IP Library › Granted Patent US 12,212,592
Granted Patent B2
US 12,212,592 · App. 18/310,162 · Granted Jan 28, 2025

Apparatuses, methods, and computer program products for automatic improved network architecture generation

Inventors: Tarun Gupta (Bangalore, IN); Anusha Challa (Bangalore, IN); Chetan Siddapura Kallappa (Bangalore, IN)
Assignee: HONEYWELL INTERNATIONAL INC.
H04L63/1425H04L41/082H04L41/0886H04L41/145H04L41/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,212,592
App. No.
18/310,162
Granted
Jan 28, 2025
Kind
B2
Abstract

Various embodiments of the present disclosure are directed to automatic improved network architecture generation. In this regard, embodiments may process data representing a network architecture to generate an improved network architecture that resolves one or more vulnerabilities associated with the network architecture. In this regard, embodiments such as apparatuses, methods, and computer program products, are provided to identify a network architecture comprising a networked device set, determine cybersecurity threat set associated with the network architecture, identify an improved network configuration data set based on the cybersecurity threat set and the network device architecture, wherein each recommended sub network configuration of the improved network configuration data set decreases a threat likelihood associated with at least one determined cybersecurity threat from the cybersecurity threat set, generate an improved network architecture based on the network architecture and the improved network configuration data set, and output the improved network architecture.

Claims (64)

1. A method comprising:

receiving a network architecture analysis request from a requestor system, wherein the network architecture analysis request comprises structured data representative of a network architecture;

identifying the network architecture by extracting the structured data from the network architecture analysis request, wherein the network architecture comprises one or more networked devices that are connected;

identifying a first subset of devices from amongst the one or more networked devices in the network architecture based on at least one of a type of the device in the first subset of devices, a functionality of the device in the first subset of devices, and a level associated with a network layer at which the device in the first subset of devices is configured to operate in the network architecture;

identifying from amongst a plurality of an architecture threat rule set, a first rule set applicable for the first subset of devices in the network architecture;

identifying from amongst the plurality of the architecture threat rule set, a second rule set applicable for a second subset of the devices in the network architecture different from the first subset of devices, wherein the second subset of devices are identified based on at least one of a type of the device in the second subset of devices, a functionality of the device in the second subset of devices, and a level associated with a network layer at which the device in the second subset of devices is configured to operate in the network architecture; and

determining a solution to mitigate vulnerabilities associated with the first and second subset of devices in the network architecture, wherein the vulnerabilities are identified for the first and second subset of devices based on the first rule set and the second rule set respectively, wherein determining the solution to mitigate vulnerabilities associated with the first subset of devices in the network architecture comprises:

retrieving a set threat solution data objects, wherein each of the set of threat solution data objects is associated with a number f changes to the network architecture;

selecting a first threat solution data object from the set of threat solution data objects based on a determination that the first threat solution data is associated with a minimum number of changes to the network architecture of the set of threat solution data objects; and

determining at least a portion of the solution to mitigate vulnerabilities associated with the first subset of device in the network architecture based on the first threat solution data object.

2. The method of claim 1 further comprising:

determining the solution to mitigate the vulnerabilities comprising changes to be made to the network architecture to resolve the vulnerabilities,

wherein the changes comprises removing a device from the one or more networked devices.

3. The method of claim 2 , further comprising:

rendering the network architecture on a display,

wherein the rendering comprises visually distinguishing the changes made to the network architecture to resolve the vulnerabilities.

4. The method of claim 1 further comprising:

determining the solution to mitigate the vulnerabilities based on a weighted combination of factors,

wherein the factors comprises protection against vulnerabilities and a projected cost associated with changes to be implemented.

5. The method of claim 1 , wherein the one or more threat solution data objects are retrieved based on requirements of at least one of: (i) shared networked devices, (ii) device configurations, and (iii) device connections.

6. The method of claim 1 further comprising:

determining the vulnerabilities being associated with firmware versions of the one or more networked devices.

