System and method for deriving network address spaces affected by security threats to apply mitigations

US2023147714A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2023147714-A1
Application numberUS-202117541923-A
CountryUS
Kind codeA1
Filing dateDec 3, 2021
Priority dateNov 5, 2021
Publication dateMay 11, 2023
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Described embodiments provide systems and methods for generating a network space to perform mitigation actions on a plurality of users. At least one server may determine a plurality of users of one or more levels of riskiness in a network environment, and network locations of the users. Using a plurality of clustering features, the at least one server may generate a network space comprising a cluster of network locations corresponding to a subset of the users of at least a defined level of riskiness. The at least one server may perform a mitigation action on the subset of users corresponding to the generated network space.

First claim

Opening claim text (preview).

We claim: 1 . A method comprising: determining, by at least one server, a plurality of users of one or more levels of riskiness in a network environment, and network locations of the users; generating, by the at least one server using a plurality of clustering features, a network space comprising a cluster of network locations corresponding to a subset of the users of at least a defined level of riskiness; and performing, by the at least one server, a mitigation action on the subset of users corresponding to the generated network space. 2 . The method of claim 1 , comprising limiting, by the at least one server, a size of a contiguous address space that forms the network space. 3 . The method of claim 1 , comprising generating, by the at least one server, a plurality of network spaces corresponding to subsets of users of different levels of riskiness. 4 . The method of claim 1 , wherein the plurality of clustering features includes at least one of: analytics data, external threat data, user activity data, network metadata, risk scores of the users, or network performance data. 5 . The method of claim 4 , wherein the network metadata includes information of at least one of: a private network, a public network, an internet service provider, reputation or location, associated with at least one of the users. 6 . The method of claim 5 , wherein the information of the location includes at least one of: a country, a city, a region, a longitude, a latitude, a geographic indicator, a network address, a subnet identifier, or an internet protocol address. 7 . The method of claim 1 , wherein performing the mitigation action comprises at least one of: analyzing a threat associated with the subset of users, applying at least one policy to the subset of users, performing an audit on the subset of users, logging off subset of users, or recording sessions of subset of users. 8 . The method of claim 1 , comprising correlating, by the at least one server, information from at least some of the plurality of clustering features. 9 . The method of claim 1 , wherein when at least some of the users are in public network space, the plurality of clustering features includes information on geographic location. 10 . A system comprising: at least one processor configured to: determine a plurality of users of one or more levels of riskiness in a network environment, and network locations of the users; generate, using a plurality of clustering features, a network space comprising a cluster of network locations corresponding to a subset of the users of at least a defined level of riskiness; and perform a mitigation action on the subset of users corresponding to the generated network space. 11 . The system of claim 10 , wherein the at least one processor is configured to limit a size of a contiguous address space that forms the network space. 12 . The system of claim 10 , wherein the at least one processor is configured to generate a plurality of network spaces corresponding to subsets of users of different levels of riskiness. 13 . The system of claim 10 , wherein the plurality of clustering features includes at least one of: analytics data, external threat data, user activity data, network metadata, risk scores of the users, or network performance data. 14 . The system of claim 13 , wherein the network metadata includes information on at least one of: a private network, a public network, an internet service provider, reputation or location, associated with at least one of the users. 15 . The system of claim 14 , wherein the information of the location includes at least one of: a country, a city, a region, a longitude, a latitude, a geographic indicator, a network address, a subnet identifier, or an internet protocol address. 16 . The system of claim 1 , wherein the mitigation action includes at least one of: analyzing a threat associated with the subset of users, applying at least one policy to the subset of users, performing an audit on the subset of users, logging off subset of users, or recording sessions of subset of users. 17 . The system of claim 1 , wherein the at least one processor is configured to correlate information from at least some of the plurality of clustering features. 18 . The system of claim 1 , wherein when at least some of the users are in public network space, the plurality of clustering features includes information on geographic location. 19 . A non-transitory computer readable medium storing program instructions for causing at least one processor to: determine a plurality of users of one or more levels of riskiness in a network environment, and network locations of the users; generate, using a plurality of clustering features, a network space comprising a cluster of network locations corresponding to a subset of the users of at least a defined level of riskiness; and perform a mitigation action on the subset of users corresponding to the generated network space. 20 . The non-transitory computer readable medium of claim 19 , wherein the plurality of clustering features includes at least one of: analytics data, external threat data, user activity data, network metadata, risk scores of the users, or network performance data.

Assignees

Inventors

Classifications

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • Architectural arrangements, e.g. perimeter networks or demilitarized zones · CPC title

  • involving event detection and direct action · CPC title

  • Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2023147714A1 cover?
Described embodiments provide systems and methods for generating a network space to perform mitigation actions on a plurality of users. At least one server may determine a plurality of users of one or more levels of riskiness in a network environment, and network locations of the users. Using a plurality of clustering features, the at least one server may generate a network space comprising a c…
Who is the assignee on this patent?
Citrix Systems Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1408. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu May 11 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).