Dynamic optimization of client application access via a secure access service edge (SASE) network optimization controller (NOC)

By using the SASE Network Optimization Controller (SNOC) and leveraging the security and network performance metrics of the SASE device, the user access modality is dynamically adjusted, solving the balance problem between user experience and security control in a distributed network environment and achieving optimization of network performance and security.

CN116601919BActive Publication Date: 2026-02-06CISCO TECHNOLOGY INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202180079589.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-09-29
Filing Date
2021-03-12
Publication Date
2026-02-06
Estimated Expiration
2041-03-12

AI Technical Summary

Technical Problem

In nondeterministic computing environments, it is difficult to balance user experience and security control, especially in remote workforce and distributed network environments, where network performance and security are difficult to optimize simultaneously.

Method used

By using the Secure Access Service Edge (SASE) Network Optimization Controller (SNOC), and leveraging the security and network performance metrics provided by the SASE device, user access patterns can be dynamically adjusted to optimize network performance while maintaining security controls.

Benefits of technology

It enables dynamic adjustment of user access patterns in a distributed network environment to optimize network performance and security, ensuring the stability and security of the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116601919B_ABST
    Figure CN116601919B_ABST
Patent Text Reader

Abstract

A network optimization controller (NOC) performs operations that include obtaining, from a secure access service edge (SASE) device that performs a security service, a first data set that defines a security performance metric provided by the security service and obtaining, from the SASE, a second data set that defines a network performance metric associated with a network device. The operations further include defining a policy based at least in part on the first data set and the second data set, determining whether the policy has been violated, and changing a first access modality provided for the network device to access a terminal host to a second access modality based at least in part on the policy being violated. The first access modality and the second access modality define different access methods to the terminal host.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Related Applications

[0002] This PCT international application claims the benefit of priority to U.S. Application No. 17 / 037,105, filed September 29, 2020, which is incorporated by reference herein. TECHNICAL FIELD

[0003] The present disclosure relates generally to continuous monitoring and optimization of networks based on security insights to address user-level application experience. More specifically, the present disclosure relates to a secure access service edge (SASE) network optimization controller (NOC) (referred to herein as a SNOC) that utilizes additional security performance metrics and network performance metrics provided by SASE devices to maintain user experience application access while also maintaining security controls. BACKGROUND

[0004] User access to applications and other services provided through computing networks. In some cases, access to these applications and other services can suffer from variations in network and user endpoint in the network security performance. In one example, key performance indicators (KPIs) are related to and / or define variations in these network and security performance. For example, a user can utilize a large corporate environment or utilize a virtual private network (VPN) service to access computing resources at a corporate headquarters. These access channels can be turned on, for example, via cloud services over the Internet, software-defined network connections in a wide area network (SD-WAN) connection from their home or other location, a non-VPN solution on their handheld device, and other computer network communication channels or access modalities. Connection time, speed, and data transfer quality, among other KPIs, can vary from user to user depending on factors surrounding the access modality(ies) used by the user endpoint. This situation can result in unexpected and / or undesirable reductions in quality of service (QoS) of the user experience when interacting with the network and applications.

[0005] A trusted application bypass process can be employed where once the performance of the system degrades beyond a defined threshold, an administrator can bypass certain security functions, such as deep packet inspection. This mechanism works when the applications are well known and 100% trusted at a central location. However, as systems and users become untrusted in the growing size and complexity of the network environment, the ability to trust various users and applications becomes a problem. Further, the workforce around the world has become a remote workforce and each user can utilize their own modality to use services. In this scenario, the network is distributed and is adapting to the increase in size and complexity of the remote workforce where trust becomes an issue between users and applications.

[0006] In one example, a user can select to access applications and other services using different access modalities that provide more efficient network performance but provide different levels of security to the user endpoint. For example, a user can utilize direct internet access (DIA), which, for example, utilizes domain name system security extensions (DNSSEC). While DIA can provide relatively better network performance by reducing network latency, increasing data packet transmission, providing more reliable connections, and other advantages associated with network performance, the user can compromise network security. Thus, the ability to provide consistent policies and user experiences from deterministic networks can prove difficult. Balancing user experiences and appropriate security controls in non-deterministic computing environments can be difficult. BRIEF DESCRIPTION OF DRAWINGS

[0007] A detailed description is set forth below with reference to the accompanying drawings. In the drawings, the left-most (one or more) digit(s) of each reference numeral may

[0008] Figure 1 A system architecture diagram of an example secure access service edge (SASE) network optimization controller (NOC) (SNOC) is shown, in accordance with an example of the principles described herein.

[0009] Figure 2 A system architecture diagram of an example SNOC is shown, in accordance with an example of the principles described herein. Figure 1 depicting the application of policies configured by the SNOC.

[0010] Figure 3 A component diagram of example components of a SNOC, in accordance with an example of the principles described herein.

[0011] Figure 4 A flow diagram of an example method of managing access modalities of user endpoints via a SNOC is shown, in accordance with an example of the principles described herein.

[0012] Figure 5 A flow diagram of an example method of managing access modalities of user endpoints via a SNOC is shown, in accordance with an example of the principles described herein.

[0013] Figure 6 A computing system diagram is shown, illustrating a configuration of a data center that can be used to implement aspects of the technology disclosed herein.

[0014] Figure 7A computer architecture diagram is shown that illustrates an example computer hardware architecture for implementing a computing device that can be used to implement aspects of the various technologies presented herein. DETAILED DESCRIPTION

[0015] Overview

[0016] Aspects of the application are set out in the independent claims, preferred features are set out in the dependent claims. Features of one aspect can be applied to any aspect, singly or in combination with features of other aspects.

[0017] Organizations (e.g., companies or individuals) can access applications and / or services via a myriad of different access modalities. In such cases, network performance can degrade because of the access modality that the user is currently using. Moreover, in some cases, one or more computing devices within a network can compromise security before and / or after a user changes access modalities within the network.

[0018] SASE can provide a multitude of different types of security performance metrics and network performance metrics to a NOC. The NOC can utilize these different types of security performance metrics and network performance metrics to configure a policy that allows a user to obtain optimized network performance while maintaining a level of security required to: a user computing device, a network, an application that the user computing device is accessing, and / or a service that the user computing device is utilizing. As used herein, an example secure access service edge (SASE) network optimization controller (NOC) can be referred to as a SNOC.

[0019] Examples described herein provide a network optimization controller (NOC) comprising one or more processors and one or more non-transitory computer-readable media storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising obtaining, from a secure access service edge (SASE) device that performs a security service, a first set of data defining a security performance metric provided by the security service, and obtaining, from the SASE, a second set of data defining a network performance metric associated with a network device. The operations further comprise defining a policy based at least in part on the first set of data and the second set of data, determining whether the policy has been violated, and changing a first access modality provided for the network device to access an end host to a second access modality based at least in part on the policy being violated. The first access modality and the second access modality define different methods of accessing the end host.

[0020] Defining the policy can include updating an existing policy based at least in part on the first data set and the second data set. Further, defining the policy can include determining whether the application executed by the end host is on a whitelist and defining the policy to allow access to a second access modality based at least in part on the application executed by the end host being on the whitelist, where the second access modality has a different security risk level relative to the first access modality. These operations further include communicating the policy to the second network device. The second network device can be configured to enforce the policy.

[0021] The policy can define a time period for which the second access modality is used. These operations further include changing the first access modality to the second access modality can include using the second access modality for the time period and changing to the first access modality based at least in part on expiration of the time period. The security performance metric provided by the security service includes a metric provided by a domain name system (DNS) layer security service, a secure web gateway (SWG) service, a firewall service, a cloud access security broker (CASB) service, an interactive threat intelligence service, and combinations thereof. Determining whether the policy has been violated includes determining whether the security performance metric violates a threshold. The network performance metric associated with the network device includes a data transfer rate, a communication latency, or a session duration. Determining whether the policy has been violated includes determining whether the security performance metric violates a threshold.

[0022] Examples described herein further provide a method that includes obtaining, from a secure access service edge (SASE) device that enforces a security service, a first data set defining a security performance metric provided by the security service and obtaining, from the SASE, a second data set defining a network performance metric associated with a network device. The method further includes defining a policy based at least in part on the first data set and the second data set, determining whether the policy has been violated, and changing a first access modality provided for the network device to access an end host to a second access modality based at least in part on the policy being violated, where the first access modality and the second access modality define different access methods to the end host. Defining the policy includes updating an existing policy based at least in part on the first data set and the second data set.

[0023] Defining the policy includes determining whether the application executed by the end host is on a whitelist. The method can further include defining the policy to allow access to a second access modality based at least in part on the application executed by the end host being on the whitelist. The second access modality has a different security risk level relative to the first access modality.

[0024] The method also includes communicating the policy to a second network device. The second network device can be configured to enforce the policy. The policy can define a time period during which the second access modality is to be used. Changing the first access modality to the second access modality includes using the second access modality for the time period and changing to the first access modality based at least in part on expiration of the time period.

[0025] The security performance metrics provided by the security service can include metrics provided by a domain name system (DNS) layer security service, a secure web gateway (SWG) service, a firewall service, a cloud access security broker (CASB) service, an interactive threat intelligence service, and combinations thereof. Determining whether the policy has been violated includes determining whether the security performance metric violates a threshold. The network performance metrics associated with the network device include a data transfer rate, a communication latency, or a session duration. Determining whether the policy has been violated includes determining whether the security performance metric violates a threshold.

[0026] Examples described herein also provide a non-transitory computer-readable medium storing instructions that, when executed, cause one or more processors to perform operations including obtaining, from a secure access service edge (SASE) device that enforces a security service, a first data set defining a security performance metric provided by the security service and obtaining, from the SASE, a second data set defining a network performance metric associated with a network device. The operations can also include defining a policy based at least in part on the first data set and the second data set, determining whether the policy has been violated, and changing a first access modality provided for the network device to access an end host to a second access modality based at least in part on the policy being violated. The first access modality and the second access modality define different access methods to the end host.

