Incremental micro-segmentation system and incremental micro-segmentation method
An incremental micro-segmentation system includes a shared network and a network control device. The network control device is configured to perform operations of: retrieving multiple key values from a network flow; adding the multiple key values to be a policy rule of a temporary policy group based on an interested attribute of the temporary policy group of a candidate policy group set; computing a group score of each temporary policy group according to a recommended factor; when determining that the group score is greater than a threshold, generating a recommendation set including the temporary policy groups; and deploying the recommendation set to an access control list to make the temporary policy groups be enforced.
1 . An incremental micro-segmentation system, comprising:
a shared network, wherein multiple network assets are deployed in the shared network; and
a network control device, authorized to monitor the shared network and perform in a learning stage being parallel to a generating stage and a deployment stage, the network control device comprises a hardware processor and the hardware processor is configured to:
retrieve multiple key values from a network flow in the learning stage;
based on an interested attribute of one or multiple temporary policy groups of a candidate policy group set that is not enforced, add the multiple key values to be a policy rule of the one or multiple temporary policy groups, and different combinations of the multiple key values form different policy rules;
compute a group score of each of the temporary policy groups according to a recommended factor value, wherein each recommended factor value being independently computed based on a state of respective temporary policy group with respect to corresponding recommended factors taken from the group of: update interval, restricted range, confidential or sensitive level, involvement in management services, out-of-date services, or services with vulnerabilities;
when determining that the group score is greater than a threshold, generate a recommendation set comprising the one or multiple temporary policy groups in the generation stage; and
deploy the recommendation set to an access control list in the deployment stage to make content of the one or multiple temporary policy groups be enforced, wherein the temporary policy groups of the candidate policy group set are not added to the access control list before the deployment stage is performed;
wherein a regular policy group in the access control list has a priority, and the network control device is configured to:
when adding the one or multiple temporary policy groups to the regular policy group of the access control list each time, reorder all the regular policy groups of the access control list according to the priority.
2 . The incremental micro-segmentation system of claim 1 , wherein the interested attribute comprises a control attribute and an observation attribute, and the network control device is configured to, based on the multiple key values indicated by the control attribute and the multiple key values listed by the observation attribute, take the multiple key values as a key value-set by referring to the interested attribute of the one or multiple temporary policy groups, and add the key value-set to the policy rule of the one or multiple temporary policy groups.
3 . The incremental micro-segmentation system of claim 1 , after generating the recommendation set comprising the one or multiple temporary policy groups, the network control device is configured to:
perform a process for optimizing content of the recommendation set, wherein the process comprises deactivating a duplicate policy rule of the one or multiple temporary policy group that is repeated in the access control list; and
perform the process for optimizing the one or multiple temporary policy groups, wherein the process comprises adding a default setting to the one or multiple temporary policy groups, and the default setting comprises a log file setting or an intrusion prevention security (IPS) setting.
4 . The incremental micro-segmentation system of claim 1 , wherein the network control device deploys the recommendation set to the access control list further comprises:
adding the one or multiple temporary policy groups whose group score is greater than the threshold to a section of the access control list as the regular policy group; and
removing the one or multiple temporary policy groups that are added to the access control list from the candidate policy group set.
5 . The incremental micro-segmentation system of claim 4 , wherein the network control device is configured to:
compute a restricted range of all the regular policy groups of the access control list; and
set a high priority to a small restricted range and set a low priority to a large restricted range.
6 . The incremental micro-segmentation system of claim 4 , after removing the one or multiple temporary policy groups from the candidate policy group set, the network control device is configured to:
determine whether the candidate policy group set is empty and remains for a period of time; and
when the candidate policy group set is empty and remains for the period of time, determine that the access control list is well-defined.
7 . The incremental micro-segmentation system of claim 6 , after determining that the access control list is well-defined, the network control device is configured to:
inspect a test network flow with the regular policy groups by the priority of the regular policy groups of the access control list; and
when determining that a key value-set of the test network flow matches the policy rule of the access control list, allow or block the test network flow based on an attribute of the policy rule that is allowed-access or denied-access.
