Secure network communication system and method
A method for securing a network is described. The method includes receiving, by a virtual-edge (VE) docker of the network, a flow-tuple including data associated with at least a source device of the network, from an Internet Protocol (IP) flow cache. The method further includes performing, by the VE docker, a policy lookup for the flow-tuple in policy for the source device. The method furthermore includes pushing, by the VE docker, a transformed network access control (NAC) including NAC constructs based on the policy lookup, to an enforcement point (EP) in proximity to the source device.
1 . A method for securing a network, the method comprising:
receiving, by a virtual-edge (VE) docker of the network, a flow-tuple including data associated with at least a source device of the network, from an Internet Protocol (IP) flow cache;
performing, by the VE docker, a policy lookup for the flow-tuple in one or more policy databases for the source device; and
pushing, by the VE docker, a transformed network access control (NAC) including NAC constructs based on the policy lookup, to an enforcement point (EP) in proximity to the source device.
2 . The method of claim 1 , further comprising receiving, by the VE docker, a policy from a software-defined perimeter controller (SDP-C).
3 . The method of claim 2 , further comprising storing, by the VE docker, the policy in the one or more policy databases included in the VE docker.
4 . The method of claim 3 , wherein performing the policy lookup for the flow-tuple in the policy comprises determining whether a policy for the flow-tuple exists in the one or more policy databases.
5 . The method of claim 4 , wherein pushing the transformed NAC to the EP in priority to the source device comprises pushing the transformed NAC to the EP in proximity to the source device in response to determining that the policy for the flow-tuple exists in the one or more policy databases.
6 . The method of claim 1 , further comprising:
configuring, by the VE docker, netflows for one or more EPs, including the EP in proximity to the source device and controlled by the VE docker in the network, such that the one or more EPs are enabled to stream netflow records associated with IP flows detected by the one or more EPs, to the VE docker.
7 . The method of claim 6 , further comprising:
receiving, by the VE docker, the netflow records associated with the IP flows streamed by the EP in proximity to the source device, wherein the netflow records include the flow-tuple.
8 . The method of claim 7 , further comprising:
updating, by the VE docker, the netflow records in the IP flow cache.
9 . The method of claim 8 , further comprising:
awaiting, by the VE docker, for one or more of additions, deletions, and modifications of the policy from a software-defined perimeter controller (SDP-C).
10 . The method of claim 9 , further comprising:
receiving, by the VE docker, an IP flow timeout from the IP flow cache; and
in response to receiving the IP flow timeout, withdrawing, by the VE docker, the transformed NAC applicable for the EP in proximity to the source device.
11 . The method of claim 6 , further comprising:
receiving, by the VE docker, the netflow records associated with the IP flows streamed by an EP in proximity to a destination device of the network, wherein the netflow records include a flow-tuple including data associated with at least the destination device.
12 . The method of claim 11 , further comprising:
updating, by the VE docker, the netflow records associated with the IP flows streamed by the EP in proximity to the destination device, in the IP flow cache.
13 . The method of claim 12 , further comprising:
receiving, by the VE docker, the flow-tuple including the data associated with at least the destination device, from the IP flow cache;
performing, by the VE docker, a policy lookup for the flow-tuple including the data associated with at least the destination device in the one or more policy databases; and
pushing, by the VE docker, a transformed NAC based on the policy lookup for the flow-tuple including the data associated with at least the destination device, to the EP in proximity to the destination device.
14 . The method of claim 13 , further comprising:
awaiting, by the VE docker, for one or more of additions, deletions, and modifications of a policy from a software-defined perimeter controller (SDP-C).
15 . The method of claim 14 , further comprising:
receiving, by the VE docker, an IP flow timeout for the destination device from the IP flow cache; and
in response to receiving the IP flow timeout for the destination device, withdrawing, by the VE docker, the transformed NAC applicable for the EP in proximity to the destination device.
16 . A virtual-edge (VE) docker for securing a network, the VE docker comprising:
a processor; and
a memory storing computer-executable instructions that when executed, cause the processor to:
receive, a flow-tuple including data associated with at least a source device of the network, from an Internet Protocol (IP) flow cache;
perform a policy lookup for the flow-tuple in one or more policy databases for the source device; and
push a transformed network access control (NAC) including NAC constructs based on the policy lookup, to an enforcement point (EP) in proximity to the source device.
17 . The VE docker of claim 16 , wherein the processor is further configured to:
configure netflows for one or more EPs, including the EP in proximity to the source device and controlled by the VE docker in the network, such that the one or more EPs are enabled to stream netflow records associated with IP flows detected by the one or more EPs, to the VE docker; and
receive the netflow records associated with the IP flows streamed by the EP in proximity to the source device, wherein the netflow records include the flow-tuple.
18 . The VE docker of claim 17 , wherein the processor is further configured to:
update the netflow records in the IP flow cache.
19 . The VE docker of claim 18 , wherein the processor is further configured to:
await for one or more of additions, deletions, and modifications of a policy from a software-defined perimeter controller (SDP-C).
20 . The VE docker of claim 19 , wherein the processor is further configured to:
receive an IP flow timeout from the IP flow cache; and
in response to the reception of the IP flow timeout, withdraw the transformed NAC applicable for the EP in proximity to the source device.