Protecting network resources from known threats
Patent Information
- Application Number
- CN202180072628.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-08-26
- Filing Date
- 2021-08-16
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2041-08-16
Smart Images

Figure CN116458120B_ABST
Abstract
Description
[0001] Cross-reference to related applications
[0002] This application claims the benefit and priority of U.S. nonprovisional patent application No. 17 / 003,364, filed on August 26, 2020, the entire disclosure of which is expressly and completely incorporated herein by reference. Technical Field
[0003] The subject matter of this disclosure generally relates to the field of computer networks, and more specifically, to protecting network workloads by identifying compromised components communicating with the network and preventing them from accessing network resources. Background Technology
[0004] As enterprise networks expand and their applicability increases, the applications and workloads available on these networks can be accessed by a variety of devices. To ensure the security of applications and workloads, enterprises must develop and implement policies to control the accessibility of network workloads. However, given that devices are exposed to unauthorized and malicious external resources, enterprises often lack the information to implement granular policies for accessing specific applications. Attached Figure Description
[0005] To illustrate how the above and other advantages and features of this disclosure are attainable, a more specific description of the principles briefly described above will be presented by reference to specific embodiments illustrated in the accompanying drawings. It should be understood that these drawings depict only embodiments of this disclosure and should therefore not be considered as limiting its scope, in order to describe and explain the principles herein in a more specific and detailed manner using the drawings, in which:
[0006] Figure 1 An example of a network traffic monitoring system according to one aspect of this disclosure is shown;
[0007] Figure 2 An example of a network environment according to one aspect of this disclosure is shown;
[0008] Figure 3 An example of a data pipeline for generating network insights based on collected network information, according to one aspect of this disclosure, is shown;
[0009] Figure 4 A simplified version of a configuration according to one aspect of this disclosure is shown, in which, Figure 2 The components of the network environment communicate with potential network threats;
[0010] Figure 5 Another simplified version of the setup according to one aspect of this disclosure is shown, in which, Figure 2The network environment components communicate with potentially malicious hosts;
[0011] Figure 6 A process according to one aspect of this disclosure is described for processing a list of known cyber threats and extracting it to network sensors for detecting compromised workloads and endpoints;
[0012] Figure 7 This is an example of a network monitoring process according to one aspect of this disclosure, the network monitoring process being used to block network access from malicious sources; and
[0013] Figure 8 An example computing system according to one aspect of this disclosure is shown. Detailed Implementation
[0014] Various embodiments of this disclosure are discussed in detail below. Although specific implementations are discussed, it should be understood that this is done for illustrative purposes only. Those skilled in the art will recognize that other components and configurations can be used without departing from the spirit and scope of this disclosure. Therefore, the following description and drawings are illustrative and should not be construed as limiting. Numerous specific details have been described to provide a thorough understanding of this disclosure. However, in some instances, well-known or conventional details have not been described to avoid obscuring the description. References to one embodiment or an embodiment in this disclosure may be references to the same embodiment or any of the embodiments; and such references imply at least one embodiment.
[0015] References to "an embodiment" or "an embodiment" indicate that a particular feature, structure, or characteristic described with respect to that embodiment is included in at least one embodiment of this disclosure. The phrase "in an embodiment" appearing in various places throughout the specification does not necessarily refer to the same embodiment, nor is it necessarily a separate or alternative embodiment that is mutually exclusive with other embodiments. Furthermore, various features that may be presented in some embodiments but not in others are described.
[0016] The terms used in this specification generally have their ordinary meanings in the art, in the context of this disclosure, and in the specific context in which each term is used. Alternative languages and synonyms may be used for any one or more terms discussed herein and should not be given special meaning regardless of whether the terms are elaborated or discussed herein. In some cases, synonyms are provided for certain terms. The description of one or more synonyms does not preclude the use of other synonyms. The use of examples anywhere in this specification, including examples of any terms discussed herein, is illustrative only and is not intended to further limit the scope and meaning of this disclosure or any of the example terms. Likewise, this disclosure is not limited to the various embodiments given in this specification.
[0017] Examples of instruments, apparatus, methods, and related results according to embodiments of this disclosure are given below, but are not intended to limit the scope of this disclosure. Note that headings or subheadings may be used in the examples for the reader's convenience, but these should in no way limit the scope of this disclosure. Unless otherwise defined, the technical and scientific terms used herein have the meanings commonly understood by one of ordinary skill in the art to which this disclosure pertains. In the event of any conflict, this document (including the definitions) shall prevail.
[0018] Additional features and advantages of this disclosure will be set forth in the following description and will be apparent in part from the description, or may be learned by practicing the principles disclosed herein. The features and advantages of this disclosure can be realized and obtained by the instruments and combinations particularly pointed out in the appended claims. These and other features of this disclosure will become more apparent from the following description and the appended claims, or may be learned by practicing the principles set forth herein.
[0019] Overview
[0020] The invention is set forth in the independent claims and in the dependent claims. A feature of one aspect may be applied to any aspect alone or in combination with other aspects.
[0021] This document discloses methods, systems, and nontransitory computer-readable media for protecting network workloads by identifying compromised components communicating with the network and preventing them from accessing network resources. More specifically, methods, systems, and nontransitory computer-readable media are disclosed for applying dynamic access blocking schemes to compromised components communicating with resources within the network based on the nature of the potential threats detected to the compromised component(s).
[0022] In one aspect, a method includes: monitoring network traffic at network elements of a network; detecting a compromised element communicating with one or more network elements, the compromised element being associated with at least one network threat; and applying one of a plurality of different access blocking schemes to the compromised element to prevent the compromised element from accessing the network, based on a defined network policy.
[0023] On the other hand, detecting compromised elements includes: identifying at least one network threat in the corresponding network traffic monitored for at least one network element; and marking at least one network element as a compromised element.
[0024] On the other hand, identifying at least one cyber threat includes: receiving a list of known cyber threats; generating a label for identifying the known cyber threats; and using the label to identify at least one cyber threat.
[0025] On the other hand, several different access blocking schemes include: blocking the compromised element from accessing at least one of the network elements; or isolating the compromised element for a period of time, wherein the isolation prevents any communication to and from the compromised element.
[0026] On the other hand, one of several different access blocking schemes includes blocking a compromised element from accessing a first workload on one or more network elements, but allowing the compromised element to access a second workload on one or more network elements.
[0027] On the other hand, a cyber threat is one of the known network IP addresses or malware categories.
[0028] On the other hand, a compromised component is an endpoint registered with the network that has accessed an external source with at least one network threat.
[0029] In one aspect, a network element includes one or more memories and one or more processors, the memories storing computer-readable instructions. The one or more processors are configured to execute the computer-readable instructions to: monitor network traffic at the network element; detect a compromised element communicating with one or more network elements, the compromised element being associated with at least one network threat; and, based on a defined network policy, apply one of several different access blocking schemes to the compromised element to prevent it from accessing the network.
[0030] In one aspect, one or more non-transitory computer-readable media include computer-readable instructions that, when executed by one or more processors, cause one or more processors to: monitor network traffic at network elements of the network; detect a compromised element communicating with one or more network elements, the compromised element being associated with at least one network threat; and, based on a defined network policy, apply one of a plurality of different access blocking schemes to the compromised element to prevent the compromised element from accessing the network.
[0031] describe
[0032] Various embodiments of this disclosure are discussed in detail below. Although specific implementations are discussed, it should be understood that this is done for illustrative purposes only. Those skilled in the art will recognize that other components and configurations can be used without departing from the spirit and scope of this disclosure.
[0033] The disclosed technology addresses the need in the art to ensure network security by detecting compromised workloads and endpoints (compromised elements) and blocking network resources from partial or complete access to or from compromised elements. As described below, and depending on the nature of the threat detected to be associated with the compromised element, different access blocking schemes can be applied, wherein the compromised element may be partially blocked from accessing one or more specific nodes, one or more specific workloads in the network, or completely blocked through isolation. Detection of compromised elements can be based on the identification of threats using a list of known threats (e.g., known network threat alliance (CTA) threats) that identifies the malicious source, the malicious category of the threat, the malicious Uniform Resource Locator (URL), and the malicious IP address. Such a list can be distributed to agents deployed on network nodes, which are configured to monitor network traffic and detect threats.
[0034] The present technology will be described in more detail below. This disclosure begins with an initial discussion of systems and techniques used for monitoring Figures 1 to 3 Network activities within a network environment. This will continue to discuss the potential exposure of network components to network threats (…). Figure 4 and Figure 5 The following is a setup example, and the subsequent procedures discuss the process of establishing a scheme to identify network threats and implement dynamic access blocking when a threat is identified. Figure 6 and Figure 7 This discussion will conclude with examples of system and device configurations and architectures that can be used within the context of this disclosure. Figures 1 to 5 Various components of the system.
[0035] Sensors deployed within a network can be used to collect network information related to network traffic of nodes operating within the network, and to process information about the nodes and applications running in the network. The collected network information can be analyzed to provide insights into the operations of nodes within the network, or otherwise referred to as analytics. Specifically, network traffic data can be used to determine for the network identified applications or inventories, application dependencies, policies, efficiency, resource and bandwidth usage, and network flow. For example, analytics engines can be configured to automatically discover applications running in the network, map internal dependencies of applications, or generate a set of recommended network policies for implementation.
