IP Library Granted Patent US 12,368,749
Granted Patent B2
US 12,368,749 · App. 18/352,036 · Granted Jul 22, 2025

Secure neighborhoods assessment in enterprise networks

Inventors: Supreeth Rao (Cupertino, CA); Navindra Yadav (Cupertino, CA); Prasannakumar Jobigenahally Malleshaiah (Sunnyvale, CA); Hanlin He (San Jose, CA); Umamaheswaran Arumugam (San Jose, CA); Robert Bukofser (Mason, OH); Aiyesha Ma (San Francisco, CA); Kai Zhu (San Jose, CA); Ashok Kumar (Pleasanton, CA)
Assignee: Cisco Technology, Inc.
H04L63/1433G06F16/9024G06F16/9035H04L41/22H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,368,749
App. No.
18/352,036
Granted
Jul 22, 2025
Kind
B2
Abstract

Systems, methods, and computer-readable media for determine a neighborhood graph can include the following processes. A neighborhood graph system generates a neighborhood graph for a plurality of nodes in an enterprise network, the neighborhood graph representing a multi-hop connections between any two nodes of the plurality of nodes. A security score service determines a security score for each of the plurality of nodes to yield a plurality of scores. The neighborhood graph system updates the neighborhood graph of the plurality of nodes using the plurality of scores to provide a visual representation of securities of the plurality of nodes relative to each other.

Claims (38)

1. A method comprising:

generating a neighborhood graph for a plurality of nodes in an enterprise network, the neighborhood graph representing a multi-hop connection between any two nodes of the plurality of nodes;

determining a plurality of sub-scores for each of the plurality of nodes, each of the plurality of sub-scores being indicative of a different security aspect of a corresponding one of the plurality of nodes, the plurality of sub-scores including at least a corresponding vulnerability score and a corresponding attack surface score for each of the plurality of nodes;

determining, based on the plurality of sub-scores, an overall security score for each of the plurality of nodes to yield a plurality of scores; and

updating the neighborhood graph of the plurality of nodes using the plurality of scores to provide a visual representation of securities of the plurality of nodes relative to each other.

2. The method of claim 1 , wherein the plurality of sub-scores further include a corresponding process hash score, a corresponding forensics score, a corresponding network anomaly score, and a corresponding segmentation compliance score for each of the plurality of nodes.

3. The method of claim 1 , further comprising:

filtering the updated neighborhood graph.

4. The method of claim 3 , wherein the filtering is based on a filtering parameter associated with at least one of a number of source nodes and a number of destination nodes in the enterprise network.

5. The method of claim 4 , wherein the filtering parameter includes a threshold attack surface score of each of the number of source nodes, a threshold attack surface score of

each of the number of destination nodes, a vulnerability score of each of the number of source nodes, or a vulnerability score of each of the number of destination nodes.

6. The method of claim 1 , further comprising:

receiving a request for generating the neighborhood graph.

7. The method of claim 1 , further comprising:

creating an alert for the updated neighborhood graph, the alert indicating presence of one or more new network connections between the plurality of nodes having a threshold security score.

8. A network controller comprising:

one or more memories computer-readable instructions; and one or more processors configured to execute the computer-readable instructions to:

generate a neighborhood graph for a plurality of nodes in an enterprise network, the neighborhood graph representing a multi-hop connection between any two nodes of the plurality of nodes;

determine a plurality of sub-scores for each of the plurality of nodes, each of the plurality of sub-scores being indicative of a different security aspect of a corresponding one of the plurality of nodes, the plurality of sub-scores including at least a corresponding vulnerability score and a corresponding attack surface score for each of the plurality of nodes;

determine, based on the plurality of sub-scores, an overall security score for each of the plurality of nodes to yield a plurality of scores; and

update the neighborhood graph of the plurality of nodes using the plurality of scores to provide a visual representation of securities of the plurality of nodes relative to each other.

9. The network controller of claim 8 , wherein the plurality of sub-scores further include a corresponding process hash score, a corresponding forensics score, a corresponding network anomaly score, and a corresponding segmentation compliance score for each of the plurality of nodes.

10. The network controller of claim 8 , wherein the one or more processors are further configured to execute the computer-readable instructions to filter the updated neighborhood graph.

11. The network controller of claim 10 , wherein the one or more processors are further configured to execute the computer-readable instructions to filter the updated neighborhood graph based on a filtering parameter associated with at least one of a number of source nodes and a number of destination nodes in the enterprise network.

