IP Library Granted Patent US 10,958,519
Granted Patent B2
US 10,958,519 · App. 16/696,679 · Granted Mar 23, 2021

Dynamic, load-based, auto-scaling network security microservices architecture

Inventors: Ratinder Paul Singh Ahuja (Saratoga, CA); Manuel Nedbal (Santa Clara, CA)
Assignee: ShieldX Networks, Inc.
H04L41/0816G06F21/554H04L41/08H04L41/0803H04L63/0227H04L63/101H04L63/20H04L67/1002H04L67/1031H04L67/16H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,958,519
App. No.
16/696,679
Granted
Mar 23, 2021
Kind
B2
Abstract

System, methods, and apparatuses used to monitor network traffic of a datacenter and report security threats are described. For example, one embodiment selects a first microservice of a first hierarchy, configures the microservices of a second lower-level hierarchy to remove the first microservice from load balancing decisions to the first hierarchy, moves the first microservice to another server, configures data plane connectivity to the first microservice to reflect a change in server, and configures the microservices of the second hierarchy to include the first microservice in load balancing decisions to the first hierarchy.

Claims (38)

1. A computer-implemented method comprising:

selecting a first security microservice of a first level of a hierarchy of security microservices, the first security microservice accepting serviced data from a second security microservice of a second lower-level of the hierarchy of security microservices;

configuring the second security microservice of the second lower-level of the hierarchy of security microservices to remove the first security microservice from load balancing decisions to the first level of the hierarchy;

moving the first security microservice to another server;

configuring data plane connectivity to the first security microservice to reflect a change to the another server; and

configuring the second security microservice of the second lower-level of the hierarchy to include the first security microservice in load balancing decisions to the second lower-level of the hierarchy.

2. The computer-implemented method of claim 1 , wherein the first security microservice was created by an existing microservice.

3. The computer-implemented method of claim 2 , wherein the existing microservice is a configuration microservice.

4. The computer-implemented method of claim 2 , wherein the first security microservice of the first level of the hierarchy and the second security microservice of the second lower-level of the hierarchy communicate over a backplane.

5. The computer-implemented method of claim 4 , wherein the first security microservice is configured to use the data plane.

6. The computer-implemented method of claim 5 , wherein there exists, prior to the moving of the first security microservice to the another server, a microservice of a same hierarchy level as the first security microservice.

7. The computer-implemented method of claim 1 , wherein the load balancing decisions utilize information from a third security microservice of a third higher-level of the hierarchy than the first level of the hierarchy.

8. The computer-implemented method of claim 7 , wherein data plane connectivity is configured through communication on a backplane.

9. The computer-implemented method of claim 1 , wherein a backplane and data plane comprise managed networks.

10. A non-transitory computer-readable medium storing instructions, which when executed by a processor cause the processor to perform a method, the method comprising:

selecting a first security microservice of a first level of a hierarchy of security microservices, the first security microservice accepting serviced data from a second security microservice of a second lower-level of the hierarchy of security microservices;

configuring the second security microservice of the second lower-level of the hierarchy of security microservices to remove the first security microservice from load balancing decisions to the first level of the hierarchy;

moving the first security microservice to another server;

configuring data plane connectivity to the first security microservice to reflect a change to the another server; and

configuring the second security microservice of the second lower-level of the hierarchy to include the first security microservice in load balancing decisions to the second lower-level of the hierarchy.

11. The non-transitory computer-readable medium of claim 10 , wherein the first security microservice was created by an existing microservice.

12. The non-transitory computer-readable medium of claim 11 , wherein the existing microservice is a configuration microservice.

13. The non-transitory computer-readable medium of claim 11 , wherein the first security microservice of the first level of the hierarchy and the second security microservice of the second lower-level of the hierarchy communicate over a backplane.

14. The non-transitory computer-readable medium of claim 13 , wherein the first security microservice is configured to use the data plane.

15. The non-transitory computer-readable medium of claim 14 , wherein there exists, prior to the moving of the first security microservice to the another server, a microservice of a same hierarchy level as the first security microservice.

16. The non-transitory computer-readable medium of claim 10 , wherein the load balancing decisions utilize information from a third security microservice of a third higher-level of the hierarchy than the first level of the hierarchy.

17. The non-transitory computer-readable medium of claim 16 , wherein data plane connectivity is configured through communication on a backplane.

18. An apparatus comprising:

a hardware processor to execute instructions; and

memory coupled to the processor, the memory to store the instructions which when executed by the processor cause:

selecting a first security microservice of a first level of a hierarchy of security microservices, the first security microservice to accept serviced data from a second security microservice of a second lower-level of the hierarchy of security microservices,

configuring the second security microservice of the second lower-level of the hierarchy of security microservices to remove the first security microservice from load balancing decisions to the first level of the hierarchy,

moving the first security microservice to another server,

configuring data plane connectivity to the first security microservice to reflect a change to the another server, and

configuring the second security microservice of the second lower-level of the hierarchy to include the first security microservice in load balancing decisions to the second lower-level of the hierarchy.

19. The apparatus of claim 18 , wherein the first security microservice of the first level of the hierarchy and the second security microservice of the second lower-level of the hierarchy communicate over a backplane.

20. The apparatus of claim 18 , wherein

the load balancing decisions utilize information from a third security microservice of a third higher-level of the hierarchy than the first level of the hierarchy.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2021
From: SHIELDX NETWORKS, INC.
To: FORTINET, INC.
Reel/Frame 056227/0125 →
RELEASE OF SECURITY INTEREST Recorded Mar 15, 2021
From: COMERICA BANK
To: SHIELDX NETWORKS, INC.
Reel/Frame 055585/0847 →
SECURITY INTEREST Recorded Jul 27, 2020
From: SHIELDX NETWORKS, INC.
To: COMERICA BANK
Reel/Frame 053313/0544 →
Continuity (4)
Continuation 16174884 · Oct 30, 2018
Continuation 15194561 · Jun 27, 2016
Continuation 15182573 · Jun 14, 2016
Related Publication 20200195503A1 · Jun 18, 2020
Cited By (2)
US 12,368,736 US 12,549,571