Auto re-segmentation to assign new applications in a microsegmented network

US2021314250A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2021314250-A1
Application numberUS-202117350180-A
CountryUS
Kind codeA1
Filing dateJun 17, 2021
Priority dateJun 11, 2019
Publication dateOct 7, 2021
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods include, subsequent to performing auto segmentation on a network that includes a set of policies of allowable and block communications, observing communication between a plurality of hosts on the network; determining unassigned communication paths based on the observing that are either blocked because of a lack of a policy of the set of policies or because there is no policy of the set of policies for coverage thereof; and assigning the unassigned communication paths to corresponding policies of the set of policies. The assigning can be based on heuristics. The assigning can be performed without reperforming auto segmentation.

First claim

Opening claim text (preview).

What is claimed is: 1 . A non-transitory computer-readable storage medium having computer-readable code stored thereon for programming a computing system to perform steps of: subsequent to performing auto segmentation on a network that includes a set of policies of allowable and block communications, observing communication between a plurality of hosts on the network; determining unassigned communication paths based on the observing that are either blocked because of a lack of a policy of the set of policies or because there is no policy of the set of policies for coverage thereof; and assigning the unassigned communication paths to corresponding policies of the set of policies. 2 . The non-transitory computer-readable storage medium of claim 1 , wherein the assigning is based on heuristics. 3 . The non-transitory computer-readable storage medium of claim 1 , wherein the assigning is performed without reperforming auto segmentation. 4 . The non-transitory computer-readable storage medium of claim 1 , wherein the assigning further includes providing the unassigned communication paths to a user; and receiving input from the user for the assigning. 5 . The non-transitory computer-readable storage medium of claim 1 , wherein each of the communication paths is a flow in the network where the flow is communication between a first application and a second application. 6 . The non-transitory computer-readable storage medium of claim 1 , wherein the auto segmentation includes obtaining network communication information about the plurality of hosts in the network and applications executed on the plurality of hosts; and automatically generating one or more microsegments in the network based on analysis of the obtained network communication information, wherein each microsegment of the one or more microsegments is a grouping of resources including the hosts and the applications executed on the hosts that have rules for network communication. 7 . The non-transitory computer-readable storage medium of claim 6 , wherein each of the communication paths is a flow in the network where the flow is communication between a first application and a second application, wherein the communication between the first application and the second application was not included in the network communication information. 8 . A method comprising the steps of: subsequent to performing auto segmentation on a network that includes a set of policies of allowable and block communications, observing communication between a plurality of hosts on the network; determining unassigned communication paths based on the observing that are either blocked because of a lack of a policy of the set of policies or because there is no policy of the set of policies for coverage thereof; and assigning the unassigned communication paths to corresponding policies of the set of policies. 9 . The method of claim 8 , wherein the assigning is based on heuristics. 10 . The method of claim 8 , wherein the assigning is performed without reperforming auto segmentation. 11 . The method of claim 8 , wherein the assigning further includes providing the unassigned communication paths to a user; and receiving input from the user for the assigning. 12 . The method of claim 8 , wherein each of the communication paths is a flow in the network where the flow is communication between a first application and a second application. 13 . The method of claim 8 , wherein the auto segmentation includes obtaining network communication information about the plurality of hosts in the network and applications executed on the plurality of hosts; and automatically generating one or more microsegments in the network based on analysis of the obtained network communication information, wherein each microsegment of the one or more microsegments is a grouping of resources including the hosts and the applications executed on the hosts that have rules for network communication. 14 . The method of claim 13 , wherein each of the communication paths is a flow in the network where the flow is communication between a first application and a second application, wherein the communication between the first application and the second application was not included in the network communication information. 15 . A server comprising: one or more processors and memory comprising instructions that, when executed, cause the one or more processors to subsequent to performance of auto segmentation on a network that includes a set of policies of allowable and block communications, observe communication between a plurality of hosts on the network, determine unassigned communication paths based on the observation that are either blocked because of a lack of a policy of the set of policies or because there is no policy of the set of policies for coverage thereof, and assign the unassigned communication paths to corresponding policies of the set of policies. 16 . The server of claim 15 , wherein the unassigned communication paths are assigned based on heuristics. 17 . The server of claim 15 , wherein the unassigned communication paths are assigned without reperforming auto segmentation. 18 . The server of claim 15 , wherein the unassigned communication paths are assigned by providing the unassigned communication paths to a user; and receiving input from the user for the assigning. 19 . The server of claim 15 wherein each of the communication paths is a flow in the network where the flow is communication between a first application and a second application. 20 . The server of claim 15 , wherein the auto segmentation includes obtaining network communication information about the plurality of hosts in the network and applications executed on the plurality of hosts; and automatically generating one or more microsegments in the network based on analysis of the obtained network communication information, wherein each microsegment of the one or more microsegments is a grouping of resources including the hosts and the applications executed on the hosts that have rules for network communication.

Assignees

Inventors

Classifications

  • H04L45/02Primary

    Topology update or discovery · CPC title

  • H04L63/10Primary

    for controlling access to devices or network resources · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • Multiple levels of security · CPC title

  • Miscellaneous aspects · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2021314250A1 cover?
Systems and methods include, subsequent to performing auto segmentation on a network that includes a set of policies of allowable and block communications, observing communication between a plurality of hosts on the network; determining unassigned communication paths based on the observing that are either blocked because of a lack of a policy of the set of policies or because there is no policy…
Who is the assignee on this patent?
Zscaler Inc
What technology area does this patent fall under?
Primary CPC classification H04L45/02. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Oct 07 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).