IP Library Granted Patent US 11,120,148
Granted Patent B2
US 11,120,148 · App. 16/245,242 · Granted Sep 14, 2021

Dynamically applying application security settings and policies based on workload properties

Inventors: Rajiv Sreedhar (Sunnyvale, CA); Ratinder Paul Singh Ahuja (Saratoga, CA); Manuel Nedbal (Santa Clara, CA); Damodar Hegde (Cupertino, CA); Jitendra Gaitonde (Cupertino, CA); Manoj Ahluwalia (San Jose, CA); Stuart Gibson (Seattle, WA)
Assignee: Fortinet, Inc.
G06F21/604G06F9/45558G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,120,148
App. No.
16/245,242
Granted
Sep 14, 2021
Kind
B2
Abstract

Systems, methods, and apparatuses enable a security orchestrator to detect a virtual machine deployed in a virtual environment. The virtual machine includes a tag storing information associated with the virtual machine. The security orchestrator determines that the tag contains one or more security elements, the security elements indicating information for determining security settings and policies to be applied to the virtual machine. The security orchestrator determines the security settings and policies associated with the one or more security elements. The security orchestrator then assigns or applies the security settings and policies for the virtual machine based on values of the one or more security elements.

Claims (56)

1. A computer-implemented method comprising:

detecting a virtual machine deployed in a virtual environment, the virtual machine including a tag storing information associated with the virtual machine;

determining the tag contains one or more security elements, the security elements indicating information for determining security settings and policies to be applied to the virtual machine, and wherein the security elements are hierarchical security elements;

determining the security settings and policies associated with the one or more security elements; and

applying the security settings and policies for the virtual machine based on values of the one or more security elements.

2. The computer-implemented method of claim 1 , wherein determining the security settings and policies associated with the one or more security elements further comprises:

identifying values of each security element of the one or more security elements; and

accessing a policy store to determine the security settings and policies based on at least one of the identified values.

3. The computer-implemented method of claim 1 , further comprising:

receiving network traffic from the virtual machine; and

applying a security action to the received network traffic from the virtual machine.

4. The computer-implemented method of claim 3 , wherein the security action includes applying the security settings and policies to block the received network traffic from the virtual machine from being sent.

5. The computer-implemented method of claim 3 , wherein the security action includes configuring a microservice to perform security processing.

6. The computer-implemented method of claim 1 , wherein metadata is used to abstract the values of the security elements.

7. The computer-implemented method of claim 1 , further comprising:

receiving network traffic from the virtual machine;

applying a security action to traffic directed to the virtual machine.

8. The computer-implemented method of claim 1 , wherein the security settings and policies includes configuring a capture interface to inspect network traffic received from the virtual machine.

9. One or more non-transitory computer-readable storage media storing instructions which, when executed by one or more hardware processors, cause performance of a method comprising:

detecting a virtual machine deployed in a virtual environment, the virtual machine including a tag storing information associated with the virtual machine;

determining whether the tag contains one or more security elements, the security elements indicating information for determining security settings and policies to be applied to the virtual machine, and wherein the security elements are hierarchical security elements;

determining the security settings and policies associated with the one or more security elements; and

applying the security settings and policies for the virtual machine based on values of the one or more security elements.

10. The one or more non-transitory computer-readable storage media of claim 9 , wherein determining the security settings and policies associated with the one or more security elements further comprises:

identifying values of each security element of the one or more security elements; and

accessing a policy store to determine the security settings and policies based on at least one of the identified values.

11. The one or more non-transitory computer-readable storage media of claim 9 , further comprising:

receiving network traffic from the virtual machine; and

applying a security action to the received network traffic from the virtual machine.

12. The one or more non-transitory computer-readable storage media of claim 11 , wherein the security action includes applying the security settings and policies to block the received network traffic from the virtual machine from being sent.

13. The one or more non-transitory computer-readable storage media of claim 11 , wherein the security action includes configuring a microservice to perform security processing.

14. The one or more non-transitory computer-readable storage media of claim 9 , wherein metadata is used to abstract the values of the security elements.

15. The one or more non-transitory computer-readable storage media of claim 9 , further comprising:

receiving network traffic from the virtual machine; and

applying a security action to traffic directed to the virtual machine.

16. The one or more non-transitory computer-readable storage media of claim 9 , wherein the security settings and policies includes configuring a capture interface to inspect network traffic received from the virtual machine.

17. An apparatus comprising:

one or more hardware processors;

memory coupled to the one or more hardware processors, the memory storing instructions which, when executed by the one or more hardware processors, causes the apparatus to:

detect a virtual machine deployed in a virtual environment, the virtual machine including a tag storing information associated with the virtual machine;

determine whether the tag contains one or more security elements, the security elements indicating information for determining security settings and policies to be applied to the virtual machine, and wherein the security elements are hierarchical security elements;

determine the security settings and policies associated with the one or more security elements; and

apply the security settings and policies for the virtual machine based on values of the one or more security elements.

18. The apparatus of claim 17 , wherein determining the security settings and policies associated with the one or more security elements further causes the apparatus to:

identify values of each security element of the one or more security elements; and

access a policy store to determine the security settings and policies based on at least one of the identified values.

19. The apparatus of claim 17 , wherein the instructions further causes the apparatus to:

receive network traffic from the virtual machine; and

apply a security action to the received network traffic from the virtual machine.

20. The apparatus of claim 19 , wherein the security action includes applying the security settings and policies to block the received network traffic from the virtual machine from being sent.

21. The apparatus of claim 19 , wherein the security action includes configuring a microservice to perform security processing.

22. The apparatus of claim 17 , metadata is used to abstract the values of the security elements.

23. The apparatus of claim 17 , wherein the instructions further causes the apparatus to:

receive network traffic from the virtual machine; and

apply a security action to traffic directed to the virtual machine.

24. The apparatus of claim 17 , wherein the security settings and policies includes configuring a capture interface to inspect network traffic received from the virtual machine.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2021
From: SHIELDX NETWORKS, INC.
To: FORTINET, INC.
Reel/Frame 055661/0470 →
RELEASE OF SECURITY INTEREST Recorded Mar 15, 2021
From: COMERICA BANK
To: SHIELDX NETWORKS, INC.
Reel/Frame 055585/0847 →
SECURITY INTEREST Recorded Jul 27, 2020
From: SHIELDX NETWORKS, INC.
To: COMERICA BANK
Reel/Frame 053313/0544 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2019
From: GIBSON, STUART
To: SHIELDX NETWORKS, INC.
Reel/Frame 048298/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2019
From: SREEDHAR, RAJIV; AHUJA, RATINDER PAUL SINGH; NEDBAL, MANUEL; HEGDE, DAMODAR; GAITONDE, JITENDRA; AHLUWALIA, MANOJ
To: SHIELDX NETWORKS, INC.
Reel/Frame 048053/0460 →
Continuity (1)
Related Publication 20200226271A1 · Jul 16, 2020
Cited By (3)
US 12,261,875 US 12,627,667 US 12,645,922