Patents by Inventor Rupesh Kumar Mishra

Rupesh Kumar Mishra has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20230362066
    Abstract: A computing device (e.g., a policy management server) obtains a segmentation policy that includes a set of rules for controlling network traffic between workloads. The computing device also receives infrastructure feedback regarding configuration of third-party network infrastructure. The computing device uses the infrastructure feedback to identify a discrepancy between the segmentation policy and the configuration of the third-party network infrastructure and triggers a corrective action in response. The corrective action may include providing a notification or suggestive remedy for the discrepancy to the user or automatically remedying the discrepancy.
    Type: Application
    Filed: July 14, 2023
    Publication date: November 9, 2023
    Inventors: Rushabh Sanghvi, George Jeffrey Francis, Rupesh Kumar Mishra
  • Patent number: 11743142
    Abstract: A computing device (e.g., a policy management server) obtains a segmentation policy that includes a set of rules for controlling network traffic between workloads. The computing device also receives infrastructure feedback regarding configuration of third-party network infrastructure. The computing device uses the infrastructure feedback to identify a discrepancy between the segmentation policy and the configuration of the third-party network infrastructure and triggers a corrective action in response. The corrective action may include providing a notification or suggestive remedy for the discrepancy to the user or automatically remedying the discrepancy.
    Type: Grant
    Filed: December 20, 2021
    Date of Patent: August 29, 2023
    Assignee: Illumio, Inc.
    Inventors: Rushabh Sanghvi, George Jeffrey Francis, Rupesh Kumar Mishra
  • Patent number: 11516242
    Abstract: A segmentation server configures and distributes rules for enforcing a segmentation policy that includes one or more virtual patches. The rules including the virtual patches are enforced by distributed enforcement modules that may execute on host devices or on network devices upstream from the host devices. An enforcement module enforces the rules using traffic filters that filter traffic based on network layer data. To implement a virtual patch, the traffic filters are configured to redirect traffic to or from an application being patched to a transparent application proxy. The transparent application proxy implements an application layer filter that filters traffic based on application layer data to block specific types of traffic associated with a vulnerability addressed by the virtual patch.
    Type: Grant
    Filed: August 27, 2019
    Date of Patent: November 29, 2022
    Assignee: Illumio, Inc.
    Inventors: Rupesh Kumar Mishra, Pritesh Kothari
  • Patent number: 11356483
    Abstract: A policy management server manages a segmentation policy for segmenting a network and a deception policy for implementing deception services. The policy management server distributes segmentation rules and deception rules to distributed enforcement modules that configure respective traffic filters to enforce the policies. The deception rule may be enforced directly by the traffic filter acting as a deception service, or the traffic filter may act as a proxy to an external deception service. The deception service can behave similarly to a real service to obtain information about the malicious actor that is reported to the policy management server to enable the policy management server to take a remedial action. Furthermore, the policy management server may automatically generate the deception policy based on the segmentation policy such that connection requests that are not allowed by the segmentation policy are automatically sent to a deception service.
    Type: Grant
    Filed: November 13, 2019
    Date of Patent: June 7, 2022
    Assignee: Illumio, Inc.
    Inventors: Rupesh Kumar Mishra, Paul James Kirner, Rushabh Sanghvi
  • Patent number: 11223643
    Abstract: A policy management server detects attack patterns in traffic flows reported by distributed enforcement modules enforcing the segmentation policy. The policy management server generates a traffic flow graph representing traffic flows between workloads or groups of workloads. Traffic flows matching one or more traffic flow patterns may be tagged in the traffic flow graph. For example, if an attack pattern is present in a connection that is blocked under the segmentation policy, the policy management server may block updates to the segmentation policy that attempt to enable the connection or may alert an administrator prior to enabling the update. If an attack pattern is present in a connection that is allowed under the segmentation policy, the segmentation policy may be updated to block the connection, alert an administrator, redirect traffic to a deception service, or take other remedial action.
    Type: Grant
    Filed: November 7, 2019
    Date of Patent: January 11, 2022
    Assignee: Illumio, Inc.
