Creating, visualizing, and simulating a threat based whitelisting security policy and security zones for networks
Techniques described herein are directed toward creating, visualizing, and simulating a threat based whitelisting security policy and security zones for networks. The disclosed technology may be implemented by providing a graphical user interface (GUI) on a network orchestration and security platform that facilitates creation and visualization of security zones and security policies for networks.
1. A method comprising:
generating a plurality of security zones in a network comprising a plurality of assets, wherein each of the plurality of security zones comprises a respective set of assets of the plurality of assets, wherein the plurality of security zones are generated based at least in part on a regularity of communications between assets of the plurality of assets and a type of protocol communication between assets of the plurality of assets;
initializing an application comprising a graphical user interface for editing and visually representing the plurality of security zones of the network;
displaying, on the graphical user interface, a visual representation of a first security zone of the plurality of security zones of the network, wherein the first security zone comprises a first set of assets of the plurality of assets;
receiving data corresponding to user input at the graphical user interface editing the first security zone; and
in response to receiving the data, editing the first security zone.
2. The method of claim 1 wherein the visual representation of the first security zone is a logical container of at least two or more of the plurality of assets.
3. The method of claim 2 , wherein the network is an industrial network and wherein the plurality of assets comprises industrial devices.
4. The method of claim 3 , wherein the network comprises a controller communicatively coupled to a plurality of forwarding devices, wherein each of the plurality of assets is communicatively coupled to a port of one of the plurality of forwarding devices, wherein the controller is configured to generate the plurality of security zones.
5. The method of claim 2 , wherein the user input at the graphical user interface editing the first security zone comprises at least one of: moving a visual representation of one of the plurality of assets into the logical container of the first security zone or moving a visual representation of one of the assets from the logical container of the first security zone into a logical container of a second security zone of the network.
6. The method of claim 5 , wherein the user input at the graphical user interface editing the first security zone comprises dragging a visual representation of an asset not assigned to a security zone into the logical container of the first security zone.
7. The method of claim 5 , wherein the user input at the graphical user interface editing the first security zone comprises dragging a visual representation of one of the assets from the logical container of the first security zone into a logical container of a second security zone of the network.
8. A non-transitory computer-readable medium having instructions stored thereon that, when executed by a processor, causes a system to:
generate a plurality of security zones in a network comprising a plurality of assets, wherein each of the plurality of security zones comprises a respective set of assets of the plurality of assets, wherein the plurality of security zones are generated based at least in part on a regularity of communications between assets of the plurality of assets and a type of protocol communication between assets of the plurality of assets;
initialize an application comprising a graphical user interface for editing and visually representing the plurality of security zones of the network;
display, on the graphical user interface, a visual representation of a first security zone of the plurality of security zones of the network, wherein the first security zone comprises a first set of assets of the plurality of assets;
receive data corresponding to user input at the graphical user interface editing the first security zone; and
in response to receiving the data, editing the first security zone.
9. The non-transitory computer-readable medium of claim 8 , wherein the visual representation of the first security zone is a logical container of at least two or more of the plurality of assets.
10. The non-transitory computer-readable medium of claim 9 , wherein the network is an industrial network and wherein the plurality of assets comprises industrial devices.
11. The non-transitory computer-readable medium of claim 10 , wherein the network comprises a controller communicatively coupled to a plurality of forwarding devices, wherein each of the plurality of assets is communicatively coupled to a port of one of the plurality of forwarding devices.
12. The non-transitory computer-readable medium of claim 9 , wherein the user input at the graphical user interface editing the first security zone comprises at least one of: moving a visual representation of one of the plurality of assets into the logical container of the first security zone or moving a visual representation of one of the assets from the logical container of the first security zone into a logical container of a second security zone of the network.
13. The non-transitory computer-readable medium of claim 12 , wherein the user input at the graphical user interface editing the first security zone comprises dragging a visual representation of an asset not assigned to a security zone into the logical container of the first security zone.
14. The non-transitory computer-readable medium of claim 12 , wherein the user input at the graphical user interface editing the first security zone comprises dragging a visual representation of one of the assets from the logical container of the first security zone into a logical container of a second security zone of the network.
15. An industrial network system, comprising:
a controller;
a plurality of forwarding devices communicatively coupled to the controller over an industrial network;
a plurality of assets, wherein each of the plurality of assets is communicatively coupled to a port of one of the plurality of forwarding devices; and
a non-transitory computer-readable medium having instructions stored thereon that, when executed by a processor, causes the system to:
generate a plurality of security zones in the industrial network, wherein each of the plurality of security zones comprises a respective set of assets of the plurality of assets, wherein the plurality of security zones are generated based at least in part on a regularity of communications between assets of the plurality of assets and a type of protocol communication between assets of the plurality of assets;
initialize an application comprising a graphical user interface for editing and visually representing the plurality of the security zones of the industrial network;
display, on the graphical user interface, a visual representation of a first security zone of the plurality of security zones of the network, wherein the first security zone comprises a first set of assets of the plurality of assets;
receive data corresponding to user input at the graphical user interface editing the first security zone; and
in response to receiving the data, editing the first security zone.
16. The industrial network system of claim 15 , wherein the visual representation of the first security zone is a logical container of at least two or more of the plurality of assets.
17. The industrial network system of claim 16 , wherein the user input at the graphical user interface editing the first security zone comprises at least one of: moving a visual representation of one of the plurality of assets into the logical container of the first security zone or moving a visual representation of one of the assets from the logical container of the first security zone into a logical container of a second security zone of the network.
18. The industrial network system of claim 17 , wherein the user input at the graphical user interface editing the first security zone comprises dragging a visual representation of an asset not assigned to a security zone into the logical container of the first security zone.