×

NETWORK SEGMENTATION

  • US 20150236935A1
  • Filed: 02/17/2015
  • Published: 08/20/2015
  • Est. Priority Date: 02/19/2014
  • Status: Active Grant
First Claim
Patent Images

1. A system for automatically generating segments in a network, the system comprising:

  • a plurality of hosts configured to generate network activity information, at least a portion of the hosts belonging to an organization and connected via the network;

    an analyzer server configured to analyze the network activity information, the analyzer server comprising;

    memory that stores computer-executable instructions; and

    at least one processor configured to access the memory and execute the computer-executable instructions to at least;

    receive a portion of the network activity information, the portion of the network activity information describing interactions of the plurality of hosts on the network;

    identify one or more metrics based in part on at least the portion of the network activity information, the one or more metrics identifying relationships between hosts of the plurality of hosts;

    determine a plurality of observation vectors based at least in part on the one or more metrics, individual observation vectors of the plurality comprising one or more dimensions and corresponding to individual hosts of the plurality of hosts;

    generate a plurality of clusters based at least in part on the plurality of observation vectors, each cluster of the plurality of clusters including at least some hosts of the plurality of hosts;

    in response to generating the plurality of clusters, identify a profile for at least one cluster of the plurality of clusters, the profile representative of at least a potential system of the network; and

    determine at least one segment within the network, the at least one segment including or excluding the potential system with respect to interactions on the network.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×