[0027] Defining the policy includes updating an existing policy based at least in part on the first data set and the second data set. Further, defining the policy includes determining whether an application executed by the end host is on a whitelist and defining the policy to allow access to the second access modality based at least in part on the application executed by the end host being on the whitelist. The second access modality has a different security risk level relative to the first access modality.

[0028] The operations also include transmitting the policy to a second network device, where the second network device is configured to enforce the policy. The security performance metrics provided by the security service can include metrics provided by a domain name system (DNS) layer security service, a secure web gateway (SWG) service, a firewall service, a cloud access security broker (CASB) service, an interactive threat intelligence service, and combinations thereof. Determining whether the policy has been violated includes determining whether the security performance metric violates a threshold. The network performance metrics associated with the network device can include a data transfer rate, a communication latency, or a session duration. Determining whether the policy has been violated includes determining whether the security performance metric violates a threshold.

[0029] Further, the technology described in this disclosure can be performed as a method, and / or by a system having a non-transitory computer-readable medium storing computer-executable instructions that, when executed by one or more processors, perform the technology described above.

[0030] Example Embodiments

[0031] Turning now to the drawings, Figure 1 A system architecture diagram 100 of an example secure access service edge (SASE) network optimization controller (NOC) (referred to herein as SNOC) 102 is shown, in accordance with an example of the principles described herein. The SASE 104 can include hardware and software that provide network security functions, including, for example, a domain name system (DNS) layer security 106 service, a secure web gateway (SWG) 108 service, a firewall 110 service, a cloud access security broker (CASB) 112 service, an interactive threat intelligence (ITI) 114 service, and other network and security services. The SASE 104 can include capabilities provided by a WAN, such as a software-defined network (SD-WAN) in a wide area network (WAN) to support any dynamic security access needs of an organization. In one example, the capabilities of the SASE 104 can be delivered as a service (aaS) and the capabilities of the SASE 104 can be based on the identity of an entity, real-time context, enterprise security / compliance policies, and continuous assessment of risk / trust for the entire session. The identity of an entity can be associated with a person, a group of people (e.g., an office division), a device, an application, a service, an internet of things (IoT) system, and / or an edge computing location, among other associations. The SASE 104 described herein includes client-optimized security edge and / or client-optimized security access functions to provide optimization of user experience through or via the SASE network. Using the network ecosystem of the SASE 104, insights including network performance and security intelligence can be obtained, improving the performance of applications used by user endpoints 120.

[0032] In one example, the SASE 104 is a cloud-based Umbrella® network security product suite developed by TM cybersecurity intelligence data. As described in greater detail herein, the SASE 104 provides the SNOC 102 with myriad different network and security intelligence data. The security and network services provided by the SASE 104 can protect users, their respective user endpoints 120 and other computing devices 132 from malware, botnets, phishing, targeted online attacks, and other security threats that can be encountered within and / or outside of the SASE 104 environment. The other computing devices 132 can include, for example, any special-purpose SD-WAN 124, any corporate SD-WAN 126, network devices 128 (e.g., laptop computing devices, desktop computing devices, mobile phones, smart phones, tablet computers, servers, routers, workstations, Internet of Things (IoT) devices, etc.), virtual private network (VPN) devices 130, and myriad other computing devices communicatively coupled to the SASE 104.

[0033] In one example, the SASE 104 can provide a Domain Name System (DNS) layer security 106 service. The DNS layer security service 106 provided by the SASE 104 can include, for example, the ability to create and enforce security policies related to the execution of devices behind the network perimeter. The SASE 104 can include any type of data-driven threat intelligence engine that automatically updates malware, botnet, and phishing domains and IP whitelists and blacklists enforced by the SASE 104. The intelligence data can be derived from DNS requests received by the SASE 104 and Border Gateway Protocol (BGP) routing tables managed by the network operations center of the SASE 104. In this manner, the DNS layer security 106 service allows security policies to be created and enforced not only for user endpoints 120 and other computing devices 132, but also for devices within the entire computing environment. The use of security intelligence provided by the DNS layer security 106 service reduces or eliminates the likelihood that malicious applications and / or content will be installed or introduced into the user endpoints 120 and other computing devices 132. The security intelligence provided by the DNS layer security 106 service can be provided to the SNOC 102 for use in creating and enforcing policies for devices communicatively coupled to the SNOC 102.

[0034] ​Further, in one example, the SASE 104 can provide a secure web gateway (SWG) 128 service. The SWG 108 service provides secure internet access, for example, to users that do not use a corporate network or a virtual private network (VPN) to connect to a remote data center. The SWG 108 provides protection against online security threats by enforcing the enterprise’s security policies and by filtering malicious internet traffic. In one example, the malicious internet traffic can be filtered in real-time. The SWG 108 provides uniform resource locator (URL) filtering, application control for web applications, and detection and filtering of malicious code. Further, the SWG 108 provides a data leak prevention service. With respect to real-time traffic inspection, the SWG 108 inspects network traffic in real-time, analyzes content against enterprise policies, and ensures that any content that is inappropriate or violates enterprise policies is blocked. The SWG 108 can perform any type of file inspection to ensure that content transmitted via network traffic is appropriate. In one example, the SWG 108 can allow an administrator to enforce a ready-made security policy template and also allow the administrator to configure a policy that is appropriate for the company’s business model and / or compliance requirements. In this way, the SWG 108 can interact with the SNOC 102 to create, modify, edit, remove, delete, and otherwise configure policies for execution within the SASE 104. Further, the SWG 108 provides seamless authentication to roaming users and applies the same security policies to their respective computing devices as if the computing devices were communicatively coupled to the company’s network. In this way, the SWG 108 can also be used to protect user endpoints 120 and other computing devices 132 when they access the internet and when internet-related policies are created and enforced by the SWG 108. With respect to data leak prevention, the SWG 108 reduces or eliminates situations where company data is leaked to or stolen by third parties by detecting business terms (e.g., payment card industry (PCI) number patterns and phrases or personally identifiable information). Any security intelligence provided by the SWG 108 can be provided to the SNOC 102 for creating and enforcing policies for devices communicatively coupled to the SASE 104.

[0035] In one example, SASE 104 can also provide firewall 110 services. Firewall 110 services monitor and control incoming and outgoing network traffic based on a number of predetermined security rules and establish a barrier between trusted internal networks and untrusted external networks, such as the Internet. In this way, firewall 110 services can interact with SNOC 102 to enforce policies within SASE 104 that are at least partially configured by SNOC 102. Security services provided by firewall 110 can be provided to user endpoints 120 and other computing devices 132. Specifically, security intelligence provided by firewall 110 can be provided to SNOC 102 for use in creating and enforcing policies for user endpoints 120 and other computing devices 132 within SASE 104.

[0036] Further, in one example, SASE 104 can also include a cloud access security broker (CASB) 112 service. CASB 112 can be any locally deployed software or cloud-based software that sits between cloud service users and cloud applications and monitors all activity as well as enforces security policies. CASB provides a number of services, such as monitoring user activity, alerting administrators of potentially dangerous actions, enforcing security policy compliance, and automatically preventing malware and other activities. CASB 112 can deliver security by preventing high-risk events and / or by managing through monitoring and mitigating high-risk events. In one example, CASB 112 can utilize application program interfaces (APIs), performance probes, telemetry, and other programming to inspect data and activity in the cloud to alert of dangerous events after the fact. Further, CASB 112 can inspect firewall or proxy logs for usage of cloud applications. The same functionality with respect to SASE 104 provided by CASB 112 can similarly apply to user endpoints 120 and other computing devices 132. Specifically, security intelligence provided by CASB 112 can be provided to SNOC 102 for use in creating and enforcing policies for devices communicatively coupled to SASE 104.

[0037] In one example, SASE 104 can also include an interactive threat intelligence (ITI) 114 service. ITI 114 service provides intelligence associated with the relationships and evolution of internet domains, IPs, and files to assist in unearthing an attacker’s infrastructure and predicting future threats. Similar to the above example, the same functionality with respect to SASE 104 provided by ITI 114 can similarly apply to user endpoints 120 and other computing devices 132. Specifically, security intelligence provided by ITI 114 can be provided to SNOC 102 for use in creating and enforcing policies for devices communicatively coupled to SASE 104.

[0038] Intelligence provided by the SASE 104 can be provided to the SNOC 102 to create and enforce policies based on intelligence obtained in conjunction with the SASE 104 and computing devices communicating via the SASE 104. In one example, data defining intelligence from at least one security service performed by the SASE can be used by the SNOC 102 to configure a plurality of policies, where the SASE includes: a DNS layer security 106 service, a SWG 108 service, a firewall 110 service, a CASB 112 service, an ITI 114 service, and combinations thereof.

[0039] In examples described herein, SNOC 102 services provided via the SASE 104 can be provided as one of the security services in the SASE 104. In one example, an enterprise can subscribe to services provided by the SNOC 102 to manage user experience within the SASE 104 by dynamically and autonomously adjusting policies that improve security and functionality of user endpoints 120 and / or other computing devices 132. Management of user experience within the SASE 104 includes leveraging differentiated and relevant access modalities 134 to allow the SASE 104 to handle myriad network and security parameters and / or key performance indicators (KPIs) as adjustable or configurable parameters to optimize user performance.

[0040] The SNOC 102 can be any network optimization controller (NOC) that resides on or is intricately performed with the SASE 104. The NOC can be any combination of hardware and software that functions as a controller. Thus, the SNOC 102 can be used to control any policy-related activities, including, for example, policy creation, modification, editing, removal, deletion, and otherwise altering policies for enforcement within the SASE 104.

