IP Library › Granted Patent US 12,244,616
Granted Patent B2
US 12,244,616 · App. 17/986,661 · Granted Mar 4, 2025

Prioritizing assets using security metrics

Inventors: Travis Nathan Sugarbaker (Seattle, WA); Srivatsa Shripathi Modambu (Karnataka, IN)
Assignee: Cisco Technology, Inc.
H04L63/1416H04L63/0236H04L63/105H04L63/1425H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,616
App. No.
17/986,661
Granted
Mar 4, 2025
Kind
B2
Abstract

This disclosure describes techniques for identifying the criticality of an asset in a network. In an example method, a first security metric of a first asset in a network, as well as network data that identifies data flows associated with a second asset in the network are identified. The second asset is a nearest neighbor of the first asset in the network. The method includes determining, based on the network data, a number of hosts in the network that exchanged data traffic with the second asset during a time period and generating a second security metric of the second asset based on the first security metric and the number of hosts. A security policy of the second asset is adjusted based on the security metric.

Claims (64)

1. A method, comprising:

exchanging, by a first asset, first data traffic during a time period;

determining a number of hosts that exchanged the first data traffic with the first asset during the time period;

determining a first security metric of the first asset based on the number of the hosts, the first security metric indicating a vulnerability to attack associated with the first asset;

determining a second security metric of a second asset comprising a nearest neighbor of the first asset, the nearest neighbor of the first asset being directly connected to the first asset in a network, and the second security metric indicating a vulnerability to attack associated with the second asset;

determining a third security metric indicating the vulnerability to attack associated with the first asset based on the first security metric and the second security metric, and based on the second security metric comprising a nearest neighbor of the first asset;

adjusting a security policy of the first asset based on the third security metric; and

exchanging, by the first asset, second data traffic based at least in part on the security policy.

2. The method of claim 1 , wherein determining the number of the hosts that exchanged the first data traffic with the first asset comprises:

identifying, based on network data, addresses of the hosts;

generating shortened addresses by extracting a subset of most significant digits of the addresses, the shortened addresses being shorter than the addresses; and

determining the number of the hosts based on a number of the shortened addresses.

3. The method of claim 1 , wherein the time period is greater than or equal to 7 days and less than or equal to 31 days.

4. The method of claim 1 , the hosts being first hosts, wherein the first asset comprises at least one of an application, a port, or a second host.

5. The method of claim 1 , wherein the nearest neighbor comprises a graph neighbor of the first asset.

6. The method of claim 1 , wherein determining the third security metric of the first asset comprises adding the first security metric and a product of the second security metric and a propagation factor associated with the second asset.

7. The method of claim 1 , wherein the nearest neighbor of the first asset is connected to the first asset without any intermediary nodes being disposed between the nearest neighbor of the first asset and the first asset in the network.

8. The method of claim 1 , wherein determining the second security metric of the second asset comprising the nearest neighbor of the first asset comprises determining the second security metric based on data traffic transmitted between the nearest neighbor of the first asset and the first asset.

9. The method of claim 1 , wherein the third security metric is a function of an exposure associated with the first asset and an exploitation risk associated with the first asset.

10. A system, comprising:

at least one processor; and

one or more non-transitory media storing instructions that, when executed by the system, cause the system to perform operations comprising:

determining a number of hosts that exchanged first data traffic with a first asset;

determining a first security metric of the first asset based on the number of the hosts, the first security metric indicating a vulnerability to attack associated with the first asset;

determining a second security metric of a second asset comprising a nearest neighbor of the first asset, the nearest neighbor of the first asset being directly connected to the first asset in a network, and the second security metric indicating a vulnerability to attack assoicated with the second asset;

determining a third security metric indicating the vulnerability to attack associated with the first asset based on the first security metric and the second security metric, and further based on the second security metric comprising a nearest neighbor of the first asset;

causing an external entity configured to adjust a security policy of the first asset based on the third security metric; and

causing the first asset to exchange second data traffic based at least in part on the security policy.

11. The system of claim 10 , wherein determining the number of the hosts that exchanged the first data traffic with the first asset comprises:

identifying addresses of the hosts;

generating shortened addresses by extracting a subset of most significant digits of the addresses, the shortened addresses being shorter than the addresses; and

determining the number of the hosts based on a number of the shortened addresses.

12. The system of claim 10 , wherein the nearest neighbor comprises a graph neighbor of the first asset.

13. The system of claim 10 , wherein determining the third security metric of the first asset comprises adding the first security metric and a product of the second security metric and a propagation factor associated with the second asset.

14. The system of claim 10 , wherein the security policy comprises a multi-factor authentication (MFA) interval or a firewall policy of the first asset.

