IP Library › Granted Patent US 12,598,203
Granted Patent B2
US 12,598,203 · App. 18/360,613 · Granted Apr 7, 2026

Analyzing and recommending rogue classification policies for a communication network

Inventors: Sreecharan Guduri (Bangalore, IN); Sekhar Karimbedu (Bangalore, IN); Gururaj Pralhad Cowkur (Bangalore, IN); Pradeep Kumar Golakonda (Bangalore, IN); Venkata Sandeepu Lade (Bangalore, IN)
Assignee: Hewlett Packard Enterprise Development LP
H04L63/1425G06F18/2415
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,203
App. No.
18/360,613
Granted
Apr 7, 2026
Kind
B2
Abstract

In certain embodiments, a method performed by a processing device includes obtaining, at multiple times, rogue classification information for electronic devices detected within a communication network. The rogue classification information for each time includes: timestamp information identifying the time; corresponding sets of attribute values for the electronic devices detected within the communication network at the time; and respective rogue classifications, as determined according to active rogue classification policies and the corresponding sets of attribute values, for the electronic devices. The method includes analyzing the rogue classification information for the multiple times to determine whether to modify the active rogue classification policies by analyzing, using a statistical machine learning algorithm, the respective rogue classifications and the corresponding sets of attribute values for the electronic devices for the multiple times. The method includes generating, in response to determining to modify the active rogue classification policies, a recommended rogue classification policy.

Claims (54)

1 . A method comprising:

obtaining, at a plurality of times by a processing device, rogue classification information for electronic devices detected within a communication network, the rogue classification information for each time of the plurality of times comprising:

timestamp information identifying the time of the plurality of times;

corresponding sets of attribute values for the electronic devices detected within the communication network at the time; and

respective rogue classifications, as determined according to active rogue classification policies and the corresponding sets of attribute values, for the electronic devices detected within the communication network at the time;

analyzing, by the processing device, the rogue classification information for the plurality of times to determine whether to modify the active rogue classification policies, wherein analyzing the rogue classification information for the plurality of times comprises analyzing, using a statistical machine learning algorithm, the respective rogue classifications and the corresponding sets of attribute values for the electronic devices for the plurality of times, and wherein analyzing the rogue classification information comprises assigning a threat rating to a particular electronic device, the threat rating being separate from the respective roque classification for the particular electronic device and being determined according to at least a portion of the corresponding attribute values for the particular electronic device; and

generating, by the processing device in response to determining to modify the active rogue classification policies, a recommended rogue classification policy.

2 . The method of claim 1 , wherein the active rogue classification policies comprise rules for classifying the electronic devices detected within the communication network into a rogue classification of a plurality of rogue classifications, the plurality of rogue classifications defining varying levels of a threat determined to be posed by an electronic device detected within the communication network.

3 . The method of claim 1 , wherein the corresponding attribute values for the electronic devices detected within the communication network comprise values for device attributes and activity attributes associated with the electronic devices detected within the communication network.

4 . The method of claim 1 , further comprising executing, prior to analyzing the rogue classification information, a pre-analysis of the rogue classification information to attempt to identify anomalies in the corresponding attribute values and to validate the respective rogue classifications, as determined according to the active rogue classification policies, for the electronic devices detected within the communication network.

5 . The method of claim 1 , wherein analyzing the rogue classification information using the statistical machine learning algorithm comprises:

applying a data correlation algorithm to the corresponding attribute values for the electronic devices; and

applying a data prediction algorithm to the corresponding attribute values for the electronic devices.

6 . The method of claim 1 , further comprising automatically deploying the recommended rogue classification policy on an electronic device to cause the electronic device to automatically incorporate the recommended rogue classification policy as an active rogue classification policy of the active rogue classification policies.

7 . The method of claim 1 , further comprising transmitting, by the processing device, the recommended rogue classification policy to a network manager for evaluation prior to deployment of the recommended rogue classification policy for incorporating the recommended rogue classification policy as an active rogue classification policy of the active rogue classification policies.

8 . The method of claim 7 , wherein the recommended rogue classification policy is a template rogue classification policy that includes one or more fields for configuration, the recommended rogue classification policy comprising recommended values for the one or more fields.

9 . The method of claim 1 , wherein the recommended rogue classification policy comprises a new rogue classification policy or an update to an active rogue classification policy.

10 . The method of claim 1 , wherein:

the communication network is a wireless local area network (WLAN); and

the electronic devices comprise one or more of:

a client device;

a wireless access point;

a WLAN controller; or

a network switch.

11 . The method of claim 1 , wherein the processing device comprises a network management system.

12 . A computer system, comprising:

one or more processors; and

one or more non-transitory computer-readable storage media storing programming for execution by the one or more processors, the programming comprising instructions to:

obtain, at a plurality of times, rogue classification information for electronic devices detected within a communication network, the rogue classification information for each time of the plurality of times comprising:

timestamp information identifying the time of the plurality of times;

corresponding sets of attribute values for the electronic devices detected within the communication network at the time; and

respective rogue classifications, as determined according to active rogue classification policies and the corresponding sets of attribute values, for the electronic devices detected within the communication network at the time;

analyze the rogue classification information for the plurality of times to determine whether to modify the active rogue classification policies, wherein analyzing the rogue classification information for the plurality of times comprises analyzing, using a statistical machine learning algorithm, the respective rogue classifications and the corresponding sets of attribute values for the electronic devices for the plurality of times;

generate, in response to determining to modify the active rogue classification policies, a recommended rogue classification policy; and

transmit the recommended rogue classification policy to a network manager for evaluation prior to deployment of the recommended rogue classification policy for incorporating the recommended rogue classification policy as an active roque classification policy of the active rogue classification policies.

