IP Library Granted Patent US 10,911,493
Granted Patent B2
US 10,911,493 · App. 15/921,446 · Granted Feb 2, 2021

Identifying communication paths between servers for securing network communications

Inventors: Ratinder Paul Singh Ahuja (Saratoga, CA); Manuel Nedbal (Santa Clara, CA); Meni Hillel (San Jose, CA)
Assignee: SHIELDX NETWORKS, INC.
H04L63/20H04L43/08H04L63/1425H04L43/062H04L43/0829
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,911,493
App. No.
15/921,446
Granted
Feb 2, 2021
Kind
B2
Abstract

Systems, methods, and apparatuses enable a microservice to identify server-to-server communication paths between servers in a networked environment. The system identifies a server connected to a security microservice managed by a management microservice. The system deploys a security policy on the identified server, and identifies the server-to-server communication paths between the identified server and one or more of a plurality of servers. The system identifies the active communication paths from the identified server to one or more of a plurality of servers, or a subset of communication paths determined based on search criteria. When the system identifies servers of the one or more of the plurality of servers without an existing security policy, the system processes the identified server. In one embodiment, processing the identified servers includes applying a security policy to the identified servers.

Claims (47)

1. A computer-implemented method comprising:

identifying, by a management microservice, a first server connected to a security microservice managed by the management microservice;

deploying a first security policy on the first server;

identifying server-to-server communication paths between the first server and one or more of a plurality of servers;

determining a subset of the identified server-to-server communication paths from the first server based on one or more criteria of the identified server-to-server communication paths, wherein the one or more criteria of the identified server-to-server communication paths includes frequency of use of the identified server-to-server communication paths, amount of time the identified server-to-server communication paths are active, an amount of traffic transmitted across the identified server-to-server communication paths, and a type of data transmitted across the identified server-to-server communication paths;

identifying servers without a security policy from the subset of the identified server-to-server communication paths; and

for each identified server without the security policy, processing the identified server.

2. The computer-implemented method of claim 1 , wherein processing the identified server comprises:

deploying a second security policy to the identified server.

3. The computer-implemented method of claim 2 , wherein the deployed first security policy is determined based on a server type of the identified server.

4. The computer-implemented method of claim 1 , further comprising:

determining the management microservice is not enabled to monitor communications from the first server to the one or more of the plurality of servers; and

enabling monitoring of communications between the first server and the one or more of the plurality of servers.

5. The computer-implemented method of claim 4 , wherein the enabling of the monitoring of the communications between the first server and the one or more of the plurality of servers comprises:

deploying an interface microservice on the first server.

6. One or more non-transitory computer-readable storage media storing instructions which, when executed by one or more hardware processors, cause performance of a method comprising:

identifying, by a management microservice, a first server connected to a security microservice managed by the management microservice;

deploying a first security policy on the first server;

identifying server-to-server communication paths between the first server and one or more of a plurality of servers;

determining a subset of the identified server-to-server communication paths from the first server based on one or more criteria of the identified server-to-server communication paths, wherein the one or more criteria of the identified server-to-server communication paths includes frequency of use of the identified server-to-server communication paths, amount of time the identified server-to-server communication paths are active, an amount of traffic transmitted across the identified server-to-server communication paths, and a type of data transmitted across the identified server-to-server communication paths;

identifying servers without a security policy from the subset of the identified server-to-server communication paths; and

for each identified server without the security policy, processing the identified server.

7. The one or more non-transitory computer-readable storage media of claim 6 , wherein processing the identified server comprises:

deploying a second security policy to the identified server.

8. The one or more non-transitory computer-readable storage media of claim 7 , wherein the deployed first security policy is determined based on a server type of the identified server.

9. The one or more non-transitory computer-readable storage media of claim 6 , further comprising:

determining the management microservice is not enabled to monitor communications from the first server to the one or more of the plurality of servers; and

enabling monitoring of communications between the first server and the one or more of the plurality of servers.

10. The one or more non-transitory computer-readable storage media of claim 9 , wherein the enabling of the monitoring of the communications between the first server and the one or more of the plurality of servers comprises:

deploying an interface microservice on the first server.

11. An apparatus comprising:

one or more hardware processors;

memory coupled to the one or more hardware processors, the memory storing instructions which, when executed by the one or more hardware processors, causes the apparatus to

identify, by a management microservice, a first server connected to a security microservice managed by the management microservice;

deploy a first security policy on the first server;

identify server-to-server communication paths between the first server and one or more of a plurality of servers;

determine a subset of the identified server-to-server communication paths from the first server based on one or more criteria of the identified server-to-server communication paths, wherein the one or more criteria of the identified server-to-server communication paths includes frequency of use of the identified server-to-server communication paths, amount of time the identified server-to-server communication paths are active, an amount of traffic transmitted across the identified server-to-server communication paths, and a type of data transmitted across the identified server-to-server communication paths;

identify servers without a security policy from the subset of the identified server-to-server communication paths; and

for each identified server without the security policy, process the identified server.

12. The apparatus of claim 11 , wherein processing the identified server comprises:

deploying a second security policy to the identified server.

13. The apparatus of claim 12 , wherein the deployed first security policy is determined based on a server type of the identified server.

14. The apparatus of claim 11 , wherein the instructions further cause the apparatus to:

determine the management microservice is not enabled to monitor communications from the first server to the one or more of the plurality of servers; and

enable monitoring of communications between the first server and the one or more of the plurality of servers.

15. The apparatus of claim 14 , wherein the enabling of the monitoring of the communications between the first server and the one or more of the plurality of servers comprises:

deploying an interface microservice on the first server.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2021
From: SHIELDX NETWORKS, INC.
To: FORTINET, INC.
Reel/Frame 055661/0470 →
RELEASE OF SECURITY INTEREST Recorded Mar 15, 2021
From: COMERICA BANK
To: SHIELDX NETWORKS, INC.
Reel/Frame 055585/0847 →
SECURITY INTEREST Recorded Jul 27, 2020
From: SHIELDX NETWORKS, INC.
To: COMERICA BANK
Reel/Frame 053313/0544 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2018
From: AHUJA, RATINDER PAUL SINGH; NEDBAL, MANUEL; HILLEL, MENI
To: SHIELDX NETWORKS, INC.
Reel/Frame 045307/0529 →
Continuity (1)
Related Publication 20190289035A1 · Sep 19, 2019
Cited By (1)
US 12,368,736