×

Methods and systems for improving analytics in distributed networks

  • US 10,193,929 B2
  • Filed: 03/13/2015
  • Issued: 01/29/2019
  • Est. Priority Date: 03/13/2015
  • Status: Active Grant
First Claim
Patent Images

1. A system for improving analytics in a distributed network, the system comprising:

  • a hardware processor executing instructions stored in memory, the instructions comprising;

    executing a security policy on a network packet;

    collecting network information from the network packet;

    generating a result from an analysis;

    analyzing the network information with additional group information from the security policy, the analyzing including examining communications including network packets between at least some hosts in a group, the analyzing further including identifying patterns indicative of malicious activity in the communications;

    in response to the analyzing, defining a second security policy, the second security policy applying to the group, each host of the group having a similar security attribute associated with group security attributes of the group;

    updating the security policy based on the generated result, the updating the security policy including at least one of;

    performing deep packet inspection on the communications, andblocking network communications to an infected host in the group;

    collecting at least one of application metadata, application information, and contextual information related to an application associated with another host in the group; and

    providing the collected information;

    wherein analyzing the network information correlated with the security policy includes;

    analyzing network packets between a first host in the group and a second host in the group;

    analyzing network packets between a third host in the group and a fourth host in a second group; and

    analyzing connections between the group and the second group;

    wherein the network information from the network packets regarding a current state of the distributed network is dynamic and changing over time.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×