13 . The computer system of claim 12 , wherein the corresponding attribute values for the electronic devices detected within the communication network comprise values for device attributes and activity attributes associated with the electronic devices detected within the communication network.

14 . The computer system of claim 12 , wherein the programming further comprises instructions to execute, prior to analyzing the rogue classification information, a pre-analysis of the rogue classification information to attempt to identify anomalies in the corresponding attribute values and to validate the respective rogue classifications, as determined according to the active rogue classification policies, for the electronic devices detected within the communication network.

15 . The computer system of claim 12 , wherein analyzing the rogue classification information comprises assigning a threat rating to a particular electronic device, the threat rating being separate from the respective rogue classification for the particular electronic device and being determined according to at least a portion of the corresponding attribute values for the particular electronic device.

16 . The computer system of claim 12 , wherein analyzing the rogue classification information using the statistical machine learning algorithm comprises:

analyzing the corresponding attribute values for the electronic devices using a data correlation algorithm; and

analyzing the corresponding attribute values for the electronic devices using a data prediction algorithm.

17 . The computer system of claim 12 , wherein the programming further comprises instructions to automatically deploy the recommended rogue classification policy on an electronic device to cause the electronic device to automatically incorporate the recommended rogue classification policy as an active rogue classification policy of the active rogue classification policies.

18 . One or more non-transitory computer-readable storage media storing programming for execution by one or more processors, the programming comprising instructions to:

obtain, at a plurality of times, rogue classification information for electronic devices detected within a communication network, the rogue classification information for each time of the plurality of times comprising:

timestamp information identifying the time of the plurality of times;

corresponding sets of attribute values for the electronic devices detected within the communication network at the time; and

respective rogue classifications, as determined according to active rogue classification policies and the corresponding sets of attribute values, for the electronic devices detected within the communication network at the time;

analyze the rogue classification information for the plurality of times to determine whether to modify the active rogue classification policies, wherein analyzing the rogue classification information for the plurality of times comprises analyzing, using a statistical machine learning algorithm, the respective rogue classifications and the corresponding sets of attribute values for the electronic devices for the plurality of times; and

generate, in response to determining to modify the active rogue classification policies, a recommended rogue classification policy,

wherein analyzing the rogue classification information using the statistical machine learning algorithm comprises:

analyzing the corresponding attribute values for the electronic devices using a data correlation algorithm; and

analyzing the corresponding attribute values for the electronic devices using a data prediction algorithm.

19 . The one or more non-transitory computer-readable storage media of claim 18 , wherein the programming further comprises instructions to assign a threat rating to a particular electronic device, the threat rating being separate from the respective rogue classification for the particular electronic device and being determined according to at least a portion of the corresponding attribute values for the particular electronic device.

20 . The one or more non-transitory computer-readable storage media of claim 18 , wherein the programming further comprises instructions to transmit the recommended rogue classification policy to a network manager for evaluation prior to deployment of the recommended rogue classification policy for incorporating the recommended rogue classification policy as an active rogue classification policy of the active rogue classification policies.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2023
From: GUDURI, SREECHARAN; KARIMBEDU, SEKHAR; COWKUR, GURURAJ PRALHAD; GOLAKONDA, PRADEEP KUMAR; LADE, VENKATA SANDEEPU
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 064409/0696 →
Continuity (1)
Related Publication 20250039203A1 · Jan 30, 2025
References Cited (17)
US 7295831B2 · Coleman et al. · 2007 [cited by applicant]
US 8677497B2 · Basavapatna et al. · 2014 [cited by applicant]
US 9198118B2 · Larue et al. · 2015 [cited by applicant]
US 9826399B2 · Peterson et al. · 2017 [cited by applicant]
US 10257215B2 · Watson et al. · 2019 [cited by applicant]
US 11057946B2 · Swami et al. · 2021 [cited by applicant]
US 12200001B2 · Zhang · 2025 [cited by examiner]
US 20040255167A1 · Knight · 2004 [cited by applicant]
US 20070178841A1 · Oliynyk et al. · 2007 [cited by applicant]
US 20080186932A1 · Do et al. · 2008 [cited by applicant]
US 20130291063A1 · Escamilla et al. · 2013 [cited by applicant]
US 20180027006A1 · Zimmermann · 2018 [cited by examiner]
US 20180234302A1 · James · 2018 [cited by examiner]
US 20200007391A1 · Yang · 2020 [cited by examiner]
US 20220201042A1 · Crabtree · 2022 [cited by examiner]
US 20220303805A1 · Raghuramu · 2022 [cited by examiner]
CN 106101061A · 2016 [cited by examiner]