IP Library Granted Patent US 11,962,622
Granted Patent B2
US 11,962,622 · App. 18/165,171 · Granted Apr 16, 2024

Automated enforcement of security policies in cloud and hybrid infrastructure environments

Inventors: Lisun Joao Kung (Dallas, TX); Jose Renato Goncalves Santos (Morgan Hill, CA); Sarowar Golam Sikder (Carrollton, TX)
Assignee: FireEye Security Holdings US LLC
H04L63/20H04L63/0263H04L63/101H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,962,622
App. No.
18/165,171
Granted
Apr 16, 2024
Kind
B2
Abstract

To prevent un-authorized accesses to data and resources available in workloads on an organization's or enterprise's computer network, various improvements to automated computer network security processes to enable them to enforce network security policies using native network security mechanisms to control communications to and/or from workload units of applications running on different nodes within hybrid computer network infrastructures having both traditional hardware resources and virtual resources provided by private and public cloud infrastructure services.

Claims (27)

1. At least one non-transitory machine-readable medium comprising instructions that, when executed, cause at least one processor to at least:

assign a first attribute to respective ones of a plurality of infrastructure resources of an infrastructure service provider in response to a determination that the infrastructure resource satisfies a resource property, the satisfaction of the resource property determined based on whether the infrastructure resource is constrained by a constraint rule, the first attribute being mapped to a property of the infrastructure service provider, the first attribute including a key and value pair; and

generate a configuration for an infrastructure resource based on a plurality of security policies and the assignment of the first attribute to the infrastructure resource.

2. The at least one non-transitory machine-readable medium of claim 1 , wherein the instructions cause the at least one processor to assign the first attribute based on an infrastructure tag provided by the infrastructure service provider for the infrastructure resource.

3. The at least one non-transitory machine-readable medium of claim 1 , wherein the instructions cause the at least one processor to assign a second attribute based on a property of the infrastructure resource.

4. The at least one non-transitory machine-readable medium of claim 1 , wherein the instructions cause the at least one processor to assign the first attribute to the infrastructure resource based on membership in at least one logical group.

5. The at least one non-transitory machine-readable medium of claim 1 , wherein the configuration is based on the plurality of security policies defined for a logical group and attributes of the infrastructure resources that are members of the logical group.

6. The at least one non-transitory machine-readable medium of claim 1 , wherein the instructions cause the at least one processor to request permission for the infrastructure resource to use the first attribute.

7. The at least one non-transitory machine-readable medium of claim 1 , wherein each of the plurality of security policies specifies a plurality of rules specified with logical objects.

8. An apparatus comprising:

memory;

machine-readable instructions;

logic circuitry to execute the machine-readable instructions that cause the logic circuitry to at least:

assign a first attribute to respective ones of a plurality of infrastructure resources of an infrastructure service provider in response to a determination that the infrastructure resource satisfies a resource property, the satisfaction of the resource property determined based on whether the infrastructure resource is constrained by a constraint rule, the first attribute being mapped to a property of the infrastructure service provider, the first attribute including a key and value pair; and

generate a configuration for an infrastructure resource based on a plurality of security policies and the assignment of the first attribute to the infrastructure resource.

9. The apparatus of claim 8 , wherein the logic circuitry is to assign the first attribute based on an infrastructure tag provided by the infrastructure service provider for the infrastructure resource.

10. The apparatus of claim 8 , wherein the logic circuitry is to assign a second attribute based on a property of the infrastructure resource.

11. The apparatus of claim 8 , wherein the logic circuitry is to assign the first attribute to the infrastructure resource based on membership in at least one logical group.

12. The apparatus of claim 8 , wherein the configuration is based on the security policies defined for a logical group and attributes of the infrastructure resources that are members of the logical group.

13. The apparatus of claim 8 , wherein the logic circuitry is to request permission for the infrastructure resource to use the first attribute.

14. The apparatus of claim 8 , wherein each of the security policies is to specify a plurality of rules specified with logical objects.

15. A method comprising:

assigning a first attribute to respective ones of a plurality of infrastructure resources of an infrastructure service provider in response to a determination that the infrastructure resource satisfies a resource property, the satisfaction of the resource property determined based on whether the infrastructure resource is constrained by a constraint rule, the first attribute being mapped to a property of the infrastructure service provider, the first attribute including a key and value pair; and

generating, by executing an instruction with at least one processor, a configuration for an infrastructure resource based on a plurality of security policies and the assignment of the first attribute to the infrastructure resource.

16. The method of claim 15 , wherein the assigning of the first attribute is based on an infrastructure tag provided by the infrastructure service provider for the infrastructure resource.

17. The method of claim 15 , wherein the assigning of a second attribute is based on a property of the infrastructure resource.

18. The method of claim 15 , wherein the assigning of the first attribute to the infrastructure resource is based on membership in at least one logical group.

Assignments (12)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
MERGER AND CHANGE OF NAME Recorded May 31, 2023
From: FIREEYE SECURITY HOLDINGS US LLC; MUSARUBRA US LLC
To: MUSARUBRA US LLC
Reel/Frame 063814/0320 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2023
From: KUNG, LISUN JOAO; SANTOS, JOSE RENATO GONCALVES; SIKDER, SAROWAR GOLAM
To: CLOUDVISORY LLC
Reel/Frame 063558/0352 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2023
From: CLOUDVISORY, LLC
To: FIREEYE, INC.
Reel/Frame 063558/0376 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063485/0258 →
CHANGE OF NAME Recorded Apr 27, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063485/0385 →
Continuity (6)
Continuation 16908681 · Jun 22, 2020
Continuation 15878386 · Jan 23, 2018
Provisional Application 62477376 · Mar 27, 2017
Provisional Application 62450001 · Jan 24, 2017
Provisional Application 62449571 · Jan 23, 2017
Related Publication 20230188571A1 · Jun 15, 2023
Cited By (1)
US 12,380,223