Securing Resources Using Unique Internet Protocol Addresses
A security service controller for multiple entities assigns a unique set of Internet Protocol (IP) addresses to each entity from among the multiple entities. The security service controller processes, for a client device authorized by a given entity, network traffic via the unique set of IP addresses for the given entity. The security service controller provides, to the client device authorized by the given entity, access to network resources associated with the given entity via the unique set of IP addresses for the given entity.
1 . A method comprising:
assigning, by a security service controller for multiple entities, a unique set of Internet Protocol (IP) addresses to each entity from among the multiple entities;
processing, for a client device authorized by a given entity, network traffic via the unique set of IP addresses for the given entity; and
providing, to the client device authorized by the given entity, access to network resources associated with the given entity via the unique set of IP addresses for the given entity.
2 . The method of claim 1 , wherein the unique set of IP addresses for the given entity comprises IP addresses associated with geographic regions, each IP address processing network traffic from the associated geographic region.
3 . The method of claim 1 , further comprising:
allowing access to the unique set of IP addresses for the given entity only from a predefined group of remote IP addresses specified by the given entity and/or associated with a user associated with the given entity, wherein the client device is associated with an IP address from the predefined group.
4 . The method of claim 1 , further comprising:
allowing access to a predefined set of applications specified by the given entity through the unique set of IP addresses for the given entity, wherein the client device is running an application from the predefined set of applications.
5 . The method of claim 1 , further comprising:
determining that an amount of network traffic associated with the given entity exceeds a threshold; and
assigning, by the security service controller, one or more additional gateways to the unique set of IP addresses for the given entity.
6 . The method of claim 1 , wherein the network traffic, associated with one or more predefined applications accessed via the network, processed for the given entity is isolated to the unique set of IP addresses for the given entity.
7 . The method of claim 1 , wherein the security service controller is associated with multiple IP addresses and stores applications and data for multiple entities.
8 . A non-transitory machine-readable medium storing instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:
assigning, by a security service controller for multiple entities, a unique set of Internet Protocol (IP) addresses to each entity from among the multiple entities;
processing, for a client device authorized by a given entity, network traffic via the unique set of IP addresses for the given entity; and
providing, to the client device authorized by the given entity, access to network resources associated with the given entity via the unique set of IP addresses for the given entity.
9 . The machine-readable medium of claim 8 , wherein the unique set of IP addresses for the given entity comprises IP addresses associated with geographic regions, each IP address processing network traffic from the associated geographic region.
10 . The machine-readable medium of claim 8 , the operations further comprising:
allowing access to the unique set of IP addresses for the given entity only from a predefined group of remote IP addresses specified by the given entity and/or associated with a user associated with the given entity, wherein the client device is associated with an IP address from the predefined group.
11 . The machine-readable medium of claim 8 , the operations further comprising:
allowing access to a predefined set of applications specified by the given entity through the unique set of IP addresses for the given entity, wherein the client device is running an application from the predefined set of applications.
12 . The machine-readable medium of claim 8 , the operations further comprising:
determining that an amount of network traffic associated with the given entity exceeds a threshold; and
assigning, by the security service controller, one or more additional gateways to the unique set of IP addresses for the given entity.
13 . The machine-readable medium of claim 8 , wherein the network traffic, associated with one or more predefined applications accessed via the network, processed for the given entity is isolated to the unique set of IP addresses for the given entity.
14 . The machine-readable medium of claim 8 , wherein the security service controller is associated with multiple IP addresses and stores applications and data for multiple entities.
15 . A system comprising:
processing circuitry; and
a memory storing instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:
assigning, by a security service controller for multiple entities, a unique set of Internet Protocol (IP) addresses to each entity from among the multiple entities;
processing, for a client device authorized by a given entity, network traffic via the unique set of IP addresses for the given entity; and
providing, to the client device authorized by the given entity, access to network resources associated with the given entity via the unique set of IP addresses for the given entity.
16 . The system of claim 15 , wherein the unique set of IP addresses for the given entity comprises IP addresses associated with geographic regions, each IP address processing network traffic from the associated geographic region.
17 . The system of claim 15 , the operations further comprising:
allowing access to the unique set of IP addresses for the given entity only from a predefined group of remote IP addresses specified by the given entity and/or associated with a user associated with the given entity, wherein the client device is associated with an IP address from the predefined group.
18 . The system of claim 15 , the operations further comprising:
allowing access to a predefined set of applications specified by the given entity through the unique set of IP addresses for the given entity, wherein the client device is running an application from the predefined set of applications.
19 . The system of claim 15 , the operations further comprising:
determining that an amount of network traffic associated with the given entity exceeds a threshold; and
assigning, by the security service controller, one or more additional gateways to the unique set of IP addresses for the given entity.
20 . The system of claim 15 , wherein the network traffic, associated with one or more predefined applications accessed via the network, processed for the given entity is isolated to the unique set of IP addresses for the given entity.