IP Library › Patent Application 15873896
Patent Application
App. No. 15/873,896

User-Based Visibility and Control of a Segmentation Policy

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/873,896
Abstract

A segmentation server enables user-based management of a segmentation policy. Administrators belonging to different user groups may have different limited visibility into traffic flows controlled by the segmentation policy and may be assigned different privileges with respect to viewing, creating, and modifying rules of the segmentation policy. Thus, the burden of administering the segmentation policy may be distributed between administrators associated with different user groups that each may have responsibility for a different segment.

Claims (86)

1 . A method for facilitating creation of a segmentation policy controlling communications between a plurality of workloads, the method comprising:

identifying a user group associated with an administrator logged into an administrative client accessing a segmentation server;

identifying, from a user group database, a group of label sets associated with the user group;

identifying, from a workload database, a subset of workloads of the plurality of workloads having at least one of the group of label sets associated with the user group;

generating a set of rules for controlling communications associated with the subset of workloads;

generating management instructions for enforcing the set of rules; and

sending the management instructions to respective operating system instances executing the subset of workloads, wherein the respective operating system instances enforce the set of rules based on the management instructions.

2 . The method of claim 1 , further comprising:

monitoring traffic flows associated with the subset of workloads;

generating a traffic flow graph based on the monitored traffic flows, the traffic flow graph comprising a plurality of nodes representing the subset of workloads, and a plurality of edges representing the monitored traffic flows between the subset of workloads;

generating a graphical representation of the traffic flow graph; and

outputting the graphical representation of the traffic flow graph to the administrative client.

3 . The method of claim 1 , wherein generating the set of rules comprises:

generating a rule permitting any communications between workloads having a same predefined label set.

4 . The method of claim 1 , wherein generating the set of rules comprises:

monitoring traffic flows associated with the subset of workloads; and

generating the set of rules based on the monitored traffic flows, the set of rules permitting the monitored traffic flows.

5 . The method of claim 4 , wherein generating the set of rules comprises:

detecting traffic flow between a first workload in the subset of workloads and a second workload in the plurality of workloads;

determining a first label set associated with the first workload and a second label set associated with the second workload; and

generating a rule permitting communications between workloads having the first label set and workloads having the second label set.

6 . The method of claim 4 , wherein generating the set of rules comprises:

detecting traffic flow between a first workload in the subset of workloads and a second workload in the plurality of workloads;

detecting one or more ports and one or more protocols over which the traffic flow is communicated;

determining a first label set associated with the first workload and a second label set associated with the second workload; and

generating a rule permitting communications using the one or more ports and the one or more protocols between workloads having the first label set and workloads having the second label set.

7 . The method of claim 1 , wherein generating the rule set comprises:

determining that the user group has limited ruleset creation privileges; and

generating the rule set to only include rules permitting communications between pairs workloads in the subset of workloads that both have at least one of the group of label sets associated with the user group.

8 . The method of claim 1 , wherein generating the initial rule set comprises:

determining that the user group has expanded ruleset creation privileges; and

generating the rule set to include rules permitting communications in which a workload in the subset of workloads having at least one of the group of label sets associated with the user group provides a service to a workload outside the subset of workloads.

9 . The method of claim 1 , wherein generating the management instructions comprises:

storing the rules to a rules database;

identifying access of the segmentation server by a provisioner associated with a provisioner user group;

generating a user interface presenting the rules for review; and

generating the management instructions responsive to receiving confirmation from the provisioner via the user interface to implement the rules.

10 . A non-transitory computer-readable storage medium storing instructions executable by one or more processors for facilitating creation of a segmentation policy, the instructions when executed causing the one or more processors to perform steps including:

identifying a user group associated with an administrator logged into an administrative client accessing a segmentation server;

identifying, from a user group database, a group of label sets associated with the user group;

identifying, from a workload database, a subset of workloads of the plurality of workloads having at least one of the group of label sets associated with the user group;

generating a set of rules for controlling communications associated with the subset of workloads;

generating management instructions for enforcing the set of rules; and

sending the management instructions to respective operating system instances executing the subset of workloads, wherein the respective operating system instances enforce the set of rules based on the management instructions.