[0036] The analytics engine can use a sensor network that provides multiple perspectives on traffic to monitor network information, process information, and other relevant information about the traffic passing through the network. The sensor network can include sensors for networked devices (e.g., routers, switches, network appliances), physical servers, hypervisors or shared kernels, and virtual partitions (e.g., VMs or containers) and other network elements. The analytics engine can analyze the network information, process information, and other relevant information to determine various network insights.
[0037] Figure 1 An example of a network traffic monitoring system according to one aspect of this disclosure is shown.
[0038] The network traffic monitoring system 100 may include a configuration manager 102, a sensor 104, a collector module 106, a data mover module 108, an analysis engine 110, and a presentation module 112. Figure 1 The diagram also shows the analysis engine 110 communicating with out-of-band data source 114, third-party data source 116, and network controller 118.
[0039] Configuration Manager 102 can be used to provide and maintain Sensor 104, including installing sensor software or firmware on various nodes of the network, configuring Sensor 104, updating sensor software or firmware, and other sensor management tasks. For example, Sensor 104 can be implemented as a virtual partition image (e.g., a virtual machine (VM) image or a container image), and Configuration Manager 102 can distribute this image to hosts. Generally, a virtual partition can be an instance of a VM, container, sandbox, or other isolated software environment. The software environment can include operating systems and application software. For software running in a virtual partition, the virtual partition can represent, for example, one server among many servers or one of many operating systems running on a single physical server. Configuration Manager 102 can instantiate new virtual partitions or migrate existing partitions to different physical servers. Configuration Manager 102 can also be used to configure new or migrated sensors.
[0040] Configuration Manager 102 can monitor the health of Sensor 104. For example, Configuration Manager 102 can request status updates and / or receive heartbeat messages, initiate performance tests, generate health checks, and perform other health monitoring tasks. In some embodiments, Configuration Manager 102 can also authenticate Sensor 104. For example, a unique identifier can be assigned to Sensor 104 using a one-way hash function of the sensor's Basic Input / Output System (BIOS) Universal Unique Identifier (UUID) and a key stored by Configuration Manager 102. The UUID can be a multi-digit number that is difficult for malicious sensors or other devices or components to guess. In some embodiments, Configuration Manager 102 can provide Sensor 104 with all the latest information by installing the latest version of the sensor software and / or by applying patches. Configuration Manager 102 can automatically obtain these updates from local sources or the Internet.
[0041] Sensor 104 may reside on various nodes of the network, such as virtual partitions (e.g., VMs or containers) 120, hypervisors or shared kernels managing one or more virtual partitions, and / or physical servers 122, application-specific integrated circuits (ASICs) 124 of switches, routers, gateways or other networking devices, or packet capture (pcap) devices 126 (e.g., stand-alone packet monitors, devices connected to network device monitoring ports, devices cascaded along the spine of a data center, or similar devices), or other elements of the network. Sensor 104 may monitor network traffic between nodes and send network traffic data and corresponding data (e.g., host data, process data, user data, etc.) to collector 106 for storage. For example, sensor 104 may listen for packets sent through physical or virtual network interface cards (NICs) of its host, or individual processes may be configured to report network traffic and corresponding data to sensor 104. Incorporating sensor 104 onto multiple nodes of the network and within multiple partitions of some nodes can provide robust capture of network traffic and corresponding data for each hop of data transmission. In some embodiments, each node of the network (e.g., VM, container or other virtual partition 120, hypervisor, shared kernel or physical server 122, ASIC 124, pcap 126, etc.) includes a corresponding sensor 104. However, it should be understood that various software and hardware configurations can be used to implement the sensor network 104.
[0042] As sensors 104 capture communications and corresponding data, they can continuously transmit network traffic data to collector 106. Network traffic data may include metadata related to packets, packet sets, flows, bidirectional flows, flow groups, sessions, or other granularities of network communication. That is, network traffic data can generally include any information describing communication across all layers of the Open Systems Interconnection (OSI) model. For example, network traffic data may include source / destination MAC addresses, source / destination IP addresses, protocols, port numbers, etc. In some embodiments, network traffic data may also include a summary of network activity or other network statistics, such as packet count, byte count, flow count, bandwidth usage, response time, latency, packet loss, jitter, and other network statistics.
[0043] Sensor 104 can also determine additional data for each session, bidirectional flow, stream, packet, or other network communication of a larger or smaller granularity. This additional data may include host and / or endpoint information, virtual partition information, sensor information, process information, user information, tenant information, application information, network topology, application-related mappings, cluster information, or other information specific to each flow.
[0044] In some embodiments, sensor 104 may perform some preprocessing on network traffic and corresponding data before sending the data to collector 106. For example, sensor 104 may remove irrelevant or duplicate data, or it may create data profiles (e.g., latency, number of packets per flow, number of bytes per flow, number of flows, etc.). In some embodiments, sensor 104 may be configured to capture only certain types of network information while ignoring the rest. In some embodiments, sensor 104 may be configured to capture only representative samples of packets (e.g., every 1000th packet or other appropriate sampling rate) and the corresponding data.
[0045] Because sensor 104 can be located throughout the network, network traffic and corresponding data can be collected from multiple vantage points or angles within the network to provide a more comprehensive view of network behavior. Capturing network traffic and corresponding data from multiple angles, rather than from a single sensor located in or communicating with components in the data path, allows data from various data sources to be correlated, which can then be used as additional data points by the analytics engine 110. Furthermore, collecting network traffic and corresponding data from multiple viewpoints ensures more accurate data capture. For example, other types of sensor networks may be limited to sensors operating on externally facing network devices (e.g., routers, switches, network appliances, etc.), making east-west traffic (including VM-to-VM or container-to-container traffic on the same host) potentially unmonitored. Additionally, packets dropped before traversing network devices or packets containing errors may not be accurately monitored by other types of sensor networks. Sensor networks 104 in various embodiments substantially mitigate or eliminate these problems by placing sensors at multiple potential points of failure. Furthermore, the network traffic monitoring system 100 can cross-validate multiple instances of traffic data (e.g., source endpoint flow data, network device flow data, and endpoint flow data).
[0046] In some embodiments, the network traffic monitoring system 100 can evaluate the accuracy of flow datasets from multiple sensors and utilize the flow dataset from a single sensor that is determined to be the most accurate and / or most complete. Accuracy can be based on factors such as network topology (e.g., sensors closer to the source may be more accurate than those closer to the destination), the state of the sensor or the node housing the sensor (e.g., an undamaged sensor / node may have more accurate flow data than a damaged sensor / node), or the amount of flow data (e.g., a sensor capturing more flow packets may be more accurate than one capturing fewer flow packets).
[0047] In some embodiments, the network traffic monitoring system 100 can combine the most accurate traffic datasets and corresponding data from multiple sensors. For example, a first sensor along a data path may capture traffic data for a first packet but may miss traffic data for a second packet, while the opposite is true for a second sensor along the data path. The network traffic monitoring system 100 can combine traffic data from the first packet captured by the first sensor and the second packet captured by the second sensor.
[0048] As discussed, sensor 104 can send network traffic and corresponding data to collector 106. In some embodiments, as part of a high-availability scheme, each sensor can be assigned to a primary collector and a secondary collector. If the primary collector fails or communication between the sensor and the primary collector is otherwise impossible, the sensor can send its network traffic and corresponding data to the secondary collector. In other embodiments, sensor 104 is not assigned to a specific collector, but network traffic monitoring system 100 can determine the optimal collector for receiving network traffic and corresponding data through a discovery process. In such embodiments, if the sensor's environment changes, for example, if the default collector fails, or if the sensor is relocated to a new location and the sensor sends its data to a different collector, the sensor can change where it sends its network traffic and corresponding data. For example, it may be preferred that the sensor sends its network traffic and corresponding data to a specific path and / or a specific collector based on latency, shortest path, monetary cost (e.g., using private resources vs. using public resources provided by a public cloud provider), error rate, or some combination of these factors. In other embodiments, the sensor can send different types of network traffic and corresponding data to different collectors. For example, a sensor can send a first network traffic and corresponding data associated with one type of process to a collector, and a second network traffic and corresponding data associated with another type of process to another collector.
[0049] Collector 106 can be any type of storage medium, which can act as a repository for network traffic and corresponding data captured by sensor 104. In some embodiments, the data storage device of collector 106 is located in a database within memory, for example, While the data storage device of collector 106 can be a dashDB, it should be understood that it can be any software and / or hardware capable of providing the fast random access speeds typically used in analytics software. In various embodiments, collector 106 may utilize solid-state drives, disk drives, tape drives, or combinations thereof, depending on cost, responsiveness, and size requirements. Furthermore, collector 106 may utilize various database structures, such as normalized relational databases or NoSQL databases.
