Selecting policies to apply to network traffic flows based on perception scores
A process includes prioritizing candidate network traffic flow profiles. The prioritization includes associating perception scores with respective candidate network traffic flow profiles. Each candidate network traffic flow profile is a member of a profile group of a plurality of profile groups. The process includes associating weights with respective profile groups of the plurality of categories. The process includes, responsive to a network traffic flow, identifying, by a traffic analysis engine, a first observed profile of the network traffic flow corresponding to a first candidate network traffic flow profile. The process includes, based on the perception score associated the first candidate network traffic flow profile and the weight associated with the profile group in which the first candidate network traffic flow profile is a member, determining a policy score; and selecting, by the network analysis engine, a policy to be applied to the network traffic flow based on the policy score.
1 . A method comprising:
prioritizing a plurality of candidate network traffic flow profiles, wherein the prioritizing includes associating perception scores with respective candidate network traffic flow profiles of the plurality of candidate network traffic flow profiles, wherein each candidate network traffic flow profile of the plurality of candidate network traffic flow profiles is a member of a profile group of a plurality of profile groups;
associating weights with respective profile groups of a plurality of categories;
responsive to a network traffic flow, identifying, by a traffic analysis engine, a first observed profile of the network traffic flow corresponding to a first candidate network traffic flow profile of the plurality of candidate network traffic flow profiles;
based on the perception score associated with the first candidate network traffic flow profile and the weight associated with the profile group in which the first candidate network traffic flow profile is a member, determining a policy score; and
selecting, by the traffic analysis engine, a policy to be applied to the network traffic flow based on the policy score.
2 . The method of claim 1 , wherein:
the perception score represents a security risk perception associated with the first network traffic flow profile; and
selecting the policy comprises selecting a type of inspection to be applied to the network traffic flow based on the policy score.
3 . The method of claim 2 , wherein the selecting the type of inspection comprises, based on the policy score, selecting one of:
a first inspection applying secure sockets layer (SSL) inspection, anti-malware inspection and data loss prevention (DLP) inspection to the network traffic flow;
a second inspection applying the SSL and the anti-malware inspection to the network traffic flow and foregoing the DLP inspection; or
a third inspection applying the SSL inspection, foregoing the anti-malware inspection and foregoing the DLP inspection.
4 . The method of claim 1 , wherein:
the perception score represents an application delivery perception associated with the first network traffic flow profile; and
selecting the policy comprises selecting a routing of the network traffic flow based on the policy score.
5 . The method of claim 1 , wherein the plurality of profile groups comprises at least one of a group associated with a client role, a group associated with an application, a group associated with a network, a group associated with a device and a group associated with a data.
6 . The method of claim 1 , further comprising, based on the policy score, applying a tag to the network traffic flow representing how the network traffic flow is to be processed.
7 . The method of claim 6 , wherein:
the perception score represents a security risk perception associated with the first network traffic flow profile; and
applying the tag comprises applying a tag to identify an inspection engine instance of a plurality of candidate inspection engine instances to the network traffic flow.
8 . The method of claim 1 , further comprising:
receiving an indication of the policy;
determining whether the network traffic flow qualifies for a policy override; and
determining to bypass the policy based on the determination of whether the network traffic flow qualifies for the policy override.
9 . The method of claim 1 , further comprising:
responsive to the network traffic flow, identifying, by the traffic analysis engine, a second observed profile of the network traffic flow corresponding to a second network traffic flow profile of the plurality of network traffic flow profiles other than the first network traffic flow profile; and
determining the policy score based on the perception score associated with the second network traffic flow profile and the weight associated with a category of the plurality of categories in which the second network traffic flow profile is a member.
10 . The method of claim 9 , wherein the category in which the second network traffic flow profile is a member is the same as the category in which the first network traffic flow profile is a member.
11 . The method of claim 9 , wherein the category in which the second network traffic flow profile is a member is other than the category in which the first network traffic flow profile is a member.
12 . The method of claim 1 , wherein the network traffic flow comprises a session.
13 . An apparatus comprising:
one or more processors configured to execute one or more machine-readable instructions to:
associate perception scores with a plurality of network session profiles, wherein the network session profiles of the plurality of network session profiles are classified as belonging to at least one category of a plurality of categories comprising at least one of a data profile category, a user profile category, an application profile category, a network profile category or a device profile category; and
responsive to a network session:
determine perception scores for profiles of the network session based on the association;
weight the perception scores based on the category or categories to which an observed network traffic flow profiles belong to provide weighted perception scores;
determine a policy score for the network session based on the weighted perception scores;
assign a tag to the network session based on the policy score; and
inspect a network traffic flow associated with the tag.
14 . The apparatus of claim 13 , wherein the one or more processors are configured to execute the one or more machine-readable instructions to determine a given perception score of a given profile of the profiles of the network session by identifying the given network session profile of a given traffic treatment type bucket with the given profile wherein each traffic treatment bucket is associated with a perception score of the perception scores, and the given traffic treatment bucket of a plurality of traffic treatment buckets contains a given network session profile of the plurality of network session profiles.
15 . A non-transitory machine-readable storage medium that stores machine-readable instructions, that, when executed by a machine, cause the machine to:
responsive to a network session, determine a first profile associated with the network session based on network traffic associated with the network session, wherein the first profile is associated with a first profile category, and the first profile category is associated with one of a user category, an application category or a network category;
determine a first risk score associated with the first profile;
determine a first weight associated with the first profile category;
process the network traffic associated with the network session based on the first risk score and the first weight;
responsive to the network session, determine a second profile associated with the network session based on the network traffic, wherein the second profile is associated with a second profile category other than the first profile category, and the second profile category is associated with one of the user category, the application category or the network category;
determine a second risk score associated with the second profile;
determine a second weight associated with the second profile category; and
determine a composite score based on the first risk score, the first weight, the second risk score and the second weight; and
determine how to process the network traffic based on the composite score.
16 . The storage medium of claim 15 , wherein:
the first risk score represents a perceived security risk associated with the first profile; and
the instructions, when executed by the machine, further cause the machine to select an inspection engine from a plurality of inspection engines to inspect the network traffic based on a score determined from the first weight and the first risk score.
17 . The storage medium of claim 15 , wherein:
the first profile comprises a network profile associated with the network category; and
the instructions, when executed by the machine, further cause the machine to:
determine a destination address associated with the network traffic; and
determine the network profile based on the destination address.
18 . The storage medium of claim 15 , wherein:
the first profile comprises an application profile associated with the application category; and
the instructions, when executed by the machine, further cause the machine to:
responsive to determining that a deep packet inspection has been performed, associating the network traffic with an application identifier provided as a result of the deep packet inspection; and
determine the application profile based on the application identifier.