IP Library Granted Patent US 11,153,348
Granted Patent B2
US 11,153,348 · App. 16/519,641 · Granted Oct 19, 2021

Third party integration with enterprise security management tool

Inventors: Michael Didomenico (Malvern, PA); Michael C. Leap (Malvern, PA); Emily M. Shoup (Malvern, PA); Richard W. Phelps (Cary, NC); Robert A. Johnson (Collegeville, PA); Philippe Jolly (Blue Bell, PA); Jared Poetter (Malvern, PA)
Assignee: Unisys Corporation
H04L63/20H04L41/28H04L63/0209H04L63/1433H04L67/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,153,348
App. No.
16/519,641
Granted
Oct 19, 2021
Kind
B2
Abstract

Methods and systems for providing integration between an enterprise security management configuration tool and third party network traffic software are disclosed. By defining a software interface through which configuration data for third party networking devices can be queried and configuration data accessed, the enterprise security management configuration tool can compare overall network traffic to the configuration provided by the third party networking software to assess an overall security level within an enterprise network.

Claims (37)

1. A method comprising:

receiving a definition in an enterprise security management configuration tool of anode within an enterprise network that represents a third party network traffic management device controlled using third party traffic management software, the third party network traffic management device positioned within the enterprise to manage traffic within a portion of the enterprise network;

accessing, via an Application Programming Interface of the third party traffic management software, configuration data for the third party network traffic management device;

receiving, at the enterprise security management configuration tool, network traffic data describing network traffic in the enterprise network; and

generating an assessment of network security coverage by policies in one or both of the enterprise security management configuration tool and the third party network traffic management software based at least on the network traffic data, the configuration data, and a security policy defined for the enterprise network by the enterprise security management configuration tool.

2. The method of claim 1 , wherein generating the assessment of network security coverage includes determining a security level of communication between the portion of the enterprise network protected by the third party network traffic management device and a second portion of the enterprise network outside of the portion.

3. The method of claim 2 , wherein the communication between the portion and the second portion occurs over one or more channels, each channel defining communication between a node within the portion and a different node within the second portion.

4. The method of claim 2 , further comprising, for at least one channel of the one or more channels, changing a communication policy within the enterprise security management configuration tool between the node and the second node, thereby adjusting the security level of communication between the portion and the second portion.

5. The method of claim 1 , wherein the enterprise network includes a plurality of third party network traffic management devices, and wherein accessing the configuration data comprises issuing requests to each of the plurality of third party network traffic management devices.

6. The method of claim 1 , wherein, within the enterprise security management configuration tool, network devices are grouped into one or more solutions.

7. The method of claim 6 , wherein the portion of the enterprise network managed by the third party network traffic management device comprises a solution.

8. The method of claim 7 , wherein the solution including the third party network traffic management device includes one or more nodes communicatively connected to one or more nodes outside the solution but within the enterprise network.

9. The method of claim 8 , further comprising, after accessing the configuration data for the third party network traffic management device, translating the configuration data into a logical arrangement compatible with the enterprise security management configuration tool.

10. The method of claim 9 , further comprising graphically depicting the one or more nodes within the solution based on the configuration data.

11. The method of claim 1 , further comprising generating a user interface displaying a logical network topology of at least a portion of the enterprise network and the assessment of network security coverage.

12. The method of claim 1 , further comprising:

detecting a change in a setting within the third party traffic management software; and

automatically updating the assessment of network security coverage in response to the change.

13. An enterprise security management system, the system comprising:

a computing system within an enterprise and having an enterprise security management configuration tool installed thereon, the enterprise security management configuration tool configured to:

receive a definition in an enterprise security management configuration tool of a node within an enterprise network that represents a third party network traffic management device controlled using third party traffic management software, the third party network traffic management device positioned within the enterprise to manage traffic within a portion of the enterprise network;

access, via an Application Programming Interface of the third party traffic management software, configuration data for the third party network traffic management device;

receive, at the enterprise security management configuration tool, network traffic data describing network traffic in the enterprise network; and

generate an assessment of network security coverage by policies in one or both of the enterprise security management software tool and the third party network traffic management software based at least on the network traffic data, the configuration data, and a security policy defined for the enterprise network by the enterprise security management configuration tool.

