Firewall configuration techniques based on network security risks

By deploying inspectors and controllers in a cloud computing environment, inspectable disks are generated to detect network security objects and risks, and firewall policies are dynamically configured. This solves the problem of inaccurate network firewall traffic filtering and enables real-time network security risk response and traffic management.

CN122139339APending Publication Date: 2026-06-02WIZ INC

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
WIZ INC
Filing Date
2024-08-29
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing network firewalls suffer from inaccurate traffic filtering due to the static and dynamic nature of IP addresses. They may block traffic that should be allowed while allowing traffic that should not be allowed, and lack the ability to dynamically adjust.

Method used

By deploying inspectors and inspection controllers in a cloud computing environment, inspectable disks are generated, network security objects and risks are detected, and firewall policies are dynamically configured based on the detection results, including generating and applying network traffic policies, filtering or blocking network traffic, and using sensor detection events to generate policies, dynamic network traffic management is achieved.

Benefits of technology

It enables real-time adjustment of firewall policies based on network security risks, improving the accuracy of traffic filtering, dynamically responding to network threats, reducing false alarms and vulnerabilities, and enhancing network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122139339A_ABST
    Figure CN122139339A_ABST
Patent Text Reader

Abstract

A system and method for providing dynamic network traffic policies are provided. The method includes inspecting a workload against a network security object indicating a network security risk, wherein the workload is deployed in a cloud computing environment with a firewall connected to an external network; detecting network security risks on the workload based on the network security object; generating a policy for the firewall based on the network security risks; and configuring the firewall to the policy generated by the application.
Need to check novelty before this filing date? Find Prior Art

Description

Cross-references to related applications

[0001] This application is an international application of U.S. Patent Application No. 18 / 469,159, filed on September 18, 2023, the contents of which are incorporated herein by reference. Technical Field

[0002] This disclosure generally relates to network traffic management, and specifically to configuring a network security monitoring system to provide network traffic management based on dynamic risks. Background Technology

[0003] Network firewalls are indispensable security devices in today's computing networks. Firewalls are typically implemented as measures to manage network traffic (such as network traffic to cloud computing environments, network traffic between cloud computing environments, and network traffic between components (also known as nodes) of a network environment).

[0004] As another example, firewalls can be used to create a barrier between trusted and untrusted network environments. However, there are also drawbacks to using firewalls. For instance, IP addresses may be filtered at the firewall. While IP addresses are typically static, they do change, so over time, such filters may block traffic that should be allowed while allowing traffic that shouldn't.

[0005] As with any security measure, if no benefit is realized, the advantages provided by the added security layer can easily become disadvantages.

[0006] Therefore, it would be beneficial to provide a solution that overcomes the above challenges. Summary of the Invention

[0007] The following is an overview of several exemplary embodiments of this disclosure. This overview is provided to facilitate a reader's basic understanding of these embodiments and does not necessarily limit the scope of this disclosure. This overview is not a comprehensive summary of all contemplated embodiments and is neither intended to identify key or essential elements of all embodiments nor to depict the scope of any or all aspects. Its sole purpose is to present some concepts of one or more embodiments in a simplified form as a prelude to the more detailed description that follows. For convenience, the terms "some embodiments" or "certain embodiments" may be used herein to refer to a single embodiment or multiple embodiments of this disclosure.

[0008] A system of one or more computers can be configured to perform specific operations or actions by installing software, firmware, hardware, or combinations thereof on the system, which, in operation, cause the system to perform actions. A system of one or more computer programs can be configured to perform specific operations or actions by including instructions that, when executed by a data processing device, cause the device to perform actions.

[0009] In one general aspect, the method may include detecting cybersecurity risks on workloads deployed in a cloud computing environment having firewalls connected to untrusted networks. The method may also include configuring the firewalls to filter network traffic to the workloads based on the detected cybersecurity risks. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.

[0010] Implementations may include one or more of the following features. Methods may include: inspecting workloads against network security objects; and detecting network security risks based on network security objects. Methods may include: generating an inspectable disk based on the workload's raw disk; and configuring an inspector to inspect the inspectable disk against network security objects. Methods may include: cloning the raw disk into the inspectable disk. Methods may include: configuring a firewall to block network traffic to the workload in response to determining that a network security risk is of a first type. Methods may include: initiating mitigation actions based on detected network security risks. Methods may include: tagging the workload with labels indicating detected network security risks. Methods may include: storing labels indicating network security risks on any of a security database (DB), the workload, or a combination thereof. Methods may include: configuring a firewall to filter only certain network traffic to the workload based on detected network security risks. Methods may include: configuring a firewall to detect incoming network traffic to the workload; and configuring the firewall to block incoming network traffic to the workload in response to detecting that incoming network traffic of the first type exceeds a threshold. Methods may include: configuring a firewall to remove filters in response to detecting that a network security risk has been removed from the workload. Implementations of the described technology may include hardware, methods or processes, or tangible computer media.

