Automated enforcement of security policies in cloud and hybrid infrastructure environments
To prevent un-authorized accesses to data and resources available in workloads on an organization's or enterprise's computer network, various improvements to automated computer network security processes to enable them to enforce network security policies using native network security mechanisms to control communications to and/or from workload units of applications running on different nodes within hybrid computer network infrastructures having both traditional hardware resources and virtual resources provided by private and public cloud infrastructure services.
1. At least one non-transitory machine-readable medium comprising instructions that, when executed, cause at least one processor to at least:
assign a first attribute to respective ones of a plurality of infrastructure resources of an infrastructure service provider in response to a determination that the infrastructure resource satisfies a resource property, the satisfaction of the resource property determined based on whether the infrastructure resource is constrained by a constraint rule, the first attribute being mapped to a property of the infrastructure service provider, the first attribute including a key and value pair; and
generate a configuration for an infrastructure resource based on a plurality of security policies and the assignment of the first attribute to the infrastructure resource.
2. The at least one non-transitory machine-readable medium of claim 1 , wherein the instructions cause the at least one processor to assign the first attribute based on an infrastructure tag provided by the infrastructure service provider for the infrastructure resource.
3. The at least one non-transitory machine-readable medium of claim 1 , wherein the instructions cause the at least one processor to assign a second attribute based on a property of the infrastructure resource.
4. The at least one non-transitory machine-readable medium of claim 1 , wherein the instructions cause the at least one processor to assign the first attribute to the infrastructure resource based on membership in at least one logical group.
5. The at least one non-transitory machine-readable medium of claim 1 , wherein the configuration is based on the plurality of security policies defined for a logical group and attributes of the infrastructure resources that are members of the logical group.
6. The at least one non-transitory machine-readable medium of claim 1 , wherein the instructions cause the at least one processor to request permission for the infrastructure resource to use the first attribute.
7. The at least one non-transitory machine-readable medium of claim 1 , wherein each of the plurality of security policies specifies a plurality of rules specified with logical objects.
8. An apparatus comprising:
memory;
machine-readable instructions;
logic circuitry to execute the machine-readable instructions that cause the logic circuitry to at least:
assign a first attribute to respective ones of a plurality of infrastructure resources of an infrastructure service provider in response to a determination that the infrastructure resource satisfies a resource property, the satisfaction of the resource property determined based on whether the infrastructure resource is constrained by a constraint rule, the first attribute being mapped to a property of the infrastructure service provider, the first attribute including a key and value pair; and
generate a configuration for an infrastructure resource based on a plurality of security policies and the assignment of the first attribute to the infrastructure resource.
9. The apparatus of claim 8 , wherein the logic circuitry is to assign the first attribute based on an infrastructure tag provided by the infrastructure service provider for the infrastructure resource.
10. The apparatus of claim 8 , wherein the logic circuitry is to assign a second attribute based on a property of the infrastructure resource.
11. The apparatus of claim 8 , wherein the logic circuitry is to assign the first attribute to the infrastructure resource based on membership in at least one logical group.
12. The apparatus of claim 8 , wherein the configuration is based on the security policies defined for a logical group and attributes of the infrastructure resources that are members of the logical group.
13. The apparatus of claim 8 , wherein the logic circuitry is to request permission for the infrastructure resource to use the first attribute.
14. The apparatus of claim 8 , wherein each of the security policies is to specify a plurality of rules specified with logical objects.
15. A method comprising:
assigning a first attribute to respective ones of a plurality of infrastructure resources of an infrastructure service provider in response to a determination that the infrastructure resource satisfies a resource property, the satisfaction of the resource property determined based on whether the infrastructure resource is constrained by a constraint rule, the first attribute being mapped to a property of the infrastructure service provider, the first attribute including a key and value pair; and
generating, by executing an instruction with at least one processor, a configuration for an infrastructure resource based on a plurality of security policies and the assignment of the first attribute to the infrastructure resource.
16. The method of claim 15 , wherein the assigning of the first attribute is based on an infrastructure tag provided by the infrastructure service provider for the infrastructure resource.
17. The method of claim 15 , wherein the assigning of a second attribute is based on a property of the infrastructure resource.
18. The method of claim 15 , wherein the assigning of the first attribute to the infrastructure resource is based on membership in at least one logical group.