IP Library › Granted Patent US 12,388,711
Granted Patent B2
US 12,388,711 · App. 17/701,467 · Granted Aug 12, 2025

Policy management across multiple cloud computing environments within a network

Inventors: Jonathan Michael Bosanac (San Francisco, CA); Christopher Robert Geeringh (Berkeley, CA); Jason Eggleston (Newport Beach, CA); Lonhyn Jasinskyj (Palo Alto, CA); John Sengenberger (Meridian, ID)
Assignee: Netskope, Inc.
H04L41/0866H04L41/0893H04L41/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,388,711
App. No.
17/701,467
Granted
Aug 12, 2025
Kind
B2
Abstract

A system for providing policy-controlled communication between a plurality of different cloud computing environments includes a user interface that receives configuration settings to be applied to a plurality of first instances and a plurality of second instances. A plurality of collectors of the system that retrieve information from a first cloud computing environment and a second cloud computing environment, and a controller determines policies for the plurality of first instances and the plurality of second instances. A configurator of the system applies the policies to the plurality of first instances and the plurality of second instances, a first tester that inspects operations of the plurality of first instances and detects violations of the policies, and an enforcer responds to the detected violations. The controller instructs the configurator to apply the first policy to the first instance again, shut down the first instance or cut off communications with the first instance.

Claims (42)

1. A system for providing policy-controlled communication over the Internet between a plurality of different cloud computing environments, detecting violations of policies and responding to the violations, the system comprising:

a user interface that receives configuration settings to be applied to a plurality of first instances within a first cloud computing environment and a plurality of second instances within a second cloud computing environment, wherein:

the first cloud computing environment comprises one or more first processors and one or more first memories, and

the second cloud computing environment comprises one or more second processors and one or more memories;

a plurality of collectors that retrieve information from the first cloud computing environment and the second cloud computing environment, wherein the information comprises a plurality of functionalities of the first cloud computing environment and the second cloud computing environment;

a controller that determines policies for the plurality of first instances within the first cloud computing environment and the plurality of second instances within the second cloud computing environment as functions of the configuration settings and the information;

a configurator that applies the policies to the plurality of first instances within the first cloud computing environment and the plurality of second instances within the second cloud computing environment;

a first tester that inspects operations of the plurality of first instances within the first cloud computing environment and detects violations of the policies by the plurality of first instances within the first cloud computing environment, wherein the first tester inspects the operations based on a testing schedule which indicates a frequency of testing for the first instance for compliance after each specific policies was applied to the first instance and a table that stores a list of a number of times at which the first instance was tested for the compliance with the specific policies; and

an enforcer that responds to the detected violations by receiving a notification from the first tester that a first instance from the plurality of first instances violated a first policy, wherein the controller instructs the configurator to apply the first policy to the first instance again, shut down the first instance or cut off communications with the first instance.

2. The system of claim 1 , wherein the plurality of functionalities of the first cloud computing environment and the second cloud computing environment comprises at least one of network configurations, firewall rules, cloud application programming interfaces (APIs), resources, cloud service providers, or data sets.

3. The system of claim 1 , wherein the information further comprises at least one of a data input type, a data type, a data size, or a data age, and the plurality of collectors are further configured to normalize the information to have a common format.

4. The system of claim 1 , wherein the policies comprise at least one of firewall rules, forwarding rules, network configurations, cross-cloud routing rules, IP addressing rules, cross-cloud peering rules, security group management rules, storage bucket access rules, resource management rules, or subnet configurations.