[0011] In one general aspect, a non-transitory computer-readable medium may include one or more instructions, which, when executed by one or more processors of a device, cause the device to: detect cybersecurity risks on workloads deployed in a cloud computing environment having firewalls connected to untrusted networks. The medium may further include: configuring the firewall to filter network traffic to the workloads based on the detected cybersecurity risks. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.

[0012] In one general aspect, the system may include processing circuitry. The system may also include memory containing instructions that, when executed by the processing circuitry, configure the system to: detect cybersecurity risks on workloads deployed in a cloud computing environment having firewalls connected to untrusted networks. Additionally, the system may configure the firewalls to filter network traffic to the workloads based on the detected cybersecurity risks. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.

[0013] The implementation may include one or more of the following features. The system memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: inspect the workload for network security objects; and detect network security risks based on the network security objects. The system memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: generate an inspectable disk based on the raw disk of the workload; and configure the inspector to inspect the inspectable disk for network security objects. The system memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: clone the raw disk into the inspectable disk. The system memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: configure the firewall to block network traffic to the workload in response to determining that a network security risk is of type one. The system memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: initiate mitigation actions based on the detected network security risks. The system memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: tag the workload with a label indicating the detected network security risks. The system memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: store tags indicating network security risks on any one of a security database, a workload, or a combination thereof. The system memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: configure the firewall to filter only certain network traffic to the workload based on detected network security risks. The system memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: configure the firewall to detect incoming network traffic to the workload; and, in response to detecting that incoming network traffic of a first type exceeds a threshold, configure the firewall to block incoming network traffic to the workload. The system memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: configure the firewall to remove filters in response to detecting that a network security risk has been removed from the workload. Implementations of the described techniques may include hardware, methods, processes, or tangible computer media.

[0014] A system of one or more computers can be configured to perform a specific operation or action by installing software, firmware, hardware, or a combination thereof on the system, which, in operation, causes the system to perform the action. A system of one or more computer programs can be configured to perform a specific operation or action by including instructions that, when executed by a data processing device, cause that device to perform the action.

[0015] Implementations may include one or more of the following features. The method may include: determining the severity of a cybersecurity risk based on detected cybersecurity objects; generating a network traffic policy based on the determined severity; and configuring a firewall to apply the generated network traffic policy. The method may include: determining that the cybersecurity risk is any of the following: misconfiguration, vulnerability, exposure, attack path, reachability path, or a combination thereof. Implementations of the described techniques may include hardware, methods or processes, or tangible computer media.

[0016] Implementations may include one or more of the following features. The system memory contains further instructions, which, when executed by processing circuitry, further configure the system to: determine the severity of a network security risk based on detected network security objects; generate a network traffic policy based on the determined severity; and configure a firewall to apply the generated network traffic policy. The system memory contains further instructions, which, when executed by processing circuitry, further configure the system to: determine that the network security risk is any of the following: misconfiguration, vulnerability, exposure, attack path, reachability path, or a combination thereof. Implementations of the described techniques may include hardware, methods or processes, or a tangible computer medium. Attached Figure Description

[0017] The claims in the specification specifically point out and expressly claim protection for the subject matter disclosed herein. The above and other objects, features, and advantages of the disclosed embodiments will become apparent from the following detailed description taken in conjunction with the accompanying drawings.

[0018] Figure 1 This is an example network diagram used to describe a computing environment including a dynamic policy firewall, as illustrated in the embodiments.

[0019] Figure 2 This is an example flowchart used to describe a method for determining cybersecurity risks in an embodiment.

[0020] Figure 3 This is an example flowchart used to describe an embodiment of a method for inspecting workloads against network security objects.

[0021] Figure 4 This is an example flowchart of a dynamic firewall configuration method with a policy based on network security risks, implemented according to an embodiment.

[0022] Figure 5 This is an example schematic diagram of an inspection controller according to an embodiment. Detailed Implementation

[0023] It is important to note that the embodiments disclosed herein are merely examples of the many advantageous uses of the inventive teachings herein. Generally, the statements made in the specification of this application do not necessarily limit any of the various claimed embodiments. Furthermore, some statements may apply to some inventive features but not others. Generally, unless otherwise stated, singular elements may be plural, and vice versa, without loss of generality. In the drawings, the same reference numerals denote the same parts in several views.

[0024] The disclosed embodiments include methods and systems for providing dynamic network traffic policies. According to embodiments, network filtering policies are generated based on network security objects, network security risks, and combinations thereof detected on workloads in computing environments (such as cloud computing environments).