7. A system comprising at least one processor and at least one non-transitory memory comprising program code, wherein the at least one non-transitory memory and the program code are configured to, with the at least one processor, cause the system to at least:

receive a network architecture analysis request from a requestor system, wherein the network architecture analysis request comprises structured data representative of a network architecture;

identify the network architecture by extracting the structured data from the network architecture analysis request, wherein the network architecture comprises one or more networked devices that are connected;

identify a first subset of devices from amongst the one or more networked devices in the network architecture based on at least one of a type of the device in the first subset of devices, a functionality of the device in the first subset of devices, and a level associated with a network layer at which the device in the first subset of devices is configured to operate in the network architecture;

identify a first rule set from amongst a plurality of an architecture threat rule set, the first rule set is applicable for the first subset of devices in the network architecture;

identify a second rule set from amongst the plurality of the architecture threat rule set and applicable for a second subset of devices in the network architecture, wherein the second subset of the devices are different from the first subset of devices, further the second subset of devices are identified based on at least one of a type of the device in the second subset of devices, a functionality of the device in the second subset of devices, and a level associated with a network layer at which the device in the second subset of devices is configured to operate in the network architecture; and

determine a solution to mitigate vulnerabilities associated with the first and second subset of devices in the network architecture, wherein the vulnerabilities are identified for the first and second subset of devices based on the first rule set and the second rule set respectively, wherein to determine the solution to mitigate vulnerabilities associated with the first subset of devices in the network architecture comprises the at least one non-transitory memory and the program code being configured to, with the at least one processor, cause the system to further:

retrieve a set of threat solution data objects, wherein each of the set of threat solution data objects is associated with a number of changes to the network architecture;

select a first threat solution data object from the set of threat solution data objects based on a determination that the first threat solution data is associated with a minimum number of changes to the network architecture of the set of threat solution data objects, and

determine at least a portion of the solution to mitigate abilities associated with the first subset of device in the network architecture based on the first threat solution data object.

8. The system of claim 7 , wherein the at least one non-transitory memory and the program code are configured to, with the at least one processor, cause the system to further:

determine the solution to mitigate the vulnerabilities comprising changes to be made to the network architecture to resolve the vulnerabilities,

wherein the changes comprises removing a device from the one or more networked devices.

9. The system of claim 8 , wherein the at least one non-transitory memory and the program code are configured to, with the at least one processor, cause the system to further:

render the network architecture on a display,

wherein the rendering comprises visually distinguishing the changes made to the network architecture to resolve the vulnerabilities.

10. The system of claim 7 , wherein the at least one non-transitory memory and the program code are configured to, with the at least one processor, cause the system to further:

determine the solution to mitigate the vulnerabilities based on a weighted combination of factors,

wherein the factors comprises protection against vulnerabilities and a projected cost associated with changes to be implemented.

11. The system of claim 7 , wherein the one or more threat solution data objects are retrieved based on (i) requirements of one or more of shared networked devices, (ii) device configurations, and/or (iii) device connections.

12. The system of claim 7 , wherein the at least one non-transitory memory and the program code are configured to, with the at least one processor, cause the system to further:

determine the vulnerabilities being associated with firmware versions of the one or more networked devices.

13. A non-transitory computer-readable storage medium having computer program instructions thereon, the computer program instructions, in execution with one or more processors configured to:

receive a network architecture analysis request from a requestor system, wherein the network architecture analysis request comprises structured data representative of a network architecture;

identify the network architecture by extracting the structured data from the network architecture analysis request, wherein the network architecture comprises one or more networked devices that are connected;

identify a first subset of devices from amongst the one or more networked devices in the network architecture based on at least one of a type of the device in the first subset of devices, a functionality of the device in the first subset of devices, and a level associated with a network layer at which the device in the first subset of devices is configured to operate in the network architecture;

identify from amongst a plurality of an architecture threat rule set, a first rule set applicable for the first subset of devices in the network architecture;

identify from amongst the plurality of the architecture threat rule set, a second rule set applicable for a second subset of the devices in the network architecture different from the first subset of devices, wherein the second subset of devices are identified based on at least one of a type of the device in the second subset of devices, a functionality of the device in the second subset of devices, and a level associated with a network layer at which the device in the second subset of devices is configured to operate in the network architecture; and

determine a solution to mitigate vulnerabilities associated with the first and second subset of devices in the network architecture, wherein the vulnerabilities are identified for the first and second subset of devices based on the first rule set and the second rule set respectively, wherein to determine the solution to mitigate vulnerabilities associated with the first subset of devices in the network architecture comprises the computer program instructions, in execution with one or more processors being further configured to:

