IP Library Granted Patent US 9,467,476
Granted Patent B1
US 9,467,476 · App. 14/839,649 · Granted Oct 11, 2016

Context aware microsegmentation

Inventors: Choung-Yaw Shieh (Palo Alto, CA); Jia-Jyi Lian (Saratoga, CA); Yi Sun (San Jose, CA); Meng Xu (Los Altos, CA)
Assignee: vArmour Networks, Inc.
H04L63/20G06F9/45558G06F21/55H04L63/107G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,467,476
App. No.
14/839,649
Granted
Oct 11, 2016
Kind
B1
Abstract

Context aware microservice networks and contextual security policies for microservice networks are provided herein. In some embodiments, a system includes a plurality of microservices, each of the plurality of microservices having a plurality of distributed microservice components. At least a portion of the distributed microservice components execute on different physical or virtual servers in a data center or a cloud. The system also includes a plurality of logical security boundaries, with each of the plurality of logical security boundaries being created by a plurality of enforcement points positioned in association with the plurality of distributed microservice components. Each of plurality of microservices is bounded by one of the plurality of logical security boundaries.

Claims (30)

1. A method for context aware security policy enforcement, the method comprising:

receiving, by a first enforcement point, network traffic sent to and from a first virtual machine, the first virtual machine providing a first microservice component;

selecting, by the first enforcement point, a first contextual security policy using attributes of the first virtual machine;

receiving, by a second enforcement point, network traffic sent to and from a second virtual machine, the second virtual machine providing a second microservice component;

selecting, by the second enforcement point, a second contextual security policy using attributes of the second virtual machine;

receiving, by a third enforcement point, network traffic sent to and from a third virtual machine, the third virtual machine providing a third microservice component, the first, the second, and the third virtual machines collectively providing a microservice, the microservice comprising the first, the second, and the third microservice components;

selecting, by the third enforcement point, a third contextual security policy using attributes of the third virtual machine; and

controlling, by the first, the second, and the third enforcement points, network traffic to and from the respective first, the second, and the third virtual machines using the respective first, the second, and the third contextual security policies, such that the first, the second, and the third virtual machines are logically partitioned together into one logical subnetwork, the controlling including:

applying a first set of security rules to the network traffic into and out of the logical subnetwork, the first set of security rules determined using at least one of the first, the second, and the third contextual security policies; and

applying a second set of security rules to the network traffic within the logical subnetwork, the second set of security rules determined using one or more of the first, the second, and the third contextual security policies.

2. The method according to claim 1 , further comprising comparing the attributes of the first, the second, and the third virtual machines to security policies stored in a security policy database of a data center.

3. The method according to claim 1 , wherein the attributes of the first, the second, and the third virtual machines comprise a location of a data center where the first, the second, and the third virtual machines reside.

4. The method according to claim 1 , further comprising rejecting network traffic that violates at least one of the first and the second sets of security rules.

5. The method according to claim 1 , wherein the first virtual machine within the logical subnetwork is subject to different local security requirements, the different local security requirements manifesting in the first contextual security policy.

6. The method according to claim 5 , wherein the first virtual machine is located in a first country and the second and the third virtual machines are located in a second country, the first country being subject to a first set of security requirements and the second country being subject to a second set of security requirements, the first set of security requirements manifesting in the first contextual security policy, and the second set of security requirements manifesting in the second and the third contextual security policies.

7. The method of claim 1 , wherein at least two of the first, the second, and the third virtual machines are physically collocated in a data center.

8. The method of claim 1 , wherein at least one of the first, the second, and the third enforcement points is a virtual machine.

9. The method of claim 1 further comprising:

inspecting the received network traffic for malicious behavior.

10. The method of claim 9 , wherein the inspecting comprises:

performing stateful inspection of the received network traffic.

11. The method of claim 1 further comprising:

measuring network traffic associated with one of the first, the second, and the third virtual machines; and

determining that the measured network traffic is indicative of malicious behavior.

12. The method of claim 11 , wherein the determining includes:

comparing the measured network traffic to traffic rules, the traffic rules being included in at least one of the first, the second, and the third contextual security policies.

13. The method of claim 11 further comprising:

providing a warning about the malicious behavior when the malicious behavior is determined.

14. The method of claim 1 further comprising:

quarantining at least one of the first, the second, and the third virtual machines when network traffic associated with a respective one of the at least one of the first, the second, and the third virtual machines violates one or more of the first and the second sets of security rules.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded Jul 18, 2025
From: GRYPHO5, LLC
To: EVP CREDIT SPV I LP
Reel/Frame 072053/0141 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: VARMOUR NETWORKS, INC.
To: GRYPHO5, LLC
Reel/Frame 070287/0007 →
SECURITY INTEREST Recorded Feb 22, 2024
From: VARMOUR NETWORKS, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 066530/0399 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2018
From: SHIEH, CHOUNG-YAW; LIAN, JIA-JYI
To: VARMOUR NETWORKS, INC.
Reel/Frame 045436/0639 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNORS NAME PREVIOUSLY RECORDED AT REEL: 036906 FRAME: 0356. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jul 14, 2016
From: SHIEH, CHOUNG-YAW; LIAN, JIA-JYI; SUN, YI; XU, MENG
To: VARMOUR NETWORKS, INC.
Reel/Frame 039339/0077 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2015
From: SHIEH, CHOUNG-YAW MICHAEL; LIAN, JIA-JYI ROGER; SUN, YI; XU, MENG
To: VARMOUR NETWORKS, INC.
Reel/Frame 036906/0356 →