[0025] In some embodiments, the firewall is continuously configured with dynamic network traffic policies based on continuous detection of network security objects in the network computing environment. In some embodiments, the policy includes an expulsion mechanism such that the policy is removed from the firewall after a predetermined time. In some embodiments, the policy is generated based on risks, vulnerabilities, misconfigurations, exposures, threats, attack paths, reachability paths, and combinations thereof. In some embodiments, the network traffic policy is also generated based on a severity score assigned to a network security risk. For example, according to an embodiment, a workload with a misconfigured database has a "medium" network security risk score, while a workload with a misconfigured database storing sensitive data has a "severe" network security risk score. In some embodiments, network traffic is modified based on a combination of detecting network security objects and network security risks on the same workload.

[0026] While it's understandable that humans can generate policies for filtering network traffic, it's clear that humans cannot detect cybersecurity risks on workloads in a cloud computing environment, nor can they generate policies based on such detection. For example, human thinking lacks the capacity to inspect workloads against cybersecurity targets, nor can it perform actions such as deep packet inspection to determine whether packets crossing firewalls comply with dynamic policies.

[0027] Figure 1 This is an example network diagram used to describe a computing environment including a dynamic policy firewall in an embodiment. In an embodiment, computing environment 110 includes multiple entities. In some embodiments, entities are, for example, resources, subjects, and cloud entities. In some embodiments, resources are, for example, virtual machines 112, software containers 114, serverless functions 116, and combinations thereof.

[0028] According to an embodiment, virtual machine 112 is implemented using Oracle® VirtualBox®. In some embodiments, software container 114 is implemented using the Docker® platform, Kubernetes® platform, or combinations thereof. In an embodiment, serverless function 116 is implemented using, for example, Amazon® Lambda functions.

[0029] In some embodiments, computing environment 110 includes entities such as user accounts, service accounts, roles, and combinations thereof. In embodiments, computing environment 110 is a cloud computing environment, a hybrid computing environment, a network computing environment, and combinations thereof. In some embodiments, computing environment 110 is implemented on multiple computing environments.

[0030] In some embodiments, the cloud computing environment is, for example, a virtual private cloud (VPC) or a virtual network (VNet). In some embodiments, the cloud computing environment is implemented on cloud computing infrastructure such as Amazon® Web Services (AWS), Google® Cloud Platform (GCP), Microsoft® Azure®, and combinations thereof.

[0031] According to an embodiment, computing environment 110 includes firewall 118. In this embodiment, firewall 118 is a software device, a hardware device, or a combination thereof. In some embodiments, firewall 118 is a network-based system, a host-based system, or a combination thereof. According to an embodiment, firewall 118 is deployed within computing environment 110, between computing environment 110 and untrusted network 130, or a combination thereof. In this embodiment, untrusted network 130 is a public network, such as the Internet.

[0032] In some embodiments, firewall 118 is configured to filter data packets. In some embodiments, firewall 118 includes access control lists. In these embodiments, access control lists are used to filter which data packets should be allowed through and which should be dropped (i.e., blocked).

[0033] In some embodiments, firewall 118 is configured to filter network traffic at the application layer. In embodiments, the application firewall is implemented as, for example, a web application firewall (WAF). In some embodiments, firewall 118 is also configured to perform deep packet inspection.

[0034] In some embodiments, firewall 118 includes routing tables, policies, rules, and combinations thereof. For example, in an embodiment, firewall 118 is configured to receive data packets and network data packets, and apply policies and rules to the received data packets. In an embodiment, for example, a policy includes actions that are initiated when the policy is applied to a received data packet. For example, an action could be to pass a data packet into the network, pass a data packet from the network, drop a data packet, send an error response, or a combination thereof.

[0035] In this embodiment, firewall 118 is configured to communicate with the inspection environment and receive generated policies, dynamic policies and combinations thereof, and apply such policies to network traffic passing through firewall 118.

[0036] In some embodiments, the inspection environment 120 is configured to inspect a computing environment (such as computing environment 110, etc.) against a network security object. In some embodiments, the inspection environment 120 is further configured to determine network security risks based on the detection of the network security object and multiple network security objects, etc.

[0037] According to an embodiment, the inspection environment 120 is deployed as, for example, a cloud computing environment, an account in the cloud environment of computing environment 110, and combinations thereof.

[0038] In some embodiments, the inspection environment 120 includes an inspection controller 124, an inspector 126, and a security database 122, etc. In some embodiments, the inspection controller 124, the inspector 126, and the security database 122 are implemented using virtual machines, software containers, serverless functions, and combinations thereof.

[0039] In this embodiment, inspector 126 and inspector controller 124 are also configured to assume roles and access service accounts within the computing environment 110. For example, in this embodiment, inspector 126 is configured to assume a role within the computing environment 110 that grants inspector 126 (e.g., based on the raw disk of virtual machine 112) permission to generate inspectable disks.

