IP Library › Granted Patent US 12,309,206
Granted Patent B2
US 12,309,206 · App. 17/396,895 · Granted May 20, 2025

System and method for creating access control policies for individual users, user groups, network host or network host groups through network traffic analysis

Inventor: John Peterson (Morgan Hll, CA)
Assignee: ERICOM SOFTWARE LTD.
H04L63/205H04L63/102H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,206
App. No.
17/396,895
Granted
May 20, 2025
Kind
B2
Abstract

A method and system for automatically creating access control policies for a network, including: (a) automatically identifying and recording user or host entities that attach to the network; (b) monitoring allowed network communications from the user or host entities; (c) correlating network address information from the allowed network communications with names of the user or host entities; and (d) proposing a respective access control policy for each of the user or host entities based on information gleaned during a learning process.

Claims (13)

1. A method for automatically creating access control policies for a network, comprising:

(a) automatically identifying and recording user or host entities that attach to the network, each of the user or host entities being assigned respective network addresses;

(b) monitoring allowed network communications from said user or host entities to extract the respective network addresses;

(c) removing any existing access control policies previously assigned to the network addresses;

(d) correlating the respective network addresses with corresponding existing access control policies of said user or host entities based on said allowed network communications;

(e) performing a learning process, on user or host entities for which no existing access control policies exist; and

(f) proposing a respective access control policy for each of said user or host entities based on information gleaned during the learning process.

2. The method of claim 1 , wherein said learning process includes at least one of:

(i) performing network traffic analysis on network traffic to and from said user or host entities;

(ii) performing behavior analysis on said user or host entities; and

(iii) performing machine learning on activities of said user or host entities.

3. The method of claim 1 , wherein said respective access control policy for each of said entities is reviewed by a human security administrator or automatically implemented.

4. The method of claim 1 , wherein said user or host entities are selected from groups including: users, user groups, network hosts or network host groups.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 9, 2021
From: PETERSON, JOHN
To: ERICOM SOFTWARE LTD.
Reel/Frame 057118/0570 →
Continuity (2)
Provisional Application 63063357 · Aug 9, 2020
Related Publication 20220046063A1 · Feb 10, 2022
References Cited (13)
US 9413778B1 · Elisha · 2016 [cited by examiner]
US 10263868B1 · Baldi · 2019 [cited by examiner]
US 20120167168A1 · Orr · 2012 [cited by examiner]
US 20180084012A1 · Joseph · 2018 [cited by examiner]
US 20180227184A1 · Mentze · 2018 [cited by examiner]
US 20180288063A1 · Koottayi · 2018 [cited by examiner]
US 20200228404A1 · Hooda · 2020 [cited by examiner]
US 20210006542A1 · Myneni · 2021 [cited by examiner]
US 20210037061A1 · Trost · 2021 [cited by examiner]
US 20210243604A1 · Lepp · 2021 [cited by examiner]
US 20210306354A1 · Raghuramu · 2021 [cited by examiner]
WO WO2019172762A1 · 2019 [cited by examiner]
R. Droms, “Automated configuration of TCP/IP with DHCP,” in IEEE Internet Computing, vol. 3, No. 4, pp. 45-53, Jul.-Aug. 1999, doi: 10.1109/4236.780960. (Year: 1999). [cited by examiner]