[0041] Further, the SNOC 102 can be used to modify access modalities 134 of the user endpoints 120 and / or other computing devices 132 directly or indirectly (e.g., via policy). As used in this specification and the appended claims, the term “access modality” or similar language is intended to be understood broadly as any communication channel and / or method used by a user endpoint 120, other computing device 132, or any other device associated with the SASE 104 to access an application and / or utilize a service provided via a computing network. Examples of access modalities 134 include direct internet access (DIA) utilizing, for example, domain name system security extensions (DNSSEC), private and / or corporate virtual private networks (VPNs), secure internet gateways (SIGs), secure web gateways (SWGs), different types of private and / or corporate SD-WANs including remote access VPNs (RAVPNs) and site-to-site VPNs (S2SVPNs), enterprise headend networks, cellular networks and associated devices, cloud networks, and other access modalities 134 as described herein. Access modalities 134 can also utilize split tunneling, where a user can access different security domains, such as a public network (e.g., the internet) and a LAN or WAN, simultaneously using the same or different network connections. As described in greater detail herein, the SNOC 102 can configure multiple policies based on KPIs that define security performance metrics and network performance metrics provided by the SASE 104 in conjunction with the user endpoints 120 and / or other computing devices 132. Further, the SNOC 102 provides access to the user endpoints 120 and / or other computing devices 132 via any communication path through multiple networks including cloud networks and the like.

[0042] While depicted as an element of the SASE 104, the SNOC 102 can be located anywhere within the network systems described and / or depicted herein. Further, the policy configurations 116 configured by the SNOC 102 can be transmitted to any device within the network systems described herein and stored as policies 118 in those devices, including the various elements of the SASE 104, such as devices associated with the DNS layer security 106 service, the SWG 108 service, the firewall 110 service, the CASB 112 service, and the ITI 114 service, among other network and security services. Further, the policy configurations 116 configured by the SNOC 102 can be transmitted to the user endpoints 120, other computing devices 132, and / or any other device coupled to the network systems described herein and can be presented as policies 118. Figure 1Policy 118, as depicted, may be a copy of policy configuration 116 generated by SNOC 102. In one example, policy 118 may be updated continuously or at regular intervals as SNOC 102 creates new policies and / or updates existing policies. Based at least in part on the creation and / or updating of new policies by SNOC 102, new and / or updated policy 118 may be pushed to user endpoint 120, other computing devices 132, and / or any other devices coupled to the network system.

[0043] In one example, SNOC 102 can receive a baseline access modality policy, referred to herein as the baseline policy. The baseline policy can be pre-configured and enforced by SNOC 102, SASE 104, and other devices described herein. Therefore, the baseline policy can be instantiated within the system described herein without using the security performance metrics and / or network performance metrics described herein. In later examples, the baseline policy can be dynamically modified based on the security performance metrics and / or network performance metrics described herein.

[0044] User endpoint 120 can be any computing device that communicates back and forth with SASE 104 to access applications and / or services. In one example, user endpoint 120 can be a laptop, desktop, mobile phone, smartphone, tablet, server, router, workstation, Internet of Things (IoT) device, virtual private network (VPN) device 130, and numerous other computing devices communicatively coupled to SASE 104. User endpoint 120 may include endpoint security client 122 for authenticating and configuring routing and encrypting and transmitting data packets and other network traffic via an access mode 134 (e.g., private and / or corporate VPN, DIA, DNSSEC, SIG, SWG, private and / or corporate SD-WAN, RAVPN, S2SVPN, enterprise headend network, cellular network and associated devices, cloud network, and other access modes 134 as described herein). In one example, endpoint security client 122 may include a device... AnyConnect for development and distribution TM Endpoint security client 122. In one example, user endpoint 120 may include policy 118 obtained from SNOC 102 when SNOC 102 configures policies and generates policy configuration 116.

[0045] Similarly, other computing devices 132 can also include an endpoint security client 122 for authenticating and configuring routing and encrypting and transmitting data packets and other network traffic via one access modality 134. In one example, other computing devices 132 can also include policies 118 obtained from SNOC 102 when SNOC 102 configures policies and produces policy configurations 116.

[0046] SASE 104 and SNOC 102 are used to provide a cross-architecture controller (e.g., SNOC 102) that continuously monitors and optimizes network performance based on security insights received from security suites (e.g., services provided by SASE 104) under user-level application experience. An integrated closed-loop security and network telemetry automation solution is provided by SASE 104 and SNOC 102. Further, SASE 104 and SNOC 102 provide the ability to maintain user experience (including access to applications) provided via the network while maintaining security controls. Differentiated and relevant access modalities 134 allow users to treat any network and security parameters or KPIs as adjustable or configurable parameters to optimize user performance. Further, SASE 104 and SNOC 102 provide a converged network and agent / client-based solution with the ability to measure real-time user experience and subsequently adjust network, security, and / or application policies to maintain security and user experience levels. Further, networks can be optimized using policies created and / or updated by SNOC 102, at least partially based on performance of traffic, or threat-related re-routing or throttling.

[0047] SASE 104 and its SNOC 102 provide a converged system in which multiple network and security devices identify at least one KPI indicating a performance value (e.g., a performance degradation in network or security). In one example, depending on the criticality of the application being accessed, control signals can be sent to user endpoints 120 and / or other computing devices 132 to direct traffic through different access modalities 134 (e.g., connection methods) and / or dynamically modify quality of service (QoS) settings on the security SD-WAN overlay provided by SASE 104 for a period of time (e.g., in instances where there are potentially unstable communication links (e.g., satellite, cellular, or degraded internet communication links)).

[0048] To exert control and optimize the performance of the incoming traffic into the SASE 104, areas at which control points can be created can be identified. The SNOC 102 can identify these control points and create the control points within the network environment. One such control point can be created within the SASE 104 and / or the SNOC 102 itself. Further, control points can be created at one or more of the DNS layer security 106 services, SWG 108 services, firewall 110 services, CASB 112 services, and ITI 114 services, and other network and security services provided by the SASE 104. Further, in one example, a control point can be created at a head-end module within the cloud network, where VPNs, different types of SDWAN connections (RA VPN / S2S VPN), and other network architectures can be terminated, and traffic routing decisions can also be influenced by the SNOC 102. Further, multiple control points can be created at the client layer of the network (e.g., at the user endpoints 120 and / or other computing devices 132) via a provisioning or security posture agent connected to the SASE 104.

[0049] In one example, the SNOC 102 executing on the SASE 104 can determine that a connection with the user endpoint 120 is, for example, running slowly by looking at the SASE 104 elements (106, 108, 110, 112, 114) including firewalls, proxies, and / or security elements. The SNOC 102 can determine, based on common analysis from different sources (106, 108, 110, 112, 114), that a VPN connection that the user endpoint 120 is utilizing should be optimized for a particular user or network. Based on the detected anomaly, the SNOC 102 can determine that the user can need to optimize their connection. The SNOC 102 can apply multiple thresholds in making decisions about when a network connection is underperforming and / or when to seek a correction to performance, including changing access modalities 134 and / or changing security settings, and other changes to the current network or security performance metrics as defined by KPIs as described herein. For example, the user endpoint 120 can be accessing a network through a first VPN headend in a first cloud network as a first access modality 134. However, the SNOC 102 can determine that a first VPN cluster or a second VPN cluster on a second cloud network can provide network and / or security performance above a threshold and / or as required by the application being accessed by the user endpoint 120 as a second access modality 134. The SNOC 102 can make such a determination based on a number of predetermined remediation steps when a performance issue is detected. The SNOC 102 can then cause network traffic from the user endpoint 120 to be redirected through the second access modality (e.g., the first VPN cluster or the second VPN cluster on the second cloud network) to ensure that the user utilizing the user endpoint 120 will benefit from relatively better network performance.

[0050] In one example, the functionality of the SNOC 102 is extended to end hosts via VPN providers of the end hosts (e.g., an entity at one end of a point-to-point LAN segment that is being authenticated by an authenticator that is attached to the other end of the link). When decisions are made at the SNOC 102 based on network or security performance metrics as defined by KPIs as described herein, client devices that are utilizing the VPN providers can tune in to perform various access modalities 134 (e.g., module and path selection options). In one example, the module and path selection options can include split tunneling path selection or endpoint security clients 122 (e.g., AnyConnect® VPN, Cisco® Umbrella®, Cisco® Duo®) as described above. TM module selection).

[0051] In the example of a split tunnel being selected by the SNOC 102 as a module and path selection option, the SNOC 102 can remotely manage the split tunnel policy by integrating ideal traffic routing to send traffic for a given application directly to the SASE 104 or allow the traffic to egress through the client’s local internet via tunnel bypass. The split tunnel method can utilize statically defined policies based on domain name system (DNS) and fully qualified domain name (FQDN) information. With the SASE 104 and the SNOC 102, the split tunnel policy can be dynamic based on the impact of the SNOC 102 over a period of time. In one example, the SNOC 102 can restore the access modalities 134 to the original access modalities 134 based at least in part on expiration of the period of time.

[0052] In the example of the endpoint security client 122 (e.g., AnyConnect® TM Module selection) being used for selection of the access modalities 134, the endpoint security client 122 can have the ability to indicate that any given end host uses various modules to connect each application being accessed as defined by the policies 118 and as defined by the policy configuration 116 made by the SNOC 102. For example, the user endpoint 120 acting as a client can use a direct VPN to the SIG cloud, a direct VPN to a locally deployed VPN headend, or other access modalities 134, and the local client agent settings can be modified to direct traffic at the SWG for direct proxy access while utilizing the SASE 104 for access to other internet applications. In another example, remote access and reverse proxy capabilities via multi-factor authentication (MFA) (e.g., Duo® Duo® TM two-factor authentication method) developed and distributed by Cisco® can be utilized. The endpoint security client 122 when preloaded onto the client can receive the benefit of the impact of the SNOC 102 by selecting the best access modality 134 for a given application and allowing for simultaneous use of multiple access modalities 134.