[0040] For example, according to an embodiment, the inspection controller 124 is configured to assign inspector 126 to inspect the raw disk of a network security object (e.g., virtual machine 112). In this embodiment, the network security object indicates a network security risk.

[0041] In some embodiments, the inspection controller 124 is configured to initiate the action of generating an inspectable disk from a raw disk, wherein the raw disk is deployed in the computing environment 110. In embodiments, the inspectable disk is generated by cloning, copying, generating snapshots, and combinations thereof.

[0042] In some embodiments, inspector 126 is configured to inspect disks and workloads for network security objects, network security risks, network security threats, and combinations thereof. In embodiments, network security objects include, for example, passwords (e.g., stored as text), certificates, encryption keys, applications, operating systems, code objects, registry files, hash values, sensitive data, and combinations thereof. In some embodiments, inspector 126 is configured to detect malware objects, misconfigurations, vulnerabilities, exposures, and combinations thereof.

[0043] In an embodiment, inspector 126 is configured to detect malware, for example by generating signatures, hashes, and combinations thereof from network security objects detected on an inspectable disk, and comparing the generated signatures and hashes with signatures received from a malware database.

[0044] In some embodiments, the security database 122 includes a representation of a computing environment, such as computing environment 110. In some embodiments, this representation includes representations of entities within computing environment 110. For example, in some embodiments, entities are cloud entities such as resources and subjects. In some embodiments, the representation stored on the security database 122 further represents enrichment information, cybersecurity objects, and mitigation actions.

[0045] For example, according to an embodiment, security database 122 is a graph database (e.g., Neo4j®) that stores a security graph including a representation of computing environment 110. In an embodiment, inspector 126 and inspector controller 124, etc., are configured to populate the security graph (or other database structure). For example, in an embodiment, inspector 126 is configured to detect entities, cloud entities, workloads, resources, and subjects in the computing environment.

[0046] For example, each cloud entity is represented as a node in the graph. According to an embodiment, an edge connecting a pair of nodes represents the relationship and direction between the two nodes. In some embodiments, nodes are generated based on a unified data pattern. For example, in an embodiment, the data pattern includes multiple templates, each corresponding to an entity. In an embodiment, a first template of the data pattern corresponds to a resource, such that the first template is used to generate representations of resources and workloads such as virtual machines 112, software containers 114, and serverless functions 116.

[0047] In some embodiments, the generated representations utilize a unified data schema used across multiple different computing environments. For example, a first computing environment is deployed on AWS, while a second computing environment is deployed on GCP; both representations are generated based on the same unified data schema.

[0048] In one embodiment, the inspection controller 124 is configured to generate policies for the firewall 118 based on network security objects, network security risks, and network security threats. In some embodiments, policies are generated based on network security objects on the inspection workload.

[0049] In some embodiments, the policy of firewall 118 is generated based on the detection of network security risks. In these embodiments, network security risks are detected and determined based on detecting network security objects on the workload. For example, in some embodiments, network security risks are determined based on both detecting network security objects and detecting exposures on the same workload. In some embodiments, policies are generated based on a combination of detecting network security objects and network security exposures, misconfigurations, vulnerabilities, and combinations thereof.

[0050] In some embodiments, the workload includes sensors (not shown) deployed thereon. In some embodiments, the sensors are configured to detect runtime data of the workload. In embodiments, the sensors are configured to monitor the workload's data link layer and the workload's kernel space, etc. In some embodiments, the sensors are configured to send events detected in the runtime data to the inspection environment 120.

[0051] In some embodiments, strategies are also generated based on events detected by sensors. For example, in some embodiments, strategies are generated based on events detected by sensors, network security objects detected by inspectors, network security threats, network security risks, misconfigurations, exposures, vulnerabilities, and combinations thereof.

[0052] Figure 2 This is an example flowchart illustrating a method for determining cybersecurity risks in an embodiment. In this embodiment, cybersecurity risks are determined based on detecting cybersecurity objects on a workload and further identifying the workload as including vulnerabilities, exposures, and misconfigurations.

[0053] At 210, access the computing environment. In this embodiment, the computing environment is a cloud computing environment, such as a virtual private cloud deployed on Amazon® Web Services. In some embodiments, accessing the computing environment includes configuring checkers and check controllers to assume roles, service accounts, and principals within the computing environment.

[0054] In some embodiments, the subject is configured to generate an inspectable disk based on a raw disk detected in a computing environment. In embodiments, the inspectable disk is generated in the computing environment, in the inspection environment, in an account within the inspection environment, in an account within the computing environment, or a combination thereof.

[0055] In some embodiments, the inspectable disk is generated based on clones, copies, snapshots, and combinations thereof of the original disk. For example, in one embodiment, the inspection controller is configured to generate clones of the original disk into the inspection account. According to some embodiments, this is advantageous because it utilizes fewer resources in the target account (i.e., the account deployed in the computing environment and being inspected).

