Microsegmentation for serverless computing

US11792194B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11792194-B2
Application numberUS-202017124693-A
CountryUS
Kind codeB2
Filing dateDec 17, 2020
Priority dateDec 17, 2020
Publication dateOct 17, 2023
Grant dateOct 17, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods include obtaining a set of policies to in the serverless computing system, wherein the set of policies specify which applications are authorized for communication with the serverless computing system; and modifying rules in a network Access Control List (ACL) associated with the serverless computing system based on the set of policies, wherein the network ACL includes rules that specify allowing and blocking communication. The serverless computing system includes having underlying hardware abstracted therefrom. The network ACL is provided by a cloud provider that hosts the serverless computing system.

First claim

Opening claim text (preview).

What is claimed is: 1. A non-transitory computer-readable storage medium having computer-readable code stored thereon for programming a serverless computing system to perform steps of: obtaining a set of policies in the serverless computing system, wherein the set of policies specify which applications are authorized for communication with the serverless computing system; modifying rules in a network Access Control List (ACL) associated with the serverless computing system based on the set of policies, wherein the network ACL includes rules that specify allowing and blocking communication and operations with the applications; obtaining updated network communication information based on monitoring in a microsegmentation system, wherein the microsegmentation system is a part of a Zero Trust Network Access (ZTNA) framework; providing an update for the set of policies based on the updated network communication information; and updating the rules in the network ACL based on the update. 2. The non-transitory computer-readable storage medium of claim 1 , wherein the network ACL is obtained from a cloud provider that hosts the serverless computing system. 3. The non-transitory computer-readable storage medium of claim 1 , wherein the set of policies include authorized applications that are on a same network as the serverless computing system and applications that are deemed authorized based on monitoring by the microsegmentation system. 4. The non-transitory computer-readable storage medium of claim 1 , wherein the set of policies include a plurality of applications on associated systems that are monitored by the microsegmentation system. 5. The non-transitory computer-readable storage medium of claim 1 , wherein the rules include whether to allow or deny specified traffic based on any of a type of traffic, traffic protocol, ports, traffic source, and traffic destination. 6. The non-transitory computer-readable storage medium of claim 1 , wherein the set of policies are determined by the microsegmentation system that monitors communication associated with the applications to generate a network communication model based thereon. 7. A method comprising steps of: obtaining a set of policies in the serverless computing system, wherein the set of policies specify which applications are authorized for communication with the serverless computing system; modifying rules in a network Access Control List (ACL) associated with the serverless computing system based on the set of policies, wherein the network ACL includes rules that specify allowing and blocking communication and operations with the applications; obtaining updated network communication information based on monitoring in a microsegmentation system, wherein the microsegmentation system is a part of a Zero Trust Network Access (ZTNA) framework; providing an update for the set of policies based on the updated network communication information; and updating the rules in the network ACL based on the update. 8. The method of claim 7 , wherein the network ACL is obtained from a cloud provider that hosts the serverless computing system. 9. The method of claim 7 , wherein the set of policies include authorized applications that are on a same network as the serverless computing system and applications that are deemed authorized based on monitoring by the microsegmentation system. 10. The method of claim 7 , wherein the set of policies include a plurality of applications on associated systems that are monitored by the microsegmentation system. 11. The method of claim 7 , wherein the rules include whether to allow or deny specified traffic based on any of a type of traffic, traffic protocol, ports, traffic source, and traffic destination. 12. The method of claim 7 , wherein the set of policies are determined by the microsegmentation system that monitors communication associated with the applications to generate a network communication model based thereon. 13. A cloud-based system comprising: a plurality of nodes interconnected to one another and collectively configured to operate a serverless computing system, wherein the plurality of nodes comprise memory and one or more processors, and wherein one or more nodes of the plurality of nodes are configured to: obtain a set of policies in the serverless computing system, wherein the set of policies specify which applications are authorized for communication with the serverless computing system, modify rules in a network Access Control List (ACL) associated with the serverless computing system based on the set of policies, wherein the network ACL includes rules that specify allowing and blocking communication and operations with the applications, obtain updated network communication information based on monitoring in a microsegmentation system, wherein the microsegmentation system is a part of a Zero Trust Network Access (ZTNA) framework, provide an update for the set of policies based on the updated network communication information, and update the rules in the network ACL based on the update. 14. The cloud-based system of claim 13 , wherein the set of policies include authorized applications that are on a same network as the serverless computing system and applications that are deemed authorized based on monitoring by the microsegmentation system. 15. The cloud-based system of claim 13 , wherein the rules include whether to allow or deny specified traffic based on any of a type of traffic, traffic protocol, ports, traffic source, and traffic destination.

Assignees

Inventors

Classifications

  • H04L63/101Primary

    Access control lists [ACL] · CPC title

  • Rule management · CPC title

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11792194B2 cover?
Systems and methods include obtaining a set of policies to in the serverless computing system, wherein the set of policies specify which applications are authorized for communication with the serverless computing system; and modifying rules in a network Access Control List (ACL) associated with the serverless computing system based on the set of policies, wherein the network ACL includes rules …
Who is the assignee on this patent?
Zscaler Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/101. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Oct 17 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).