[0050] In some embodiments, collector 106 may simply function as a network storage device for network traffic monitoring system 100. In such embodiments, network traffic monitoring system 100 may include a data mover module 108 for retrieving data from collector 106 and making the data available to network clients (e.g., components of analytics engine 110). In effect, data mover module 108 may act as a gateway presenting the network-attached storage device to network clients. In other embodiments, collector 106 may perform additional functions, such as organizing, summarizing, and preprocessing data. For example, collector 106 may tabulate the frequency of packets of certain sizes or types being transmitted from different nodes in the network. Collector 106 may also characterize traffic flows to and from various nodes. In some embodiments, collector 106 may match packets based on sequence numbers to identify traffic flows and connection links. Because retaining all data indefinitely can be inefficient in some cases, in some embodiments, collector 106 may periodically replace detailed network traffic data with a consolidated summary. In this way, collector 106 can retain a complete dataset describing a time period (e.g., past minutes or an appropriate time period), as well as a smaller dataset for another time period (e.g., the previous 2 to 10 minutes or another appropriate time period), and progressively merge network traffic and corresponding data for other time periods (e.g., daily, weekly, monthly, yearly, etc.). In some embodiments, network traffic and corresponding data identified as normal or regular flow sets can be selected for an earlier period, while a more complete dataset can be retained for a longer period for another flow set identified as anomalous or under attack.
[0051] Computer networks can be vulnerable to various attacks that expose weaknesses in computer systems to compromise their security. Some network traffic may be associated with malware or devices. Analysis engine 110 can provide examples of network states corresponding to attacks and those corresponding to normal operation. Analysis engine 110 can then analyze the network traffic and corresponding data to identify when the network was attacked. In some embodiments, the network can operate in a trusted environment for a period of time, allowing analysis engine 110 to determine a baseline for normal operation. Because malware is constantly evolving and changing, machine learning can be used to dynamically update the model used to identify malicious traffic patterns.
[0052] In some embodiments, the analysis engine 110 can be used to identify observations that differ from other examples in the dataset. For example, if a training set of example data with known culling values exists, supervised anomaly detection techniques can be used. Supervised anomaly detection techniques utilize datasets that have been labeled as normal and anomalous and train a classifier. Unsupervised anomaly detection techniques can be used when it is unknown whether the examples in the training data are culling values. Unsupervised anomaly detection techniques can be used to detect anomalies in an unlabeled test dataset by looking for instances that appear to fit into the rest of the dataset, assuming that most instances in the dataset are normal.
[0053] The analytics engine 110 may include a data lake 130, an application relevance mapping (ADM) module 140, and a resilient processing engine 150. The data lake 130 is a large-scale storage facility that provides high-capacity storage for various types of data, massive processing power, and the ability to handle virtually unlimited concurrent tasks or jobs. In some embodiments, it uses data from Maryland... Software Foundation of Forest Hill Distributed File System (HDFS) TM This will enable the implementation of Data Lake 130. HDFS TM It is a highly scalable distributed file system that can scale to thousands of cluster nodes, millions of files, and billions of bytes of data. HDFS TM Optimized for batch processing, where data locations are exposed to allow computation to be performed where the data resides. HDFS TM A single namespace is provided for the entire cluster to ensure data consistency in the write-once-read-many access model. That is, clients can only append to existing files on a node. In HDFS... TM In this process, files are divided into blocks, typically 64MB in size, and replicated across multiple data nodes. Clients access data directly from the data nodes.
[0054] In some embodiments, the data mover 108 receives raw network traffic and corresponding data from the collector 106 and distributes or pushes the data to the data lake 130. The data lake 130 may also receive and store out-of-band data 114 (e.g., power level status, network availability, server performance, temperature conditions, cage door location, and other data from internal sources) and third-party data 116 (e.g., security reports, such as those from San Jose, California). Systems, Inc., Arbor of Burlington, Massachusetts Sunnyvale, California Corp., Abingdon, England Group plc, Seattle, Washington Corp., New York, New York (Provided by Communications, Inc., etc.)), geographic location data, IP surveillance lists, Whois data, a Configuration Management Database (CMDB) or Configuration Management System (CMS) as a service, and other data from external sources. Conversely, in other embodiments, data lake 130 may extract or acquire raw traffic and corresponding data from collector 106, and extract or acquire relevant data from out-of-band data source 114 and third-party data source 116. In other embodiments, the functions of collector 106, data mover 108, out-of-band data source 114, third-party data source 116, and data lake 130 can be combined. As is known to those skilled in the art, various combinations and configurations are possible.
[0055] Each component of the data lake 130 can perform some processing on raw network traffic data and / or other data (e.g., host data, process data, user data, out-of-band data, or third-party data) to transform the raw data into a form that can be used by the elastic processing engine 150. In some embodiments, the data lake 130 may include a repository of flow attributes 132, host and / or endpoint attributes 134, process attributes 136, and policy attributes 138. In some embodiments, the data lake 130 may also include a repository of VM or container attributes, application attributes, tenant attributes, network topology, application dependency mappings, cluster attributes, etc.
[0056] Flow attribute 132 relates to information about flows traversing a network. A flow is generally one or more packets sharing certain attributes that are transmitted within the network over a specified period of time. Flow attribute 132 may include packet header fields (e.g., source address (e.g., Internet Protocol (IP) address, Media Access Control (MAC) address, Domain Name System (DNS) name, or other network address)), source port, destination address, destination port, protocol type, service class, and other fields. The source address may correspond to a first endpoint of the network (e.g., a network device, physical server, virtual partition, etc.), while the destination address may correspond to a second endpoint, multicast group, or broadcast domain. Flow attribute 132 may also include aggregated packet data, such as flow start time, flow end time, number of packets in the flow, number of bytes in the flow, union of TCP flags in the flow, and other flow data.
[0057] Host and / or endpoint attributes 134 describe host and / or endpoint data for each flow and may include host and / or endpoint name, network address, operating system, CPU usage, network usage, disk space, port, logged users, scheduled jobs, open files, and information about files and / or directories stored on the host and / or endpoint (e.g., information about the presence, absence, or modification of log files, configuration files, device-specific files, or protected electronic information). As discussed, in some embodiments, host and / or endpoint attributes 134 may also include out-of-band data 114 about the host (e.g., power level, temperature, and physical location (e.g., room, row, rack, cage door location, etc.)) or third-party data 116 (e.g., whether the host and / or endpoint is on an IP surveillance list or otherwise associated with a security threat, Whois data, or geographic coordinates). In some embodiments, out-of-band data 114 and third-party data 116 may be associated with processes, users, flows, or other larger or smaller granular network elements or network communications.
[0058] Process attribute 136 relates to the process data corresponding to each flow and may include process name (e.g., bash, httpd, netstat, etc.), ID, parent process ID, path (e.g., / usr2 / username / bin / , / usr / local / bin, / usr / bin, etc.), CPU utilization, memory utilization, memory address, scheduling information, appropriate values, flags, priority, status, start time, terminal type, CPU time used by the process, command that started the process, and information about the process owner (e.g., username, ID, user's real name, email address, user group, terminal information, login time, login expiration date, idle time, and information about the user's files and / or directories).
[0059] Policy attribute 138 contains information related to network policies. Policies determine whether a particular flow is allowed or denied by the network and a specific route through which packets traverse the network. Policies can also be used to label packets so that certain types of traffic receive differentiated service when used in conjunction with queuing techniques such as priority-based, fairness, weighted fairness, token bucket, random early detection, round-robin, etc. Policy attribute 138 may include policy statistics, such as the number of times a policy has been enforced or not enforced. Policy attribute 138 may also include associations with network traffic data. For example, corresponding policies can be used to link or flag flows found to be inconsistent to aid in investigating inconsistencies.
[0060] Analysis engine 110 may include any number of engines 150, including, for example, a flow engine 152 for identifying flows (e.g., flow engine 152) or an attack engine 154 for identifying attacks on the network. In some embodiments, the analysis engine may include a separate distributed denial-of-service (DDoS) attack engine 155 specifically designed to detect DDoS attacks. In other embodiments, the DDoS attack engine may be a component or sub-engine of a general-purpose attack engine. In some embodiments, attack engine 154 and / or DDoS engine 155 may use machine learning techniques to identify security threats to the network. For example, attack engine 154 and / or DDoS engine 155 may be provided with examples of network states corresponding to attacks and network states corresponding to normal operation. Attack engine 154 and / or DDoS engine 155 can then analyze network traffic data to identify when the network is under attack. In some embodiments, the network may operate in a trusted environment for a period of time to establish a baseline for normal network operation against attack engine 154 and / or DDoS.
[0061] The analytics engine 110 may also include a search engine 156. The search engine 156 can be configured to perform, for example, structured search, NLP (Natural Language Processing) search, or visual search. Data can be fed to the engine from one or more processing components.
[0062] The analysis engine 110 may also include a policy engine 158 for managing network policies, including creating and / or importing policies, monitoring policy consistency and inconsistency, enforcing policies, simulating changes to policies or network elements that affect policies, and other policy-related tasks.