5. A method for providing policy-controlled communication over the Internet between a plurality of different cloud computing environments, detecting violations of policies and responding to the violations, the method comprising:

receiving configuration settings to be applied to a plurality of first instances within a first cloud computing environment and a plurality of second instances within a second cloud computing environment;

retrieving information from the first cloud computing environment and the second cloud computing environment, wherein the information comprises a plurality of functionalities of the first cloud computing environment and the second cloud computing environment;

determining policies for the plurality of first instances within the first cloud computing environment and the plurality of second instances within the second cloud computing environment as functions of the configuration settings and the information;

applying the policies to the plurality of first instances within the first cloud computing environment and the plurality of second instances within the second cloud computing environment;

inspecting operations of the plurality of first instances within the first cloud computing environment and the plurality of second instances within the second cloud computing environment and detecting violations of the policies by the plurality of first instances within the first cloud computing environment and the plurality of second instances within the second cloud computing environment; and

responding to the detected violations by receiving a notification that a first instance from the plurality of first instances violated a first policy, wherein a controller instructs a configurator to apply the first policy to the first instance again, shut down the first instance or cut off communications with the first instance.

6. The method of claim 5 , wherein determining the policies comprises determining general policies as functions of the configuration settings and translating the general policies to specific policies for the first cloud computing environment and the second cloud computing environment by using the information.

7. The method of claim 6 , wherein applying the policies comprises retrieving scripts corresponding to the specific policies and applying the specific policies to the plurality of first instances within the first cloud computing environment and the plurality of second instances within the second cloud computing environment by executing the scripts.

8. The method of claim 5 , further comprising sending the notification of a detected violation of a policy by an instance of the plurality of first instances within the first cloud computing environment to a user interface.

9. The method of claim 5 , wherein a first tester may inspect the first instance to determine whether it complies with various policies, such as whether a load balancer was set up, whether the load balancer is running correctly, whether the load balancer has enough processing power, and whether the load balancer has a correct IP address.

10. A system for providing policy-controlled communication over the Internet between a plurality of different cloud computing environments, detecting violations of policies and responding to the violations, the system comprising one or more processors and one or more memories with code for:

a user interface that is configured to receive configuration settings to be applied to a plurality of first instances within a first cloud computing environment and a plurality of second instances within a second cloud computing environment, wherein:

the first cloud computing environment comprises one or more first processors and one or more first memories, and

the second cloud computing environment comprises one or more second processors and one or more memories;

a plurality of collectors that are configured to retrieve information from the first cloud computing environment and the second cloud computing environment, wherein the information comprises a plurality of functionalities of the first cloud computing environment and the second cloud computing environment;

a controller that is configured to determine policies for the plurality of first instances within the first cloud computing environment and the plurality of second instances within the second cloud computing environment as functions of the configuration settings and the information;

a configurator that is configured to apply the policies to the plurality of first instances within the first cloud computing environment and the plurality of second instances within the second cloud computing environment;

a first tester that is configured to inspect operations of the plurality of first instances within the first cloud computing environment, wherein the first tester inspects the operations based on a testing schedule which indicates a frequency of testing for the first instance for compliance after each specific policies was applied to the first instance and a table that stores a list of a number of times at which the first instance was tested for the compliance with the specific policies, and a second tester that inspect operations of the plurality of second instances within the second cloud computing environment to detect violations of the policies by the plurality of first instances within the first cloud computing environment and violations of the policies by the plurality of second instances within the second cloud computing environment, respectively; and

an enforcer that is configured to respond to the detected violations by receiving a notification from the first tester that a first instance from the plurality of first instances violated a first policy, wherein the controller instructs the configurator to apply the first policy to the first instance again, shut down the first instance or cut off communications with the first instance.

11. The system of claim 10 , wherein the controller is configured to determine the policies by determining general policies as functions of the configuration settings and translating the general policies to specific policies for the first cloud computing environment and the second cloud computing environment by using the information.

12. The system of claim 11 , wherein the controller is configured to translate the general policies to the specific policies at a service layer and a software-defined data center layer.

13. The system of claim 11 , wherein the configurator is configured to retrieve scripts corresponding to the specific policies and to apply the specific policies to the plurality of first instances within the first cloud computing environment and the plurality of second instances within the second cloud computing environment by executing the scripts.

14. The system of claim 10 , further comprising a reporter is configured to send the notification via a short message service (SMS), an email, an Application Programming Interface (API) call, or another notification method.

