IP Library › Granted Patent US 12,267,343
Granted Patent B2
US 12,267,343 · App. 17/711,613 · Granted Apr 1, 2025

Risk driven planning and simulation for a computer network

Inventors: Eli Fainberg (Tel Aviv, IL); Yafit Maor (Even-Yehuda, IL)
Assignee: Forescout Technologies, Inc.
H04L63/1425H04L63/1416H04L63/1433H04L63/145H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,343
App. No.
17/711,613
Granted
Apr 1, 2025
Kind
B2
Abstract

Systems, methods, and related technologies for a risk driven planning and simulation tool for a computer network are described. A security risk is determined for each of a plurality of devices on a network. A network traffic map is presented to a display. The network traffic map shows network traffic between the plurality of devices and the security risk for each of the plurality of devices. Segmentation of one or more of the plurality of devices on the network is simulated and presented to the display with updates to the network traffic or updates to the security risk of some of the devices on the network.

Claims (41)

1. A method comprising:

determining a security risk for each of a plurality of devices on a network;

presenting, to a display, a network traffic map that comprises network traffic between one or more of the plurality of devices and the security risk for each of the plurality of devices;

presenting, to the display, one or more suggested segmentations that are determined in view of the security risk of each of the plurality of devices, wherein the one or more suggested segmentations are ordered to group the plurality of devices in view of the security risk, wherein one of the one or more suggested segmentations isolates the one or more of the plurality of devices that is deemed as critical from a second of the plurality of devices that is deemed as being vulnerable or exhibiting negative behavior;

simulating, based on the network traffic between the one or more of the plurality of devices in the network traffic map, segmentation of the one or more of the plurality of devices on the network resulting in simulated network traffic and a simulated security risk of the one or more of the plurality of the devices on the network; and

presenting, to the display, the network traffic map comprising the network traffic prior to the simulating, alongside the simulated network traffic between the one or more of the plurality of devices and the simulated security risk of the one or more of the plurality of devices on the network, wherein the simulated network traffic is displayed as an overlay to the network traffic prior to the simulating.

2. The method of claim 1 , wherein the security risk is determined in view of at least one of: a vulnerability, a criticality, or a behavior of a respective one of the plurality of devices on the network.

3. The method of claim 2 , wherein the vulnerability, the criticality, and the behavior of the respective one of the plurality of devices is determined periodically, based on periodic performance of device, classification, and analysis of the network traffic.

4. The method of claim 1 , further comprising:

presenting, to the display, a suggested patch or a suggested update, determined in view of the security risk of each of the plurality of devices on the network.

5. The method of claim 4 , wherein simulating the segmentation of the one or more of the plurality of devices on the network is performed in response to a user input that selects a suggested segmentation in the one or more suggested segmentations or the suggested patch.

6. The method of claim 1 , further comprising:

displaying the security risk of each of the plurality of devices on the network as a heat map.

7. A system, comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

determine a security risk for each of a plurality of devices on a network;

present, to a display, a network traffic map that comprises network traffic between one or more of the plurality of devices and the security risk for each of the plurality of devices;

present, to the display, one or more suggested segmentations that are determined in view of the security risk of each of the plurality of devices, wherein the one or more suggested segmentations are ordered to group the plurality of devices in view of the security risk, wherein one of the one or more suggested segmentations isolates the one or more of the plurality of devices that is deemed as critical from a second of the plurality of devices that is deemed as being vulnerable or exhibiting negative behavior;

simulate, based on the network traffic between the one or more of the plurality of devices in the network traffic map, segmentation of the one or more of the plurality of devices on the network resulting in simulated network traffic and a simulated security risk of the one or more of the plurality of the devices on the network; and

present, to the display, the network traffic map comprising the network traffic prior to the simulating, alongside the simulated network traffic between the one or more of the plurality of devices and the security risk of the one or more of the plurality of devices on the network, wherein the simulated network traffic is displayed as an overlay to the network traffic prior to the simulating.

8. The system of claim 7 , wherein to determine the security risk, the processing device is to determine the security risk in view of at least one of: a vulnerability, a criticality, or a behavior of a respective one of the plurality of devices on the network.

9. The system of claim 8 , wherein the vulnerability, the criticality, and the behavior of the respective one of the plurality of devices is determined periodically, based on periodic performance of device, classification, and analysis of the network traffic.

10. The system of claim 7 , wherein the processing device is further to:

present, to the display, a suggested patch or a suggested update, determined in view of the security risk of each of the plurality of devices on the network.