[0063] ADM module 140 can determine the application dependencies of the network. That is, specific traffic patterns can correspond to applications, and the interconnectivity or dependencies of applications can be mapped to generate a graph of the applications (i.e., an application dependency mapping). In this context, an application references a set of networking components that provide connectivity for a given set of workloads. For example, in a three-tier architecture of a web application, the first endpoint of the web layer, the second endpoint of the application layer, and the third endpoint of the data layer constitute the web application. ADM module 140 can receive input data (e.g., flow attributes 132, host and / or endpoint attributes 134, process attributes 136, etc.) from various repositories of data lake 130. ADM module 140 can analyze the input data to determine the existence of first traffic flowing between external endpoints on port 80 of the first endpoint, corresponding to Hypertext Transfer Protocol (HTTP) requests and responses. The input data can also indicate second traffic flowing between the first port of the first endpoint and the second port of the second endpoint, corresponding to application server requests and responses, and third traffic flowing between the third port of the second endpoint and the fourth port of the third endpoint, corresponding to database requests and responses. ADM module 140 can define the ADM of a web application as a three-tier application, which includes a first EPG (which includes a first endpoint), a second EPG (which includes a second endpoint), and a third EPG (which includes a third endpoint).
[0064] The presentation module 112 may include an application programming interface (API) or command-line interface (CLI) 160, a security information and event management (SIEM) interface 162, and a web frontend 164. When the analytics engine 110 processes network traffic and corresponding data and generates analytics data, the analytics data may not be in a human-readable format, or it may be too large for a user to understand. The presentation module 112 can acquire the analytics data generated by the analytics engine 110 and further summarize, filter, and organize the analytics data, as well as create intuitive presentations of the analytics data.
[0065] In some embodiments, the backend can be used from... of Hive and from Redwood Shores, California CorporationOracle Database Connectivity (JDBC) is used as the API layer to implement the API or CLI 160. Hive is a data warehouse infrastructure that provides data summarization and self-organizing queries. Hive provides a mechanism for querying data using a variant of Structured Query Language (SQL), known as HiveQL. JDBC is a programming language. The application programming interface (API) defines how clients can access the database.
[0066] In some embodiments, Kafka can be used for the backend, and a system developed by San Francisco, California can be used. The software provided by Inc. implements the SIEM interface 162 as a SIEM platform. Kafka is a partitioned and replicated distributed messaging system. Kafka uses the concept of topics. A topic is a specific category of message feed. In some embodiments, Kafka can take raw packet capture and telemetry information from data mover 108 as input and output messages to the SIEM platform (e.g., ).Should The platform is used to search, monitor, and analyze machine-generated data.
[0067] In some embodiments, the New York City government can be involved. The company, and from Used for the backend ElasticSearch and Ruby on Rails TM The provided software is used as a web application framework to implement the web front-end 164. It is a document-oriented NoSQL database that is based on a dynamic summary. Documents in Object Notation (JSON) format. Elastic Search is a scalable, real-time search and analytics engine that provides full JSON-based Domain-Specific Language (DSL) queries. Rubyon Rails TM It's a Model-View-Controller (MVC) framework that provides a default structure for databases, web services, and web pages. (Ruby on Rails) TM This relies on web standards, such as JSON or Extensible Markup Language (XML) for data transmission, and Hypertext Markup Language (HTML), Cascading Style Sheets (CSS), and others for display and user interfaces.
[0068] Although Figure 1An example configuration of the various components of the network traffic monitoring system is shown; however, those skilled in the art will understand that the components of the network traffic monitoring system 100 or any system described herein can be configured in a variety of different ways and can include any other type and number of components. For example, sensor 104, collector 106, data mover 108, and data lake 130 may belong to a single hardware and / or software module or multiple separate modules. Other modules may also be combined into fewer components and / or further divided into more components.
[0069] Figure 2 An example of a network environment according to one aspect of this disclosure is shown.
[0070] In some embodiments, such as Figure 1 A network traffic monitoring system, such as network traffic monitoring system 100, can be implemented in network environment 200. It should be understood that for network environment 200 and any environment discussed herein, additional or fewer nodes, devices, links, networks, or components may exist in similar or alternative configurations. This document also considers embodiments with different numbers and / or types of clients, networks, nodes, cloud components, servers, software components, devices, virtual or physical resources, configurations, topologies, services, appliances, deployments, or network devices. Furthermore, network environment 200 may include any number or type of resources that can be accessed and utilized by clients or tenants. For clarity and simplicity, illustrations and examples are provided herein.
[0071] Network environment 200 may include network structure 202, Layer 2 (L2) network 204, Layer 3 (L3) network 206, and servers 208a, 208b, 208c, 208d, and 208e (collectively referred to as server 208). Network structure 202 may include spine switches 210a, 210b, 210c, and 210d (collectively referred to as "spine switch 210") and leaf switches 212a, 212b, 212c, 212d, and 212e (collectively referred to as "leaf switch 212"). Spine switch 210 may be connected to leaf switch 212 in network structure 202. Leaf switch 212 may include access ports (or non-structure ports) and structure ports. Organizational structure ports can provide uplinks to spine switch 210, while access ports can provide connectivity to endpoints (e.g., server 208), internal networks (e.g., L2 network 204), or external networks (e.g., L3 network 206).
[0072] Leaf switch 212 can reside at the edge of network structure 202 and can therefore represent a physical network edge. For example, in some embodiments, leaf switches 212d and 212e operate as boundary leaf switches communicating with edge device 214 located in external network 206. Boundary leaf switches 212d and 212e can be used to connect any type of external network device, service (e.g., firewall, deep packet inspector, traffic monitor, load balancer, etc.) or network (e.g., L3 network 206) to structure 202.
[0073] While this document illustrates and describes network organization 202 as an example leaf-spine architecture, those skilled in the art will readily recognize that various embodiments can be implemented based on any network topology, including any data center or cloud network organization. In fact, other architectures, designs, infrastructures, and variations are considered herein. For example, the principles disclosed herein can be applied to topologies including three layers (including a core layer, aggregation layer, and access layer), fat trees, meshes, buses, hubs, and spokes, etc. Thus, in some embodiments, leaf switch 212 may be a top-of-rack switch configured according to a top-of-rack architecture. In other embodiments, leaf switch 212 may be an aggregation switch in any particular topology (e.g., end-of-row topology or middle-of-row topology). In some embodiments, leaf switch 212 may also be implemented using an aggregation switch.
[0074] also, Figure 2 The topologies shown and described herein are easily scalable and can accommodate a large number of components as well as more complex arrangements and configurations. For example, a network can include any number of organizational structures 202 that can be geographically dispersed or located within the same geographical region. Therefore, network nodes can be used in any suitable network topology, which can include any number of servers, virtual machines or containers, switches, routers, appliances, controllers, gateways, or other nodes interconnected to form a large, complex network. Nodes can be coupled to other nodes or networks via one or more interfaces employing any suitable wired or wireless connection, providing a viable pathway for electronic communication.
[0075] Network communication in network architecture 202 can flow through leaf switches 212. In some embodiments, leaf switches 212 can provide access to network architecture 202 to endpoints (e.g., server 208), internal networks (e.g., L2 network 204), or external networks (e.g., L3 network 206), and leaf switches 212 can be interconnected. In some embodiments, leaf switches 212 can connect endpoint groups (EPGs) to network architecture 202, internal networks (e.g., L2 network 204), and / or any external network (e.g., L3 network 206). An EPG is a grouping of applications, or application components, and layers used to implement forwarding and policy logic. EPGs can allow the decoupling of network policies, security, and forwarding from addressing by using logical application boundaries. EPGs can be used in network environment 200 to map applications in the network. For example, an EPG can include groups of endpoints in the network that indicate connections and policies for applications.
[0076] As discussed, server 208 can be connected to network organization 202 via leaf switch 212. For example, servers 208a and 208b can be directly connected to leaf switches 212a and 212b, which in turn can connect servers 208a and 208b to network organization 202 and / or any other leaf switch. Servers 208c and 208d can be connected to leaf switches 212b and 212c via L2 network 204. Servers 208c and 208d, along with L2 network 204, constitute a local area network (LAN). A LAN can connect nodes via dedicated private communication links located in the same physical location (e.g., a building or campus).
[0077] WAN 206 can be connected to leaf switch 212d or leaf switch 212e via L3 network 206. WAN can connect geographically dispersed nodes via long-distance communication links (e.g., public carrier telephone lines, optical paths, Synchronous Optical Network (SONET) or Synchronous Digital Hierarchy (SDH) links). LAN and WAN can include L2 and / or L3 networks and endpoints.
[0078] The Internet is an example of a WAN (Wide Internet Protocol) that connects different networks around the world and provides global communication between nodes on various networks. Nodes typically communicate on a network by exchanging discrete data frames or packets according to predefined protocols, such as Transmission Control Protocol / Internet Protocol (TCP / IP). In this context, a protocol can refer to a set of rules that define how nodes interact. Computer networks can be further interconnected through intermediate network nodes such as routers to extend the effective size of each network. Endpoints can include any communication device or component, such as computers, servers, blades, hypervisors, virtual machines, containers, processes (e.g., running on a virtual machine), switches, routers, gateways, hosts, devices, external networks, and so on.
[0079] In some embodiments, the network environment 200 further includes a network controller running on the host 208a. The network controller uses data from... Application Policy Infrastructure Controller (APIC) TM This is achieved through APIC. TM Structure 202 can provide a centralized point for automation and management, policy programming, application deployment, and health monitoring. In some embodiments, APIC TM It operates as a synchronized cluster controller that is replicated. In other embodiments, other configurations or software-defined networking (SDN) platforms may be used to manage organizational structure 202.
