IP Library › Patent Application 17348121
Patent Application
App. No. 17/348,121

SYSTEMS AND METHODS FOR FOCUSED LEARNING OF APPLICATION STRUCTURE AND ZTNA POLICY GENERATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/348,121
Abstract

Systems, devices, and methods are discussed for determining zero trust network access policy from a policy from a perspective focused on one or more network elements.

Claims (71)

1 . A method for focused development of a zero trust network access policy, the method comprising:

accessing, by a processing resource, a focus list, wherein the focus list identifies at least one network element;

monitoring, by the processing resource, network activity to yield a set of network traffic;

identifying, by the processing resource, a set of workloads in the set of network traffic that are either sourced from any of the at least one network focus, or destined to any of the at least one network element; and

augmenting, by the processing resource, an access control list to include one or more workload rules allowing the set of workloads.

2 . The method of claim 1 , wherein the network element is selected from a group consisting of: a network endpoint, a network appliance, an application, and a port of a network appliance.

3 . The method of claim 1 , wherein the set of network traffic is a first set of network traffic, wherein the set of workloads is a first set of workloads, the method further comprising:

monitoring, by the processing resource, network activity to yield a second set of network traffic;

identifying, by the processing resource, a second set of workloads in the second set of network traffic that are either sourced from any of the at least one network focus, or destined to any of the at least one network focus;

identifying, by the processing resource, at least one workload in the second set of workloads that is not in the first set of workloads; and

augmenting, by the processing resource, the access control list to include the at least one workload in the second set of workloads that is not in the first set of workloads.

4 . The method of claim 1 , wherein the network element is a first network element, the method further comprising:

identifying, by the processing resource, a second network element that is either the source of a workload in the set of workloads or a destination of a workload in the set of workloads; and

augmenting, by the processing resource, the focus list to include the second network element.

5 . The method of claim 4 , wherein the set of network traffic is a first set of network traffic, wherein the set of workloads is a first set of workloads, the method further comprising:

monitoring, by the processing resource, network activity to yield a second set of network traffic;

identifying, by the processing resource, a second set of workloads in the second set of network traffic that are either sourced from any of the at least one network focus, or destined to any of the at least one network element; and

identifying, by the processing resource, at least one workload in the second set of workloads that is not in the first set of workloads; and

augmenting, by the processing resource, the access control list to include the at least one workload in the second set of workloads that is not in the first set of workloads.

6 . The method of claim 1 , the method further comprising:

identifying, by the processing resource, a first application associated with two or more workloads in the set of workloads, and a second application associated with two or more other workloads in the set of workloads;

wherein augmenting, by the processing resource, the access control list to include one or more workload rules allowing the set of workloads is an incremental modification, and wherein the incremental modification includes:

augmenting, by the processing device, the access control list to include first workload rules corresponding to the two or more workloads associated with the first application to yield a first augmented access control list;

forward testing, by the processing device, the first augmented access control list;

subsequent to forward testing the first augmented access control list, augmenting, by the processing device, the first access control list to include second workload rules corresponding to the two or more workloads associated with the second application to yield a second augmented access control list; and

forward testing, by the processing device, the second augmented access control list.

7 . The method of claim 6 , wherein the access control list includes a default rule that allows any network traffic between any source and any destination, and wherein the forward testing the first augmented access control list comprises:

applying the first workload rules; and

applying the default rule after the first workload rules.

8 . The method of claim 6 , wherein the access control list includes a default rule that allows any network traffic between any source and any destination, and wherein the forward testing the second augmented access control list comprises:

applying the first workload rules;

applying the second workload rules; and

applying the default rule after applying all of the first workload rules and the second workload rules.

9 . The method of claim 1 , wherein the access control list includes a default rule that allows any network traffic between any source and any destination.

10 . The method of claim 9 , the method further comprising:

modifying, by the processing resource, the default rule to block any network traffic between any source and any destination.

11 . A network appliance, the network appliance comprising:

a processing resource;

a non-transitory computer-readable medium, coupled to the processing resource, having stored therein instructions that when executed by the processing resource cause the processing resource to:

access a focus list, wherein the focus list identifies at least one network element;

monitor network activity to yield a set of network traffic;

identify a set of workloads in the set of network traffic that are either sourced from any of the at least one network focus, or destined to any of the at least one network element; and

augment an access control list to include one or more workload rules allowing the set of workloads.

12 . The network appliance of claim 11 , wherein the network element is selected from a group consisting of: a network endpoint, a network appliance, an application, and a port of a network appliance.

13 . The network appliance of claim 11 , wherein the set of network traffic is a first set of network traffic, wherein the set of workloads is a first set of workloads, and wherein the instructions that when executed by the processing resource cause the processing resource further to:

monitor network activity to yield a second set of network traffic;

identify a second set of workloads in the second set of network traffic that are either sourced from any of the at least one network focus, or destined to any of the at least one network focus;

identify at least one workload in the second set of workloads that is not in the first set of workloads; and

augment the access control list to include the at least one workload in the second set of workloads that is not in the first set of workloads.

14 . The network appliance of claim 11 , wherein the network element is a first network element, and wherein the instructions that when executed by the processing resource cause the processing resource further to:

identify a second network element that is either the source of a workload in the set of workloads or a destination of a workload in the set of workloads; and

augment the focus list to include the second network element.

15 . The network appliance of claim 11 , wherein the set of network traffic is a first set of network traffic, wherein the set of workloads is a first set of workloads, and wherein the instructions that when executed by the processing resource cause the processing resource further to:

monitor network activity to yield a second set of network traffic;

identify a second set of workloads in the second set of network traffic that are either sourced from any of the at least one network focus, or destined to any of the at least one network element;

identify at least one workload in the second set of workloads that is not in the first set of workloads; and

augment the access control list to include the at least one workload in the second set of workloads that is not in the first set of workloads.

16 . The network appliance of claim 11 , wherein the access control list includes a default rule that allows any network traffic between any source and any destination.

17 . The network appliance of claim 16 , and wherein the instructions that when executed by the processing resource cause the processing resource further to:

modify the default rule to block any network traffic between any source and any destination.

18 . A non-transitory computer-readable storage medium embodying a set of instructions, which when executed by a processing resource, causes the processing resource to:

access a focus list, wherein the focus list identifies at least one network element;

monitor network activity to yield a set of network traffic;

identify a set of workloads in the set of network traffic that are either sourced from any of the at least one network focus, or destined to any of the at least one network element; and

augment an access control list to include one or more workload rules allowing the set of workloads.

19 . The non-transitory computer-readable storage medium of claim 18 , wherein the network element is selected from a group consisting of: a network endpoint, a network appliance, an application, and a port of a network appliance.

20 . The non-transitory computer-readable storage medium of claim 18 , wherein the set of network traffic is a first set of network traffic, wherein the set of workloads is a first set of workloads, and wherein the instructions that when executed by the processing resource cause the processing resource further to:

monitor network activity to yield a second set of network traffic;

identify a second set of workloads in the second set of network traffic that are either sourced from any of the at least one network focus, or destined to any of the at least one network focus;

identify at least one workload in the second set of workloads that is not in the first set of workloads; and

augment the access control list to include the at least one workload in the second set of workloads that is not in the first set of workloads.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2021
From: SREEDHAR, RAJIV; NEDBAL, MANUEL; AHLUWALIA, MANOJ; HEGDE, DAMODAR K.; GAITONDE, JITENDRA B.
To: FORTINET, INC.
Reel/Frame 056550/0085 →