Method and system for managing compliance of one or more network devices

US2016352640A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016352640-A1
Application numberUS-201514813316-A
CountryUS
Kind codeA1
Filing dateJul 30, 2015
Priority dateJun 1, 2015
Publication dateDec 1, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Embodiments of the present disclosure disclose a method and a device for managing compliance of one or more network devices. The method comprises receiving one or more configuration changes of the one or more network devices. Also, the method comprises identifying each configuration change as one of a compliant configuration change and a non-compliant configuration change by correlating, the one or more configuration changes using a first set of parameters. Further, the method generating an impact value of the one or more configuration changes and generating a recommendation for the one or more network devices based on the impact value.

First claim

Opening claim text (preview).

We claim: 1 . A method for managing compliance of one or more network devices, comprising: receiving, by a compliance management computing device, one or more configuration changes of the one or more network devices; identifying, by the compliance management computing device, each configuration change as one of a compliant configuration change and a non-compliant configuration change by correlating, the one or more configuration changes using a first set of parameters; generating, by the compliance management computing device, an impact value of the one or more configuration changes; and generating, by the compliance management computing device, a recommendation for the one or more network devices based on the impact value. 2 . The method as claimed in claim 1 , wherein each of the one or more configuration changes is associated with at least one of a configuration change identifier, an actual command executed, time of the configuration change and originator of the configuration change. 3 . The method as claimed in claim 1 further comprising receiving, by a compliance management computing device, a second set of parameters associated with at least one of an organization security policy and baseline guideline rules corresponding to the one or more network devices. 4 . The method as claimed in claim 3 further comprising identifying each of the one or more configuration changes as one of compliant configuration change and non-compliant configuration change by validating the one or more configuration changes using the second set of parameters. 5 . The method as claimed in claim 4 further comprising verifying the validated one or more configuration changes and generating an alert if the configuration change is validated as non-compliant configuration change. 6 . The method as claimed in claim 1 , wherein generating the impact value comprises: obtaining a critical value associated with the one or more network devices by analyzing the configuration changes using the first set of parameters and a third set of parameters; and generating an impact value based on at least one of the critical value, a violation severity value, or a probability of vulnerability exploited by one or more malicious elements. 7 . The method as claimed in claim 6 , wherein the third set of parameters is at least one of network connectivity, neighboring devices configuration, network device having internal facing or external facing and enrooting a network device to provide critical business services. 8 . The method as claimed in claim 1 further comprising generating a recommendation using historical data associated with one or more impact values of the one or more network devices. 9 . The method as claimed in claim 1 further comprising generating, by the compliance management computing device, a report based on at least one of the identified configuration change, impact value and the recommendation. 10 . A compliance management computing device for managing compliance of one or more network devices, comprising: a processor; and a memory communicatively coupled to the processor, wherein the memory stores processor-executable instructions, which, on execution, causes the processor to: receive one or more configuration changes of the one or more network devices; identify each configuration change as one of a compliant configuration change and a non-compliant configuration change by correlating, the one or more configuration changes using a first set of parameters; generate an impact value of the one or more configuration changes; and generate a recommendation to the one or more network devices based on the impact value. 11 . The device as claimed in claim 10 , wherein each of the one or more configuration changes is associated with at least one of configuration identifier, an actual command executed, time of the configuration change and originator of the configuration change. 12 . The device as claimed in claim 10 further comprising the processor configured to receiving a second set of parameters associated with at least one of an organization security policy and baseline guideline rules corresponding to the one or more network devices. 13 . The device as claimed in claim 12 , wherein the processor is further configured to identifying each of the one or more configuration changes as one of compliant configuration change and non-compliant configuration change by validating the one or more configuration changes using the second set of parameters. 14 . The device as claimed in claim 13 , wherein the processor is further configured to verify the validated one or more configuration changes and generate an alert if the configuration change is validated as non-compliant configuration change. 15 . The device as claimed in claim 10 , wherein the processor is configured to generate an impact value comprises: obtaining a critical value associated with the one or more network devices by analyzing the configuration changes using the first set of parameters and a third set of parameters; and generating an impact value based on at least one of the critical value, a violation severity value, and a probability of vulnerability exploited by one or more malicious elements. 16 . The device as claimed in claim 15 , wherein the third set of parameters is at least one of network connectivity, neighboring devices configuration, network device having internal facing or external facing and enrooting a network device to provide critical business services. 17 . The device as claimed in claim 10 further comprises the processor configured to generate a recommendation using historical data associated with one or more impact values of the one or more network devices 18 . The device as claimed in claim 10 further comprises the processor configured to generate a report based on at least one of the identified configuration change, impact value and the recommendation. 19 . A non-transitory computer readable medium including instructions stored thereon that when processed by at least one processor cause a system to perform operations comprising: receive one or more configuration changes of the one or more network devices; identify each configuration change as one of a compliant configuration change and a non-compliant configuration change by correlating, the one or more configuration changes using a first set of parameters; generate an impact value of the one or more configuration changes; and generate a recommendation for the one or more network devices based on the impact value.

Assignees

Inventors

Classifications

  • Discovery or management of network topologies · CPC title

  • Vulnerability analysis · CPC title

  • H04L47/20Primary

    Traffic policing · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • Policy-based network configuration management · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016352640A1 cover?
Embodiments of the present disclosure disclose a method and a device for managing compliance of one or more network devices. The method comprises receiving one or more configuration changes of the one or more network devices. Also, the method comprises identifying each configuration change as one of a compliant configuration change and a non-compliant configuration change by correlating, the on…
Who is the assignee on this patent?
Wipro Ltd
What technology area does this patent fall under?
Primary CPC classification H04L63/1433. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Dec 01 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).