    Inventors: Rushabh Sanghvi, Rupesh Kumar Mishra
  • Publication number: 20210144181
    Abstract: A policy management server manages a segmentation policy for segmenting a network and a deception policy for implementing deception services. The policy management server distributes segmentation rules and deception rules to distributed enforcement modules that configure respective traffic filters to enforce the policies. The deception rule may be enforced directly by the traffic filter acting as a deception service, or the traffic filter may act as a proxy to an external deception service. The deception service can behave similarly to a real service to obtain information about the malicious actor that is reported to the policy management server to enable the policy management server to take a remedial action. Furthermore, the policy management server may automatically generate the deception policy based on the segmentation policy such that connection requests that are not allowed by the segmentation policy are automatically sent to a deception service.
    Type: Application
    Filed: November 13, 2019
    Publication date: May 13, 2021
    Inventors: Rupesh Kumar Mishra, Paul James Kirner, Rushabh Sanghvi
  • Publication number: 20210144159
    Abstract: A policy management server detects attack patterns in traffic flows reported by distributed enforcement modules enforcing the segmentation policy. The policy management server generates a traffic flow graph representing traffic flows between workloads or groups of workloads. Traffic flows matching one or more traffic flow patterns may be tagged in the traffic flow graph. For example, if an attack pattern is present in a connection that is blocked under the segmentation policy, the policy management server may block updates to the segmentation policy that attempt to enable the connection or may alert an administrator prior to enabling the update. If an attack pattern is present in a connection that is allowed under the segmentation policy, the segmentation policy may be updated to block the connection, alert an administrator, redirect traffic to a deception service, or take other remedial action.
    Type: Application
    Filed: November 7, 2019
    Publication date: May 13, 2021
    Inventors: Rushabh Sanghvi, Rupesh Kumar Mishra
  • Patent number: 10965648
    Abstract: An enforcement module operating on a server or on a network midpoint device obtains a management instruction controlling communications of a target workload. The enforcement module configures a firewall of a network midpoint device upstream from the target workload to enforce the management instruction. The configuration mechanism may be dependent on the particular capabilities and characteristics of the network midpoint device.
    Type: Grant
    Filed: August 28, 2018
    Date of Patent: March 30, 2021
    Assignee: Illumio, Inc.
    Inventors: Rupesh Kumar Mishra, Paul James Kirner
  • Publication number: 20210067538
    Abstract: A segmentation server configures and distributes rules for enforcing a segmentation policy that includes one or more virtual patches. The rules including the virtual patches are enforced by distributed enforcement modules that may execute on host devices or on network devices upstream from the host devices. An enforcement module enforces the rules using traffic filters that filter traffic based on network layer data. To implement a virtual patch, the traffic filters are configured to redirect traffic to or from an application being patched to a transparent application proxy. The transparent application proxy implements an application layer filter that filters traffic based on application layer data to block specific types of traffic associated with a vulnerability addressed by the virtual patch.
    Type: Application
    Filed: August 27, 2019
    Publication date: March 4, 2021
    Inventors: Rupesh Kumar Mishra, Pritesh Kothari
  • Patent number: 10805166
    Abstract: An enforcement mechanism on an operating system instance enforces a segmentation policy on a container. A configuration generation module executing in a host namespace of the operating system instance receives management instructions from a segmentation server for enforcing the segmentation policy on a container. The configuration generation module executes in the host namespace to configure a traffic control and monitoring module in a container namespace associated with the container. The traffic control and monitoring module in the container namespace controls and monitors communications to and from the container in accordance with its configuration. By executing a configuration generation module in the host namespace to configure traffic control and monitoring module in the container namespace, the enforcement mechanism beneficially enables robust and lightweight enforcement in a manner that is agnostic to different containerization protocols.
    Type: Grant
    Filed: September 24, 2019
    Date of Patent: October 13, 2020
    Assignee: Illumio, Inc.