[0080] In some embodiments, physical server 208 may instantiate hypervisor 216 on which one or more virtual switches (not shown) and one or more virtual machines 218 (as shown for host 208b). In other embodiments, physical server 208 may run a shared kernel for hosting containers. In other embodiments, physical server 208 may run additional software for supporting other virtual partitioning methods. A network according to various embodiments may include any number of physical servers hosting any number of virtual machines, containers, or other virtual partitions. Hosts may also include blade / physical servers without virtual machines, containers, or other virtual partitions, such as servers 208a, 208c, 208d, and 208e.
[0081] Network Environment 200 can also integrate a network traffic monitoring system, such as Figure 1 The network traffic monitoring system 100 is shown. For example, Figure 2 The network traffic monitoring system includes sensors 220a, 220b, 220c, and 220d (collectively referred to as "sensors 220"), a collector 222, and an analysis engine running on server 208e, for example, Figure 1The analysis engine 110. The analysis engine 208e can receive and process network traffic data collected by collector 222 and detected by sensor 220, which are placed on nodes located throughout the network environment 200. Although the analysis engine 208e... Figure 2 While shown as a standalone network device, it should be understood that the analytics engine 208e can also be implemented as a virtual partition (e.g., VM or container), Software as a Service (SaaS), or other suitable distribution method that can be distributed across hosts or host clusters. In some embodiments, sensor 220 runs on leaf switch 212 (e.g., sensor 220a), host 208 (e.g., sensor 220b), hypervisor 216 (e.g., sensor 220c), and VM 218 (e.g., sensor 220d). In other embodiments, sensor 220 can also run on spine switch 210, virtual switches, server appliances (e.g., firewalls, deep packet inspectors, traffic monitors, load balancers, etc.), and among network elements. In some embodiments, sensor 220 may be located at each (or nearly each) network component to capture granular packet statistics and data at each hop of data transmission. In other embodiments, sensor 220 may not be installed in all components or portions of the network (e.g., a shared hosting environment where clients have dedicated control over some virtual machines).
[0082] like Figure 2 As shown, the host may include multiple sensors 220 (e.g., host sensor 220b) running on the host and various components of the host (e.g., hypervisor sensor 220c and VM sensor 220d) such that all (or substantially all) packets traversing the network environment 200 can be monitored. For example, if one of the VMs 218 running on host 208b receives a first packet from WAN 206, the first packet can pass through the boundary leaf switch 212d, spine switch 210b, leaf switch 212b, host 208b, hypervisor 216, and VM. Because all or substantially all of these components contain corresponding sensors, the first packet will likely be identified and reported to one of the collectors 222. As another example, if the second packet is transmitted from one of the VMs 218 running on host 208b to host 208d, sensors installed along the data path (e.g., at VM 218, hypervisor 216, host 208b, leaf switch 212b, and host 208d) may capture metadata from the second packet.
[0083] Figure 3An example of a data pipeline for generating network insights based on collected network information, according to one aspect of this disclosure, is shown.
[0084] Insights generated from the data pipeline 300 may include, for example, identified applications or inventories, application relevance, policies, efficiency, resource and bandwidth usage, network flow, and the status of devices and / or associated users accessing the network. These can be determined for the network using network traffic data. In some embodiments, the data pipeline 300 may be provided by a network traffic monitoring system (e.g., Figure 1 Network traffic monitoring system 100), analysis engine (e.g., Figure 1 The analytics engine 110 (or other network services or network devices) can be configured to discover applications running on the network, map the internal correlations of applications, generate suggested sets of network policies for implementation, and monitor policy consistency and inconsistencies, as well as other network-related tasks.
[0085] The data pipeline 300 includes a data collection phase 302, wherein network traffic data and corresponding data (e.g., host data, process data, user data, etc.) are collected by sensors located throughout the network (e.g., Figure 1 The data is captured by sensor 104. Data may include, for example, raw flow data and raw process data. As discussed, data can be captured from multiple perspectives to provide a comprehensive view of the network. The collected data may also include other types of information, such as tenant information, virtual partition information, out-of-band information, third-party information, and other relevant information. In some embodiments, flow data and associated data may be aggregated and summarized daily or according to another suitable time increment, and flow vectors, process vectors, host vectors, and other feature vectors may be calculated during data collection phase 302. This can substantially reduce processing.
[0086] The data pipeline 300 may also include an input data phase 304, where a network or security administrator or other authorized user can configure insight generation by selecting the date range of the flowing data and associated data to be analyzed, as well as the nodes the administrator wants to analyze. In some embodiments, the administrator may also input supplementary information during the input data phase 304, such as server load balancing, route labels, and previously identified clusters. In other embodiments, the supplementary information may be automatically obtained, or it may be pushed by another network element.
[0087] The next stage of the data pipeline 300 is preprocessing 306. During preprocessing stage 306, network nodes are divided into selected node and related node subnets. Selected nodes are those nodes for which the user applies correlation mappings and cluster information according to their request. Related nodes are those nodes that were not explicitly selected by the user for ADM operation but communicate with the selected nodes. To obtain partitioning information, the edges of the applied correlation mappings (i.e., flowing data) and unprocessed feature vectors can be analyzed.
[0088] Other tasks may also be performed during preprocessing phase 306, including identifying the relevance of selected nodes and related nodes, replacing related nodes with labels based on the subnet names of related nodes, extracting feature vectors of selected nodes (e.g., by aggregating daily vectors across multiple days, calculating term frequency-inverse document frequency (TF-IDF), and normalizing vectors (e.g., L2 normalization)), and identifying existing clusters.
[0089] In some embodiments, preprocessing stage 306 may include early feature fusion preprocessing. Early fusion is a fusion scheme in which features are combined into a single representation. Features can be derived from various domains (e.g., network, host, virtual partition, process, user, etc.), and feature vectors in an early fusion system can represent concatenations of different feature types or domains.
[0090] Early fusion may be effective for similar features or features with similar structures (e.g., fields of TCP and UDP packets or streams). These features may be characterized as being of the same type or within the same domain. Early fusion may be less effective for features that are far apart or of different types or domains (e.g., stream-based features vs. process-based features). Therefore, in some embodiments, features may be analyzed only in the network domain (i.e., network traffic-based features, such as packet header information, the number of packets flowing, the number of bytes flowing, and similar data). In other embodiments, analysis may be limited to features in the process domain (i.e., process-based features, such as process name, parent process, process owner, etc.). In other embodiments, it may be a set of features in other domains (e.g., host domain, virtual subdomain, user domain, etc.).
[0091] After preprocessing, data pipeline 300 can proceed to insight generation phase 308. During insight generation phase 308, the data collected and input into data pipeline 300 can be used to generate various network insights. For example, analytics engine 110 can be configured to discover applications running in the network, map internal correlations of applications, generate a set of recommended network strategies for implementation, and monitor strategy consistency and inconsistency, as well as other network-related tasks. Various machine learning techniques can be implemented to analyze feature vectors within a single domain or across different domains to generate insights. Machine learning is a field of computer science where the goal is to develop models that can be used to predict new observations using example observations (i.e., training data). The models or logic are not based on theory but are based on experience or are data-driven.
[0092] After the cluster is identified, the data pipeline 300 may include a post-processing stage 310. Post-processing stage 310 may include tasks such as filtering the insight data, transforming the insight data into a consumable format, or any other preparation required to prepare the insight data for end-user consumption. In output stage 312, the generated insights may be provided to the end user. The end user may be, for example, a network administrator, a third-party computing system, a computing system within the network, or any other entity configured to receive the insight data. In some cases, the insight data may be configured to be displayed on a screen or provided to a system for further processing, consumption, or storage.
[0093] As mentioned above, it is necessary to improve, such as Figure 2 Network environments like the 200 series, where hundreds to thousands of endpoints and workloads continuously communicate with each other and / or with sources outside the network, pose security risks. This external communication can provide unauthorized access to such networks. Accordingly, an example method for improving network security is to detect compromised workloads and endpoints and block other nodes in the network from accessing or originating from these workloads and endpoints, in whole or in part. As described below, blocking access to these compromised workloads and endpoints can be achieved by blocking access to them and / or by isolating the affected endpoints. Detection of compromised workloads and endpoints can be based on the identification of threats using a known threat list (e.g., a known network threat alliance (CTA) threat list) that identifies malicious sources, malicious Uniform Resource Locators (URLs), etc. Such a list can be distributed to agents deployed on network nodes, configured to monitor network traffic and its corresponding sources and destinations.
[0094] Based on the examples of network traffic monitoring systems described above, their operation, and the network environments in which they can be deployed, this disclosure now turns to… Figure 4 and Figure 5 , Figure 4 and Figure 5 This describes a setup example in which network components may be exposed to malicious threats.
[0095] Figure 4 A simplified version of a configuration according to one aspect of this disclosure is shown, in which, Figure 2 The network environment components communicate with potential network threats.