[0053] Figure 2 FIG. 1 is a system diagram 100 of an example SNOC 102 according to the principles described herein. Figure 1 FIG. 2 is a system architecture diagram 200 of an example SNOC 102 depicting application of policies configured by the SNOC 102. Reference is additionally made to FIG. 1. Figure 2, the SNOC 102 functions as a controller for the SASE 104 computing architecture, the SNOC 102 can receive logs, telemetry data, and other forms of network and performance data from the SNOC 102, the SASE 104, and / or the various security devices (106, 108, 110, 112, 114) of the SASE 104. The SNOC 102, with the network and performance data, can correlate and compare them with the application policies defined within the policy configuration 116 and push them as policies 118 to other computing devices. The policies 118 defined by the SNOC 102 function as rules for the SASE 104 to operate. Depending on the connection modality, the policies can be triggered or violated by one or more client policies. The first class of policies that can be triggered or violated include performance-based policies, where the SNOC 102 seeks to optimize network performance within the network. The performance-based optimization can include client-based network optimization and can be based on security insights obtained from the various security devices (106, 108, 110, 112, 114) of the SASE 104. In one example, an application owner can set a plurality of threshold and / or tolerance measures that best suit and optimize the client flow sessions with respect to the application. For example, when the session duration through the firewall 110 is deemed longer than a threshold time period and / or lacks traffic to a degree below a data transfer threshold, the application policy can dynamically send an update to the client to stop using a first VPN as the first access modality 134 and instead use a second access modality 134. The second modality can include, for example, a second VPN, using DIA, or using an alternative policy for a given time period. The time period allows for dynamic updates to the policies 118 and allows for dynamic changes to the access modalities 134. The ability to dynamically switch between access modalities 134 optimizes the client connection without compromising security. Thus, the goal of the SNOC 102 is to optimize traffic rather than reduce security measures.

[0054] The second class of policies that can be triggered or violated include security-based policies, where the SNOC 102 seeks to optimize network security performance within the network. Security-based optimizations can include manipulating and throttling client-based network based on security insights obtained from the SNOC 102, the SASE 104, and / or various security devices (106, 108, 110, 112, 114) of the SASE 104. Based on various risk factors, client devices that trigger various security detection mechanisms can experience a reduced experience. In some instances, the client device can exhibit malicious behavior. In these instances, the client device can be placed in quarantine and isolated from the network, cloud, or any assets being accessed to ensure that data within those networks is not compromised. While isolating the client device from the network is a viable option to maintain security for a client device that is acting maliciously, the SNOC 102 provides a mechanism by which security can be increased to allow a client device that is acting maliciously to continue to access the network and reduce the tolerance of the client device experience. In instances where the normal operation of the network takes precedence over the full isolation of the client device, this relaxation of security policy can be based on a risk level of not fully isolating the client device. The SNOC 102 can use a number of security performance metrics to determine a threat level from devices that are communicatively coupled to the network. Security performance metrics can include, for example, a threat feed of connection events in a cloud-delivered firewall (CDFW), suspicious domains / uniform resource locators (URLs) in a proxy / DNS security service, bulk data transfers, malicious traffic patterns determined through pattern matching communication behavior, and countless other security performance metrics. The security performance metrics can be fed into the SNOC 102 to configure a number of performance-based policies or policy-based redirections on the client. For example, a client device can access an application or service via a CDFW and it can be determined that the destination IP address is a malicious IP address. In this example, if it is determined that the communication is on port 80 / 443, the SNOC 102 can redirect the client device to further inspect the traffic; port 80 / 443 is typically classified as an open, security risk prone port. The SNOC 102 can identify that the client device is attempting to share a large amount of data based on the traffic pattern. A performance-based policy can be enacted to throttle the client device traffic but still allow the communication. However, the experience can be significantly reduced in the case where the normal operation of the network is preserved for other low overhead activities until it can be fully investigated and determined that the client device needs to be allowed to transfer data or be fully denied access. In this way, the SNOC 102 can create a policy configuration regarding the applications and / or services that the client device is using to reduce security risk while still at least maintaining a level of network performance.

[0055] In the above example, the SNOC 102 can configure multiple performance-based policies and multiple security-based policies to obtain the policy configuration 116. The policy configuration can then be used to ensure that both performance and security of the client device are not compromised, and can do so in a dynamic manner such that users of the client device (e.g., the user endpoint 120, other computing devices 132, or any other device associated with the SASE 104) can experience a reasonable level of network performance without compromising security. The use of the various security devices (106, 108, 110, 112, 114) of the SASE 104 assist the SNOC 102 in determining the optimal policy configuration 116 that can be created to address these network performance and security issues in a dynamic manner.

[0056] In one example, based at least in part on the trigger being identified, at least one of the policy configurations provided by the SNOC 102 to the SDWAN (used as a control point) can be to dynamically adjust QoS to prioritize traffic or drop other unnecessary traffic. The enforcement of this policy as defined by the SNOC 102 provides an abstraction layer to the SDWAN and leverages security insights to improve network connectivity to critical applications.

[0057] In one example, based at least in part on the initial inspection of network traffic by the various security devices (106, 108, 110, 112, 114) of the SASE 104 through the cloud-hosted proxy solution, temporary inspection of network traffic can be conducted under suboptimal traffic conditions to determine if there are applications that are deemed business critical to the user and / or the enterprise to which the user belongs. In this example, the SNOC 102 can obtain a whitelist of those business critical applications from the security devices (106, 108, 110, 112, 114). The SNOC 102 can create multiple policies 116, policies 118 to ultimately optimize traffic flow to the proxy device. This whitelist can be dynamically applied to a proxy auto-configuration (PAC) file. A PAC file defines how a web browser and other user agents automatically select the appropriate proxy server (access modality) to fetch a given URL. In one example, a proxy-based client solution can be provided on the user endpoint 120 or VPN headend device. In this way, by whitelisting potentially more trusted business critical applications within the SNOC 102 and creating policies 116, policies 118 based on the whitelist, the business critical applications can be prioritized based on network performance over security.

[0058] Turning again to Figure 2 and with continued reference to Figure 1The control plane of the system architecture diagram 200 is the vehicle by which client devices and network elements request and receive a plurality of policies related to network performance and security and apply connection policies. In examples described herein, the control plane is managed via the SNOC 102. In one example, the SNOC 102 can be installed as a function in the SIG 202 or in a cloud provider environment. For example, an administrator of an enterprise can configure policies that define access modalities to applications that comply with the requirements and security policies of the enterprise. The policies 116 configured by the SNOC 102 dictate path selection (access modalities 134) for various applications. In one example, the enterprise can manage the applications. In one example, the applications can be SaaS applications, where the company is a cloud consumer of application services provided by a third party. For example, a user wanting to access application A 210 can be directed to use a VPN connection to the SIG 202. Conversely, access to application C 216 can be provided through a corporate VPN (e.g., enterprise headend 208). The policy configuration 116 created by the SNOC 102 can be applied in a top-down process and no further processing occurs once a match between the network topology and the policy is found. An implicit rule can be included at the end of the policy to tell the client device how to access applications that do not have a desired access modality (e.g., connection method), such as general internet browsing. In one example, the newly configured policies 116 can be sent to the client devices and network elements to be executed locally as policies 118.

[0059] In one example, based at least in part on a client device (e.g., user endpoint 120, other computing device 132, or any other device associated with the SASE 104) being launched, an endpoint security client 122 of the client device can be executed, for example. The client device can initiate a request to the SNOC 102 to receive a plurality of policies 118 based on the policy configuration 116 of the SNOC 102. The policies 118 can be preprogrammed into the client device when the client device is deployed or installed. The SNOC 102 can push down to the client device a plurality of policies that were previously configured to be executed locally at the client device. In this way, the policies are shared across the network with any computing device. In one example, role-based access control (RBAC) that defines a plurality of roles and permissions associated with the client device can be used to provide granular or custom control deemed necessary by an administrator and / or enterprise.

[0060] Pushing policies 118 from SNOC 102 down to client devices causes client devices that utilize policies 118 to direct network traffic in various access modalities 134 based at least in part on policies 118. In one example, some network traffic can be transmitted through a VPN to enterprise headend 208. In this example, enterprise headend 208 can provide access to a plurality of applications and / or services, such as access to application C 216, where application C 216 is considered a relatively low-risk application, such that SNOC 102 can allow such an access modality and understand that application C 216 is a trusted application designated by the enterprise.

[0061] In one example, some network traffic can be transmitted to SWG 204. In this example, SWG 204 provides access to a plurality of applications and / or services, including application B 212. In this example, SWG 204 can include Figure 1 SWG 108, and can be directly influenced by SNOC 102 through the use of policy configurations 116 and network performance metrics and / or security performance metrics obtained from SWG 108, SWG 204.

[0062] In one example, some network traffic can be transmitted through a VPN to SIG 202. SIG 202 can provide access to a plurality of applications and / or services, such as including Figure 2 application A 210, as depicted.

[0063] In one example, some network traffic can be transmitted through DIA to DNSSEC 206 to enterprise headend 206. In this example, a user can choose to access applications and other services using a different access modality that provides more efficient network performance but provides a different level of security to the user endpoint (e.g., DIA-DNSSEC 206). While DIA can provide relatively better network performance by reducing network latency, increasing data packet transmission, providing more reliable connections, and other advantages associated with network performance, the user can compromise network security. Moreover, as Figure 2 depicted, DIA-DNSSEC 206 can provide access to a plurality of applications and / or services, including un-policied applications 214. Accordingly, SNOC 102, SASE 104, and / or various security devices (106, 108, 110, 112, 114) of SASE 104 can closely monitor this access modality 134 to obtain network performance metrics as well as security performance metrics to ensure that the level of risk associated with DIA does not exceed a threshold value that can cause an alternative access modality 134 to be selected for at least one period of time.