    Inventors: Thomas Michael McCormick, Daniel Richard Cook, Rupesh Kumar Mishra, Matthew Kirby Glenn, Paul James Kirner, Mukesh Gupta, Juraj George Fandli
  • Patent number: 10785115
    Abstract: A segmentation server configures enforcement of a segmentation policy by allocating enforcement of management instructions between network devices and hosts. The segmentation policy comprises rules that control communications between workloads. For a particular workload, the segmentation server generates management instructions for controlling communications to and from the particular workload in accordance with the rules. The segmentation server determines an allocation of management instructions between enforcement on a host on which the particular workload executes and enforcement on a network device upstream from the workload. The segmentation server sends configuration information to at least one of the host and the network device in accordance with the allocation to enable enforcement of the management instructions.
    Type: Grant
    Filed: October 26, 2018
    Date of Patent: September 22, 2020
    Assignee: Illumio, Inc.
    Inventors: Rupesh Kumar Mishra, Paul James Kirner, Matthew Kirby Glenn
  • Publication number: 20200148635
    Abstract: The present invention relates to 4-substituted amidine derivatives of the general formula (I), wherein A1-A4, D, L, Q, R7, R7? and integer's v and w have the meanings as defined in description. The invention further relates to methods for their preparation and use of said compounds to fight undesired phytopathogenic microorganisms, and agents for said purpose, comprising said amidine derivatives, all according to the invention. This invention further relates to a method for controlling undesired phytopathogenic microorganisms by application of said 4-substituted amidine derivatives of general formula (I) to such undesired microorganisms and/or to their habitat, according to the invention.
    Type: Application
    Filed: May 17, 2018
    Publication date: May 14, 2020
    Applicant: PI INDUSTRIES LTD.
    Inventors: Maruti Naik, Vishal A. Mahajan, Manoj G. Kale, Sathiyamoorthi Sivakumar, Ankit Kumar Jain, Sulur G. Manjunatha, Santosh Shridhar Autkar, Ruchi Garg, Rupesh Kumar Mishra, Hagalavadi M. Venkatesha, Konstantin Poschnary, Alexander G.M. KLAUSENER
  • Publication number: 20200136910
    Abstract: A segmentation server configures enforcement of a segmentation policy by allocating enforcement of management instructions between network devices and hosts. The segmentation policy comprises rules that control communications between workloads. For a particular workload, the segmentation server generates management instructions for controlling communications to and from the particular workload in accordance with the rules. The segmentation server determines an allocation of management instructions between enforcement on a host on which the particular workload executes and enforcement on a network device upstream from the workload. The segmentation server sends configuration information to at least one of the host and the network device in accordance with the allocation to enable enforcement of the management instructions.
    Type: Application
    Filed: October 26, 2018
    Publication date: April 30, 2020
    Inventors: Rupesh Kumar Mishra, Paul James Kirner, Matthew Kirby Glenn
  • Publication number: 20200076769
    Abstract: An enforcement module operating on a server or on a network midpoint device obtains a management instruction controlling communications of a target workload. The enforcement module configures a firewall of a network midpoint device upstream from the target workload to enforce the management instruction. The configuration mechanism may be dependent on the particular capabilities and characteristics of the network midpoint device.
    Type: Application
    Filed: August 28, 2018
    Publication date: March 5, 2020
    Inventors: Rupesh Kumar Mishra, Paul James Kirner
  • Publication number: 20200021491
    Abstract: An enforcement mechanism on an operating system instance enforces a segmentation policy on a container. A configuration generation module executing in a host namespace of the operating system instance receives management instructions from a segmentation server for enforcing the segmentation policy on a container. The configuration generation module executes in the host namespace to configure a traffic control and monitoring module in a container namespace associated with the container. The traffic control and monitoring module in the container namespace controls and monitors communications to and from the container in accordance with its configuration. By executing a configuration generation module in the host namespace to configure traffic control and monitoring module in the container namespace, the enforcement mechanism beneficially enables robust and lightweight enforcement in a manner that is agnostic to different containerization protocols.
