Zoned mesh network isolation
Embodiments of the present disclosure include a processing device that determines that a first node device of a plurality of node devices in a network is non-compliant with a network policy, identifies a subset of the plurality of node devices that is associated with the first node device, and disrupts, by the processing device, a communication path of the subset of the plurality of node devices and the first node device within the network.
1. A method comprising:
determining that a first node device of a plurality of node devices in a network is non-compliant with a network policy;
identifying a first subset of the plurality of node devices that are associated with the first node device and a second subset of the plurality of node devices that are not associated with the first node device; and
in response to determining that the first node device is non-compliant with the network policy, disrupting, by a processing device, a communication path of the first subset of the plurality of node devices and the first node device within the network, wherein disrupting the communication path of the first subset of the plurality of node devices and the first node device comprises altering a second cryptographic state of the second subset of the plurality of node devices to be incompatible with a first cryptographic state of the first subset of the plurality of node devices and the first node device, and
wherein disrupting the communication path of the first subset of the plurality of node devices and the first node device is performed without directly accessing the first subset of the plurality of node devices.
2. The method of claim 1 , wherein altering the second cryptographic state of the second subset of the plurality of node devices to be incompatible with the first cryptographic state of the first subset of the plurality of node devices and the first node device comprises altering a cryptographic key utilized by the communication path.
3. The method of claim 1 , wherein altering the second cryptographic state of the second subset of the plurality of node devices to be incompatible with the first cryptographic state of the first subset of the plurality of node devices and the first node device comprises altering a seed used to generate a cryptographic key utilized by the communication path.
4. The method of claim 1 , wherein the first subset of the plurality of node devices that are associated with the first node device each share a common feature with the first node device.
5. The method of claim 1 , wherein the first subset of the plurality of node devices that are associated with the first node device provide a same service to the network as the first node device.
6. The method of claim 1 , wherein the first subset of the plurality of node devices comprises node devices of the plurality of node devices within a threshold number of connections from the first node device.
7. A system comprising:
a memory; and
a processing device, operatively coupled to the memory, to:
determine that a first node device of a plurality of node devices in a network is non-compliant with a network policy;
identify a first subset of the plurality of node devices that are associated with the first node device and a second subset of the plurality of node devices that are not associated with the first node device; and
in response to determining that the first node device is non-compliant with the network policy, disrupt, by the processing device, a communication path of the first subset of the plurality of node devices and the first node device within the network, wherein, to disrupt the communication path of the first subset of the plurality of node devices and the first node device, the processing device is to alter a second cryptographic state of the second subset of the plurality of node devices to be incompatible with a first cryptographic state of the first subset of the plurality of node devices and the first node device, and
wherein disrupting the communication path of the first subset of the plurality of node devices and the first node device is performed by the processing device without directly accessing the first subset of the plurality of node devices.
8. The system of claim 7 , wherein, to alter the second cryptographic state of the second subset of the plurality of node devices to be incompatible with the first cryptographic state of the first subset of the plurality of node devices and the first node device, the processing device is to alter a cryptographic key utilized by the communication path.
9. The system of claim 7 , wherein, to alter the second cryptographic state of the second subset of the plurality of node devices to be incompatible with the first cryptographic state of the first subset of the plurality of node devices and the first node device, the processing device is to alter a seed used to generate a cryptographic key utilized by the communication path.
10. The system of claim 7 , wherein the first subset of the plurality of node devices that are associated with the first node device each share a common feature with the first node device.
11. The system of claim 7 , wherein the first subset of the plurality of node devices that are associated with the first node device provide a same service to the network as the first node device.
12. The system of claim 7 , wherein the first subset of the plurality of node devices comprises node devices of the plurality of node devices within a threshold number of connections from the first node device.
13. A non-transitory computer-readable storage medium including instructions that, when executed by a processing device, cause the processing device to:
determine that a first node device of a plurality of node devices in a network is non-compliant with a network policy;
identify a first subset of the plurality of node devices that are associated with the first node device and a second subset of the plurality of node devices that are not associated with the first node device; and
in response to determining that the first node device is non-compliant with the network policy, disrupt, by the processing device, a communication path of the first subset of the plurality of node devices and the first node device within the network, wherein, to disrupt the communication path of the first subset of the plurality of node devices and the first node device, the processing device is to alter a second cryptographic state of the second subset of the plurality of node devices to be incompatible with a first cryptographic state of the first subset of the plurality of node devices and the first node device, and
wherein disrupting the communication path of the first subset of the plurality of node devices and the first node device is performed by the processing device without directly accessing the first subset of the plurality of node devices.
14. The non-transitory computer-readable storage medium of claim 13 , wherein, to alter the second cryptographic state of the second subset of the plurality of node devices to be incompatible with the first cryptographic state of the first subset of the plurality of node devices and the first node device, the processing device is to alter a cryptographic key utilized by the communication path.
15. The non-transitory computer-readable storage medium of claim 13 , wherein, to alter the second cryptographic state of the second subset of the plurality of node devices to be incompatible with the first cryptographic state of the first subset of the plurality of node devices and the first node device, the processing device is to alter a seed used to generate a cryptographic key utilized by the communication path.
16. The non-transitory computer-readable storage medium of claim 13 , wherein the first subset of the plurality of node devices that are associated with the first node device each share a common feature with the first node device.
17. The non-transitory computer-readable storage medium of claim 13 , wherein the first subset of the plurality of node devices that are associated with the first node device provide a same service to the network as the first node device.
18. The non-transitory computer-readable storage medium of claim 13 , wherein the first subset of the plurality of node devices comprises node devices of the plurality of node devices within a threshold number of connections from the first node device.