Dynamic security policy management
Security policies can be dynamically updated in response to changes in endpoints associated with those policies. A user can indicate one or more regions or networks from which access is to be granted under a specific security policy. The user can subscribe to receive notifications upon a change relating to those endpoints, such as the addition or removal of one or more endpoints. When a change is detected, new policy information can be generated automatically and published for subscribed policies, which can then have the updates applied automatically or provided for manual review and application. Such a process enables access determinations to be made based upon up-to-date endpoint information.
1. A computer-implemented method, comprising:
detecting, by a poller, a change in network endpoints associated with a sub-network, the network endpoints related to a subscription that is associated with a network endpoint topic and that is associated with a security policy for a resource, the security policy including an indication from an entity associated with the sub-network to automatically update policy information responsive to the change in the network endpoints;
publishing, on the network endpoint topic, new policy information associated with the change in the network endpoints;
determining, based at least in part on the security policy, that the new policy information should be applied; and
causing the new policy information to be applied for the security policy, wherein the security policy including the new policy information will be enforced for a subsequent access request relating to the resource.
2. The computer-implemented method of claim 1 , further comprising:
causing the new policy information to be applied for the security policy using a policy manager of a resource provider environment, the resource being at least one of a physical computing resource or a virtual computing resource provided using resources of the resource provider environment.
3. The computer-implemented method of claim 1 , further comprising:
receiving the new policy information to a customer policy manager;
generating a notification to a customer resource administrator regarding the new policy information; and
causing the new policy information to be applied for the security policy by enabling the customer resource administrator to manually review and apply the new policy information for the security policy.
4. The computer-implemented method of claim 1 , further comprising:
detecting the change in the network endpoints using a task-based resource;
generating the new policy information based at least in part upon the change in the network endpoints; and
providing the new policy information for publication by the notification service.
5. The computer-implemented method of claim 4 , wherein the new policy information is provided by at least one of storing the new policy information to an information queue or transmitting the new policy information using a data streaming service.
6. The computer-implemented method of claim 5 , further comprising:
periodically polling, by the poller, the information queue for the new policy information wherein the new policy information includes at least one of a new policy definition or a new access control list.
7. The computer-implemented method of claim 1 , wherein the new policy information specifies at least one of endpoints for which access to the resource is to be granted or endpoints for which access is to be denied to the resource.
8. The computer-implemented method of claim 1 , wherein the new policy information is published to at least one subscriber using at least one of email messaging, instant messaging, short message service messaging, or text messaging.
9. The computer-implemented method of claim 1 , wherein the security policy is one of an access policy or a credential management policy.
10. The computer-implemented method of claim wherein the network endpoints correspond to IP addresses or geo-locations of at least one of a sub-network or region of computing resources.
11. The computer-implemented method of claim 1 , further comprising:
validating a customer access credential, received with the subsequent access request, before granting access to the resource in response to an endpoint of the subsequent access request falling within permissible network endpoints specified by the new policy information.
12. A system, comprising:
at least one processor; and
memory including instructions that, when executed by the at least one processor, cause the system to:
detect, by a poller, a change in network endpoints associated with a sub-network, the network endpoints related to a subscription that is associated with a network endpoint topic and that is associated with a security policy for a resource, the security policy including an indication from an entity associated with the sub-network to automatically update policy information responsive to the change in the network endpoints;
publish, on the network endpoint topic, new policy information associated with the change in the network endpoints;
determine, based at least in part on the security policy, that the new policy information should be applied; and
cause the new policy information to be applied for the security policy, wherein the security policy including the new policy information will be enforced for a subsequent access request relating to the resource.
13. The system of claim 12 , wherein the instructions when executed further cause the system to:
cause the new policy information to be applied for the security policy using a policy manager of a resource provider environment, the resource being at least one of a physical computing resource or a virtual computing resource provided using resources of the resource provider environment.
14. The system of claim 12 , wherein the instructions when executed further cause the system to:
receive the new policy information to a customer policy manager;
generate a notification to a customer resource administrator regarding the new policy information; and
enable the customer resource administrator to manually review and apply the new policy information for the security policy.
15. The system of claim 12 , wherein the instructions when executed further cause the system to:
detect the change in the network endpoints using a task-based resource;
generate the new policy information based at least in part upon the change in the network endpoints; and
provide the new policy information for publication by a notification service.
16. The system of claim 12 , wherein the new policy information is published to at least one subscriber using at least one of email messaging, instant messaging, short message service messaging, or text messaging.
17. The system of claim 12 , wherein the instructions when executed further cause the system to:
validate a customer access credential, received with the subsequent access request, before granting access to the resource in response to an endpoint of the subsequent access request falling within permissible network endpoints specified by the new policy information.
18. A computer-implemented method, comprising:
detecting, by a poller, a change in network endpoints associated with a sub-network, the network endpoints related to a subscription that is associated with a network endpoint topic and that is associated with a security policy for a resource, the security policy including an indication from an entity associated with the sub-network to automatically update policy information responsive to the change in the network endpoints;
publishing, on the network endpoint topic, new policy information associated with the change in the network endpoints to at least one subscriber using at least one of email messaging, instant messaging, short message service messaging, or text messaging;
determining, based at least in part on the security policy, that the new policy information should be applied;
causing the new policy information to be applied for the security policy, wherein the security policy including the new policy information will be enforced for a subsequent access request relating to the resource; and
validating a customer access credential, received with the subsequent access request, before granting access to the resource in response to an endpoint of the subsequent access request falling within permissible network endpoints specified by the new policy information.
19. The computer-implemented method of claim 18 , further comprising:
causing the new policy information to be applied for the security policy using a policy manager of a resource provider environment, the resource being at least one of a physical computing resource or a virtual computing resource provided using resources of the resource provider environment.
20. The computer-implemented method of claim 18 , further comprising:
receiving the new policy information to a customer policy manager;
generating a notification to a customer resource administrator regarding the new policy information; and
causing the new policy information to be applied for the security policy by enabling the customer resource administrator to manually review and apply the new policy information for the security policy.