Granular segmentation using events

US9787639B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9787639-B1
Application numberUS-201615387584-A
CountryUS
Kind codeB1
Filing dateDec 21, 2016
Priority dateJun 24, 2016
Publication dateOct 10, 2017
Grant dateOct 10, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods and systems for granular segmentation of data networks are provided herein. Exemplary methods include: receiving from a metadata source event metadata associated with a workload; identifying a workload type using the event metadata; determining a high-level declarative security policy using the workload type; launching a compiler to generate a low-level firewall rule set using the high-level declarative policy and the event metadata; and configuring by a plurality of enforcement points a respective network switch of a plurality of network switches to process packets in accordance with the low-level firewall ruleset, the network switches being collectively communicatively coupled to a plurality of workloads, such that network communications between a first group of workloads of the plurality of workloads and the workload are not permitted, and between a second group of workloads of the plurality of workloads and the workload are permitted.

First claim

Opening claim text (preview).

What is claimed is: 1. A method implemented by at least one hardware processor for granular segmentation of data networks, the method comprising: receiving from a metadata source event metadata associated with a workload; identifying a workload type using the event metadata; determining a high-level declarative security policy using the workload type; launching a compiler to generate a low-level firewall rule set using the high-level declarative security policy and the event metadata; and configuring by a plurality of enforcement points a respective network switch of a plurality of network switches to process packets in accordance with the low-level firewall rule set, the plurality of network switches being collectively communicatively coupled to a plurality of workloads, such that network communications between a first group of workloads of the plurality of workloads and the workload are not permitted, and between a second group of workloads of the plurality of workloads and the workload are permitted. 2. The method of claim 1 , wherein the metadata source is at least one of a hypervisor and an orchestration layer. 3. The method of claim 1 , wherein the event metadata is received in response to an event. 4. The method of claim 3 , wherein the event is at least one of: the workload being instantiated, the workload being removed, the workload being migrated, and workload metadata being changed. 5. The method of claim 4 , further comprising: disseminating, to a destination enforcement point of a migrated workload, a state of a communications session of the migrated workload. 6. The method of claim 1 , wherein the workload is at least one of a: bare-metal server, virtual machine (VM), container, and microservice. 7. The method of claim 1 , wherein the event metadata includes at least one of: an event, an application name, a service name, a user-defined tag/label, an IP address, a port number, an operating system name, a software version, and a location. 8. The method of claim 1 , wherein: the event metadata includes at least one of: a date and a time; and the high-level declarative security policy includes a time-based provision. 9. The method of claim 1 , wherein the high-level declarative security policy comprises an intent-driven model, the intent-driven model specifying groups of workloads and describing permitted connectivity, security, and network services between the groups. 10. The method of claim 1 , wherein the low-level firewall rule set comprises individual workload addresses to and/or from which network communications are at least one of forwarded, blocked, redirected, and logged. 11. A system for granular segmentation of data networks, the system comprising: at least one hardware processor; and a memory coupled to the at least one hardware processor, the memory storing instructions executable by the at least one hardware processor to perform a method comprising: receiving from a metadata source event metadata associated with a workload; identifying a workload type using the event metadata; determining a high-level declarative security policy using the workload type; launching a compiler to generate a low-level firewall rule set using the high-level declarative security policy and the event metadata; and configuring by a plurality of enforcement points a respective network switch of a plurality of network switches to process packets in accordance with the low-level firewall rule set, the plurality of network switches being collectively communicatively coupled to a plurality of workloads, such that network communications between a first group of workloads of the plurality of workloads and the workload are not permitted, and between a second group of workloads of the plurality of workloads and the workload are permitted. 12. The system of claim 11 , wherein the metadata source is at least one of a hypervisor and an orchestration layer. 13. The system of claim 11 , wherein the metadata source sends the event metadata in response to an event. 14. The system of claim 13 , wherein the event is at least one of: the workload being instantiated, the workload being removed, the workload being migrated, and workload metadata being changed. 15. The system of claim 14 , wherein the method further comprises: disseminating, to a destination enforcement point of a migrated workload, a state of a communications session of the migrated workload. 16. The system of claim 11 , wherein the workload is at least one of a: bare-metal server, virtual machine, container, and microservice. 17. The system of claim 11 , wherein the event metadata includes at least one of: an event, an application name, a service name, a user-defined tag/label, an IP address, a port number, an operating system name, a software version, and a location. 18. The system of claim 11 , wherein: the event metadata includes at least one of a date and a time; and the high-level declarative security policy includes a time-based provision. 19. The system of claim 11 , wherein the high-level declarative policy comprises an intent-driven model, the intent-driven model specifying groups of workloads and describing permitted connectivity, security, and network services between the groups. 20. The system of claim 11 , wherein the low-level firewall rule set comprises individual workload addresses to and/or from which network communications are at least one of forwarded, blocked, redirected, and logged.

Assignees

Inventors

Classifications

  • Rule management · CPC title

  • Isolation or security of virtual machine instances · CPC title

  • Hypervisor-specific management and integration aspects · CPC title

  • Filtering by information in the payload · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9787639B1 cover?
Methods and systems for granular segmentation of data networks are provided herein. Exemplary methods include: receiving from a metadata source event metadata associated with a workload; identifying a workload type using the event metadata; determining a high-level declarative security policy using the workload type; launching a compiler to generate a low-level firewall rule set using the high-…
Who is the assignee on this patent?
Varmour Networks Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/0245. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Oct 10 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).