[0096] Setting 400 can include options that can be used with... Figure 2 The network environment 401 is the same as the network environment 200 (e.g., a data center, enterprise network, etc.). Network environment 401 may include multiple components such as server 402, which can be accessed via cloud 404. Among other known or to be developed features, server 402 may communicate with one or more network nodes and workloads, such as components 406-1, 406-2, and 406-3 (collectively referred to as network components 406). Any given network component 406 can be a network node, including but not limited to: physical hosts, physical servers, network devices (e.g., routers, switches, virtual servers, hypervisors, or shared kernels), virtual partitions (e.g., VMs or containers), etc. Furthermore, network component 406 can be network-wide workloads / application workloads or segments executed on different hosts or network nodes of setup 400. For example, network component 406 may correspond to human resources procurement software utilized by an organization associated with network environment 401, such as its billing system, etc.
[0097] Each network element 406 may have a corresponding sensor mounted thereon. For example, network element 406-1 may have sensor 408-1 mounted thereon, network element 406-2 may have sensor 408-2 mounted thereon, network element 406-3 may have sensor 408-3 mounted thereon, and so on. Sensors 408-1, 408-2, and 408-3 may be collectively referred to as sensor 408. Sensor 408 may be the same as sensor 104. (See above reference for example.) Figure 1Among the functions described, sensor 408 can monitor various statistics associated with the operation of network element 406, including but not limited to the source and destination of network traffic to and from network element 406. Furthermore, sensor 408 can receive updates from server 402 regarding network threats (e.g., malicious IP addresses, threat categories, malware, etc.). This will be described further below. Where network element 406 is a software package / workload, the corresponding sensor 408 can also be a software package installed and executed as part of such a workload.
[0098] Communication between server 402 and sensor 408 can be via link 410, but communication between network elements 406 can be via link 412. Links 410 and 412 can be any known or to be developed wired and / or wireless communication links, supporting one-way and / or two-way communication connection points to them.
[0099] Although only three network elements 406 are shown in the example network environment 401, this disclosure is not limited thereto, and network environment 401 may include many more such network elements 406 (e.g., on the order of tens, hundreds, thousands, and / or hundreds of thousands of network elements). Furthermore, although network environment 401 shows each network element 406 having a dedicated sensor 408, this disclosure is not limited thereto. For example, two or more network elements 406 may share a sensor 408, or alternatively, a given network element may have more than one sensor 408 mounted thereon.
[0100] In example setup 400, network element 406 can communicate with one or more hosts, such as host 414-1 and host 414-2 (collectively referred to as host 414). Host 414 can be outside network environment 401 (as shown) or inside network environment 401. For example, host 414 can be an external server accessed by one or more network elements 406. Figure 4 In the example, network element 406-3 is shown communicating with host 414 via link 416, which, like links 410 and 412, can be any known or to-be-developed wired and / or wireless communication link, supporting one-way and / or two-way communication connection points to it. However, this disclosure is not limited thereto, and any one of the network elements 406 can communicate with / access any one of the hosts 414. Furthermore, although... Figure 4 Two hosts 414 are shown, but this disclosure is not limited thereto, and setup 400 may have any number of hosts 414 communicating with one or more network elements 406.
[0101] At any given point in time, one or more hosts 414 may be associated with a network threat, which could be malicious (unauthorized) software, malware, a known malicious IP address, a source associated with a class of threats, etc. In one example, one or more hosts 414 may have malware running on them or may have attempted to access malware or a host. Such a host 414 may be referred to as a compromised host (impaired element). Network environment 401 includes list 418 (described further below). List 418 may be a list of known threats (e.g., the CTA threat mentioned above) that can be periodically obtained (provided to server 402) by server 402. List 418 may be generated by crowdsourcing a threat database. Further details regarding list 418 and its availability to server 402 will be described below.
[0102] Server 402 can transmit an updated list of known threats to sensor 408. Upon detecting access to a compromised host by any of network elements 406, sensor 408 can block access to such compromised host by network element 406, as described below. For example, in setup 400, host 414-1 may contain malware. Therefore, host 414-1 can be considered a compromised host. Sensor 408-3, operating on network element 406-3, can detect access to compromised host 414-1. As described below, because sensor 408-3 knows the malware or malicious nature of host 414-1 (based on the updated list provided to sensor 408-3 by server 402), sensor 408-3 can cause network element 406-3 to block (interrupt) communication links 416 to and from compromised host 414-1. This disruption of communication link 416 can be limited to the compromised host 414-1 and network element 406-3 only, and may include blocking any direct or indirect communication between the compromised host 414-1 and any other network element 406 in setup 400, or between the compromised host 414-1 and server 402 in setup 400. Alternatively, the compromised host 414-1 can be (e.g., temporarily) isolated from access to any resources on setup 400 until the threat associated with the compromised host 414-1 is resolved by server 402. This will be described further below. Different types of access blocking will be described further below.
[0103] Figure 5 Another simplified version of the setup according to one aspect of this disclosure is shown, wherein, Figure 2 The network environment components communicate with potentially malicious hosts.
[0104] Similar to setting 400, setting 500 may include a network environment 501 that is the same as network environment 401. Therefore, components in network environment 501 that are identical to their counterparts in network environment 401 are numbered the same, and will not be described further for the sake of brevity. For example, server 402 in network environment 501 and... Figure 4 The network environment 401 is the same as the server 402, and the network element 406 of the network environment 501 is the same as... Figure 4 The network environment 401 is the same as the network element 406.
[0105] Compared to network environment 401, network environment 501 includes one or more endpoints 1 520-1 and 2 520-2 (collectively referred to as endpoints 520). Endpoints 520 can be any known or to-be-developed device capable of communicating with one or more elements of network environment 501. For example, endpoint 520 can be any of a mobile phone, laptop computer, tablet computer, desktop computer, Internet of Things (IoT) device, etc. Endpoint 520 can register with network environment 501 according to any known or to-be-developed method. Endpoint 520 can be physically located at the same location where network environment 501 is deployed, or it can be located far from one or more nodes or elements of network environment 501 and can be communicatively coupled to one or more nodes or elements of network environment 501. For example, endpoint 520 can have a remote connection agent (e.g., ANYCONNECT developed by Cisco Inc. of San Jose, CA) installed on it, which requires the corresponding user to provide credentials through the installed agent upon activation. After authentication, this remote connection agent enables endpoint 520 to remotely access the resources of network environment 501.
[0106] Endpoint 520 (e.g., for accessing workloads) can communicate with one or more network elements 502. For example, endpoint 520-1 can communicate via communication link 522 (communication link 522 can be connected to...). Figure 4 The communication links 410 and 412 are the same, and therefore will not be described further. Endpoint 520-1 can communicate with network elements 506-2 and 506-3 via communication link 524 (which can be connected to...). Figure 4 (The communication links 410 and 412 are the same, so they will not be described further) and communicate with network element 406-1 and network element 406-3.
[0107] In setup 500, one or more endpoints 520 can communicate with an external source such as host 526. For example, while connected to network environment 501 and accessing workloads on network elements 406-2 and 406-3 (e.g., the billing system of an organization associated with network environment 501), a user of endpoint 520-1 can communicate via a website and communication link 528 (communication link 528 can connect to...). Figure 4 (Communication link 410 / Communication link 412 are the same, and therefore will not be described further.) Access to external host 526. Host 526 may have one or more known threats associated with it, such as malware. Communication with host 526 may cause endpoint 520-1 to be considered a compromised endpoint (compromised component). Therefore, sensors 408-2 and 408-3, which operate network components 406-2 and 406-3, can compare endpoint 520-1's access to host 526 with list 418 and determine that host 526 is a malicious host (bad host). Accordingly, endpoint 520-1 can be blocked / isolated, preventing communication between network environment 501 components and endpoint 520-1. This isolation can be temporary (e.g., lasting for a period of time, such as an hour, a day, a week, etc.) or permanent (e.g., requiring endpoint 520-1 to be restarted with its original settings). Different types of access blocking will be further described below.
[0108] Next, we will refer to Figure 6 and Figure 7 Describe an example of a process for establishing a network threat identification procedure and implementing a dynamic access blocking scheme when a threat is identified.
[0109] Figure 6 A process according to one aspect of this disclosure is described for processing a list of known cyber threats and extracting it to network sensors for detecting compromised workloads and endpoints.
[0110] From Figure 4 402 server angle description Figure 6 The process. However, it should be understood that server 402 may have one or more processors associated with it, which are configured to execute computer-readable instructions to perform... Figure 6 The steps.
[0111] At S600, server 402 receives a list of network threats (or simply threats). This threat list can be a list of known threats (e.g., malicious IP addresses, malware, etc.) developed using a CTA and can be referred to as a CTA list. CTAs or any other known threat list can be developed using crowdsourcing or similar methods and can be publicly available. Such a list can be received from any known source (e.g., a CTA from an Amazon Web Services (AWS) Lambda bucket) or any other type of source containing such a list (queried by server 402). In one example, the threat list can be sent to server 402 periodically (e.g., once a day, once a week, once a month, etc.) or can be queried periodically by server 402.
[0112] At S602, server 402 transforms the network threat list. This transformation process can be an optional step and is performed to ensure that the format of the data packets containing the threat list information is compatible with the existing exchange protocol between server 402 and sensor 408.