15. The system of claim 10 , further comprising a metadata service endpoint that is configured to receive the policies from the configurator and to host changes to the plurality of first instances and the plurality of second instances, wherein the plurality of first instances within the first cloud computing environment and the plurality of second instances within the second cloud computing environment are configured to retrieve the changes from the metadata service endpoint and to apply the changes.

16. The system of claim 10 , wherein the enforcer is further configured to send the notification of the detected violation to the controller, which directs the configurator to apply the first policy that was violated to a non-complying instance.

17. The system of claim 10 , wherein the notification identifies the first instance that violated the first policy, the first cloud computing environment in which the first instance is located, and the first policy that was violated.

18. The system of claim 17 , wherein the controller is further configured to receive the notification of the detected violation and to require the first instance of the plurality of first instances within the first cloud computing environment to comply with the first policy that was violated.

19. The system of claim 10 , wherein the first tester is further configured to inspect existing IP addresses of the plurality of first instances and to send a notification to the enforcer to request new IP addresses from the first cloud computing environment upon identifying an overlap between the existing IP addresses.

20. The system of claim 10 , wherein the first tester is further configured to inspect the operations of the plurality of first instances based on a testing schedule which indicates a frequency of testing for the plurality of first instances for compliance with the policies.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2022
From: BOSANAC, JONATHAN MICHAEL; SENGENBERGER, JOHN; EGGLESTON, JASON; JASINSKYJ, LONHYN; GEERINGH, CHRISTOPHER ROBERT
To: NETSKOPE, INC.
Reel/Frame 059345/0175 →
Continuity (2)
Continuation 17101892 · Nov 23, 2020
Related Publication 20220217050A1 · Jul 7, 2022
References Cited (131)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 6353866B1 · Fensore · 2002 [cited by examiner]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7000006B1 · Chen · 2006 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8112379B2 · Voskuil et al. · 2012 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8719804B2 · Jain · 2014 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9282118B2 · Elzur · 2016 [cited by applicant]
US 9729465B2 · Labocki et al. · 2017 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 10051042B2 · Diwakar et al. · 2018 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10437625B2 · Kaufman et al. · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10498693B1 · Strauss · 2019 [cited by examiner]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-LeMair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050044197A1 · Lai · 2005 [cited by examiner]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20100318642A1 · Dozier · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20120185913A1 · Martinez · 2012 [cited by examiner]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20160218926A1 · Johnson et al. · 2016 [cited by applicant]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250877A1 · Seyvet et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20180069948A1 · Blank et al. · 2018 [cited by applicant]
US 20180115463A1 · Sinha et al. · 2018 [cited by applicant]
US 20180173604A1 · Bhat et al. · 2018 [cited by applicant]
US 20180234459A1 · Kung · 2018 [cited by examiner]
US 20180241751A1 · Kruse · 2018 [cited by examiner]
US 20200004589A1 · Geiger et al. · 2020 [cited by applicant]
US 20200028894A1 · Memon · 2020 [cited by examiner]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20200295999A1 · Anandam et al. · 2020 [cited by applicant]
US 20200364078A1 · Potter · 2020 [cited by applicant]
EP 1063833A2 · 2000 [cited by applicant]
Yifei Yuan, Rajeev Alur, and Boon Thau Loo. 2014. NetEgg: Programming Network Policies by Examples. In Proceedings of the 13th ACM Workshop on Hot Topics in Networks (HotNets-XIII). Association for Computing Machinery, … [cited by examiner]
Tang, Y., Cheng, G., Xu, Z. et al. Automatic belief network modeling via policy inference for SDN fault localization. J Internet Serv Appl 7, 1 (2016) (Year: 2016). [cited by examiner]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff Ending Clear Text Protocols, Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Nevvton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
McCullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al. “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., Farsite: Federated, available, and reliable storage for an incompletely trusted environment, SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al. , Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html#:˜:text=mode of communication.-,What are the different email protoco… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” Tech Target, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?%20Offe… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1 , Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet,FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/%2010.1007/978-3-319… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs, 1999. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al. “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&P 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management for Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]