Multi-layered policy management

US12438774B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12438774-B2
Application numberUS-202318142799-A
CountryUS
Kind codeB2
Filing dateMay 3, 2023
Priority dateDec 31, 2018
Publication dateOct 7, 2025
Grant dateOct 7, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Techniques for enforcing policy on multiple levels are disclosed. A multi-level policy includes at least one policy at a low level of abstraction and at least one policy at a high level of abstraction. An Internet of Things (IoT) device is discovered on a network. The IoT device is classified. The set of multi-level policies is applied to the IoT device based on the classification of the IoT device.

First claim

Opening claim text (preview).

The invention claimed is: 1. A system comprising: a multi-level policy management engine configured to generate a multi-level policy for a network environment, wherein the multi-level policy includes a first policy at a low level of abstraction and a second policy at a high level of abstraction, and wherein the second policy at the high level of abstraction references an action to take if a particular activity is attempted by a device included in the network environment; an Internet Protocol (IP) endpoint discovery and classification engine configured to: discover, in the network environment, an Internet of Things (IoT) device which does not match at least one of the first or second policies, and classify the IoT device to make at least one of the first or second policies applicable to the IoT device, including by identifying that the IoT device does not have at least one of the first or second policies as an applicable policy, determining that the IoT device has violated at least one of the first or second policies, and in response, make the at least one of the first or second policies that has been violated applicable to the IoT device; and a multi-level policy compliance detection engine configured to apply a set of multi-level policies to the IoT device based on the classification of the IoT device. 2. The system of claim 1 , wherein the multi-level policy compliance detection engine is further configured to detect a deviation, by the IoT device, from the applicable policy, and wherein the system further comprises a signal correlation engine configured to generate and send an alert to an administrator of the network environment. 3. The system of claim 1 , wherein the first policy at the low level of abstraction is at least context-based, and includes one or more of background event context, identity-based context, and group-based context. 4. The system of claim 1 , wherein the first policy at the low level of abstraction is at least packet-based, and is based at least in part on patterns in packets that match regular expressions of policy rules. 5. The system of claim 1 , wherein the second policy at the high level of abstraction is at least event-based, and is based at least in part on converting patterns to fields of an event. 6. The system of claim 1 , wherein the second policy at the high level of abstraction is one of at least activity-based or behavior based. 7. The system of claim 1 , wherein an administrator of the network environment is permitted to modify the second policy at the high level of abstraction and the first policy at the low level of abstraction. 8. The system of claim 1 , wherein the multi-level policy management engine is configured to permit an administrator of the network environment to modify the second policy at the high level of abstraction and prevent the administrator from modifying the first policy at the low level of abstraction. 9. The system of claim 1 , wherein generating the multi-level policy is based at least in part on machine learning. 10. The system of claim 1 , wherein classifying the IoT device is based at least in part on machine learning. 11. A method comprising: generating a multi-level policy for a network environment, wherein the multi-level policy includes a first policy at a low level of abstraction and a second policy at a high level of abstraction, and wherein the second policy at the high level of abstraction references an action to take if a particular activity is attempted by a device included in the network environment; discovering, in the network environment, an Internet of Things (IoT) device which does not match at least one of the first or second policies, and classifying the IoT device to make at least one of the first or second policies applicable to the IoT device, including by identifying that the IoT device does not have at least one of the first or second policies as an applicable policy, determining that the IoT device has violated at least one of the first or second policies, and in response, making the at least one of the first or second policies that has been violated applicable to the IoT device; and applying the set of multi-level policies to the IoT device based on the classification of the IoT device. 12. The method of claim 11 , further comprising detecting a deviation, by the IoT device, from the applicable policy, and in response generating and sending an alert to an administrator of the network environment. 13. The method of claim 11 , wherein the first policy at the low level of abstraction is at least context-based, and includes one or more of background event context, identity-based context, and group-based context. 14. The method of claim 11 , wherein the first policy at the low level of abstraction is at least packet-based, and is based at least in part on patterns in packets that match regular expressions of policy rules. 15. The method of claim 11 , wherein the second policy at the high level of abstraction is at least event-based, and is based at least in part on converting patterns to fields of an event. 16. The method of claim 11 , wherein the second policy at the high level of abstraction is one of at least activity-based or behavior-based. 17. The method of claim 11 , wherein an administrator of the network environment is permitted to modify the second policy at the high level of abstraction and the first policy at the low level of abstraction. 18. The method of claim 11 , wherein an administrator of the network environment is permitted to modify the second policy at the high level of abstraction and is not permitted to modify the first policy at the low level of abstraction. 19. The method of claim 11 , wherein generating the multi-level policy is based at least in part on machine learning. 20. The method of claim 11 , wherein classifying the IoT device is based at least in part on machine learning.

Assignees

Inventors

Classifications

  • specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks · CPC title

  • Policy-based network configuration management · CPC title

  • Grouping of entities · CPC title

  • comprising specially adapted graphical user interfaces [GUI] · CPC title

  • using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12438774B2 cover?
Techniques for enforcing policy on multiple levels are disclosed. A multi-level policy includes at least one policy at a low level of abstraction and at least one policy at a high level of abstraction. An Internet of Things (IoT) device is discovered on a network. The IoT device is classified. The set of multi-level policies is applied to the IoT device based on the classification of the IoT de…
Who is the assignee on this patent?
Palo Alto Networks Inc
What technology area does this patent fall under?
Primary CPC classification H04L41/0853. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Oct 07 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).