[0064] In one example, network traffic can be transported using multiple access modalities of any of the access modalities described herein. For example, the access modalities and path selection options can include split tunnel path selection or an endpoint security client 122 (e.g., AnyConnect® TM Module Selection) as described herein. Further, in one example, multiple backup transport paths can be configured for failover purposes. In this example, the SNOC 102 can switch to a redundant or backup access modality 134 when the previously selected access modality 134 fails or terminates abnormally. Further, in the examples described herein, the access modalities can include access via or to third party cloud networks, third party networks, and other remote and non-dedicated applications and services provided to users as a service (aaS).

[0065] In one example, if the client device does not include an endpoint security client 122, the startup sequence can occur on a router device or any edge device that supports the capabilities of the endpoint security client 122. For example, an SD-WAN router can start up. In response to the SD-WAN router starting up, the SD-WAN router can communicate with a vBond that provides the SD-WAN router with details about the environment including the presence of the SNOC 102. The SD-WAN router can receive connection information from the vBond and create a connection to the SNOC 102. Further, the SD-WAN router can request policies that specify applications for the Internet, thereby increasing the DIA use case for the SD-WAN.

[0066] In one example, if the client device in the above SD-WAN router example does include an endpoint security client 122 with the application path control capabilities described herein, the policies 118 can be received from the SD-WAN router. In this example, if the client device behind the SD-WAN router starts up and attempts to communicate with the SNOC 102 in order to download the policies 118, the SD-WAN router can see the request and respond on behalf of the SNOC 102. In this example, the SD-WAN router can respond with instructions in the form of an app->con table, for example, instructing the client device to send all traffic to the SD-WAN router. In this way, the policy duplication issue can be avoided. If the client device is not behind an element that supports application path control (e.g., the SD-WAN router used in this example), the client device can download the policies 118 from another intermediary device or directly from the SNOC 102 to execute locally on the client. If the client device is behind an element that supports application path control (e.g., the SD-WAN router), the client device can receive the policies 118 from that element, which directs all traffic to itself as Figure 1 shown.

[0067] The example scenarios above are binary in nature when the policies 118 are preprogrammed and executed. However, in one example, the concepts described herein can be extended and made more dynamic using traffic analysis data, and based at least in part on that analysis data, the policies 118 can be dynamically changed. In this example, the SNOC 102 can be “developed” into the cloud environment through network metadata capture and application analysis. The network metadata capture and application analysis can include, for example, an application referred to as “mercury”; “mercury” is a Linux TM based application written in the Python TM programming language and described, for example, at https: / / github.com / cisco / mercury. The network metadata capture and application analysis can receive traffic analysis data from its connections or associations to applications in the cloud. Multiple virtual network interface cards (vNICs) included within the SNOC 102 can be connected to virtual personal computers (vPCs) or virtual networks (vNETs) in the cloud provider environment or in the application stack itself in order to monitor network traffic flows and obtain traffic analysis data to determine network performance metrics and security performance metrics. As described herein, the network performance metrics and security performance metrics can be used by the SNOC 102 to dynamically configure any of the policies 116 including the preprogrammed policies discovered within the client device. In one example in which the SIG 202 is deployed within a cloud network as depicted in FIG. 2, the SNOC 102 can include mercury-enabled vNICs that are connected to both the SWG 204 and the application profiles housed in the cloud environment. Figure 2

[0068] ​In one example, the SNOC 102, the SASE 104, and / or various security devices (106, 108, 110, 112, 114) of the SASE 104 can benefit from the functionality of a security monitoring system 218. The security monitoring system 218 can be communicatively coupled to the SNOC 102, directly or indirectly, or via a network (e.g., a cloud network). In one example, the security monitoring system 218 can provide a plurality of playbook configurations and launch processes in which pre-built playbooks and user-generated playbooks can be executed to extract observable security issues, determine decisions for the observable security issues, detect targets involved in the security issues, and / or take mitigating and / or preventative actions (e.g., isolate the involved targets and block malicious domains, among other security tasks). The security monitoring system 218 can include aspects and functionality of a security information and event management (SIEM) application, a security operations center (SOC), and / or a security orchestration, automation, and response (SOAR) program. In one example, the SNOC can interact with the security monitoring system 218 and / or launch automated capabilities to assist the SNOC 102 in identifying security-related instances and orchestrating security responses in an autonomous manner. Further, in one example, the SNOC 102 can push policies 116 in the form of policies 118 to the security monitoring system 218 to allow the security monitoring system 218 to utilize the policies 118 to provide its security functionality.

[0069] While the above is described in conjunction with the Figure 2 The client devices are described as devices that interact with the network architecture, but the client devices can include the user endpoints 120, any other computing devices 132, and / or any computing devices described herein that are communicatively coupled to the network architecture and the SNOC 102.

[0070] Figure 3Component diagram 300 of example components of SNOC 102 that are examples of examples of SNOCs in accordance with the principles described herein. As shown, SNOC 102 can include one or more hardware processors 302, one or more devices configured to execute one or more stored instructions. Processor(s) 302 can include one or more cores. Further, SNOC 102 can include one or more network interfaces 304 configured to provide communication between SNOC 102 and other devices, e.g., devices associated with SASE 104, user endpoints 120, other computing devices 132, devices associated with DNS layer security 106 services, SWG 108 services, firewall 110 services, CASB 112 services, and ITI 114 services, devices associated with cloud services, SIG 202, SWG 204, DIA-DNSSEC 206, enterprise headend 208, and / or other systems or devices associated with and / or remote from SNOC 102. Network interfaces 304 can include devices configured to couple to personal area networks (PANs), wired and wireless local area networks (LANs), wired and wireless wide area networks (WANs), etc. For example, network interfaces 304 can include devices compatible with SASE 104, user endpoints 120, other computing devices 132, devices associated with DNS layer security 106 services, SWG 108 services, firewall 110 services, CASB 112 services, and ITI 114 services, devices associated with cloud services, SIG 202, SWG 204, DIA-DNSSEC 206, enterprise headend 208, and / or other systems or devices associated with and / or remote from SNOC 102.

[0071] SNOC 102 can also include a user interface 306. User interface 306 can allow a user (e.g., an administrator) to interact with SNOC 102 to instruct SNOC 102 to perform its functions, which functions can include, for example, participating in policy configuration 116, enforcing and maintaining policies 118 within a network environment, and pushing policies 118 to a plurality of associated computing devices, as well as other functions described herein.

[0072] The SNOC 102 can also include a computer-readable medium 308 that stores various executable components (e.g., software-based components, firmware-based components, etc.). In addition to the various components discussed herein, the computer-readable medium 308 can store components to implement the functionality described herein. Although not shown, the computer-readable medium 308 can store one or more operating systems for controlling the operation of one or more devices including the SNOC 102. According to one example, the operating system includes a LINUX operating system. According to another example, the operating system(s) include a WINDOWS SERVER operating system from Microsoft Corporation of Redmond, Washington. According to other examples, the operating system(s) can include one of a UNIX operating system or a variant thereof. It can be appreciated that other operating systems can also be utilized.

[0073] Additionally, the SNOC 102 can include a data store 310, which can include one or more repositories or other storage locations for permanently storing and managing collections of data such as databases, simple files, binary data, and / or any other data. The data store 310 can include one or more storage locations that can be managed by one or more database management systems. For example, the data store 310 can store performance data 312 that defines network performance metrics and security performance metrics obtained from various security devices (106, 108, 110, 112, 114) of the SASE 104 and other services that can be operated via the SASE 104. Further, the data store 310 can store security data 312. The security data 312 can include any data obtained by the SNOC 102 regarding the security of devices communicatively coupled to the SNOC 102. For example, the security data 314 can include lists of whitelists, blacklists, and / or graylists of applications executing within the network environment of the SNOC 102, lists of malware, botnets, and phishing domains, other data defining the security of devices communicatively coupled to the SNOC 102, and combinations thereof.

[0074] The data store 310 can also store policy data 316. The policy data 316 can include any data defining policies that were configured and / or executed within the SNOC 102 in the past and / or currently, including the policy configurations 116 and the policies 118 that were pushed to other computing devices within the network environment. In one example, the policies can be created by an enterprise utilizing the SNOC 102 and stored in the data store 310 of the SNOC 102 so that the SNOC 102 can apply them to the management of computing devices within the network environment.

[0075] Additionally, the policy data 316 stored within the data store 310 can include rule data 318 that supports or defines the policy data 316. The rule data 318 can include executable code for enforcing the policies 118 within the network environment.

[0076] The computer-readable media 308 can store portions or components of a client experience application control service 320. For example, the client experience application control service 320 of the computer-readable media 308 can include a network optimization component 322 that, when executed by the processor(s) 302, optimizes network performance for client devices (e.g., user endpoints 120 and / or other computing devices 132). The network optimization component 322 can obtain information (e.g., security and intelligence data) from the various security devices (106, 108, 110, 112, 114) of the SASE 104 when enforcing the policies 118 on behalf of the client devices. Additionally, the network optimization component 322 can assist in determining when to implement different access modalities 134 for the client devices and / or functionality of the different access modalities 134.

[0077] The client experience application control service 320 can also include a security optimization component 324 that, when executed by the processor(s) 302, obtains security intelligence data from the various security devices (106, 108, 110, 112, 114) of the SASE 104 and other services including the security monitoring system 218 in accordance with the techniques described herein. The security optimization component 324 can also collect security data associated with accessing and utilizing the devices described herein. Additionally, the security optimization component 324 can also collect the following security data: white, black, and / or gray lists of applications executing within the network environment of the SNOC 102, lists of malware, botnets, and phishing domains, and IP white and black lists, other data defining the security of devices communicatively coupled to the SNOC 102, and combinations thereof. The security optimization component 324 can store the data collected in the performance data 312, security data 314, and / or policy data 316 of the data store 310 as described herein.

