Methods and systems for improving analytics in distributed networks

US2016269442A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016269442-A1
Application numberUS-201514657210-A
CountryUS
Kind codeA1
Filing dateMar 13, 2015
Priority dateMar 13, 2015
Publication dateSep 15, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods for improving analytics in a distributed network are described herein. An example system can comprise at least one processor, an analytics module, and a security policy module. The security policy module is operable to define a security policy. The security policy is executed by the processor on a network packet. Furthermore, the processor collects network information from the network packet. The analytics module is operable to analyze the network information with additional group information from the security policy. The analysis is used by the processor to generate the result. Based on the generated result, the security policy module updates the security policy.

First claim

Opening claim text (preview).

What is claimed is: 1 . A system for improving analytics in a distributed network, the system comprising: at least one processor operable to: execute a security policy on a network packet; collect network information from the network packet; and generate a result from an analysis; an analytics module operable to analyze the network information with additional group information from the security policy; and a security policy module operable to: define the security policy; and update the security policy based on the generated result. 2 . The system of claim 1 , wherein the security policy is associated with at least one host or one group, the at least one group including at least one host. 3 . The system of claim 2 , wherein the at least one processor is further operable to extract group information from the security policy, the group information including group security attributes associated with the at least one group. 4 . The system of claim 2 , wherein analyzing the network information using the analytics module correlated with the security policy includes at least one of the following: analyzing network packets inside the at least one host or one group; analyzing network packets between two or more hosts or groups; and analyzing connections between the two or more hosts or groups. 5 . The system of claim 1 , wherein the updating the security policy based on the generated result includes one or more of the following: permitting a connection; denying the connection rearranging at least one group, the rearranging including moving hosts between groups; and modifying security system parameters for the at least one group. 6 . The system of claim 1 , wherein the analyzing the network information using the analytics module correlated with the security policy includes at least one of the following: determining Domain Name Server (DNS) information for the network packet; based on the DNS information, determining if a Domain Generation Algorithm (DGA) was used to generate a domain name of a domain associated with the network packet; and based on log information associated with at least one group, checking the network information for security threats. 7 . The system of claim 6 , wherein a result includes at least one of the following: determining that the domain associated with the network packet is valid; determining that the domain associated with the network packet is invalid; and determining that the domain associated with the network packet requires an elevated scrutiny. 8 . The system of claim 7 , wherein the elevated scrutiny includes applying a packet capture (PCAP) to further network packets associated with the domain. 9 . The system of claim 1 , wherein the generating of the network information related to the network packet is based on log information associated with at least one group. 10 . The system of claim 1 , wherein the updating the security policy based on the generated result includes one or more of the following: generating an enforcement policy associated with at least one group; collecting Packet Capture (PCAP) to analyze contents of the network packet associated with the at least one group; and modifying a monitoring policy associated with the at least one group. 11 . A method for improving analytics in a distributed network, the method comprising: defining a security policy; executing the security policy on a network packet; collecting network information from the network packet; analyzing the network information with additional group information from the security policy; generating a result from the analysis; and updating the security policy based on the generated result. 12 . The method of claim 11 , wherein the security policy is associated with at least one host or one group, the at least one group including at least one host. 13 . The method of claim 12 , further comprising extracting group information from the security policy, the group information including group security attributes associated with the at least one group. 14 . The method of claim 12 , wherein the analyzing the network information includes at least one of the following: analyzing network packets inside the at least one host or one group; analyzing network packets between two or more hosts or groups; and analyzing connections between the two or more hosts or groups. 15 . The method of claim 11 , wherein the updating the security policy includes one or more of the following: permitting a connection; denying the connection rearranging at least one group, the rearranging including moving hosts between groups; and modifying security system parameters for the at least one group. 16 . The method of claim 11 , wherein the analyzing includes at least one of the following: determining Domain Name System (DNS) information for the network packet; based on the DNS information, determining if a Domain Generation Algorithm (DGA) was used to generate a domain name of a domain associated with the network packet; and based on log information associated with at least one group, checking the network information for security threats. 17 . The method of claim 16 , wherein a result includes at least one of the following: determining that the domain associated with the network packet is valid; determining that the domain associated with the network packet is invalid; and determining that the domain associated with the network packet requires an elevated scrutiny. 18 . The method of claim 17 , wherein the elevated scrutiny includes applying a packet capture (PCAP) to further network packets associated with the domain. 19 . The method of claim 11 , wherein the updating the security policy includes one or more of the following: generating an enforcement policy associated with at least one group; collecting Packet Capture (PCAP) to analyze contents of the network packet associated with the at least one group; and modifying a monitoring policy associated with the at least one group. 20 . A system for improving analytics in a distributed network, the system comprising: at least one processor operable to: execute a security policy on a network packet, wherein the security policy is associated with at least one group, the at least one group including at least one host; collect network information from the network packet; generate a result from an analysis; an analytics module operable to: analyze the network information with additional group information from the security policy, wherein the analyzing includes at least one of the following: determining Domain Name System (DNS) information for the network packet; based on the DNS information, determining if a Domain Generation Algorithm (DGA) was used to generate a domain name of a domain associated with the network packet; and based on log information associated with at least one group, checking the network information for security threats; a security policy module operable to: define the security policy; and update the security policy based on the generated result, wherein the updating includes one or more of the following: generating an enforcement policy associated with at least one group; applying Packet Capture (PCAP) to analyze contents of the network packet associated with at least one group; and modifying a monitoring policy associated with the at least one group.

Assignees

Inventors

Classifications

  • Traffic logging, e.g. anomaly detection · CPC title

  • Vulnerability analysis · CPC title

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016269442A1 cover?
Systems and methods for improving analytics in a distributed network are described herein. An example system can comprise at least one processor, an analytics module, and a security policy module. The security policy module is operable to define a security policy. The security policy is executed by the processor on a network packet. Furthermore, the processor collects network information from t…
Who is the assignee on this patent?
Varmour Networks Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Sep 15 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).