[0056] At 220, the workload is inspected against the network security object. In an embodiment, the workload is a virtual machine, software container, serverless function, or a combination thereof. In some embodiments, the inspector is configured to detect network security objects and multiple network security objects. In an embodiment, the inspector is configured to detect multiple network security objects, including a first network security object of a first type (e.g., an encryption key) and a second network security object of a second type (e.g., a software application).

[0057] In some embodiments, network security objects are passwords, certificates, encryption keys, applications, operating systems, code objects, registry files, hash values, sensitive data, malware objects, and combinations thereof. In some embodiments, the inspector is configured to detect configuration errors, vulnerabilities, exposures, and combinations thereof.

[0058] In some embodiments, in response to determining that the check is complete, the checkable disk is unallocated. In some embodiments, unallocating the checkable disk includes releasing resources allocated to the checkable disk by the computing environment. For example, in embodiments, resources (e.g., processors, memory, storage devices, etc.) are allocated (i.e., allocated) to virtual instances such as virtual disks, virtual machines, software containers, and serverless functions.

[0059] At 230, a cybersecurity risk was detected. In some embodiments, the cybersecurity risk is determined based on the detection of a cybersecurity object. In some embodiments, the cybersecurity risk is determined based on the detection of a cybersecurity object and any of the following: misconfiguration, vulnerability, exposure, or a combination thereof.

[0060] In some embodiments, cybersecurity risks are indicated by detecting cybersecurity objects and vulnerabilities on the same workload. In one embodiment, the inspector detects vulnerabilities on the workload. In some embodiments, vulnerabilities are represented in a security database, such as as nodes in a security graph.

[0061] In some embodiments, a node representing a workload is connected to a node representing a vulnerability to indicate that the workload includes a vulnerability. In some embodiments, the node representing a vulnerability also includes a remediation action.

[0062] In some embodiments, mitigation actions are initiated in response to determining that the workload includes a cybersecurity risk. In some embodiments, mitigation actions are initiated based on remediation actions indicated by the node representing the vulnerability.

[0063] Figure 3 This is an example flowchart used to describe an embodiment of a method for inspecting workloads against network security objects.

[0064] At 310, the raw disk of the workload deployed in a cloud computing environment is accessed. In this embodiment, the computing environment is a cloud computing environment, such as a virtual private cloud deployed on Amazon® Web Services. In this embodiment, the workload is a virtual machine, a software container, a serverless function, or a combination thereof. In some embodiments, accessing the computing environment includes configuring an inspector and an inspection controller to identify roles, service accounts, and principals within the computing environment.

[0065] At 320, the original disk is cloned into the checkable disk. In some embodiments, the subject is configured to generate the checkable disk based on the original disk detected in the computing environment. In embodiments, the checkable disk is generated in the computing environment, in the check environment, in an account in the check environment, in an account in the computing environment, or a combination thereof.

[0066] In some embodiments, the disk to be inspected is generated based on a clone of the original disk. For example, in one embodiment, the inspection controller is configured to generate a clone of the original disk into the inspection account. According to some embodiments, this is advantageous because it utilizes fewer resources in the target account (i.e., the account deployed in the computing environment and being inspected).

[0067] At 330, the inspector begins examining network security objects on the inspectable disk. In some embodiments, network security objects are passwords, certificates, encryption keys, applications, operating systems, code objects, registry files, hash values, sensitive data, malware objects, and combinations thereof. In some embodiments, the inspector is configured to detect misconfigurations, vulnerabilities, exposures, and combinations thereof.

[0068] In some embodiments, in response to determining that the check is complete, the checkable disk is unallocated. In some embodiments, unallocating the checkable disk includes releasing resources allocated to the checkable disk by the computing environment. For example, in embodiments, resources (e.g., processors, memory, storage devices, etc.) are allocated (i.e., allocated) to virtual instances such as virtual disks, virtual machines, software containers, and serverless functions.

[0069] Figure 4 This is an example flowchart of a dynamic firewall configuration method with a policy based on network security risks, implemented according to an embodiment.

[0070] In 410, a cybersecurity risk was detected on a workload deployed in a cloud computing environment that has a firewall connecting to an untrusted network. In this embodiment, the computing environment is a cloud computing environment, such as a Virtual Private Cloud deployed on Amazon® Web Services. In this embodiment, the workload is a virtual machine, software container, serverless function, or a combination thereof. In this embodiment, the firewall is a software device, a hardware device, or a combination thereof. In some embodiments, the firewall is a network-based system, a host-based system, or a combination thereof.

[0071] In some embodiments, network security objects are passwords, certificates, encryption keys, applications, operating systems, code objects, registry files, hash values, sensitive data, malware objects, and combinations thereof. In some embodiments, the inspector is configured to detect configuration errors, vulnerabilities, exposures, and combinations thereof.

