IP Library Granted Patent US 10,158,672
Granted Patent B2
US 10,158,672 · App. 15/255,132 · Granted Dec 18, 2018

Context aware microsegmentation

Inventors: Choung-Yaw Shieh (Palo Alto, CA); Jia-Jyi Lian (Saratoga, CA); Yi Sun (San Jose, CA); Meng Xu (Los Altos, CA)
Assignee: vArmour Networks, Inc.
H04L63/20G06F9/45558G06F21/55H04L63/0254H04L63/107H04L63/1408G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,158,672
App. No.
15/255,132
Granted
Dec 18, 2018
Kind
B2
Abstract

Context aware microservice networks and contextual security policies for microservice networks are provided herein. In some embodiments, a system includes a plurality of microservices, each of the plurality of microservices having a plurality of distributed microservice components. At least a portion of the distributed microservice components execute on different physical or virtual servers in a data center or a cloud. The system also includes a plurality of logical security boundaries, with each of the plurality of logical security boundaries being created by a plurality of enforcement points positioned in association with the plurality of distributed microservice components. Each of plurality of microservices is bounded by one of the plurality of logical security boundaries.

Claims (47)

1. A context aware microsegmented network, comprising:

an enforcement point creating a logical security boundary around at least a first and a second virtual machine collectively providing a microservice, the microservice comprising a first microservice component and a second microservice component, the first microservice component being provided by the first virtual machine, the second microservice component being provided by the second virtual machine, the enforcement point configured to:

select at least a first and a second contextual security policy based upon attributes of the first and the second virtual machines respectively; and

apply at least one of the first and the second contextual security policies to control network traffic of the first and the second virtual machines within the logical security boundary based on the attributes of the first and the second virtual machines; and

a central enforcement controller that:

determines a packet forwarding path for the enforcement point;

selects a third contextual security policy based on at least one of a location of the enforcement point and security attributes of the enforcement point; and

applies the third contextual security policy to network traffic into and out of the logical security boundary received by at least one of the location of the enforcement point or the packet forwarding path.

2. The context aware microsegmented network according to claim 1 , wherein the attributes of the first and the second virtual machines comprise a location of a data center where the first and second virtual machines reside.

3. The context aware microsegmented network according to claim 1 , wherein the first and the second virtual machines are physically collocated in a data center.

4. The context aware microsegmented network according to claim 1 , wherein the enforcement point is a virtual machine.

5. The context aware microsegmented network according to claim 1 , wherein network traffic that violates at least of the first contextual security policy, the second contextual security policy, and the third contextual security policy is rejected.

6. The context aware microsegmented network according to claim 1 , wherein network traffic that violates at least one of the first contextual security policy, the second contextual security policy, and the third contextual security policy is subjected to intrusion prevention scanning.

7. The context aware microsegmented network according to claim 1 , wherein the first virtual machine within the logical security boundary is subject to different local security requirements, the different local security requirements manifesting in the first contextual security policy.

8. The context aware microsegmented network according to claim 1 , wherein the first virtual machine is located in a first country and the second virtual machine is located in a second country, wherein the first country is subject to a first set of security requirements manifesting in the first contextual security policy and the second country is subject to a second set of security requirements manifesting in the second contextual security policy.

9. The context aware microsegmented network according to claim 1 , wherein the central enforcement controller further inspects the network traffic into and out of the logical security boundary for malicious behavior by performing a stateful inspection of the network traffic.

10. The context aware microsegmented network according to claim 1 , wherein the enforcement point quarantines at least one of the first and the second virtual machines when network traffic associated with a respective one of the first and the second virtual machines violates one or more of the first, the second and the third contextual security policies.

11. The context aware microsegmented network according to claim 1 , wherein the enforcement point measures network traffic associated with one of the first and the second virtual machines and determines the measured network traffic is indicative of malicious behavior.

12. The context aware microsegmented network according to claim 11 , wherein the determining includes comparing the measured network traffic to traffic rules, the traffic rules being included in at least one of the first, the second, and the third contextual security policies.

13. The context aware microsegmented network according to claim 11 , wherein the enforcement point further provides a warning for the malicious behavior when the malicious behavior is determined.