11. The system of claim 10 , wherein to simulate the segmentation of the one or more of the plurality of devices on the network, the processing device is to simulate the segmentation of the one or more of the plurality of devices on the network in response to a user input that selects a suggested segmentation in the one or more suggested segmentations or the suggested patch.

12. The system of claim 7 , wherein the processing device is further to:

display the security risk of each of the plurality of devices on the network as a heat map.

13. A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device, cause the processing device to:

determine a security risk for each of a plurality of entities on a network;

present, to a display, a network traffic map that comprises network traffic between one or more of the plurality of entities and the security risk for each of the plurality of entities;

present, to the display, one or more suggested segmentations that are determined in view of the security risk of each of the plurality of devices, wherein the one or more suggested segmentations are ordered to group the plurality of devices in view of the security risk, wherein one of the one or more suggested segmentations isolates the one or more of the plurality of devices that is deemed as critical from a second of the plurality of devices that is deemed as being vulnerable or exhibiting negative behavior;

simulate, based on the network traffic between the one or more of the plurality of devices in the network traffic map, segmentation of the one or more of the plurality of entities on the network resulting in simulated network traffic and a simulated security risk of the one or more of the plurality of the entities on the network; and

present, to the display, the network traffic map comprising the network traffic prior to the simulating, alongside the simulated the network traffic between the plurality of entities and the simulated security risk of the one or more of the plurality of entities on the network, wherein the simulated network traffic is displayed as an overlay to the network traffic prior to the simulating.

14. The non-transitory computer readable medium of claim 13 , wherein to determine the security risk, the instructions, when executed by the processing device, cause the processing device to determine the security risk in view of at least one of: a vulnerability, a criticality, or a behavior of a respective one of the plurality of entities on the network.

15. The non-transitory computer readable medium of claim 14 , wherein the vulnerability, the criticality, and the behavior of the respective one of the plurality of entities is determined periodically, based on periodic performance of device, classification, and analysis of the network traffic.

16. The non-transitory computer readable medium of claim 13 , wherein the instructions, when executed by the processing device, cause the processing device further to:

present, to the display, a suggested patch or a suggested update, determined in view of the security risk of each of the plurality of devices on the network.

17. The non-transitory computer readable medium of claim 16 , wherein to simulate the segmentation of the one or more of the plurality of devices on the network, the instructions, when executed by the processing device, cause the processing device to simulate the segmentation of the one or more of the plurality of devices on the network in response to a user input that selects a suggested segmentation in the one or more suggested segmentations or the suggested patch.

18. The non-transitory computer readable medium of claim 13 , wherein the instructions, when executed by the processing device, cause the processing device further to:

display the security risk of each of the plurality of devices on the network as a heat map.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2022
From: FAINBERG, ELI; MAOR, YAFIT
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 059474/0780 →
Continuity (1)
Related Publication 20230319081A1 · Oct 5, 2023
References Cited (26)
US 7315801B1 · Dowd · 2008 [cited by examiner]
US 7890869B1 · Mayer · 2011 [cited by examiner]
US 11411822B2 · Fainberg · 2022 [cited by examiner]
US 20060265324A1 · Leclerc · 2006 [cited by examiner]
US 20170126727A1 · Beam · 2017 [cited by examiner]
US 20180048668A1 · Gupta · 2018 [cited by examiner]
US 20180115469A1 · Erickson · 2018 [cited by examiner]
US 20180139104A1 · Seddigh · 2018 [cited by examiner]
US 20190089742A1 · Hill · 2019 [cited by examiner]
US 20190215246A1 · Kawalay · 2019 [cited by examiner]
US 20200007396A1 · Fainberg · 2020 [cited by examiner]
US 20200007397A1 · Fainberg · 2020 [cited by examiner]
US 20200112485A1 · Shen · 2020 [cited by examiner]
US 20200351297A1 · Seiver · 2020 [cited by examiner]
US 20210006582A1 · Yamada · 2021 [cited by examiner]
US 20210136101A1 · Ben-Yosef · 2021 [cited by examiner]
US 20210152590A1 · Urias · 2021 [cited by examiner]
US 20210306354A1 · Raghuramu · 2021 [cited by examiner]
US 20210352099A1 · Rogers · 2021 [cited by examiner]
US 20220021697A1 · Adamson · 2022 [cited by examiner]
US 20220060512A1 · Crabtree · 2022 [cited by examiner]
US 20220067158A1 · Sloane · 2022 [cited by examiner]
US 20220083027A1 · Brooks · 2022 [cited by examiner]
US 20220239564A1 · Jiang · 2022 [cited by examiner]
US 20220261714A1 · Aslam · 2022 [cited by examiner]
US 20230042671A1 · Zaman · 2023 [cited by examiner]