[0113] At S604, server 402 can store the converted list of network threats in a database or storage device associated with server 402. Figure 4 and Figure 5 (Not shown in the text)
[0114] At S606, the transformed list of network threats (threat feed) is encapsulated within existing data packets exchanged between server 402 and sensor 408. The data packets may include an auxiliary information portion, which may include the threat feed. The data packets are provided to server 402 and sensor 408 via known external resources. For example, the data packets may originate from a cloud headend that hosts one or more data jobs, wherein the data packets are created in association with one or more data jobs and sent to server 402.
[0115] In one example, encapsulating threat feeds into packets can be done via a feature known as cloud connectivity. This could be an AWS service, which sensor 408 can connect to, for example, via server 402 to retrieve the latest packets. In response, sensor 408 can also send usage statistics about various features back to server 402. In another example, data packets can be encapsulated in Red Hat Packet Manager (RPM), which can be downloaded from a website and uploaded to sensor 408. In one example, RPM is a mechanism in which packets are encapsulated and sent as a unit from the cloud headend to server 402. RPM can be any set of files that can be sent and processed on a system such as a UNIX system.
[0116] At S608, server 402 can define a policy for threat feeds by creating annotations, which can then be used to tag / identify compromised workloads / endpoints. Such annotations can be labels identifying known malicious (bad) IP addresses on a received list, or labels identifying threat categories and one or more sources of that category.
[0117] For example, a policy could be defined as identifying workloads / endpoints that should be blocked from connections to malicious IP addresses. In this case, when data packets arrive at such workloads / endpoints (e.g., Figure 4 When the data packet is in network element 406-3, the source of the data packet is checked by the corresponding sensor 408, and if the source matches a known malicious IP (e.g., associated with host 414-1), the connection from network element 406-3 to host 414-1 is canceled / blocked.
[0118] At S610, server 402 deploys the defined policies and threat feeds to sensor 408 for implementation, and prevents compromised workloads / endpoints from accessing network resources and components. This will be referenced below. Figure 7 Further description.
[0119] At S612, server 402 can receive continuous feedback from sensor 408 regarding various statistical data collected by sensor 408, which pertains to data traffic and performance between corresponding network elements 406 and / or between other endpoints and hosts within or outside network environment 401 / 501. This statistical data can be used by server 402 to further refine / update annotations and policies created to prevent malicious sources and known threats from accessing network resources. For example, when sensor 408 detects the occurrence of malware in ten network elements (potentially across different clients), based on this increasing frequency, server 402 can define policies on other network elements to block any host or endpoint on which malware is detected, or to isolate any endpoint on which malware is detected.
[0120] Figure 7 This is an example of a network monitoring process according to one aspect of this disclosure, which is used to block network access from malicious sources.
[0121] From Figure 4 402 server angle description Figure 7 However, it should be understood that server 402 can be implemented using one or more sensors 408. Figure 7 The process.
[0122] At S700, using sensor 408, server 402 monitors network traffic between network elements 406 and one or more endpoints and / or hosts (e.g., host 414 and / or endpoint 520) in network environment 401.
[0123] At S702, use with Figure 6 Each process defines a policy associated with a label, and server 402 identifies network threats (e.g., malicious IP addresses, malware, etc.) associated with any of host 414 and / or endpoint 520. This identification can be based on the above references. Figure 6 The description includes the corresponding resources, as well as the defined bad IP addresses and / or tags associated with malicious types such as malware, viruses, vulnerabilities, and known network threats. One or more hosts 414, one or more endpoints 520, and / or associated workloads related to detected malicious addresses / malware can be referred to as compromised components.
[0124] At S704, server 402 detects one or more compromised components (e.g., one or more workloads, one or more endpoints, etc.) based on one or more malicious addresses and / or malware identified at S702. In one example, one or more hosts 414 and / or one or more endpoints 520 associated with the detected malicious addresses / malicious malware are referred to as one or more compromised workloads / endpoints.
[0125] At S706, using one or more of the sensors 408, the server 402 applies an access blocking scheme to each detected compromised element to prevent that compromised element from accessing network resources. This access blocking scheme can be one of several available access blocking schemes, each corresponding to a specific policy defined for addressing different potential network threats, which are identified in association with the compromised element.
[0126] An example access blocking scheme could be blocking a specific connection between a compromised host / workload and one or more specific workloads within a network environment (401). This could be referred to as a network element-based access blocking scheme. For example, see reference... Figure 4 As described, the connection between host 414 and network element 406-3 can be terminated / blocked.
[0127] Another example of an access blocking scheme can be used to isolate compromised hosts / workloads as described above. This can be referred to as an isolation-based access blocking scheme. For example, the policy can be created based on threat categories and / or the sources of such categories. This policy can be used to isolate (one or more) compromised components. For example, a policy can be created to instruct when an endpoint accesses an ad host with a specific ad tag (e.g., Figure 5 When endpoint 520-1 accesses host 526 and the advertising tag is detected in data packets received at network element 406-2 and / or network element 406-3, endpoint 520-1 should be isolated. As mentioned above, this strategy can also define isolation periods. Such periods can be determined based on experimental and / or empirical studies.
[0128] Another example of an access blocking scheme could be this: based on the nature of the potential malware or threat, a compromised host / endpoint is blocked from accessing a specific workload on a specific network element 406, but the same compromised workload / endpoint can still access other workloads on that specific network element 406. This policy can be defined to address situations where a specific category of threat or a specific IP address is considered harmful to one workload but harmless to others. This can be called a workload-based access blocking scheme. For example, network element 406-1 may have multiple applications or workloads running on it. Access originating from an external source might be a threat to a first application running on network element 406-1, but not to a second application running on network element 406-1. A policy could be defined to indicate that access to the first application on network element 406-1 should be blocked, but access to the second application on the same network element 406-1 should be allowed.
[0129] Accordingly, at S706, server 402 dynamically applies access blocking schemes based on the nature of potential network threats. This dynamic application of access blocking addresses each unique threat differently, rather than uniformly applying a single type of access blocking to all compromised hosts / endpoints. Therefore, a more efficient access blocking process is provided, making the use of network environment 401 more efficient and with better performance. This advantage is highlighted by the fact that if a uniform access blocking were applied, it might block connections or isolate many endpoints, which might not be the case when considering the nature of the potential threat.
[0130] After that, the process returns to S700, and S700, S702, S704 and S706 are repeated periodically (or alternatively, continuously) to detect and block compromised hosts / endpoints.
[0131] Next, example device and system configurations are described, which can be used in the context of this disclosure. Figures 1 to 5 Various components of the system (e.g., server 402, network component 406, sensor 408, host 414, endpoint 520, etc.) are used to implement the reference. Figure 6 and Figure 7 Describe the example functions and processes.
[0132] Figure 8 An example computing system according to one aspect of this disclosure is shown.
[0133] Figure 8 An example of a computing system 800 is shown, which can be any computing device or any component thereof constituting, for example, authentication service 415, wherein the components of the system communicate with each other using connection 805. Connection 805 can be a physical connection via a bus or a direct connection to processor 810 (e.g., in a chipset architecture). Connection 805 can also be a virtual connection, a networking connection, or a logical connection.
[0134] In some embodiments, the computing system 800 is a distributed system, wherein the functions described herein may be distributed across a data center, multiple data centers, a peer-to-peer network, etc. In some embodiments, one or more system components described represent a plurality of such components, each performing some or all of the functions described for that component. In some embodiments, a component may be a physical device or a virtual device.
[0135] The example computing system 800 includes at least one processing unit (CPU or processor) 810 and a connection 805 that couples various system components, including system memory 815, read-only memory (ROM) 820, and random access memory (RAM) 825, to the processor 810. The computing system 800 may include a high-speed memory cache 812 that is directly connected to, adjacent to, or integrated into the processor 810.
[0136] Processor 810 may include any general-purpose processor and hardware or software services (e.g., services 832, 834, and 836 stored in storage device 830) configured to control processor 810 and dedicated processors, wherein software instructions are incorporated into the actual processor design. Processor 810 may essentially be a completely independent computing system including a bus, memory controller, cache, and multiple cores or processors. Multi-core processors may be symmetric or asymmetric.
[0137] To enable user interaction, the computing system 800 includes an input device 845, which can represent any number of input mechanisms, such as a microphone for voice, a touch-sensitive screen for gesture or graphical input, a keyboard, a mouse, motion input, voice, etc. The computing system 800 may also include an output device 835, which can be one or more of a plurality of output mechanisms known to those skilled in the art. In some instances, a multi-mode system allows the user to provide multiple types of input / output to communicate with the computing system 800. The computing system 800 may include a communication interface 840, which generally controls and manages user input and system output. There are no limitations on operating any particular hardware arrangement, and therefore modified hardware or firmware arrangements can readily replace the basic features described herein when they are developed.
[0138] Storage device 830 may be a non-volatile storage device and may be a hard disk or other type of computer-readable medium that stores data accessible by a computer, such as a magnetic tape cassette, flash memory card, solid-state storage device, digital multifunction disk, magnetic tape cassette, random access memory (RAM), read-only memory (ROM), and / or some combination of these devices.
