The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 08, 2020

Filed:

Jun. 29, 2018
Applicant:

Juniper Networks, Inc., Sunnyvale, CA (US);

Inventors:

Prakash T. Seshadri, Fremont, CA (US);

Binh Phu Le, San Jose, CA (US);

Srinivas Nimmagadda, San Jose, CA (US);

Jeffrey S. Marshall, Santa Clara, CA (US);

Kartik Krishnan S. Iyyer, San Jose, CA (US);

Assignee:

Juniper Networks, Inc., Sunnyvale, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06F 16/23 (2019.01); G06F 16/22 (2019.01); H04L 29/08 (2006.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); G06F 16/2228 (2019.01); G06F 16/2379 (2019.01); H04L 63/0209 (2013.01); H04L 63/1416 (2013.01); H04L 63/1433 (2013.01); H04L 63/1441 (2013.01); H04L 63/20 (2013.01); H04L 67/18 (2013.01);
Abstract

A device receives network segment information identifying network segments associated with a network, and receives endpoint host session information identifying sessions associated with endpoint hosts communicating with the network. The device generates, based on the network segment information and the endpoint host session information, a data structure that includes information associating the network segments with the sessions associated with the endpoint hosts. The device updates the data structure based on changes in the sessions associated with the endpoint hosts and based on changes in locations of the endpoint hosts within the network segments, and identifies, based on the data structure, a particular endpoint host, of the endpoint hosts, that changed locations within the network segments. The device determines a threat policy action to enforce for the particular endpoint host, and causes the threat policy action to be enforced, by the network, for the particular endpoint host.


Find Patent Forward Citations

Loading…