IP Library Granted Patent US 10,721,273
Granted Patent B2
US 10,721,273 · App. 15/791,840 · Granted Jul 21, 2020

Automated security policy

Inventor: Dmitri Rubakha (Santa Clara, CA)
Assignee: McAfee LLC
H04L63/20G06F8/61G06F9/45545G06F9/45558G06F21/53G06F21/566H04L63/105G06F8/63G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,721,273
App. No.
15/791,840
Granted
Jul 21, 2020
Kind
B2
Abstract

There is disclosed a computing apparatus, including: a hardware platform; a service mapping requirements table including a plurality of components and having associated therewith a plurality of service requirements; an isolation platform; and a security policy engine configured to: receive a new appliance image for the isolation platform; scan the new appliance image and build a bill of materials (BoM) for the new container image, the BoM including a plurality of components; search the service mapping requirements table for the plurality of components and identify service requirements for the components; and generate a security policy for the new appliance image.

Claims (45)

1. A computing apparatus, comprising:

a hardware platform;

a service mapping requirements table comprising a plurality of components and having associated therewith a plurality of service requirements;

an isolation platform; and

a security policy engine configured to:

receive a new appliance image for the isolation platform;

scan the new appliance image, comprising hashing components and comparing the hash to a hash of a known good version, and build a bill of materials (BoM) for the new appliance image, the BoM comprising a list of layers and software components of the appliance image;

search the service mapping requirements table for the layers and software components, and identify security service requirements for the layers and software components; and

generate a security policy for the new appliance image according to the security service requirements.

2. The computing apparatus of claim 1 , wherein the isolation platform is a hypervisor or virtual machine manager.

3. The computing apparatus of claim 1 , wherein the isolation platform is a container platform, and wherein the appliance image is a container image.

4. The computing apparatus of claim 1 , wherein the security policy engine is further to receive an update for the service mapping requirements table, and to update the security policy according to the update.

5. The computing apparatus of claim 1 , wherein scanning the new appliance image comprises a binary scan.

6. The computing apparatus of claim 1 , wherein scanning the new appliance image further comprises scanning headers of one or more components.

7. The computing apparatus of claim 1 , wherein the plurality of components comprises a composite component including a plurality of discrete components.

8. The computing apparatus of claim 1 , wherein the security policy is an intrusion prevention system (IPS) or intrusion detection system (IDS) policy.

9. The computing apparatus of claim 8 , wherein the security policy engine is further to push the security policy to an IPS or IDS.

10. One or more tangible, non-transitory computer-readable storage mediums having stored thereon executable instructions to instruct a hardware computer platform to:

provision a service mapping requirements table comprising a plurality of software components and having associated therewith a plurality of service requirements for the software components;

provide an isolation platform;

receive a new appliance image for the isolation platform;

scan the new appliance image, comprising hashing components and comparing the hash to a hash of a known good version, and build a listing of software components for the new appliance image;

search the service mapping requirements table for the plurality of software components and identify associated service requirements for the components; and

generate a security policy for the new appliance image from the associated security requirements.

11. The one or more tangible, non-transitory computer-readable mediums of claim 10 , wherein the isolation platform is a hypervisor or virtual machine manager.

12. The one or more tangible, non-transitory computer-readable mediums of claim 10 , wherein the isolation platform is a container platform, and wherein the appliance image is a container image.

13. The one or more tangible, non-transitory computer-readable mediums of claim 10 , wherein the security policy engine is further to receive an update for the service mapping requirements table, and to update the security policy according to the update.

14. The one or more tangible, non-transitory computer-readable mediums of claim 10 , wherein scanning the new appliance image comprises a binary scan.

15. The one or more tangible, non-transitory computer-readable mediums of claim 10 , wherein scanning the new appliance image further comprises scanning headers of one or more components.

16. The one or more tangible, non-transitory computer-readable mediums of claim 10 , wherein the plurality of components comprises a composite component including a plurality of discrete components.

17. The one or more tangible, non-transitory computer-readable mediums of claim 10 , wherein the security policy is an intrusion prevention system (IPS) or intrusion detection system (IDS) policy.

18. The one or more tangible, non-transitory computer-readable mediums of claim 17 , wherein the security policy engine is further to push the security policy to an IPS or IDS.

19. A computer-implemented method of providing an automated security policy, comprising:

provisioning a service mapping requirements table associating one or more security requirements with each of a plurality of software layers and/or components;

providing an isolation platform;

receiving a new appliance image for the isolation platform;

scanning the new appliance image to identify software layers and/or components of the new appliance image, comprising hashing components and comparing the hash to a hash of a known good version;

searching the service mapping requirements table for the software layers and/or components of the new appliance image and for associated security requirements; and

generating a security policy for the new appliance image, including policy derived from the associated security requirements.

20. The method of claim 19 , wherein the isolation platform is a hypervisor or virtual machine manager.

21. The method of claim 19 , wherein the isolation platform is a container platform, and wherein the appliance image is a container image.

22. The method of claim 19 , wherein the security policy engine is further to receive an update for the service mapping requirements table, and to update the security policy according to the update.

23. The method of claim 19 , wherein scanning the new appliance image comprises a binary scan.

24. The method of claim 19 , wherein scanning the new appliance image further comprises scanning headers of one or more components.

25. The method of claim 19 , wherein the plurality of components comprises a composite component including a plurality of discrete components.

Assignments (14)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2018
From: RUBAKHA, DMITRI
To: MCAFEE, LLC
Reel/Frame 045564/0506 →
Continuity (2)
Provisional Application 62413134 · Oct 26, 2016
Related Publication 20180115585A1 · Apr 26, 2018
Cited By (2)
US 12,323,301 US 12,457,276