[0139] Storage device 830 may include software services, servers, etc., which enable the system to perform functions when the code defining such software is executed by processor 810. In some embodiments, hardware services that perform a particular function may include software components stored in a computer-readable medium connected to necessary hardware components (e.g., processor 810, connection 805, output device 835, etc.) to perform that function.
[0140] This disclosure relates to protecting network workloads by identifying compromised components communicating with the network and preventing them from accessing network resources. In one aspect, a method includes: monitoring network traffic at network components of the network; detecting a compromised component communicating with one or more network components, the compromised component being associated with at least one network threat; and applying one of a plurality of different access blocking schemes to the compromised component to prevent the compromised component from accessing the network, based on a defined network policy.
[0141] For clarity, in some instances, various embodiments may be represented as including various functional blocks, which include functional blocks of devices, device components, steps or routines of methods embodied in software, or a combination of hardware and software.
[0142] In some embodiments, computer-readable storage devices, media, and memories may include cables or wireless signals containing bit streams, etc. However, when referred to, non-transitory computer-readable storage media explicitly excludes media such as energy, carrier signals, electromagnetic waves, and the signals themselves.
[0143] The methods according to the examples above can be implemented using computer-executable instructions stored on a computer-readable medium or otherwise obtainable from a computer-readable medium. Such instructions may include, for example, instructions and data that cause or otherwise configure a general-purpose computer, special-purpose computer, or special-purpose processing device to perform a function or set of functions. Some of the computer resources used may be accessible via a network. The computer-executable instructions may be, for example, binary, intermediate format instructions (e.g., assembly language, firmware, or source code). Examples of computer-readable media that may be used to store instructions, information used and / or created during the methods according to the examples include hard disks or optical disks, flash memory, USB devices equipped with non-volatile memory, network storage devices, and the like.
[0144] Devices implementing these disclosed methods may include hardware, firmware, and / or software, and may be any of a variety of form factors. Typical examples of such form factors include laptops, smartphones, small form factor personal computers, personal digital assistants, rack-mounted devices, standalone devices, etc. The functionality described herein may also be embodied in peripheral devices or add-in cards. As a further example, such functionality may also be implemented on a circuit board between different chips or between different processes performed in a single device.
[0145] Instructions, a medium for conveying such instructions, computing resources for executing such instructions, and other structures supporting such computing resources are devices that provide the functionality described in these disclosures.
[0146] While various examples and other information are used to interpret aspects within the scope of the appended claims, no limitation on the claims should be implied based on specific features or arrangements in such examples, as those skilled in the art will be able to derive a wide variety of implementations from these examples. Furthermore, while some subjects may have been described in language specific to structural features and / or method steps, it should be understood that the subject matter defined in the appended claims is not necessarily limited to these described features or actions. For example, such functionality may be distributed differently in or performed in components other than those identified herein. Instead, the described features and steps are disclosed as examples of components and methods of a system within the scope of the appended claims.
Claims
1. A method for a computer network, comprising: The server inserts a list of known network threats into existing data packets exchanged between the server and the sensors of network elements; The server defines network policies by generating tags for the known network threats, wherein the generated tags identify the known network threats; The server monitors network traffic at network elements of the network via the sensors; The server uses generated tags to identify network threats associated with elements communicating with one or more of the network elements. Based on the monitoring and identification using at least one of the generated tags, a compromised element communicating with one or more network elements is detected, the compromised element being associated with at least one network threat and the network threat being determined to be harmful to a first application on the one or more network elements but harmless to a second application on the one or more network elements; and The server applies an access blocking scheme to the damaged component via the sensor, the access blocking scheme comprising: The compromised element is blocked from accessing the first application on the one or more network elements, but is allowed to access the second application on the one or more network elements.
2. The method according to claim 1, wherein, Detecting the damaged component includes: Identify the at least one network threat in the corresponding network traffic monitored for at least one of the network elements; and The at least one network element is marked as the damaged element.
3. The method according to claim 2, wherein, Identifying the at least one network threat includes: Receive a list of known network threats; Generate tags for identifying the known network threats; and The label is used to identify the at least one network threat.
4. The method according to any one of claims 1 to 3, wherein, Several different access blocking schemes include: Block the damaged element from accessing at least one of the network elements; or The damaged component is isolated for a period of time, wherein the isolation prevents any communication to and from the damaged component.
5. The method according to any one of claims 1 to 3, wherein, The network threat is either a known network IP address or a type of malware.
6. The method according to any one of claims 1 to 3, wherein, The compromised component is an endpoint registered with the network that has accessed an external source carrying the at least one network threat.
7. A network element, comprising: One or more memories containing computer-readable instructions; as well as One or more processors are configured to execute the computer-readable instructions to: The server inserts a list of known network threats into existing data packets exchanged between the server and the sensors of network elements; The server defines network policies by generating tags for the known network threats, wherein the generated tags identify the known network threats; Monitor network traffic at network components within the network; The server uses generated tags to identify network threats associated with elements communicating with one or more of the network elements. Based on the monitoring and identification using at least one of the generated tags, a compromised element communicating with one or more network elements is detected, the compromised element being associated with at least one network threat and the network threat being determined to be harmful to a first application on the one or more network elements but harmless to a second application on the one or more network elements; and The access blocking scheme is applied to the damaged component, and the access blocking scheme includes: The compromised element is blocked from accessing the first application on the one or more network elements, but is allowed to access the second application on the one or more network elements.
8. The network element according to claim 7, wherein, The one or more processors are configured to detect the damaged component by: Identify the at least one network threat in the corresponding network traffic monitored for at least one of the network elements; as well as The at least one network element is marked as the damaged element.
9. The network element according to claim 8, wherein, The one or more processors are configured to identify the at least one network threat by: Receive a list of known network threats; Generate tags for identifying the known network threats; and The label is used to identify the at least one network threat.
10. The network element according to any one of claims 7 to 9, wherein, Several different access blocking schemes include: Block the damaged element from accessing at least one of the network elements; or The damaged component is isolated for a period of time, wherein the isolation prevents any communication to and from the damaged component.
11. The network element according to any one of claims 7 to 9, wherein, The network threat is either a known network IP address or a type of malware.
12. The network element according to any one of claims 7 to 9, wherein, The compromised component is an endpoint registered with the network that has accessed an external source carrying the at least one network threat.
13. One or more non-transitory computer-readable media, comprising computer-readable instructions that, when executed by one or more processors, cause the one or more processors to: The server inserts a list of known network threats into existing data packets exchanged between the server and the sensors of network elements; The server defines network policies by generating labels for the known network threats, wherein... The generated tags identify the known network threats; Monitor network traffic at network components within the network; The server uses generated tags to identify network threats associated with elements communicating with one or more of the network elements. Based on the monitoring and identification using at least one of the generated tags, a compromised element communicating with one or more network elements is detected, the compromised element being associated with at least one network threat and the network threat being determined to be harmful to a first application on the one or more network elements but harmless to a second application on the one or more network elements; as well as The access blocking scheme is applied to the damaged component, and the access blocking scheme includes: The compromised element is blocked from accessing the first application on the one or more network elements, but is allowed to access the second application on the one or more network elements.
14. One or more non-transitory computer-readable media according to claim 13, wherein, Execution of the computer-readable instructions causes the one or more processors to detect the damaged component by: Identify the at least one network threat in the corresponding network traffic monitored for at least one of the network elements; as well as The at least one network element is marked as the damaged element.
15. One or more non-transitory computer-readable media according to claim 14, wherein, Execution of the computer-readable instructions causes the one or more processors to identify the at least one network threat by: Receive a list of known network threats; Generate tags for identifying the known network threats; and The label is used to identify the at least one network threat.
16. One or more non-transitory computer-readable media according to any one of claims 13 to 15, wherein, Several different access blocking schemes include: Block the damaged element from accessing at least one of the network elements; or The damaged component is isolated for a period of time, wherein the isolation prevents any communication to and from the damaged component.
17. One or more non-transitory computer-readable media according to any one of claims 13 to 15, wherein, The network threat is either a known network IP address or a type of malware.
18. One or more non-transitory computer-readable media according to any one of claims 13 to 15, wherein, The compromised component is an endpoint registered with the network that has accessed an external source carrying the at least one network threat.
19. A device for a computer network, comprising: A means for inserting a list of known network threats into existing data packets exchanged between the server and sensors of network elements; A means for defining a network policy by the server through generating labels for the known network threats, wherein the generated labels identify the known network threats; Devices used to monitor network traffic at network elements of a network; A means for identifying, by the server, network threats associated with an element communicating with one or more of the network elements using generated tags; A means for detecting, based on the monitoring and identification using at least one of the generated tags, a compromised element communicating with one or more network elements, the compromised element being associated with at least one network threat and determining that the network threat is harmful to a first application on the one or more network elements but harmless to a second application on the one or more network elements; and A means for applying an access blocking scheme to the damaged component, the access blocking scheme comprising: The compromised element is blocked from accessing the first application on the one or more network elements, but is allowed to access the second application on the one or more network elements.
20. The apparatus of claim 19, further comprising means for implementing the method of any one of claims 2 to 6.
21. A computer program product or computer-readable medium comprising instructions that, when executed by a computer, cause the computer to perform the steps of the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Distributed intrusion response system
US20050108568A1