15. The system of claim 10 , wherein:

the operations further comprise determining a number of locations of the hosts, and

determining the first security metric of the first asset is further based on the number of locations.

16. The system of claim 10 , wherein:

the operations further comprise determining a number of users of the hosts, and

determining the first security metric of the first asset is further based on the number of users.

17. A system, comprising:

at least one processor; and

one or more non-transitory media storing instructions that, when executed by the system, cause the system to perform operations comprising:

determining a number of hosts that exchanged first data traffic with a first asset;

generating a first security metric of the first asset based on the number of the hosts;

determining second security metrics of n second assets, the n second assets respectively comprising nearest neighbors of the first asset, n being a positive integer;

determining propagation factors of the n second assets based on the second security metrics;

determining a third security metric of the first asset based on a following equation:

S+Σ 1 n f prop ( n ),

wherein S is the first security metric and f prop (n) is a propagation factor contributed by an nth second asset;

causing an external entity configured to adjust a security policy of the first asset based on the third security metric; and

causing the first asset to exchange second data traffic based at least in part on the security policy.

18. The system of claim 17 , wherein determining the number of the hosts that exchanged first data traffic with the first asset comprises:

identifying Internet Protocol (IP) addresses of the hosts;

generating binary addresses by converting the IP addresses to a binary form;

generating shortened addresses that are a predetermined number of leftmost digits of the binary addresses; and

determining the number of the hosts by determining a number of the shortened addresses.

19. The system of claim 17 , wherein the nearest neighbors are directly adjacent to the first asset.

20. The system of claim 17 , wherein:

the operations further comprise:

determining a number of locations of the hosts; and

determining a number of users of the hosts, and

generating the first security metric is further based on the number of locations and the number of users.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2022
From: SUGARBAKER, TRAVIS NATHAN; MODAMBU, SRIVATSA SHRIPATHI
To: CISCO TECHNOLOGY, INC.
Reel/Frame 061763/0314 →
Priority Claims (1)
IN 202041032709 · Jul 30, 2020 · national
Continuity (2)
Continuation 17026093 · Sep 18, 2020
Related Publication 20230072859A1 · Mar 9, 2023
References Cited (33)
US 8245296B2 · Archer · 2012 [cited by examiner]
US 10320830B2 · Ahuja et al. · 2019 [cited by applicant]
US 10896268B2 · Dayan · 2021 [cited by examiner]
US 20120278861A1 · Lu · 2012 [cited by examiner]
US 20130031634A1 · McClure et al. · 2013 [cited by applicant]
US 20140173739A1 · Ahuja · 2014 [cited by examiner]
US 20140215550A1 · Adams · 2014 [cited by examiner]
US 20140289827A1 · Tang · 2014 [cited by examiner]
US 20180097828A1 · Coskun · 2018 [cited by examiner]
US 20180131716A1 · Chantz · 2018 [cited by examiner]
US 20180309778A1 · Sugarbaker · 2018 [cited by applicant]
US 20180351988A1 · Ahuja et al. · 2018 [cited by applicant]
US 20190005276A1 · Dayan · 2019 [cited by examiner]
US 20190147162A1 · Mejbah · 2019 [cited by examiner]
US 20190215688A1 · Zavesky · 2019 [cited by examiner]
US 20190238584A1 · Somasundaram et al. · 2019 [cited by applicant]
US 20190253450A1 · Ahuja et al. · 2019 [cited by applicant]
US 20200092319A1 · Spisak et al. · 2020 [cited by applicant]
US 20200162497A1 · Iyer et al. · 2020 [cited by applicant]
US 20200162498A1 · Ababtain et al. · 2020 [cited by applicant]
US 20200204576A1 · Davis · 2020 [cited by examiner]
US 20210279565A1 · Akella · 2021 [cited by examiner]
US 20220038471A1 · Sugarbaker et al. · 2022 [cited by applicant]
AU 2019232785A1 · 2020 [cited by applicant]
CA 3055978A1 · 2020 [cited by applicant]
CN 104798079A · 2015 [cited by applicant]
EP 2936374A1 · 2015 [cited by applicant]
EP 3654220A1 · 2020 [cited by applicant]
KR 20150070331A · 2015 [cited by applicant]
WO WO2014100103A1 · 2014 [cited by applicant]
WO WO2020106479A1 · 2020 [cited by applicant]
Office Action for U.S. Appl. No. 17/026,093, mailed on Mar. 16, 2022, Sugarbaker, “Prioritizing Assets Using Security Metrics”, 16 pages. [cited by applicant]
The International Search Report and Written Opinion for PCT Application No. PCT/US21/43585, mailed Nov. 4, 2021, 16 pages. [cited by applicant]