Data storage management system for holistic protection of serverless applications across multi-cloud computing environments
US-2020351345-A1 · Nov 5, 2020 · US
US11792194B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11792194-B2 |
| Application number | US-202017124693-A |
| Country | US |
| Kind code | B2 |
| Filing date | Dec 17, 2020 |
| Priority date | Dec 17, 2020 |
| Publication date | Oct 17, 2023 |
| Grant date | Oct 17, 2023 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Systems and methods include obtaining a set of policies to in the serverless computing system, wherein the set of policies specify which applications are authorized for communication with the serverless computing system; and modifying rules in a network Access Control List (ACL) associated with the serverless computing system based on the set of policies, wherein the network ACL includes rules that specify allowing and blocking communication. The serverless computing system includes having underlying hardware abstracted therefrom. The network ACL is provided by a cloud provider that hosts the serverless computing system.
Opening claim text (preview).
What is claimed is: 1. A non-transitory computer-readable storage medium having computer-readable code stored thereon for programming a serverless computing system to perform steps of: obtaining a set of policies in the serverless computing system, wherein the set of policies specify which applications are authorized for communication with the serverless computing system; modifying rules in a network Access Control List (ACL) associated with the serverless computing system based on the set of policies, wherein the network ACL includes rules that specify allowing and blocking communication and operations with the applications; obtaining updated network communication information based on monitoring in a microsegmentation system, wherein the microsegmentation system is a part of a Zero Trust Network Access (ZTNA) framework; providing an update for the set of policies based on the updated network communication information; and updating the rules in the network ACL based on the update. 2. The non-transitory computer-readable storage medium of claim 1 , wherein the network ACL is obtained from a cloud provider that hosts the serverless computing system. 3. The non-transitory computer-readable storage medium of claim 1 , wherein the set of policies include authorized applications that are on a same network as the serverless computing system and applications that are deemed authorized based on monitoring by the microsegmentation system. 4. The non-transitory computer-readable storage medium of claim 1 , wherein the set of policies include a plurality of applications on associated systems that are monitored by the microsegmentation system. 5. The non-transitory computer-readable storage medium of claim 1 , wherein the rules include whether to allow or deny specified traffic based on any of a type of traffic, traffic protocol, ports, traffic source, and traffic destination. 6. The non-transitory computer-readable storage medium of claim 1 , wherein the set of policies are determined by the microsegmentation system that monitors communication associated with the applications to generate a network communication model based thereon. 7. A method comprising steps of: obtaining a set of policies in the serverless computing system, wherein the set of policies specify which applications are authorized for communication with the serverless computing system; modifying rules in a network Access Control List (ACL) associated with the serverless computing system based on the set of policies, wherein the network ACL includes rules that specify allowing and blocking communication and operations with the applications; obtaining updated network communication information based on monitoring in a microsegmentation system, wherein the microsegmentation system is a part of a Zero Trust Network Access (ZTNA) framework; providing an update for the set of policies based on the updated network communication information; and updating the rules in the network ACL based on the update. 8. The method of claim 7 , wherein the network ACL is obtained from a cloud provider that hosts the serverless computing system. 9. The method of claim 7 , wherein the set of policies include authorized applications that are on a same network as the serverless computing system and applications that are deemed authorized based on monitoring by the microsegmentation system. 10. The method of claim 7 , wherein the set of policies include a plurality of applications on associated systems that are monitored by the microsegmentation system. 11. The method of claim 7 , wherein the rules include whether to allow or deny specified traffic based on any of a type of traffic, traffic protocol, ports, traffic source, and traffic destination. 12. The method of claim 7 , wherein the set of policies are determined by the microsegmentation system that monitors communication associated with the applications to generate a network communication model based thereon. 13. A cloud-based system comprising: a plurality of nodes interconnected to one another and collectively configured to operate a serverless computing system, wherein the plurality of nodes comprise memory and one or more processors, and wherein one or more nodes of the plurality of nodes are configured to: obtain a set of policies in the serverless computing system, wherein the set of policies specify which applications are authorized for communication with the serverless computing system, modify rules in a network Access Control List (ACL) associated with the serverless computing system based on the set of policies, wherein the network ACL includes rules that specify allowing and blocking communication and operations with the applications, obtain updated network communication information based on monitoring in a microsegmentation system, wherein the microsegmentation system is a part of a Zero Trust Network Access (ZTNA) framework, provide an update for the set of policies based on the updated network communication information, and update the rules in the network ACL based on the update. 14. The cloud-based system of claim 13 , wherein the set of policies include authorized applications that are on a same network as the serverless computing system and applications that are deemed authorized based on monitoring by the microsegmentation system. 15. The cloud-based system of claim 13 , wherein the rules include whether to allow or deny specified traffic based on any of a type of traffic, traffic protocol, ports, traffic source, and traffic destination.
Access control lists [ACL] · CPC title
Rule management · CPC title
by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.