[0072] In some embodiments, cybersecurity risks are determined based on the detection of cybersecurity objects. In some embodiments, cybersecurity risks are determined based on the detection of cybersecurity objects and any of the following: misconfigurations, vulnerabilities, exposures, and combinations thereof.

[0073] In some embodiments, cybersecurity risks are indicated by detecting cybersecurity objects and vulnerabilities on the same workload. In one embodiment, the inspector detects vulnerabilities on the workload. In some embodiments, vulnerabilities are represented in a security database, such as as nodes in a security graph.

[0074] In some embodiments, a node representing a workload is connected to a node representing a vulnerability to indicate that the workload includes a vulnerability. In some embodiments, the node representing a vulnerability also includes a remediation action.

[0075] At 420, the firewall is configured to apply network security policies. In an embodiment, applying network security policies includes filtering network traffic destined for a workload from workloads and combinations thereof based on detected network security risks. In an embodiment, the inspection controller is configured to generate policies for the firewall based on network security objects, network security risks, and network security threats, as discussed in more detail herein. In some embodiments, policies are generated based on detected network security objects on the workload.

[0076] In some embodiments, a firewall includes routing tables, policies, rules, and combinations thereof. For example, in an embodiment, the firewall is configured to receive data packets and network packets, and apply policies and rules to the received packets. In an embodiment, for example, a policy includes actions that are initiated when the policy is applied to a received packet. For example, an action could be to pass a packet into the network, pass a packet from the network, drop a packet, send an error response, or a combination thereof.

[0077] In this embodiment, the firewall is configured to communicate with the inspection environment and receive generated policies, dynamic policies, and combinations thereof, and apply such policies to network traffic passing through the firewall.

[0078] In some embodiments, strategies are also generated based on events detected by sensors. For example, in some embodiments, strategies are generated based on events detected by sensors, network security objects detected by inspectors, network security threats, network security risks, misconfigurations, exposures, vulnerabilities, and combinations thereof.

[0079] In some embodiments, the workload includes sensors (not shown) deployed thereon. In some embodiments, the sensors are configured to detect runtime data of the workload. In embodiments, the sensors are configured to monitor the workload's data link layer and kernel space, etc. In some embodiments, the sensors are configured to send events detected in the runtime data to an inspection environment.

[0080] At 430, mitigation actions are initiated based on detected cybersecurity risks. In some embodiments, mitigation actions are initiated in response to determining that a workload includes a cybersecurity risk. In other embodiments, mitigation actions are initiated based on remediation actions indicated by the node representing the vulnerability.

[0081] In some embodiments, the check controller is configured to perform another check (e.g., by configuring the checker to check the workload again) in response to initiating a mitigation action and determining that the initiation mitigation action has been completed.

[0082] In some embodiments, the inspector detects in another inspection that the cybersecurity risk no longer exists on the workload. In some embodiments, since no further cybersecurity risk was detected during another inspection, the firewall is configured to remove and ban previously applied network traffic policies associated with the no longer detected cybersecurity threat, etc.

[0083] For example, in one embodiment, the inspection controller is configured to perform inspections (e.g., by configuring an inspector to inspect workloads). The inspector, configured to detect the presence of malware (as a cybersecurity risk), detects malware code objects on the first workload. Therefore, a policy is generated based on the first workload and the detected malware code objects. For example, according to one embodiment, the policy is generated based on identifiers of the first workload, such as Internet Protocol (IP) addresses, Media Access Control (MAC) addresses, names from namespaces, and combinations thereof.

[0084] In some embodiments, the policy is also generated based on protocols such as Transmission Control Protocol / Internet Protocol (TCP / IP), User Datagram Protocol (UDP), Hypertext Transfer Protocol (HTTP), File Transfer Protocol (FTP), Secure Shell Protocol (SSH), and combinations thereof. In embodiments, the firewall is configured to apply network filtering policies (e.g., to block network traffic to specific destinations, such as inbound traffic, outbound traffic, and combinations thereof).

[0085] In some embodiments, remedial actions are initiated in response to the detection of malware. In some embodiments, remedial actions include: configuring workloads to remove malware, sandboxing affected machines from the network, isolating infected resources and combinations thereof on compromised host systems, etc.

[0086] In one embodiment, the inspection controller is configured to initiate another inspection. In some embodiments, when a cybersecurity risk is detected as having been removed (e.g., no cybersecurity risk was detected in a subsequent inspection), the firewall is configured to remove and ban previously applied network traffic policies associated with the no longer detected cybersecurity risk.

