12. The computing system of claim 9 , wherein the program instructions further direct the processing system to:

identify a virtual node of the virtual nodes associated with a threat; and

wherein the threat propagation summary indicates one or more virtual nodes of the virtual nodes with connections to the virtual node.

13. The computing system of claim 12 , wherein the threat comprises malware executing on the virtual node.

14. The computing system of claim 9 , wherein the program instructions further direct the processing system to:

identify a virtual node of the virtual nodes associated with a threat; and

identify one or more virtual nodes of the virtual nodes that satisfy propagation criteria based on the one or more minimum or maximum spanning trees; and

wherein the threat propagation summary indicates the one or more virtual nodes of the virtual nodes with connections to the virtual node.

15. The computing system claim 9 , wherein determining the threat value is further based on data stored on virtual nodes associated with the connection or applications executing on virtual nodes associated with the connection.

16. The computing system of claim 9 , wherein the program instructions further direct the processing system to:

identify a virtual node of the virtual nodes associated with a threat; and

wherein generating the threat propagation summary comprises generating an interface that indicates a propagation threat hierarchy to one or more other virtual nodes of the virtual nodes in the computing environment.

17. A computing system comprising:

a storage system;

program instructions stored on the storage system that, when executed by a processing system, direct the processing system to:

identify a connection tree for a computing environment based on forwarding rules for virtual nodes in the computing environment, wherein the connection tree comprises a plurality of connections between the virtual nodes;

for each connection in the connection tree, determine a threat value based at least on a protocol associated with the connection;

identify a threat to a virtual node of the virtual nodes; and

generate a threat propagation summary for the threat based on the threat values for the connections in the connection tree.

18. The computing system of claim 17 , wherein determining the threat value based at least on the protocol associated with the connection comprises determining the threat value based at least on packet size associated with the protocol and security measures implemented by the protocol.

19. The computing system of claim 17 , wherein the threat comprises malware executing on the virtual node.

20. The computing system of claim 17 , wherein the program instructions further direct the processing system to:

identify one or more virtual nodes that satisfy propagation criteria from the virtual node based on the threat values; and

wherein generating the threat propagation summary comprises generating an interface that indicates a propagation threat hierarchy to the one or more other virtual nodes of the virtual nodes in the computing environment.

Assignments (3)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE FIRST INVENTOR'S LEGAL NAME PREVIOUSLY RECORDED ON REEL 051144 FRAME 0420. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Dec 14, 2022
From: BHALERAO, ANAND JAYSINGH; DESAI, ANERI RAJIV; AJMANI, DASHMEET KAUR
To: VMWARE, INC.
Reel/Frame 062119/0430 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2019
From: JAYSINGH, BHALERAO ANAND; DESAI, ANERI RAJIV; AJMANI, DASHMEET KAUR
To: VMWARE, INC.
Reel/Frame 051144/0420 →
Priority Claims (1)
IN 201941037953 · Sep 20, 2019 · national
Continuity (1)
Related Publication 20210092145A1 · Mar 25, 2021
Cited By (1)
US 12,585,784