Coordinated and device-distributed detection of abnormal network device operation
US-9026840-B1 · May 5, 2015 · US
US9917860B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9917860-B2 |
| Application number | US-201514733899-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jun 8, 2015 |
| Priority date | Jan 16, 2015 |
| Publication date | Mar 13, 2018 |
| Grant date | Mar 13, 2018 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Network security management technology as disclosed herein generates and dynamically updates an intuitive, interactive visualization of a computer network in live operation. The network security management technology interprets human user interactions, such as gestures, as network directives. The network directives may be implemented by the network in response to security events.
Opening claim text (preview).
The invention claimed is: 1. A network security management system comprising one or more computing devices including instructions embodied in one or more non-transitory machine-readable storage media, wherein the instructions are executable by the one or more computing devices to cause the one or more computing devices to: determine a current context of a computer network in live operation; generate an interactive visualization of the network for display by a display device, the interactive visualization comprising a plurality of graphical elements arranged to depict the current context of the network, at least one of the graphical elements indicative of a network security event detected on the network; using an interaction model and the interactive visualization of the current context of the network, determine interpretations of gesture-based interactions with a computing system, wherein determine interpretations comprises interpreting at least one of the gesture-based interactions as a network security directive and interpreting at least one of the gesture-based interactions as a network exploration directive and interpreting at least one of the gesture-based interactions as an interaction that should be disregarded as neither a network security directive nor a network exploration directive; when a gesture-based interaction is interpreted as a network security directive, convert the network security directive to a set of instructions executable by one or more switching devices of the computer network; when a gesture-based interaction is interpreted as a network exploration directive, update a displayed view of the interaction visualization; when a gesture-based interaction is interpreted as an interaction that should be disregarded as neither a network security directive nor a network exploration directive, neither convert the network security directive to a set of instructions executable by one or more switching devices of the computer network nor update the displayed view of the interaction visualization. 2. The network security management system of claim 1 , configured to determine the current context of the network at least in part by algorithmically correlating network activity data indicative of live data communication flows on the network with one or more of: network infection data generated by one or more network analytics systems, network role data, network topology data, and network policy data. 3. The network security management system of claim 1 , configured to determine a characteristic of the current context of the network and configure at least a portion of the interactive visualization based on the determined characteristic of the current context of the network, wherein to configure comprises at least one of: selecting a graphical element based on the current context, modifying a field of view of the interactive visualization, and modifying the presentation of a graphical element of the interactive visualization based on the current context. 4. The network security management system of claim 1 , configured to determine a characteristic of the network security event and to generate at least a portion of the interactive visualization based on the determined characteristic of the network security event, wherein to generate comprises at least one of: selecting a graphical element based on the current context, modifying a field of view of the interactive visualization, executing a query, and modifying the presentation of a graphical element based on the current context. 5. The network security management system of claim 1 , configured to interpret the gesture-based interaction as a network security remediation action, wherein the network security remediation action comprises one or more of: a redirection of one or more network flows, a quarantine of one or more internal nodes of the network, a replication of network traffic, a diversion of one or more network flows away from an external node, a diversion of one or more network flows to an external node, and a reconfiguration of a switching device on the computer network. 6. The network security management system of claim 5 , configured to convert the network security remediation action to a set of instructions executable by one or more switching devices of the computer network, wherein the computer network is configured as a software-defined network. 7. The network security management system of claim 6 , configured to identify a conflict between the network security remediation action and a network policy, and modify the network security remediation action based on the network policy. 8. The network security management system of claim 1 , configured to generate the interactive visualization to include, based on the current context of the network, graphical elements indicative of one or more of: a direction of a network flow, a volume of network flows within the network, a hardware or software configuration of one or more network nodes, a relationship between a security threat and one or more network nodes or flows, and a relationship between a network infection and one or more network nodes or flows. 9. The network security management system of claim 1 , configured to generate at least a portion of the interactive visualization as a Sankey diagram comprising one or more graphical elements configured to visually depict relative network flow volumes within the computer network. 10. The network security management system of claim 1 , configured to generate at least a portion of the interactive visualization as a game-like virtual-world representation of the computer network in live operation. 11. A method for network security management with a computing system comprising one or more computing devices, the method comprising: determining a current context of the computer network; generating an interactive visualization of the network for display by a display device, the interactive visualization comprising a plurality of graphical elements arranged to depict the current context of the network; using an interaction model and the interactive visualization of the current context of the network, determining interpretations of gesture-based interactions with a computing system, wherein determining interpretations comprises interpreting at least one of the gesture-based interactions as a network security directive and interpreting at least one of the gesture-based interactions as a network exploration directive and interpreting at least one of the gesture-based interactions as an interaction that should be disregarded as neither a network security directive nor a network exploration directive; when a gesture-based interaction is interpreted as a network security directive, convert the network security directive to a set of instructions executable by one or more switching devices of the computer network; when a gesture-based interaction is interpreted as a network exploration directive, update a displayed view of the interaction visualization; when a gesture-based interaction is interpreted as an interaction that should be disregarded as neither a network security directive nor a network exploration directive, neither convert the network security directive to a set of instructions executable by one or more switching devices of the computer network nor update the displayed view of the interaction visualization. 12. The method of claim 11 , comprising determining a characteristic of the current context of the network and dynamically configuring one or more graphical elements of the interactive visualization based on the determined characteristic of the current context of the network. 13. The method of claim 11 , c
Eye tracking input arrangements (G06F3/015 takes precedence) · CPC title
Interaction with lists of selectable items, e.g. menus · CPC title
for inputting data by handwriting, e.g. gesture or text · CPC title
by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title
Audio in a user interface, e.g. using voice commands for navigating, audio feedback · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.