[0078] The client experience application control service 320 can also include a modal selection component 326 that, when executed by the processor(s) 302, selects an alternative access modal 134 for the client device in response to at least one policy 118 being violated. The modal selection component 326, when executed by the processor(s) 302, can also determine when a time period has elapsed in which the original access modal 134 is utilized again after switching to the alternative access modal 134. In one example, the modal selection component 326 can be executed by the processor(s) 302 in response to security performance metrics and / or network performance metrics provided by the various security devices (106, 108, 110, 112, 114) of the SASE 104 that define a state at which the access modal 134 utilized by the client device is to be switched based on the policy configuration 116 defined by the policy management component 328 of the SNOC 102.

[0079] The client experience application control service 320 can also include a policy management component 328 that, when executed by the processor(s) 302, configures a plurality of policies 116 based on data collected by the network optimization component 322 and / or the security optimization component 324. Further, the policy management component 328, when executed by the processor(s) 302, can also push policies 118 down to a plurality of computing devices within the network environment, including the user endpoint 120, other computing devices 132, and / or other computing devices described herein. Further still, the policy management component 328, when executed by the processor(s) 302, can also store the configured policies 116, 118 as policy data 316 in the data store 310. Even further still, the policy management component 328, when executed by the processor(s) 302, can also enforce the policies 118 in response to a violation of the policies 118.

[0080] Figure 4 A flow diagram 400 is shown of an example method of managing access modals of a user endpoint 120 via a SNOC 102 in accordance with examples of the principles described herein. Figure 4The method of 402 can include obtaining, at the SNOC 102 and from a SASE 104 device that performs at least one security service (e.g., a DNS layer security 106 service, a SWG 108 service, a firewall 110 service, a CASB 112 service, an ITI 114 service, and other services provided by the SASE 104 in accordance with the techniques described herein), a first data set defining security performance metrics provided by the security service (106, 108, 110, 112, 114). The SNOC 102 can obtain the first data set defining the security performance metrics with the security optimization component 324 executed by the processor(s) 302. At 404, the method can include obtaining, from the SASE 104 device that performs at least one security service (106, 108, 110, 112, 114), a second data set defining network performance metrics associated with the network device. The SNOC 102 can obtain the second data set defining the network performance metrics with the network optimization component 324 executed by the processor(s) 302.

[0081] At 406, the method can include defining a policy 116, a policy 118 based at least in part on the first data set and the second data set. The SNOC 102 can create the policy configuration 116 and the policy 118 for the user endpoint 120 and other computing devices 132. At 406, the SNOC 102 can utilize the policy management component 328 to define the policy 116, the policy 118 when executed by the processor(s) 302. In one example, defining the policy can include updating an existing policy based at least in part on the first data set and the second data set. Further, in one example, defining the policy can include determining whether an application executed by the end host is on a whitelist; and defining the policy to allow access to a second access modality 134 having a different security risk level relative to the first access modality based at least in part on the application executed by the end host being on the whitelist. The access to the second access modality 134 can be provided based at least in part on the policy being violated as described herein in connection with 408.

[0082] With the policy management component 328 executed by the processor(s) 302, the method can include determining, at 408, whether the policy 118 has been violated. The violation of the policy can be detected by the SNOC 102 and can include, for example, at least one of the network performance metrics and the security performance metrics exceeding a threshold defined by the policy 118.

[0083] In one example, the security performance metrics provided by the security services include metrics provided by the DNS layer security 106 service, the SWG 108 service, the firewall 110 service, the CASB 112 service, the ITI 114 service, and combinations thereof. Further, determining whether the policy 118 has been violated at 408 includes determining whether the security performance metrics violate a threshold. Further, the network performance metrics associated with the network device can include a data transfer rate, a communication latency, or a session duration, and determining whether the policy has been violated at 408 includes determining whether the network performance metrics violate a threshold set with respect to the network performance metrics.

[0084] At 410, the method can include changing the first access modality 134 provided for the network device to access the end host to a second access modality 134 based at least in part on the policy 118 being violated. The first access modality 134 and the second access modality 134 define different methods of access to or of the end host. In one example, the first access modality 134 can include a first network connection and the second access modality 134 can include a second network connection. In another example, the first access modality 134 can include a first network connection and the second access modality 134 can include a second network connection and a third network connection. Figure 4 In the method of, the network device can include, for example, a user endpoint 120, other computing device 132, or any other device that utilizes services provided via a computing network and / or access applications associated with the SASE 104. Further, the end host can include any application and / or service and its associated hardware and network architecture that supports the application and / or service.

[0085] In one example, the policy 118 can define a time period for which the second access modality 134 is to be used. In this example, changing the first access modality 134 to the second access modality 134 at 410 can include using the second access modality 134 for the time period and changing back to the first access modality 134 or another access modality 134 based at least in part on expiration of the time period.

[0086] Figure 4 The method of provides functionality of a cross-architecture controller (e.g., the SNOC 102) that continuously monitors and optimizes network performance based on security insights received from security suites (e.g., services provided by the SASE 104) under user-level application experiences. The functionality of the SASE 104 and the SNOC 102 are performed in a manner that is transparent to the user. Figure 4 The SASE 104 and the SNOC 102 of the method of provide an integrated closed-loop security and network telemetry automation solution. Further, by the SASE 104 and the SNOC 102, Figure 4 The method of provides the ability to maintain user experiences (including access to applications) of applications and services provided via a network while maintaining security controls. The differentiated and correlated access modalities 134 allow the user to treat any network and security parameters or KPIs as tunable or configurable parameters to optimize user performance. Further,Figure 4 The approach leverages the capabilities of SASE 104 and SNOC 102 to provide a converged network and agent / client-based solution with the ability to measure real-time user experience and subsequently adjust network, security, and / or application policies to maintain security and user experience levels. Furthermore, policies created and / or updated by SNOC 102 can be used to optimize the network, at least in part, based on traffic performance or threat-related rerouting or throttling.

[0087] Figure 5 A flowchart 500 illustrates an example method for managing the access modalities of user endpoint 120 via SNOC 102, based on the principles described herein. Figure 5 The method may include: at 502, obtaining a first dataset defining the security performance metrics provided by the security services (106, 108, 110, 112, 114), as described above. Figure 4 As described at 402. Similarly, at 504, the method may include: at 404, obtaining a second dataset defining network performance metrics associated with network devices, as described above. Figure 4 As described at 404. At 506, the method may include: defining policy 116 and policy 118, at least in part, based on the first dataset and the second dataset, as described above. Figure 4 As described at 406. Furthermore, the method may include: at 508, determining whether policy 118 has been violated, as described above. Figure 4 As described at 408. At 510, the method may include: at least in part based on a violation of policy 118, changing the first access mode 134 provided to the network device for accessing the terminal host to a second access mode 134, as described above. Figure 4 As described at 410. The first access mode 134 and the second access mode 134 define different methods of accessing or to a terminal host. Figure 4 In this method, network devices may include, for example, user endpoint 120, other computing devices 132, or any other device associated with SASE 104 that accesses applications and / or utilizes services provided via the computing network. Furthermore, terminal hosts may include any applications and / or services and their associated hardware and network architecture that support the applications and / or services.

[0088] At 512, the method can include communicating the policy to at least a second network device. In one example, the second network device can be configured to enforce the policy. The policy management component 328 of the SNOC 102 executed by the processor(s) 302 can configure the policy based at least in part on the first set of data defining security performance metrics and the second set of data defining network performance metrics provided by the security services (106, 108, 110, 112, 114) and push the policy configuration 116 to the user endpoints 120, other computing devices 132, and / or any other devices coupled to the network system. Further, at 512, the policy can be pushed to these computing devices based at least in part on the new policy being created and / or the existing policy being updated by the SNOC 102.

[0089] Figure 6 is a computing system diagram illustrating a configuration of a data center 600 that can be used to implement aspects of the technology disclosed herein. Figure 6 The example data center 600 shown includes several server computers 602A-602F (which can be referred to simply as “server computers 602” herein) for providing computing resources. In some examples, the resources and / or server computers 602 can include or correspond to any of the types of networked devices described herein. While described as servers, the server computers 602 can include any type of networked device, e.g., servers, switches, routers, hubs, bridges, gateways, modems, repeaters, access points, endpoints, etc.

[0090] The server computers 602 can be standard tower, rack-mounted, or blade server computers that are suitably configured to provide computing resources. In some examples, the server computers 602 can provide computing resources 604 including data processing resources such as VM instances or hardware computing systems, database clusters, computing clusters, storage clusters, data storage resources, database resources, networking resources, virtual private networks (VPNs), etc. Some of the computers 602 can also be configured to execute a resource manager 606 that is capable of instantiating and / or managing computing resources. For example, in the case of VM instances, the resource manager 606 can be a hypervisor or another type of program configured to enable multiple VM instances to be executed on a single server computer 602. The server computers 602 in the data center 600 can also be configured to provide network services and other types of services.

[0091] In Figure 6The example data center 600 also uses an appropriate LAN 608 to interconnect the server computers 602A-602F. It will be appreciated that the configurations and network topologies described herein have been greatly simplified and that more computing systems, software components, networks, and networking devices can be utilized to interconnect the various computing systems disclosed herein and provide the functionality described above. Appropriate load balancing devices or other types of network infrastructure components can also be utilized to balance the load between the data centers 600, between each server computer 602A-602F in each data center 600, and potentially between computing resources in each server computer 602. It will be appreciated that reference is made to Figure 6 The configuration of the data center 600 described is merely illustrative and other implementations can be utilized.

[0092] In one example, the server computers 602 and / or computing resources 604 can each execute / host one or more tenant containers and / or virtual machines to execute the techniques described herein.

[0093] In one example, the data center 600 can provide computing resources, such as tenant containers, VM instances, VPN instances, and storage, on a permanent or on-demand basis. The computing resources provided by the cloud computing network can be used to implement the various services and techniques described above, among other types of functionality. The computing resources 604 provided by the cloud computing network can include various types of computing resources, such as data processing resources (e.g., tenant containers and VM instances), data storage resources, networking resources, data communication resources, network services, VPN instances, etc.

