Systems and methods for resilient ZTNA micro-segmentation policy generation
Systems, devices, and methods are discussed for determining zero trust network access policy based upon intent defined groups of workloads.
1 . A method for resilient access control list development, the method comprising:
identifying, by a processing resource, a first set of workloads in a set of network traffic that share at least a first trait, and a second set of workloads in the set of network traffic that share at least a second trait;
identifying, by the processing resource, a first suggested intent of the first set of workloads based upon metadata associated with the first set of workloads;
identifying, by the processing resource, a second suggested intent of the second set of workloads based upon metadata associated with the second set of workloads;
consolidating, by the processing resource, a plurality of network ports of the first set of workloads based at least in part on a network element associated with the first set of workloads into a set of network ports, wherein a given network port of the plurality of network ports is associated with a particular network protocol that transmits communication for a specific service between a traffic source and a traffic destination;
consolidating further, by the processing resource, ports from the plurality of network ports into ranges of ports used for an application, wherein ports from the plurality of network ports are consolidated with similar workloads;
receiving, by the processing resource, an access control list including at least a first access control rule allowing defined activity over multiple network ports, and second access control rule allowing defined activity for workloads having the first suggested intent, and a third access control rule allowing defined activity for workloads having the second suggested intent; and
forward testing, by the processing resource, the access control list comprising the first access control rule, the second access control rule, and the third access control rule, at an application-level of granularity, wherein the access control list is forward tested after the addition of each application and only the most recently added application has not been fully secured.
2 . The method of claim 1 , wherein identifying the first set of workloads in the set of network traffic and the second set of workloads in the set of network traffic includes eliminating network traffic corresponding to a scanner.
3 . The method of claim 1 , wherein identifying the first set of workloads in the set of network traffic and the second set of workloads in the set of network traffic includes eliminating incomplete workflows.
4 . The method of claim 3 , wherein the incomplete workflows are associated with a scanner accessing a closed port.
5 . The method of claim 3 , wherein the incomplete workflows are associated with a scanner accessing an open port and failing to respond to an acknowledgment returned from the open port.
6 . The method of claim 1 , the method further comprising: monitoring, by the processing resource, network activity to yield the set of network traffic.
7 . The method of claim 6 , wherein monitoring network activity to yield the set of network traffic is done such that the network traffic does not include any traffic corresponding to a scanner or any incomplete workflows.
8 . The method of claim 1 , wherein the multiple network ports are selected from a group consisting of: a set of continuous network ports, and a set of discontinuous network ports.
9 . The method of claim 1 , the method further comprising:
modifying, by the processing resource, a default rule of the access control list from allow to block; and
deploying, by the processing resource, the access control list.
10 . The method of claim 1 , wherein the method further comprises: dynamically adding one of the plurality of network ports of the first set of workloads based upon a negotiation of a control channel.
11 . A network appliance, the network appliance comprising:
a processing resource;
a non-transitory computer-readable medium, coupled to the processing resource, having stored therein instructions that when executed by the processing resource cause the processing resource to:
identify a first set of workloads in a set of network traffic that share at least a first trait, and a second set of workloads in the set of network traffic that share at least a second trait;
identify a first suggested intent of the first set of workloads based upon metadata associated with the first set of workloads;
identify a second suggested intent of the second set of workloads based upon metadata associated with the second set of workloads;
consolidate a plurality of network ports of the first set of workloads based at least in part on a network element associated with the first set of workloads into a set of network ports, wherein a given network port of the plurality of network ports is associated with a particular network protocol that transmits communication for a specific service between a traffic source and a traffic destination;
consolidate further ports from the plurality of network ports into ranges of ports used for an application, wherein ports from the plurality of network ports are consolidated with similar workloads;
receive an access control list including at least a first access control rule allowing defined activity over multiple network ports, and second access control rule allowing defined activity for workloads having the first suggested intent, and a third access control rule allowing defined activity for workloads having the second suggested intent; and
forward test the access control list comprising the first access control rule, the second access control rule, and the third access control rule at an application-level of granularity, wherein the access control list is forward tested after the addition of each application and only the most recently added application has not been fully secured.
12 . The network appliance of claim 11 , wherein identifying the first set of workloads in the set of network traffic and the second set of workloads in the set of network traffic includes eliminating network traffic corresponding to a scanner.
13 . The network appliance of claim 11 , wherein identifying the first set of workloads in the set of network traffic and the second set of workloads in the set of network traffic includes eliminating incomplete workflows.
14 . The network appliance of claim 13 , wherein the incomplete workflows are associated with a scanner accessing a closed port.
15 . The network appliance of claim 13 , wherein the incomplete workflows are associated with a scanner accessing an open port and failing to respond to an acknowledgement returned from the open port.
16 . The network appliance of claim 11 , wherein the instructions, that when executed by the processing resource, cause the processing resource further to: monitoring network activity to yield the set of network traffic.
17 . The network appliance of claim 16 , wherein monitoring network activity to yield the set of network traffic is done such that the network traffic does not include any traffic corresponding to a scanner or any incomplete workflows.
18 . The network appliance of claim 11 , wherein the instructions, that when executed by the processing resource, cause the processing resource further to:
dynamically add one of the plurality of network ports of the first set of workloads based upon a negotiation of a control channel.
19 . A non-transitory computer-readable storage medium embodying a set of instructions, which when executed by a processing resource, causes the processing resource to:
identify a first set of workloads in a set of network traffic that share at least a first trait, and a second set of workloads in the set of network traffic that share at least a second trait;
identify a first suggested intent of the first set of workloads based upon metadata associated with the first set of workloads;
identify a second suggested intent of the second set of workloads based upon metadata associated with the second set of workloads; and
consolidate a plurality of network ports of the first set of workloads based at least in part on a network element associated with the first set of workloads into a set of network ports, wherein a given network port of the plurality of network ports is associated with a particular network protocol that transmits communication for a specific service between a traffic source and a traffic destination;
consolidate further ports from the plurality of network ports into ranges of ports used for an application, wherein ports from the plurality of network ports are consolidated with similar workloads;
receive an access control list including at least a first access control rule allowing defined activity over multiple network ports, and second access control rule allowing defined activity for workloads having the first suggested intent, and a third access control rule allowing defined activity for workloads having the second suggested intent; and
forward test the access control list comprising the first access control rule, the second access control rule, and the third access control rule at an application-level of granularity, wherein the access control list is forward tested after the addition of each application and only the most recently added application has not been fully secured.
20 . The non-transitory computer-readable storage medium of claim 19 , wherein the multiple network ports are selected from a group consisting of: a set of continuous network ports, and a set of discontinuous network ports.
21 . The non-transitory computer-readable storage medium of claim 19 , wherein the set of instructions, which when executed by the processing resource, further causes the processing resource to:
modify a default rule of the access control list from allow to block; and
deploy the access control list.