US2023308370A1PendingUtilityA1

Agentless network traffic mapping

Assignee: FORESCOUT TECH INCPriority: Sep 29, 2021Filed: Apr 25, 2023Published: Sep 28, 2023
Est. expirySep 29, 2041(~15.2 yrs left)· nominal 20-yr term from priority
Inventors:Eli Fainberg
H04L 43/062H04L 41/22H04L 43/0811H04L 43/0882H04L 67/303H04L 41/12H04L 43/02H04L 43/045H04L 43/0876
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems, methods, and related technologies for generating a network traffic map based on network traffic information and additional data are described. Network traffic information may be obtained from endpoints using an operating system (OS) interface, without an agent being installed on the endpoints. A network traffic map may be generated for the network based on the network traffic information.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method, comprising:
 detecting one or more managed devices that are connected to a network;   accessing an operating system (OS) interface of each of the one or more managed devices;   using each OS interface to obtain network traffic information from each of the one or more managed devices; and   generating a network traffic map based on the network traffic information from each of the one or more managed devices.   
     
     
         2 . The method of  claim 1 , wherein the network traffic information is obtained from each of the one or managed devices without having an agent residing on each of the one or more managed devices. 
     
     
         3 . The method of  claim 1 , wherein the OS interface includes secure shell (SSH). 
     
     
         4 . The method of  claim 1 , wherein the OS interface includes Windows Management Instrumentation (WMI). 
     
     
         5 . The method of  claim 1 , wherein the network traffic information comprises at least one of Layer 2 network traffic information or Layer 3 network traffic information. 
     
     
         6 . The method of  claim 1 , further comprising obtaining, from a network device, network traffic information from unmanaged devices that are connected to the network; and generating the network traffic map based on the network traffic information from each of the one or more managed devices and the network traffic information from each of the unmanaged devices. 
     
     
         7 . The method of  claim 6 , wherein the network device includes at least one of a switch, a router, a bridge, or a firewall. 
     
     
         8 . The method of  claim 1 , further comprising communicating with a network device to limit or restrict communication of at least one of the one or more managed network devices, in response to the network traffic information. 
     
     
         9 . The method of  claim 1 , further comprising causing a process to end on at least one of the one or more managed network devices, in response to the network traffic information. 
     
     
         10 . The method of  claim 1 , further comprising presenting a visual representation of the network traffic map to a display. 
     
     
         11 . The method of  claim 1 , further comprising repeating the method periodically. 
     
     
         12 . The method of  claim 1 , wherein the network traffic information from each of the one or more managed network devices comprises a local connection address and a remote connection address. 
     
     
         13 . A system, comprising:
 a memory; and   a processing device, operatively coupled to the memory, to:
 detect one or more managed devices that are connected to a network; 
 access an operating system (OS) interface of each of the one or more managed devices; 
 use each OS interface to obtain network traffic information from each of the one or more managed devices; and 
 generate a network traffic map based on the network traffic information from each of the one or more managed devices. 
   
     
     
         14 . The system of  claim 13 , wherein the network traffic information is obtained from each of the one or managed devices without having an agent residing on each of the one or more managed devices. 
     
     
         15 . The system of  claim 13 , wherein the OS interface includes secure shell (SSH). 
     
     
         16 . The system of  claim 13 , wherein the OS interface includes Windows Management Instrumentation (WMI). 
     
     
         17 . The system of  claim 13 , wherein the network traffic information comprises at least one of Layer 2 network traffic information or Layer 3 network traffic information. 
     
     
         18 . A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device, cause the processing device to:
 detect one or more managed devices that are connected to a network;   access an operating system (OS) interface of each of the one or more managed devices;   use each OS interface to obtain network traffic information from each of the one or more managed devices; and   generate, by the processing device, a network traffic map based on the network traffic information from each of the one or more managed devices.   
     
     
         19 . The non-transitory computer readable medium of  claim 18 , wherein the network traffic information is obtained from each of the one or managed devices without having an agent residing on each of the one or more managed devices. 
     
     
         20 . The non-transitory computer readable medium of  claim 18 , wherein the processing device is further to obtain from a network device, network traffic information from unmanaged devices that are connected to the network; and generate the network traffic map based on the network traffic information from each of the one or more managed devices and the network traffic information from each of the unmanaged devices.

Join the waitlist — get patent alerts

Track US2023308370A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.