11 . The non-transitory computer-readable storage medium of claim 10 , wherein the instructions when executed further cause the processor to perform steps including:

monitoring traffic flows associated with the subset of workloads;

generating a traffic flow graph based on the monitored traffic flows, the traffic flow graph comprising a plurality of nodes representing the subset of workloads, and a plurality of edges representing the monitored traffic flows between the subset of workloads;

generating a graphical representation of the traffic flow graph; and

outputting the graphical representation of the traffic flow graph to the administrative client.

12 . The non-transitory computer-readable storage medium of claim 10 , wherein generating the set of rules comprises:

generating a rule permitting any communications between workloads having a same predefined label set.

13 . The non-transitory computer-readable storage medium of claim 10 , wherein generating the set of rules comprises:

monitoring traffic flows associated with the subset of workloads; and

generating the set of rules based on the monitored traffic flows, the set of rules permitting the monitored traffic flows.

14 . The non-transitory computer-readable storage medium of claim 13 , wherein generating the set of rules comprises:

detecting traffic flow between a first workload in the subset of workloads and a second workload in the plurality of workloads;

determining a first label set associated with the first workload and a second label set associated with the second workload; and

generating a rule permitting communications between workloads having the first label set and workloads having the second label set.

15 . The non-transitory computer-readable storage medium of claim 13 , wherein generating the set of rules comprises:

detecting traffic flow between a first workload in the subset of workloads and a second workload in the plurality of workloads;

detecting one or more ports and one or more protocols over which the traffic flow is communicated;

determining a first label set associated with the first workload and a second label set associated with the second workload; and

generating a rule permitting communications using the one or more ports and the one or more protocols between workloads having the first label set and workloads having the second label set.

16 . The non-transitory computer-readable storage medium of claim 10 , wherein generating the rule set comprises:

determining that the user group has limited ruleset creation privileges; and

generating the rule set to only include rules permitting communications between pairs workloads in the subset of workloads that both have at least one of the group of label sets associated with the user group.

17 . The non-transitory computer-readable storage medium of claim 10 , wherein generating the initial rule set comprises:

determining that the user group has expanded ruleset creation privileges; and

generating the rule set to include rules permitting communications in which a workload in the subset of workloads having at least one of the group of label sets associated with the user group provides a service to a workload outside the subset of workloads.

18 . A system for facilitating creation of a segmentation policy, the system comprising:

one or more processors; and

a non-transitory computer-readable storage medium storing instructions executable by the one or more processors, the instructions when executed causing the one or more processor to perform steps including:

identifying a user group associated with an administrator logged into an administrative client accessing a segmentation server;

identifying, from a user group database, a group of label sets associated with the user group;

identifying, from a workload database, a subset of workloads of the plurality of workloads having at least one of the group of label sets associated with the user group;

generating a set of rules for controlling communications associated with the subset of workloads;

generating management instructions for enforcing the set of rules; and

sending the management instructions to respective operating system instances executing the subset of workloads, wherein the respective operating system instances enforce the set of rules based on the management instructions.

19 . The system of claim 18 , wherein the instructions when executed further cause the one or more processors to perform steps including:

monitoring traffic flows associated with the subset of workloads;

generating a traffic flow graph based on the monitored traffic flows, the traffic flow graph comprising a plurality of nodes representing the subset of workloads, and a plurality of edges representing the monitored traffic flows between the subset of workloads;

generating a graphical representation of the traffic flow graph; and

outputting the graphical representation of the traffic flow graph to the administrative client.

20 . The system of claim 18 , wherein generating the set of rules comprises:

monitoring traffic flows associated with the subset of workloads; and

generating the set of rules based on the monitored traffic flows, the set of rules permitting the monitored traffic flows.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2018
From: KIRNER, PAUL J.; BALASUBRAMANIAM, DHANALAKSHMI; FORD, SETH BRUCE; GUPTA, MUKESH; GLENN, MATTHEW K.
To: ILLUMIO, INC.
Reel/Frame 044660/0278 →