14. The enterprise security management software system of claim 13 , further comprising at least one third party networking software management tool installed on the third party networking device.

15. The enterprise security management software system of claim 13 , wherein the third party networking device comprises a firewall.

16. The enterprise security management software system of claim 13 , wherein the enterprise security management configuration tool is further configured to generate a user interface displaying a logical network topology of at least a portion of the enterprise network and the assessment of network security coverage, the logical network topology based at least on the network traffic data.

17. The enterprise security management software system of claim 13 , further comprising an enterprise security management server communicatively connected to the computing system hosting the enterprise security management configuration tool, the enterprise security management configuration tool being configured to deploy a security solution to the enterprise security management server for application within the enterprise network.

18. The enterprise security management software system of claim 13 , wherein the enterprise security management configuration tool is further configured to, after accessing the configuration data for the third party network traffic management device, translate the configuration data into a logical arrangement compatible with the enterprise security management configuration tool, the logical arrangement including one or more solutions, profiles, and nodes.

19. A non-transitory computer readable storage medium having computer-executable instructions stored thereon which, when executed by a computing system, cause the computing system to perform:

receiving a definition in an enterprise security management configuration tool of anode within an enterprise network that represents a third party network traffic management device controlled using third party traffic management software, the third party network traffic management device positioned within the enterprise to manage traffic within a portion of the enterprise network;

accessing, via an Application Programming Interface of the third party traffic management software, configuration data for the third party network traffic management device;

translating the configuration data to be displayable within the enterprise security management configuration tool;

receiving, at the enterprise security management configuration tool, network traffic data describing network traffic in the enterprise network;

generating an assessment of network security coverage by policies in one or both of the enterprise security management configuration tool and the third party network traffic management software based at least on the network traffic data, the configuration data, and a security policy defined for the enterprise network by the enterprise security management configuration tool; and

deploying a solution from the enterprise security management configuration tool to an enterprise security manager, thereby applying a security policy defined by the solution to the enterprise network.

20. The non-transitory computer readable storage medium of claim 19 , further comprising displaying network traffic data and network policy data from both the enterprise security management configuration tool and the third party traffic management software in a common user interface.

Assignments (6)
AMENDED AND RESTATED PATENT SECURITY AGREEMENT Recorded Jun 27, 2025
From: UNISYS CORPORATION; UNISYS HOLDING CORPORATION; UNISYS NPL, INC.; UNISYS AP INVESTMENT COMPANY I
To: COMPUTERSHARE TRUST COMPANY, N.A., AS COLLATERAL TRUSTEE
Reel/Frame 071759/0527 →
SECURITY INTEREST Recorded Apr 4, 2022
From: UNISYS CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 059494/0693 →
SECURITY INTEREST Recorded Nov 19, 2020
From: UNISYS CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 054481/0865 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2020
From: DI DOMENICO, MICHAEL J; LEAP, MICHAEL C; SHOUP, EMILY M; PHELPS, RICHARD W, PH.D; JOHNSON, ROBERT A; JOLLY, PHILIPPE; POETTER, JARED
To: UNISYS CORPORATION
Reel/Frame 051946/0268 →
SECURITY INTEREST Recorded Jan 31, 2020
From: UNISYS CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 051682/0760 →
SECURITY INTEREST Recorded Nov 21, 2019
From: UNISYS CORPORATION
To: WELLS FARGO NATIONAL ASSOCIATION
Reel/Frame 051075/0721 →
Continuity (2)
Provisional Application 62702144 · Jul 23, 2018
Related Publication 20200067986A1 · Feb 27, 2020
Cited By (1)
US 12,452,311