[0087] In some embodiments, workloads are inspected to detect one-day vulnerabilities. According to embodiments, a one-day vulnerability (also known as a 1-day exploit or similar vulnerability) is a vulnerability in a software application, operating system, or code object that becomes a known vulnerability. These are typically known but not yet patched because there is insufficient time to analyze and prepare a software path to resolve the issue. In embodiments, the inspector is configured to detect one-day vulnerabilities and generates a policy based on the identifier of the workload containing the one-day vulnerability. In some embodiments, a firewall applies this policy to block incoming traffic to workloads containing one-day vulnerabilities (e.g., traffic from an untrusted network).

[0088] In some embodiments, workloads are inspected for suspicious activity. In these embodiments, suspicious activity corresponds to events, event clusters, etc., detected by sensors deployed on the workload. In some embodiments, sensors, inspectors, and inspection controllers are configured to tag workloads with labels and flags. In these embodiments, firewalls are configured with policies that filter network traffic to tagged and flagged workloads in the computing environment.

[0089] According to another embodiment, the workload is checked for SSH (Secure Shell) protocol network security risks. Network security risks associated with the SSH protocol include, for example, weak passwords, exposed certificates, and combinations thereof. In this embodiment, the firewall is configured to block network traffic transmitted to the workload via the SSH protocol after a predetermined number of access attempts based on detected network security risks. This is advantageous, for example, in preventing brute-force attacks on the workload.

[0090] Figure 5 This is an example schematic diagram of an inspection controller 124 according to an embodiment. The inspection controller 124 includes processing circuitry 510 coupled to a memory 520, a storage device 530, and a network interface 540. In this embodiment, components of the inspection controller 124 may be communicatively connected via a bus 550.

[0091] The processing circuitry 510 can be implemented as one or more hardware logic components and circuits. For example, but not limited to, exemplary types of hardware logic components that can be used include field programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip systems (SOCs), graphics processing units (GPUs), tensor processing units (TPUs), general-purpose microprocessors, microcontrollers, and digital signal processors (DSPs), or any other hardware logic component capable of performing computations or other information operations.

[0092] Memory 520 may be volatile (e.g., random access memory, etc.), non-volatile (e.g., read-only memory, flash memory, etc.), or a combination thereof. In embodiments, memory 520 is on-chip memory, off-chip memory, or a combination thereof. In some embodiments, memory 520 is a note-taking memory for processing circuitry 510.

[0093] In one configuration, software for implementing one or more embodiments disclosed herein may be stored in storage device 530, memory 520, and combinations thereof. Software should be interpreted broadly to mean any type of instruction, whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise. Instructions may include code (e.g., source code format, binary code format, executable code format, or any other suitable code format). When executed by processing circuitry 510, the instructions cause processing circuitry 510 to perform the various processes described herein.

[0094] Storage device 530 is a magnetic storage device, an optical storage device, a solid-state storage device, or a combination thereof, and according to embodiments, it is implemented as: flash memory, hard disk drive or other memory technology, or any other medium that can be used to store desired information.

[0095] Network interface 540 is configured to provide communication to inspection controller 124 with, for example, inspector 126, security database 122, and firewall 118.

[0096] It should be understood that the embodiments described herein are not limited to those described herein. Figure 5 The specific architecture shown is applicable, and other architectures may be used equivalently without departing from the scope of the disclosed embodiments.

[0097] Furthermore, in some embodiments, firewall 118, inspector 126, and security database 122, etc., can be used Figure 5 The architecture shown is used for implementation. In other embodiments, other architectures may be used equivalently without departing from the scope of the disclosed embodiments.

[0098] The various embodiments disclosed herein can be implemented as hardware, firmware, software, or any combination thereof. Furthermore, the software is preferably implemented as an application program tangibly embodied in a program storage unit or computer-readable medium composed of components or combinations of devices. The application program can be uploaded to and executed by a machine including any suitable architecture. Preferably, the machine is implemented on a computer platform having hardware such as one or more central processing units (“CPUs”), memory, and input / output interfaces. The computer platform may also include an operating system and microinstruction code. The various processes and functions described herein may be part of the microinstruction code or part of an application program, or any combination thereof, which can be executed by the CPU, whether or not such a computer or processor is explicitly shown. Furthermore, various other peripheral units can be connected to the computer platform, such as additional data storage units and printing units. Additionally, a non-transitory computer-readable medium is any computer-readable medium other than a transient propagation signal.

[0099] All examples and conditional language listed herein are intended for pedagogical purposes to aid the reader in understanding the principles of the disclosed embodiments and the concepts contributed by the inventors to the field, and are to be construed as not being limited to such specifically enumerated examples and conditions. Furthermore, all statements regarding the principles, aspects, and embodiments of the disclosed embodiments listed herein, together with their specific examples, are intended to cover both their structural and functional equivalents. Moreover, it is intended that such equivalents include both currently known equivalents and those developed in the future, i.e., any developed element that performs the same function regardless of its structure.