[0094] Each type of computing resource 604 provided by the cloud computing network can be general purpose or can be available for many specific configurations. For example, data processing resources can be used as physical computers or VM instances in many different configurations. The VM instances can be configured to execute applications that include web servers, application servers, media servers, database servers, some or all of the network services described above, and / or other types of programs. Data storage resources can include file storage devices, block storage devices, etc. The cloud computing network can also be configured to provide other types of computing resources 604 not specifically mentioned herein.

[0095] The computing resources 604 provided by the cloud computing network can be enabled by one or more data centers 600 (which can be referred to herein simply as “data centers 600”) in one example. A data center 600 is a facility used to house and operate computer systems and related components. The data centers 600 can include redundant and backup power, communications, cooling, and security systems. The data centers 600 can also be located in geographically disparate locations. Reference is made to, for example, Figure 1 、 Figure 2 andFigure 3 One illustrative example of a data center 600 that can be used to implement the technology disclosed herein is described.

[0096] Figure 7 A computer architecture diagram showing an example computer hardware architecture 700 for implementing computing devices that can be used to implement aspects of the various technologies presented herein is shown. Figure 7 The illustrated computer hardware architecture 700 shows the following: a SNOC 102, a SASE 104, a DNS layer security 106 service, a SWG 108 service, a firewall 110 service, a CASB 112 service, and an ITI 114 service, and / or other systems or devices associated with and / or remote from the SASE 104 and / or the SNOC 102, an end user endpoint 120, other computing devices 132 (e.g., including: a special-purpose SD-WAN 124, a corporate SD-WAN 126, a network appliance 128, a VPN appliance 130, a workstation, a desktop computer, a laptop computer, a tablet computer, a network appliance, an e-reader, a smartphone, a mobile phone, a server, a router, an Internet-of-Things (IoT) device, or other computing device), and can be used to execute any of the software components presented herein. In some examples, the computer 700 can correspond to the network appliances described herein (e.g., the SASE 104 and / or the SNOC 102 and related devices), and can include networking devices such as servers, switches, routers, hubs, bridges, gateways, modems, repeaters, access points, and the like.

[0097] The computer 700 includes a baseboard 702, or “motherboard,” which is a printed circuit board to which a multitude of components or devices are connected. In one illustrative configuration, one or more central processing units (CPUs) 704 operate in conjunction with a chipset 706. The CPUs 704 can include one or more processors, such as a processor from the family of Intel® Core® i5, i7, or i9 processors, or the Xeon® family of processors, available from Intel® Corporation, Santa Clara, CA, and can include a standard programmable processor implementing the operations necessary to perform the functions of the computer 700.

[0098] The CPUs 704 perform operations by transitioning from one discrete, physical state to the next through the manipulation of switching elements that differentiate and change the states of components. Switching elements generally include electronic circuits that maintain one of two binary states, complement one another, and can be programmed to maintain a state between the two binary states. When switching elements maintain a state, they are said to be “on” or “activated.” When they change state, they are said to be “off” or “deactivated.” Switching elements include elements having any number of states. For example, common elements have three states: logic high, logic low, and a high-impedance state between the two states that flows no current; however, an inductor has four states, and a diode has two independent states, the off state and the on state. Switching elements can be combinations of many different active and passive devices, such as logic gates, storage latches, parametric devices, and others.

[0099] Chipset 706 provides an interface between the CPU 704 and the remainder of the components on the motherboard 702 and devices. The chipset 706 can provide an interface to RAM 708, which is used as the main memory in the computer 700. The chipset 706 can also provide an interface to a computer-readable storage medium, such as a read-only memory (ROM) 710 or non-volatile RAM (NVRAM) to store basic routines that help to start the computer 700 and transfer information between the various components and devices. The ROM 710 or NVRAM can also store other software components necessary for the operation of the computer 700 configured according to the configurations described herein.

[0100] The computer 700 can operate in a networked environment using logical connections to remote computing devices and computer systems through a network, such as the WSN 100. The chipset 706 can include functionality to provide network connectivity through a network interface controller (NIC) 712, such as a gigabit Ethernet adapter. The NIC 712 is capable of connecting the computer 700 to other computing devices through the WSN 100. It is appreciated that multiple NICs 712 can be present in the computer 700, connecting the computer to other types of networks and remote computer systems. In some examples, the NIC 712 can be configured to perform at least some of the techniques described herein, such as obtaining network and / or security performance metric(s), performing policy configuration based at least in part on network and / or security performance metric(s), performing a policy, performing adjustment of access modalities based at least in part on the policy, and / or performing other techniques described herein.

[0101] The computer 700 can be connected to a storage device 718 that provides non-volatile storage for the computer. The storage device 718 can store an operating system 720, programs 722, and data, which have been described in greater detail herein. The storage device 718 can be connected to the computer 700 through a storage controller 714 connected to the chipset 706. The storage device 718 can include one or more physical storage units. The storage controller 714 can interface to the physical storage units through a serial attached SCSI (SAS) interface, a serial advanced technology attachment (SATA) interface, a fiber channel (FC) interface, or other type of interface for making physical connection to and transferring data with an entity storage unit.

[0102] The computer 700 can store data on the storage device 718 by transforming the physical state of the physical storage units to reflect the information being stored. The specific transformation of physical state can depend on various factors, in different embodiments of this description. Examples of such factors can include, but are not limited to: the technology used to implement the physical storage units; whether the storage device 718 is characterized as primary or secondary storage; or the like.

[0103] For example, the computer 700 can store information to the storage device 718 by issuing instructions through the storage controller 714 to alter the magnetic characteristics of a particular location within a magnetic disk drive unit, the reflective or refractive characteristics of a particular location in an optical storage unit, or the electrical characteristics of a particular capacitor, transistor, or other discrete component in a solid-state storage unit. Other transformations of physical media are possible without departing from the scope and spirit of the present description, with the foregoing examples provided only to facilitate this description. The computer 700 can further read information from the storage device 718 by detecting the physical states or characteristics of one or more particular locations within the physical storage units.

[0104] In addition to the storage device 718 described above, the computer 700 can have access to other computer-readable storage media (e.g., a program module, data structures) to store and retrieve information or other data. As a person of skill in the art would recognize, the computer-readable storage media is any available media that provides for the non-transitory storage of data and that is accessible by the computer 700. In some examples, operations performed by the SNOC 102 and / or the SASE 104 and / or any components included therein can be supported by one or more devices similar to the computer 700. In other words, some or all of the operations performed by the SNOC 102 and / or the SASE 104 and / or any components included therein can be performed by one or more computer devices operating in a cloud-based arrangement. As an example and not by way of limitation, computer-readable storage media can include volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information such as computer-readable instructions, data structures, program modules or other data. Computer-readable storage media includes, but is not limited to, RAM, ROM, erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory or other solid state memory technology, compact disc ROM (CD-ROM), digital versatile disk (DVD), high definition DVD (HD-DVD), BLU-RAY, or other optical storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information in a non-transitory fashion.

[0105] As briefly mentioned above, the storage device 718 can store an operating system 720 used to control the operation of the computer 700. According to one example, the operating system comprises a LINUX operating system. According to another example, the operating system comprises a WINDOWS® server operating system from Microsoft Corporation of Redmond, Washington. According to other examples, the operating system can comprise a UNIX operating system or one of its variants. It can be appreciated that other operating systems can also be utilized. The storage device 718 can store other system or application programs and data utilized by the computer 700.

[0106] In one example, the storage device 718 or other computer readable storage medium is encoded with computer-executable instructions that, when loaded into the computer 700, transform the computer from a general-purpose computing system into a special- purpose computing system configured to implement the examples described herein. As noted above, these computer-executable instructions transform the computer 700 by specifying how the CPU 704 transitions between states, thereby transforming the computer 700 into a special purpose computer. According to one example, the computer 700 has access to computer-readable storage media storing computer-executable instructions that, when executed by the computer 700, perform the various processes described above with regard to Figures 1 to 7 the examples described herein. The computing device 700 can also include computer-readable storage media having instructions stored thereon for performing any of the other computer- implemented operations described herein.

[0107] The computer 700 can also include one or more input / output controllers 716 for receiving and processing inputs from various input devices (e.g., keyboard, mouse, touchpad, touchscreen, electronic stylus, or other type of input device). Similarly, the input / output controller 716 can provide outputs to displays, such as computer displays, flat panel displays, digital projectors, printers, or other types of output devices. It should be understood that the computer 700 can not include all of the components shown, can include other components not explicitly shown, or can utilize an architecture completely different than that shown. Figure 7 Figure 7 Figure 7

[0108] ​​​​As described herein, computer 700 can include one or more of: SNOC 102, SASE 104, DNS layer security 106 service, SWG 108 service, firewall 110 service, CASB 112 service, and ITI 114 service, and / or other systems or devices associated with and / or remote from SASE 104 and / or SNOC 102, user endpoints 120, other computing devices 132, including: special-purpose SD-WAN 124, corporate SD-WAN 126, network devices 128, VPN devices 130, workstations, desktop computers, laptop computers, tablet computers, network appliances, e-readers, smartphones, mobile phones, servers, routers, Internet-of-Things (IoT) devices, and / or other computing devices associated with and / or remote from SNOC 102. Computer 700 can include one or more hardware processors, such as CPU 704 configured to execute one or more stored instructions. CPU 704 can include one or more cores. Further, computer 700 can include one or more network interfaces configured to provide communication between computer 700 and other devices (e.g., communications described herein as being performed by SNOC 102, SASE 104, and other devices described herein). Network interfaces can include devices configured to couple to personal area networks (PANs), wired and wireless local area networks (LANs), wired and wireless wide area networks (WANs), etc. For example, network interfaces can include devices compatible with Ethernet, Wi-Fi TM etc.