8 . The incremental micro-segmentation system of claim 1 , wherein the key value comprises a client IP address, a server IP address, a service, or a port number.
9 . An incremental micro-segmentation method, performed by a network control device authorized to monitor a shared network, wherein the network control device performs in a learning stage being parallel to a generation stage and a deployment stage, the incremental micro-segmentation method comprising:
retrieving multiple key values from a network flow in the learning stage;
based on an interested attribute of one or multiple temporary policy groups of a candidate policy group set that is not enforced, adding the multiple key values to be a policy rule of the one or multiple temporary policy groups, and different combinations of the multiple key values form different policy rules;
computing a group score of each of the temporary policy groups according to a recommended factor value, wherein each recommended factor value being independently computed based on a state of respective temporary policy group with respect to corresponding recommended factors taken from a group of: update interval, restricted range, confidential or sensitive level, involvement in management services, out-of-date services, or services with vulnerabilities;
when determining that the group score is greater than a threshold, generating a recommendation set comprising the one or multiple temporary policy groups in the generation stage; and
deploying the recommendation set to an access control list in the deployment stage to make content of the one or multiple temporary policy groups be enforced, wherein the temporary policy groups of the candidate policy group set are not added to the access control list before the deployment stage is performed;
wherein a regular policy group in the access control list has a priority, and the incremental micro-segmentation method further comprises:
when adding the one or multiple temporary policy groups to the regular policy group of the access control list each time, reordering all the regular policy groups of the access control list according to the priority.
10 . The incremental micro-segmentation method of claim 9 , wherein the interested attribute comprises a control attribute and an observation attribute, and the incremental micro-segmentation method further comprises: based on the multiple key values indicated by the control attribute and listed by the observation attribute, taking the multiple key values as a key value-set by referring to the interested attribute of the one or multiple temporary policy groups and adding the key value-set to the policy rule of the one or multiple temporary policy groups.
11 . The incremental micro-segmentation method of claim 9 , after generating the recommendation set comprising the one or multiple temporary policy groups, further comprising:
performing a process for optimizing content of the recommendation set, wherein the process comprises deactivating a duplicate policy rule of the one or multiple temporary policy groups that are repeated in the access control list; and
performing the process for optimizing the one or multiple temporary policy groups, wherein the process comprises adding a default setting to the one or multiple temporary policy groups, and the default setting comprises a log file setting or an intrusion prevention security (IPS) setting.
12 . The incremental micro-segmentation method of claim 9 , wherein a step of deploying the recommendation set to the access control list comprises:
adding the one or multiple temporary policy groups whose group score is greater than the threshold to a section of the access control list as the regular policy group; and
removing the one or multiple temporary policy groups that are added to the access control list from the candidate policy group set.
13 . The incremental micro-segmentation method of claim 12 , further comprising:
computing a restricted range of all the regular policy groups of the access control list respectively; and
setting a high priority to a small restricted range and setting a low priority to a large restricted range.
14 . The incremental micro-segmentation method of claim 12 , after removing the one or multiple temporary policy groups from the candidate policy group set, further comprising:
determining whether the candidate policy group set is empty and remains for a period of time; and
when the candidate policy group set is empty and remains for the period of time, determining that the access control list is well-defined.
15 . The incremental micro-segmentation method of claim 14 , after determining that the access control list is well-defined, further comprising:
inspecting a test network flow with the regular policy groups by the priority of the regular policy groups of the access control list;
when determining that a key value-set of the test network flow matches the policy rule of the access control list, allowing or blocking the test network flow based on an attribute of the policy rule that is allowed-access or denied-access.
16 . The incremental micro-segmentation method of claim 9 , wherein the key value comprises a client IP address, a server IP address, a service, or a port number.