IP Library Granted Patent US 9,787,639
Granted Patent B1
US 9,787,639 · App. 15/387,584 · Granted Oct 10, 2017

Granular segmentation using events

Inventors: Yi Sun (San Jose, CA); Myo Zarny (Bayside Hills, NY); Marc Woolward (Santa Cruz, CA)
Assignee: vArmour Networks, Inc.
H04L63/0245G06F9/45558H04L63/0263G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,787,639
App. No.
15/387,584
Granted
Oct 10, 2017
Kind
B1
Abstract

Methods and systems for granular segmentation of data networks are provided herein. Exemplary methods include: receiving from a metadata source event metadata associated with a workload; identifying a workload type using the event metadata; determining a high-level declarative security policy using the workload type; launching a compiler to generate a low-level firewall rule set using the high-level declarative policy and the event metadata; and configuring by a plurality of enforcement points a respective network switch of a plurality of network switches to process packets in accordance with the low-level firewall ruleset, the network switches being collectively communicatively coupled to a plurality of workloads, such that network communications between a first group of workloads of the plurality of workloads and the workload are not permitted, and between a second group of workloads of the plurality of workloads and the workload are permitted.

Claims (36)

1. A method implemented by at least one hardware processor for granular segmentation of data networks, the method comprising:

receiving from a metadata source event metadata associated with a workload;

identifying a workload type using the event metadata;

determining a high-level declarative security policy using the workload type;

launching a compiler to generate a low-level firewall rule set using the high-level declarative security policy and the event metadata; and

configuring by a plurality of enforcement points a respective network switch of a plurality of network switches to process packets in accordance with the low-level firewall rule set, the plurality of network switches being collectively communicatively coupled to a plurality of workloads, such that network communications between a first group of workloads of the plurality of workloads and the workload are not permitted, and between a second group of workloads of the plurality of workloads and the workload are permitted.

2. The method of claim 1 , wherein the metadata source is at least one of a hypervisor and an orchestration layer.

3. The method of claim 1 , wherein the event metadata is received in response to an event.

4. The method of claim 3 , wherein the event is at least one of: the workload being instantiated, the workload being removed, the workload being migrated, and workload metadata being changed.

5. The method of claim 4 , further comprising: disseminating, to a destination enforcement point of a migrated workload, a state of a communications session of the migrated workload.

6. The method of claim 1 , wherein the workload is at least one of a: bare-metal server, virtual machine (VM), container, and microservice.

7. The method of claim 1 , wherein the event metadata includes at least one of: an event, an application name, a service name, a user-defined tag/label, an IP address, a port number, an operating system name, a software version, and a location.

8. The method of claim 1 , wherein:

the event metadata includes at least one of: a date and a time; and

the high-level declarative security policy includes a time-based provision.

9. The method of claim 1 , wherein the high-level declarative security policy comprises an intent-driven model, the intent-driven model specifying groups of workloads and describing permitted connectivity, security, and network services between the groups.

10. The method of claim 1 , wherein the low-level firewall rule set comprises individual workload addresses to and/or from which network communications are at least one of forwarded, blocked, redirected, and logged.

11. A system for granular segmentation of data networks, the system comprising:

at least one hardware processor; and

a memory coupled to the at least one hardware processor, the memory storing instructions executable by the at least one hardware processor to perform a method comprising:

receiving from a metadata source event metadata associated with a workload;

identifying a workload type using the event metadata;

determining a high-level declarative security policy using the workload type;

launching a compiler to generate a low-level firewall rule set using the high-level declarative security policy and the event metadata; and

configuring by a plurality of enforcement points a respective network switch of a plurality of network switches to process packets in accordance with the low-level firewall rule set, the plurality of network switches being collectively communicatively coupled to a plurality of workloads, such that network communications between a first group of workloads of the plurality of workloads and the workload are not permitted, and between a second group of workloads of the plurality of workloads and the workload are permitted.

12. The system of claim 11 , wherein the metadata source is at least one of a hypervisor and an orchestration layer.

13. The system of claim 11 , wherein the metadata source sends the event metadata in response to an event.

14. The system of claim 13 , wherein the event is at least one of: the workload being instantiated, the workload being removed, the workload being migrated, and workload metadata being changed.

15. The system of claim 14 , wherein the method further comprises: disseminating, to a destination enforcement point of a migrated workload, a state of a communications session of the migrated workload.

16. The system of claim 11 , wherein the workload is at least one of a: bare-metal server, virtual machine, container, and microservice.

17. The system of claim 11 , wherein the event metadata includes at least one of: an event, an application name, a service name, a user-defined tag/label, an IP address, a port number, an operating system name, a software version, and a location.

18. The system of claim 11 , wherein:

the event metadata includes at least one of a date and a time; and

the high-level declarative security policy includes a time-based provision.

19. The system of claim 11 , wherein the high-level declarative policy comprises an intent-driven model, the intent-driven model specifying groups of workloads and describing permitted connectivity, security, and network services between the groups.

20. The system of claim 11 , wherein the low-level firewall rule set comprises individual workload addresses to and/or from which network communications are at least one of forwarded, blocked, redirected, and logged.

Assignments (5)
PATENT SECURITY AGREEMENT Recorded Jul 18, 2025
From: GRYPHO5, LLC
To: EVP CREDIT SPV I LP
Reel/Frame 072053/0141 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: VARMOUR NETWORKS, INC.
To: GRYPHO5, LLC
Reel/Frame 070287/0007 →
SECURITY INTEREST Recorded Feb 22, 2024
From: VARMOUR NETWORKS, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 066530/0399 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2018
From: WOOLWARD, MARC
To: VARMOUR NETWORKS, INC.
Reel/Frame 045305/0590 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2017
From: SUN, YI; ZARNY, MYO
To: VARMOUR NETWORKS, INC.
Reel/Frame 042353/0174 →
Continuity (1)
Continuation In Part 15192967 · Jun 24, 2016