14. A method for context aware security policy enforcement, the method comprising:

selecting, by an enforcement point, at least a first and a second contextual security policy based upon attributes of at least a first and a second virtual machine respectively, the at least first and second virtual machines collectively providing a microservice, the microservice comprising a first microservice component and a second microservice component, the first microservice component being provided by the first virtual machine, the second microservice component being provided by the second virtual machine;

applying, by the enforcement point, at least one of the first and the second contextual security policies to control network traffic of the first and the second virtual machines within a logical security boundary based on the attributes of the first and the second virtual machines;

determining, by a central enforcement controller, a packet forwarding path for the enforcement point;

selecting, by the central enforcement controller, a third contextual security policy based on at least one of a location of the enforcement point and security attributes of the enforcement point; and

applying, by the central enforcement controller, the third contextual security policy to network traffic into and out of the logical security boundary received by at least one of the location of the enforcement point or the packet forwarding path.

15. The method according to claim 14 , wherein the attributes of the first and the second virtual machines comprise a location of a data center where the first and the second virtual machines reside.

16. The method according to claim 14 , wherein the first and the second virtual machines are physically collocated in a data center.

17. The method according to claim 14 , wherein the enforcement point is a virtual machine.

18. The method according to claim 14 , further comprising rejecting network traffic that violates at least one of the first contextual security policy, the second contextual security policy, and the third contextual security policy.

19. The method according to claim 14 , further comprising subjecting network traffic that violates at least one of the first contextual security policy, the second contextual security policy, and the third contextual security policy to intrusion prevention scanning.

20. The method according to claim 14 , further comprising subjecting the first virtual machine within the logical security boundary to different local security requirements, the different local security requirements manifesting in the first contextual security policy.

21. The method according to claim 14 , wherein the first virtual machine is located in a first country and the second virtual machine is located in a second country, wherein the first country is subject to a first set of security requirements manifesting in the first contextual security policy and the second country is subject to a second set of security requirements manifesting in the second contextual security policy.

22. The method according to claim 14 , wherein the central enforcement controller further inspects the network traffic into and out of the logical security boundary for malicious behavior by performing a stateful inspection of the network traffic.

23. The method according to claim 14 , further comprising quarantining at least one of the first and the second virtual machines when network traffic associated with a respective one of the first and the second virtual machines violates one or more of the first, the second and the third contextual security policies.

24. The method according to claim 14 , further comprising:

measuring network traffic associated with one of the first and the second virtual machines; and

determining the measured network traffic is indicative of malicious behavior.

25. The method according to claim 24 , wherein the determining includes comparing the measured network traffic to traffic rules, the traffic rules being included in at least one of the first, the second, and the third contextual security policies.

26. The method according to claim 24 , further comprising:

providing a warning for the malicious behavior when the malicious behavior is determined.

27. A non-transitory computer-readable storage medium having embodied thereon a program, the program being executable by a processor to perform a method, the method comprising:

selecting, by an enforcement point, at least a first and a second contextual security policy based upon attributes of at least a first and a second virtual machine respectively, the at least first and second virtual machines collectively providing a microservice, the microservice comprising a first microservice component and a second microservice component, the first microservice component being provided by the first virtual machine, the second microservice component being provided by the second virtual machine;

applying, by the enforcement point, at least one of the first and the second contextual security policies to control network traffic of the first and the second virtual machines within a logical security boundary based on the attributes of the first and the second virtual machines;

determining, by a central enforcement controller, a packet forwarding path for the enforcement point;

selecting, by the central enforcement controller, a third contextual security policy based on at least one of a location of the enforcement point and security attributes of the enforcement point; and

applying, by the central enforcement controller, the third contextual security policy to network traffic into and out of the logical security boundary received by at least one of the location of the enforcement point or the packet forwarding path.

Assignments (5)
PATENT SECURITY AGREEMENT Recorded Jul 18, 2025
From: GRYPHO5, LLC
To: EVP CREDIT SPV I LP
Reel/Frame 072053/0141 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: VARMOUR NETWORKS, INC.
To: GRYPHO5, LLC
Reel/Frame 070287/0007 →
SECURITY INTEREST Recorded Feb 22, 2024
From: VARMOUR NETWORKS, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 066530/0399 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2018
From: SHIEH, CHOUNG-YAW; LIAN, JIA-JYI
To: VARMOUR NETWORKS, INC.
Reel/Frame 045461/0934 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2016
From: SHIEH, CHOUNG-YAW; LIAN, JIA-JYI; SUN, YI; XU, MENG
To: VARMOUR NETWORKS, INC.
Reel/Frame 039910/0896 →
Continuity (2)
Continuation 14839649 · Aug 28, 2015
Related Publication 20170063933A1 · Mar 2, 2017
Cited By (3)
US 12,309,202 US 12,368,736 US 12,549,571