Patent · US Active

System and method for migrating to and maintaining a white-list network security model

US10587621B2 · kind B2 · utility

5Cited by
81References
17Claims
0Family size

Assignee

Inventors

Key dates

Filing dateOct 26, 2017
Grant dateMar 10, 2020
Priority date
Expiry dateApr 26, 2038

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/20
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Systems, methods, and computer-readable media for migrating to and maintaining a white-list network security model. Network traffic identified from permit-all access logs can be analyzed to determine whether it should be white-listed, and if so, a specific permit-access, without logging, policy is generated for the identified network traffic. The addition of specific permit-access policies is repeated on permit-all access logs, at which point, permit-all access policy is converted into deny-all access. In some examples, a system or method can obtain hit counts, from both hardware (eg: TCAM) and software tables, for the specific permit-access policy to determine existence of identified network traffic over a period of time. After analyzing hit counts, the specific permit-access policy can either continue to exist or be removed to maintain a white-list network security model.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.