[0109] Programs 722 can include any type of programs or processes to perform the techniques described in this disclosure by SNOC 102, which will be provided by SASE 104 and provide services of SNOC 102, in order to perform the following operations: obtaining network and / or security performance metric(s), performing policy configuration based at least in part on network and / or security performance metric(s), performing policy, performing adjustment of access modalities based at least in part on policy, and / or performing other techniques described herein. Programs 722 can enable the devices described herein to perform various operations.

[0110] Conclusion

[0111] The SASE 104 and the SNOC 102 are used to provide a cross-architecture controller (e.g., the SNOC 102) that continuously monitors and optimizes network performance based on security insights received from security suites (e.g., services provided by the SASE 104) under user-level application experience. An integrated closed-loop security and network telemetry automation solution is provided by the SASE 104 and the SNOC 102. Further, the SASE 104 and the SNOC 102 provide the ability to maintain user experience (including access to applications) provided via the network while maintaining security controls. Differentiated and correlated access modalities 134 allow users to treat any network and security parameters or KPIs as tunable or configurable parameters to optimize user performance. Further, the SASE 104 and the SNOC 102 provide a converged network and agent / client-based solution with the ability to measure real-time user experience and subsequently tune network, security, and / or application policies to maintain security and user experience levels. Further, the network can be optimized using policies created and / or updated by the SNOC 102 based at least in part on performance of traffic, or threat-related re-routing or throttling.

[0112] The SASE 104 and its SNOC 102 provide a converged system in which multiple network devices and security devices identify at least one KPI that indicates a performance value (e.g., a performance degradation in the network or security). In one example, depending on the criticality of the application being accessed, a control signal can be sent to the user endpoint 120 and / or other computing devices 132 to direct traffic through different access modalities 134 (e.g., connection methods) and / or to dynamically modify quality of service (QoS) settings on the security SD-WAN overlay provided by the SASE 104 for a period of time (e.g., in instances where there are potentially unstable communication links (e.g., satellite, cellular, or degraded internet communication links)).

[0113] In summary, a network optimization controller (NOC) performs operations that include obtaining, from a security access service edge (SASE) device that performs security services, a first data set that defines security performance metrics provided by the security services, and obtaining, from the SASE, a second data set that defines network performance metrics associated with a network device. The operations further include defining a policy based at least in part on the first data set and the second data set, determining whether the policy has been violated, and changing a first access modality provided for the network device to access a terminal host to a second access modality based at least in part on the policy being violated. The first access modality and the second access modality define different methods of accessing the terminal host.

[0114] While the system and method is described in relation to specific examples, it should be understood that the scope of the system and method is not limited to these specific examples. Because modifications and changes to the system and method can be obvious to those of ordinary skill in the art, the system and method should not be considered limited to the examples chosen for the purpose of disclosure, but are included within all changes and modifications that do not constitute departures from the true spirit and scope of the system and method.

[0115] While the present application describes examples with specific structural features and / or method acts, it should be understood that the claims are not necessarily limited to the specific features or acts described. Rather, the specific features and acts are merely illustrative of some examples falling within the scope of the claims of the present application.

Claims

1. A network optimization controller (NOC), comprising: One or more processors; as well as One or more non-transitory computer-readable media storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations, the operations including: Obtain a first dataset from the Secure Access Service Edge (SASE) device that performs the security service, defining the security performance metrics provided by the security service; A second dataset defining network performance metrics associated with network devices is obtained from the SASE; The strategy is defined based at least in part on the first dataset and the second dataset; Determine whether the policy has been violated; and The first access mode provided to the network device for accessing the terminal host is changed to a second access mode, at least in part, based on the violation of the policy. The first access mode and the second access mode define different access methods to the terminal host.

2. The NOC according to claim 1, wherein, The strategy is defined as including updating a baseline strategy based at least in part on the first dataset and the second dataset, wherein the baseline strategy is a pre-configured strategy.

3. The NOC according to claim 1 or 2, wherein, The strategy is defined as follows: Determine whether the application executed by the terminal host is on the whitelist; and The policy is defined to allow access to the second access modality, which has a different security risk level than the first access modality, based at least in part on the application being executed by the terminal host on the whitelist.

4. The NOC according to any one of claims 1 to 3, wherein the operation further comprises: The policy is transmitted to a second network device, which is configured to execute the policy.

5. The NOC according to any one of claims 1 to 4, wherein, The strategy defines the time period during which the second access modality is used, and Changing the first access mode to the second access mode includes: Utilizing the second access mode during the said time period; and The first access mode is changed at least in part based on the expiration of the time period.

6. The NOC according to any one of claims 1 to 5, wherein, The security performance metrics provided by the security services include metrics provided by: Domain Name System (DNS) layer security services, Secure Network Gateway (SWG) services, firewall services, Cloud Access Security Proxy (CASB) services, interactive threat intelligence services, and combinations thereof. Determining whether the policy has been violated includes: determining whether the security performance metric has violated a threshold.

7. The NOC according to any one of claims 1 to 6, wherein, Network performance metrics associated with the network device include: data transmission rate, communication latency, or session duration, and Determining whether the policy has been violated includes: determining whether the network performance metric has violated a threshold.

8. A method comprising: Obtain a first dataset from the Secure Access Service Edge (SASE) device that performs the security service, defining the security performance metrics provided by the security service; A second dataset defining network performance metrics associated with network devices is obtained from the SASE; The strategy is defined based at least in part on the first dataset and the second dataset; Determine whether the policy has been violated; as well as The first access mode provided to the network device for accessing the terminal host is changed to a second access mode, at least in part, based on the violation of the policy. The first access mode and the second access mode define different access methods to the terminal host.

9. The method according to claim 8, wherein, The strategy is defined as updating an existing strategy based at least in part on the first dataset and the second dataset.

10. The method according to claim 8 or 9, wherein, The strategy is defined as follows: Determine whether the application executed by the terminal host is on the whitelist; and The policy is defined to allow access to the second access modality, which has a different security risk level than the first access modality, based at least in part on the application being executed by the terminal host on the whitelist.

11. The method according to any one of claims 8 to 10, further comprising: The policy is transmitted to a second network device, which is configured to execute the policy.

12. The method according to any one of claims 8 to 11, wherein, The strategy defines the time period during which the second access modality is used, and Changing the first access mode to the second access mode includes: Utilizing the second access mode during the said time period; and The first access mode is changed at least in part based on the expiration of the time period.

13. The method according to any one of claims 8 to 12, wherein, The security performance metrics provided by the security services include metrics provided by: Domain Name System (DNS) layer security services, Secure Network Gateway (SWG) services, firewall services, Cloud Access Security Proxy (CASB) services, interactive threat intelligence services, and combinations thereof. Determining whether the policy has been violated includes: determining whether the security performance metric has violated a threshold.

14. The method according to any one of claims 8 to 13, wherein, Network performance metrics associated with the network device include: data transmission rate, communication latency, or session duration, and Determining whether the policy has been violated includes: determining whether the network performance metric has violated a threshold.

15. A non-transitory computer-readable medium storing instructions that, when executed, cause one or more processors to perform operations, the operations comprising: Obtain a first dataset from the Secure Access Service Edge (SASE) device that performs the security service, defining the security performance metrics provided by the security service; A second dataset defining network performance metrics associated with network devices is obtained from the SASE; The strategy is defined based at least in part on the first dataset and the second dataset; Determine whether the policy has been violated; as well as The first access mode provided to the network device for accessing the terminal host is changed to a second access mode, at least in part, based on the violation of the policy. The first access mode and the second access mode define different access methods to the terminal host.

16. The non-transitory computer-readable medium according to claim 15, wherein, The strategy is defined as updating an existing strategy based at least in part on the first dataset and the second dataset.

17. The non-transitory computer-readable medium according to claim 15 or 16, wherein, The strategy is defined as follows: Determine whether the application executed by the terminal host is on the whitelist; and The policy is defined to allow access to the second access modality, which has a different security risk level than the first access modality, based at least in part on the application being executed by the terminal host on the whitelist.

18. The non-transitory computer-readable medium according to any one of claims 15 to 17, wherein, The operation further includes transmitting the policy to a second network device, the second network device being configured to execute the policy.

19. The non-transitory computer-readable medium according to any one of claims 15 to 18, wherein, The security performance metrics provided by the security services include metrics provided by: Domain Name System (DNS) layer security services, Secure Network Gateway (SWG) services, firewall services, Cloud Access Security Proxy (CASB) services, interactive threat intelligence services, and combinations thereof. Determining whether the policy has been violated includes: determining whether the security performance metric has violated a threshold.

20. The non-transitory computer-readable medium according to any one of claims 15 to 19, wherein, Network performance metrics associated with the network device include: data transmission rate, communication latency, or session duration, and Determining whether the policy has been violated includes: determining whether the network performance metric has violated a threshold.

21. An apparatus comprising: A module for obtaining a first dataset from the Secure Access Service Edge (SASE) device that performs the security service, defining the security performance metrics provided by the security service; A module for obtaining a second dataset from the SASE that defines network performance metrics associated with network devices; A module for defining a strategy based at least in part on the first dataset and the second dataset; A module used to determine whether the policy has been violated; as well as A module for changing a first access mode for accessing a terminal host provided to the network device to a second access mode based at least in part on the violation of the policy, the first access mode and the second access mode defining different access methods to the terminal host.

22. The apparatus of claim 21, further comprising: A module for implementing the method according to any one of claims 9 to 14.

23. A computer program, computer program product, or computer-readable medium comprising instructions that, when executed by a computer, cause the computer to perform the steps of the method according to any one of claims 8 to 14.

Citation Information

Patent Citations

  • Dynamically defined virtual private network tunnels in hybrid cloud environments

    US20170171158A1

  • Network Application Security Policy Enforcement

    US20180234460A1