[0100] It should be understood that any reference to elements in this document using names such as "first," "second," etc., does not generally limit the number or order of these elements. Rather, these names are generally used herein as a convenient way to distinguish between two or more elements or instances of elements. Thus, references to first and second elements do not imply that only two elements can be used there, or that the first element must somehow precede the second element. Furthermore, unless otherwise stated, a group of elements includes one or more elements.

[0101] As used herein, the phrase “at least one of…” followed by a series of items means that any one of the listed items may be used alone, or any combination of two or more of the listed items may be used. For example, if a system is described as including “at least one of A, B, and C”, then the system may include: only A; only B; only C; 2 A; 2 B; 2 C; 3 A; a combination of A and B; a combination of B and C; a combination of A and C; a combination of A, B, and C; a combination of 2 A and C; a combination of A, 3 B, and 2 C; and so on.

Claims

1. A method for providing dynamic network traffic policies, comprising: The workload is inspected for network security objects that indicate network security risks, wherein the workload is deployed in a cloud computing environment with a firewall that connects to an external network; Detect the network security risks on the workload based on the network security object; Generate policies for the firewall based on the aforementioned network security risks; and Configure the firewall to use the policies generated by the application.

2. The method according to claim 1, further comprising: Detect a second network security object on the workload; as well as The network security risk detected based on the network security object and the second network security object is a toxic combination.

3. The method according to claim 2, wherein, The cybersecurity risk is any one of the following: misconfiguration, vulnerability, exposure, attack path, reachability path, or a combination thereof.

4. The method according to claim 1, further comprising: The severity of the cybersecurity risk is determined based on the detected cybersecurity objects; as well as The strategy is generated based on the determined severity.

5. The method according to claim 1, further comprising: Detect the raw disk associated with the workload; Clone the original disk to a checkable disk; as well as The inspectable disk is examined for the network security object.

6. The method according to claim 1, further comprising: In response to determining that the network security risk is of type 1, the firewall is configured to block network traffic to the workload.

7. The method according to claim 1, further comprising: In response to determining that the network security object is of the first type, the firewall is configured to block network traffic to the workload.

8. The method according to claim 1, further comprising: Based on the generated policy, the firewall is configured to block the first type of network traffic to the workload; as well as Based on the generated policy, the firewall is configured to allow the second type of network traffic to the workload.

9. The method according to claim 1, further comprising: Mitigation actions are initiated based on detected cybersecurity risks.

10. The method of claim 9, further comprising: In response to the detection that the network security risk has been removed from the workload, the firewall is configured to remove the policy.

11. A system for providing dynamic network traffic policies, comprising: Processing circuitry; A memory containing instructions that, when executed by the processing circuitry, configure the system to: The workload is inspected for network security objects that indicate network security risks, wherein the workload is deployed in a cloud computing environment with a firewall that connects to an external network; Detect the network security risks on the workload based on the network security object; Generate policies for the firewall based on the aforementioned network security risks; and Configure the firewall to use the policies generated by the application.

12. The system according to claim 11, wherein, The memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: Detecting a second network security object on the workload; and The network security risk detected based on the network security object and the second network security object is a toxic combination.

13. The system according to claim 12, wherein, The cybersecurity risk is any one of the following: misconfiguration, vulnerability, exposure, attack path, reachability path, or a combination thereof.

14. The system according to claim 11, wherein, The memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: The severity of the cybersecurity risk is determined based on the detected cybersecurity objects; and The strategy is generated based on the determined severity.

15. The system according to claim 11, wherein, The memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: Detect the raw disk associated with the workload; Cloning the original disk to a checkable disk; and The inspectable disk is examined for the network security object.

16. The system according to claim 11, wherein, The memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: In response to determining that the network security risk is of type 1, the firewall is configured to block network traffic to the workload.

17. The system according to claim 11, wherein, The memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: In response to determining that the network security object is of the first type, the firewall is configured to block network traffic to the workload.

18. The system according to claim 11, wherein, The memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: Based on the generated policy, the firewall is configured to block the first type of network traffic to the workload; as well as Based on the generated policy, the firewall is configured to allow a second type of network traffic to the workload.

19. The system according to claim 11, wherein, The memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: Mitigation actions are initiated based on detected cybersecurity risks.

20. The system according to claim 19, wherein, The memory contains further instructions, which, when executed by the processing circuitry, further configure the system to: In response to the detection that the network security risk has been removed from the workload, the firewall is configured to remove the policy.

21. A non-transitory computer-readable medium storing a set of instructions for providing dynamic network traffic policies, the set of instructions comprising: One or more instructions, when executed by one or more processors of the device, cause the device to perform: The workload is inspected for network security objects that indicate network security risks, wherein the workload is deployed in a cloud computing environment with a firewall that connects to an external network; Detecting network security risks on the workload based on the network security object; and Generate policies for the firewall based on the aforementioned network security risks; and Configure the firewall to use the policies generated by the application.