IP Library › Granted Patent US 12,255,923
Granted Patent B2
US 12,255,923 · App. 17/687,746 · Granted Mar 18, 2025

Stream processing of telemetry for a network topology

Inventors: Michael J. Melson (Arlington, MA); Scott Laplante (Bedford, NH)
Assignee: Zscaler, Inc.
H04L63/20H04L41/0816H04L41/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,255,923
App. No.
17/687,746
Granted
Mar 18, 2025
Kind
B2
Abstract

Systems and methods include receiving messages from local security agents each on a host in a network, wherein the messages include network topology of the network in terms of addresses and sockets; incrementally creating a network topology of the network based on the messages; determining security policies for one or more microsegments in the network based on flow data and the network topology; and providing the security policies to respective hosts for local implementation of the one or more microsegments.

Claims (54)

1. A method comprising steps of:

receiving messages from local security agents each on a host in a network, wherein the messages include network topology of the network in terms of addresses and sockets;

incrementally creating a network topology of the network based on the messages;

determining security policies for one or more microsegments in the network based on flow data and the network topology;

providing the security policies to respective hosts for local implementation of the one or more microsegments; and

in a local security agent,

processing raw network address events;

processing raw socket events; and

combining the raw network address events and the raw socket events.

2. The method of claim 1 , wherein the steps further include

receiving updated messages which change the network topology; and

redetermining the security policies for the one or more microsegments.

3. The method of claim 1 , wherein the raw network address events are processed by dividing addresses into groups based on any of remote system identifier, address family, and namespace.

4. The method of claim 1 , wherein the combining includes any of wildcard sockets create one resolved socket for each network address in a matching group,

single IP sockets create one resolved socket if and only if there is a network address with a matching IP address, and

changes to either network addresses or sockets triggers a new comparison.

5. The method of claim 1 , wherein the method is implemented by a cloud-based system.

6. The method of claim 5 , wherein the local implementation of the one or more microsegments is via the local security agents.

7. An apparatus comprising at least one processor and memory storing instructions that, when executed, cause the at least one processor to implement steps of:

receiving messages from local security agents each on a host in a network, wherein the messages include network topology of the network in terms of addresses and sockets;

incrementally creating a network topology of the network based on the messages;

determining security policies for one or more microsegments in the network based on flow data and the network topology;

providing the security policies to respective hosts for local implementation of the one or more microsegments; and

in a local security agent,

processing raw network address events;

processing raw socket events; and

combining the raw network address events and the raw socket events.

8. The apparatus of claim 7 , wherein the steps further include

receiving updated messages which change the network topology; and

redetermining the security policies for the one or more microsegments.

9. The apparatus of claim 7 , wherein the raw network address events are processed by dividing addresses into groups based on any of remote system identifier, address family, and namespace.

10. The apparatus of claim 7 , wherein the combining includes any of wildcard sockets create one resolved socket for each network address in a matching group,

single IP sockets create one resolved socket if and only if there is a network address with a matching IP address, and

changes to either network addresses or sockets triggers a new comparison.

11. The apparatus of claim 7 , wherein the steps are implemented by a cloud-based system.

12. The apparatus of claim 11 , wherein the local implementation of the one or more microsegments is via the local security agents.

13. A non-transitory computer-readable medium comprising instructions that, when executed, cause at least one processor to perform steps of:

receiving messages from local security agents each on a host in a network, wherein the messages include network topology of the network in terms of addresses and sockets;

incrementally creating a network topology of the network based on the messages;

determining security policies for one or more microsegments in the network based on flow data and the network topology; and

providing the security policies to respective hosts for local implementation of the one or more microsegments; and

in a local security agent,

processing raw network address events;

processing raw socket events; and

combining the raw network address events and the raw socket events.

14. The non-transitory computer-readable medium of claim 13 , wherein the steps further include

receiving updated messages which change the network topology; and

redetermining the security policies for the one or more microsegments.

15. The non-transitory computer-readable medium of claim 13 , wherein the raw network address events are processed by dividing addresses into groups based on any of remote system identifier, address family, and namespace.

16. The non-transitory computer-readable medium of claim 13 , wherein the combining includes any of

wildcard sockets create one resolved socket for each network address in a matching group,

single IP sockets create one resolved socket if and only if there is a network address with a matching IP address, and

changes to either network addresses or sockets triggers a new comparison.

17. The non-transitory computer-readable medium of claim 13 , wherein the steps are implemented by a cloud-based system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2022
From: MELSON, MICHAEL J.; LAPLANTE, SCOTT
To: ZSCALER, INC.
Reel/Frame 059180/0749 →
Continuity (1)
Related Publication 20230283639A1 · Sep 7, 2023
References Cited (10)
US 10154067B2 · Smith et al. · 2018 [cited by applicant]
US 10439985B2 · O'Neil · 2019 [cited by applicant]
US 20190349283A1 · O'Neil et al. · 2019 [cited by applicant]
US 20200021618A1 · Smith et al. · 2020 [cited by applicant]
US 20210344723A1 · O'Neil · 2021 [cited by examiner]
US 20210359995A1 · Dorrell · 2021 [cited by examiner]
US 20220095092A1 · Siddam · 2022 [cited by examiner]
US 20230018210A1 · Keiser, Jr. · 2023 [cited by examiner]
US 20230239325A1 · Keiser, Jr. · 2023 [cited by examiner]
WO 2018152303A1 · 2018 [cited by applicant]