    Type: Application
    Filed: September 24, 2019
    Publication date: January 16, 2020
    Inventors: Thomas Michael McCormick, Daniel Richard Cook, Rupesh Kumar Mishra, Matthew Kirby Glenn, Paul James Kirner, Mukesh Gupta, Juraj George Fandli
  • Publication number: 20190372848
    Abstract: An enforcement mechanism on an operating system instance enforces a segmentation policy on a container. A configuration generation module executing in a host namespace of the operating system instance receives management instructions from a segmentation server for enforcing the segmentation policy on a container. The configuration generation module executes in the host namespace to configure a traffic control and monitoring module in a container namespace associated with the container. The traffic control and monitoring module in the container namespace controls and monitors communications to and from the container in accordance with its configuration. By executing a configuration generation module in the host namespace to configure traffic control and monitoring module in the container namespace, the enforcement mechanism beneficially enables robust and lightweight enforcement in a manner that is agnostic to different containerization protocols.
    Type: Application
    Filed: May 31, 2018
    Publication date: December 5, 2019
    Inventors: Thomas Michael McCormick, Daniel Richard Cook, Rupesh Kumar Mishra, Matthew Kirby Glenn, Paul James Kirner, Mukesh Gupta, Juraj George Fandli
  • Patent number: 10476745
    Abstract: An enforcement mechanism on an operating system instance enforces a segmentation policy on a container. A configuration generation module executing in a host namespace of the operating system instance receives management instructions from a segmentation server for enforcing the segmentation policy on a container. The configuration generation module executes in the host namespace to configure a traffic control and monitoring module in a container namespace associated with the container. The traffic control and monitoring module in the container namespace controls and monitors communications to and from the container in accordance with its configuration. By executing a configuration generation module in the host namespace to configure traffic control and monitoring module in the container namespace, the enforcement mechanism beneficially enables robust and lightweight enforcement in a manner that is agnostic to different containerization protocols.
    Type: Grant
    Filed: May 31, 2018
    Date of Patent: November 12, 2019
    Assignee: Illumio, Inc.
    Inventors: Thomas Michael McCormick, Daniel Richard Cook, Rupesh Kumar Mishra, Matthew Kirby Glenn, Paul James Kirner, Mukesh Gupta, Juraj George Fandli
  • Patent number: 10467360
    Abstract: A method is described for dynamically determining availability of a computing resource. An application session is established, and an application session data matrix is generated including parameters specifying aspects of the application session, an application associated with the application session, and a computing resource on which the application session depends. A component signature block is derived based on the parameters of the application session data matrix. The component signature block identifies the computing resource on which the application session depends and a total number of sessions dependent on the computing resource. A metric signature block is generated based on one or more parameters of the application session data matrix and the component signature block. The metric signature block is classified according to one or more probability models. A computing resource availability rating for the computing resource is derived based on an output of the one or more probability models.
    Type: Grant
    Filed: January 2, 2019
    Date of Patent: November 5, 2019
    Assignee: FMR LLC
    Inventors: Deepak Gupta, Rupesh Kumar Mishra
  • Publication number: 20150290612
    Abstract: The sensor chips, processes and devices enable ultra-sensitive detection/determination, evaluation and quantitative measurement of analytes and are useful for high throughput and miniaturized assays, which enable a user to perform multiple, accurate, experiments in parallel with minimum amount of reagents resulting in low waste generation. The method enables screening of fluid samples to meet regulatory standards. The device comprises a pitted chip having a silicon-based substrate, optionally provided with an integrated heating element, a biosensor and a receptor immobilized on a cross linking element fixed to an inert metal layer in the chip. The analyte is detected up to 5 parts per trillion of the fluid sample and quantitatively measured up to 10 parts per trillion of the fluid sample by the device of the present disclosure.
    Type: Application
    Filed: March 28, 2013
    Publication date: October 15, 2015
    Applicant: Indian Council of Agricultural Research
    Inventors: Sunil Bhand, Sudhir Chandra, Hardik Pandya, Ruchi Tiwari, Rupesh Kumar Mishra