Segmented networks that implement scanning

US9609026B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9609026-B2
Application numberUS-201615219273-A
CountryUS
Kind codeB2
Filing dateJul 25, 2016
Priority dateMar 13, 2015
Publication dateMar 28, 2017
Grant dateMar 28, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems for providing scanning within distributed services are provided herein. In some embodiments, a system includes a plurality of segmented environments that each includes an enforcement point that has an active probe device, and a plurality of workloads that each implements at least one service. The system also has a data center server coupled with the plurality of segmented environments over a network. The data center server has a security controller configured to provide a security policy to each of the plurality of segmented environments and an active probe controller configured to cause the active probe device of the plurality of segmented environments to execute a scan.

First claim

Opening claim text (preview).

What is claimed is: 1. A system comprising: a memory for storing executable instructions; one or more processors executing the instructions; a plurality of segmented environments, each of the plurality of segmented environments comprising an enforcement point comprising an active probe device, and a plurality of workloads each implementing at least one service component, the plurality of segmented environments collectively providing a service, each of the plurality of segmented environments providing a portion of the service, the plurality of workloads controlled with a host server that coordinates the operations of distributed service components to provide the service; and a data center server coupled with the plurality of segmented environments over a network, the data center server comprising: a security controller providing, via the one or more processors, a security policy to each of the plurality of segmented environments, the security policy being configured using the service; and an active probe controller requesting, via the one or more processors, each active probe device of the plurality of segmented environments to perform a respective scan of a plurality of scans, wherein the active probe controller causes the active probe device to execute the respective scan when a triggering event is detected by the security controller, the respective scan is a vulnerability scan and the active probe controller implements a remediation scheme in addition to the respective scan by the active probe device, the plurality of scans including packet insertion and/or modification, the plurality of scans performed on the plurality of segmented environments collectively providing the service, the plurality of scans occurring in parallel on the plurality of workloads implementing the at least one service component. 2. The system according to claim 1 , wherein the security policy comprises a firewall that implements a firewall policy and the respective scan occurs within each of the plurality of segmented environments without traversing the network or passing through the firewall. 3. The system according to claim 1 , wherein the active probe device is configured to execute the respective scan according to a predetermined schedule. 4. The system according to claim 1 , wherein the plurality of scans are at least one of a vulnerability scan, a file scan, and a service scan. 5. The system according to claim 1 , wherein the remediation scheme comprises isolating an affected segmented environment from communicating with other segmented environments or communicating over the network. 6. The system according to claim 1 , wherein the remediation scheme comprises the security controller implementing a heightened security policy for an affected segmented environment. 7. The system according to claim 1 , wherein the remediation scheme comprises identifying an affected segmented environment for further evaluation by a security administrator. 8. A method comprising: establishing a plurality of segmented environments within a data center, each of the plurality of segmented environments comprising an enforcement point comprising an active probe device, and a plurality of workloads each implementing at least one service component, the plurality of segmented environments collectively providing a service, each of the plurality of segmented environments providing a portion of the service, the plurality of workloads controlled with a host server that coordinates operations of distributed service components to provide the service; provisioning each of the plurality of segmented environments with a security policy, the security policy being configured using the service; performing a scan on each of the plurality of segmented environments using a respective active probe device, the scans performed when a triggering event is detected, the scans including packet insertion and/or modification, the scans performed on the plurality of segmented environments collectively providing the service, the scans occurring in parallel on the plurality of workloads implementing the at least one service component, the active probe device identifying an affected segmented environment; and executing a remediation scheme in addition to the scans when malicious behavior within one or more of the plurality of segmented environments is detected, wherein the scans are vulnerability scans. 9. The method according to claim 8 , wherein the security policy comprises a firewall or virus scanning policy. 10. The method according to claim 9 , wherein the performance of the scans occur in its entirety without crossing the firewall. 11. The method according to claim 8 further comprising transmitting to the active probe device instructions to execute the scan. 12. The method according to claim 8 , wherein the active probe device is pre-provisioned to execute the scan according to a predetermined schedule. 13. The method according to claim 8 , wherein the plurality of segmented environments execute the scans synchronously without affecting performance of a network established between the data center and the plurality of segmented environments. 14. The method according to claim 8 , wherein the scans are at least one of a vulnerability scan, a file scan, and a service scan. 15. The method according to claim 8 , wherein the remediation scheme comprises isolating the affected segmented environment from communicating with other segmented environments or communicating over a network. 16. The method according to claim 8 , wherein the remediation scheme comprises a security controller implementing a heightened security policy for the affected segmented environment. 17. The method according to claim 8 , wherein the remediation scheme comprises identifying the affected segmented environment for further evaluation by a security administrator.

Assignees

Inventors

Classifications

  • Stateful filtering · CPC title

  • Vulnerability analysis · CPC title

  • Electricity · mapped topic

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • Isolation or security of virtual machine instances · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9609026B2 cover?
Systems for providing scanning within distributed services are provided herein. In some embodiments, a system includes a plurality of segmented environments that each includes an enforcement point that has an active probe device, and a plurality of workloads that each implements at least one service. The system also has a data center server coupled with the plurality of segmented environments o…
Who is the assignee on this patent?
Varmour Networks Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 28 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 10 related publications on this page (citations in our corpus or others sharing the same primary CPC).