retrieve a set of threat solution data objects, wherein each of the set of threat solution data objects is associate number of changes to the network architecture;

select a first threat solution data object from the set of threat solution data objects based on a determination that the first threat solution data is associated with a minimum number of changes to the network architecture of the set of threat solution data objects; and

determine at least a portion of the solution to mitigate vulnerabilities associated with the first subset of device in the network architecture based on the first threat solution data object.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the computer program instructions, in execution with one or more processors are further configured to:

determine the solution to mitigate the vulnerabilities comprising changes to be made to the network architecture to resolve the vulnerabilities,

wherein the changes comprises removing a device from the one or more networked devices.

15. The non-transitory computer-readable storage medium of claim 13 , wherein the computer program instructions, in execution with one or more processors are further configured to:

render the network architecture on a display,

wherein the rendering comprises visually distinguishing the changes made to the network architecture to resolve the vulnerabilities.

16. The non-transitory computer-readable storage medium of claim 13 , wherein the computer program instructions, in execution with one or more processors are further configured to:

determine the solution to mitigate the vulnerabilities based on a weighted combination of factors,

wherein the factors comprises protection against vulnerabilities and a projected cost associated with changes to be implemented.

17. The non-transitory computer-readable storage medium of claim 13 , wherein the one or more threat solution data objects are retrieved based on (i) requirements of one or more of shared networked devices, (ii) device configurations, and/or (iii) device connections.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2023
From: GUPTA, TARUN; CHALLA, ANUSHA; SIDDAPURA KALLAPPA, CHETAN
To: HONEYWELL INTERNATIONAL INC.
Reel/Frame 063495/0540 →
Continuity (2)
Continuation 16660307 · Oct 22, 2019
Related Publication 20230344850A1 · Oct 26, 2023
References Cited (25)
US 9303806B2 · Burton · 2016 [cited by examiner]
US 9306806B1 · Zhang · 2016 [cited by examiner]
US 9692784B1 · Nenov · 2017 [cited by applicant]
US 10178112B2 · Weilbacher · 2019 [cited by applicant]
US 10771506B1 · Kumar · 2020 [cited by examiner]
US 20080046393A1 · Jajodia et al. · 2008 [cited by applicant]
US 20080301765A1 · Nicol · 2008 [cited by examiner]
US 20100162383A1 · Linden · 2010 [cited by examiner]
US 20130298236A1 · Smith et al. · 2013 [cited by applicant]
US 20140331274A1 · Bitton · 2014 [cited by examiner]
US 20150117322A1 · McGrath · 2015 [cited by examiner]
US 20160352747A1 · Khan · 2016 [cited by examiner]
US 20180020018A1 · Walheim et al. · 2018 [cited by applicant]
US 20180109545A1 · Weilbacher · 2018 [cited by applicant]
US 20180309636A1 · Strom et al. · 2018 [cited by applicant]
US 20180359275A1 · Ng et al. · 2018 [cited by applicant]
US 20210099476A1 · Montgomery · 2021 [cited by examiner]
U.S. Appl. No. 16/660,307, filed Oct. 22, 2019, U.S. Pat. No. 11,677,768, Patented. [cited by applicant]
EP Office Action Mailed on Jan. 24, 2024 for EP Application No. 20202152, 5 page(s). [cited by applicant]
Applicant-Initiated Interview Summary Record (PTOL-413) Mailed on Nov. 1, 2021 for U.S. Appl. No. 16/660,307, 2 page(s). [cited by applicant]
European search opinion Mailed on Mar. 9, 2021 for EP Application No. 20202152, 3 page(s). [cited by applicant]
European search report Mailed on Mar. 9, 2021 for EP Application No. 20202152, 2 page(s). [cited by applicant]
Final Rejection Mailed on Mar. 14, 2022 for U.S. Appl. No. 16/660,307, 14 page(s). [cited by applicant]
Non-Final Rejection Mailed on Jul. 9, 2021 for U.S. Appl. No. 16/660,307, 9 page(s). [cited by applicant]
Notice of Allowance and Fees Due (PTOL-85) Mailed on Jan. 31, 2023 for U.S. Appl. No. 16/660,307, 9 pages(s). [cited by applicant]
Cited By (1)
US 12,489,774