12. The network controller of claim 11 , wherein the filtering parameter includes a threshold attack surface score of each of the number of source nodes, a threshold attack surface score of each of the number of destination nodes, a vulnerability score of each of the number of source nodes, or a vulnerability score of each of the number of destination nodes.

13. The network controller of claim 8 , wherein the one or more processors are further configured to execute the computer-readable instructions to receive a request for generating the neighborhood graph.

14. The network controller of claim 8 , wherein the one or more processors are further configured to execute the computer-readable instructions to create an alert for the updated neighborhood graph, the alert indicating presence of one or more new network connections between the plurality of nodes having a threshold security score.

15. One or more non-transitory computer-readable media comprising computer-readable instructions, which when executed by one or more processors of a network controller, cause the network controller to:

generate a neighborhood graph for a plurality of nodes in an enterprise network, the neighborhood graph representing a multi-hop connection between any two nodes of the plurality of nodes;

determine a plurality of sub-scores for each of the plurality of nodes, each of the plurality of sub-scores being indicative of a different security aspect of a corresponding one of the plurality of nodes, the plurality of sub-scores including at least a corresponding vulnerability score and a corresponding attack surface score for each of the plurality of nodes;

determine, based on the plurality of sub-scores, an overall security score for each of the plurality of nodes to yield a plurality of scores; and

update the neighborhood graph of the plurality of nodes using the plurality of scores to provide a visual representation of securities of the plurality of nodes relative to each other.

16. The one or more non-transitory computer-readable media of claim 15 , wherein the plurality of sub-scores further include a corresponding process hash score, a corresponding forensics score, a corresponding network anomaly score, and a corresponding segmentation compliance score for each of the plurality of nodes.

17. The one or more non-transitory computer-readable media of claim 15 , wherein the execution of the computer-readable instructions cause the network controller to filter the updated neighborhood graph.

18. The one or more non-transitory computer-readable media of claim 17 , wherein the execution of the computer-readable instructions cause the network controller to filter the updated neighborhood graph based on a filtering parameter associated with at least one of a number of source nodes and a number of destination nodes in the enterprise network.

19. The one or more non-transitory computer-readable media of claim 18 , wherein the filtering parameter includes a threshold attack surface score of each of the number of source nodes, a threshold attack surface score of each of the number of destination nodes, a

vulnerability score of each of the number of source nodes, or a vulnerability score of each of the number of destination nodes.

20. The one or more non-transitory computer-readable media of claim 17 , wherein the execution of the computer-readable instructions cause the network controller to create an alert for the updated neighborhood graph, the alert indicating presence of one or more new network connections between the plurality of nodes having a threshold security score.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2023
From: RAO, SUPREETH; YADAV, NAVINDRA; MALLESHAIAH, PRASANNAKUMAR JOBIGENAHALLY; HE, HANLIN; ARUMUGAM, UMAMAHESWARAN; BUKOFSER, ROBERT; MA, AIYESHA; ZHU, KAI; KUMAR, ASHOK
To: CISCO TECHNOLOGY, INC.
Reel/Frame 064250/0011 →
Continuity (2)
Continuation 16990664 · Aug 11, 2020
Related Publication 20230370489A1 · Nov 16, 2023
References Cited (15)
US 7890869B1 · Mayer et al. · 2011 [cited by applicant]
US 9098815B2 · Li et al. · 2015 [cited by applicant]
US 10193901B2 · Muddu et al. · 2019 [cited by applicant]
US 10284589B2 · Hamdi · 2019 [cited by applicant]
US 11201890B1 · Coull · 2021 [cited by examiner]
US 20160241561A1 · Bubany et al. · 2016 [cited by applicant]
US 20180219888A1 · Apostolopoulos · 2018 [cited by applicant]
US 20190379700A1 · Canzanese, Jr. · 2019 [cited by examiner]
US 20210157851A1 · Aoyama et al. · 2021 [cited by applicant]
US 20210248449A1 · Sun et al. · 2021 [cited by applicant]
US 20210406312A1 · Iwasaki · 2021 [cited by applicant]
JP 6016982B1 · 2016 [cited by applicant]
WO 03060717A1 · 2003 [cited by applicant]
Angelini M., et al., “VULNUS: Visual Vulnerability Analysis For Network Security,” Research Gate, Aug. 2018, 11 pages. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2021/042981, mailed Oct. 18, 2021, 10 Pages. [cited by applicant]