Network Access Policy Management System
A network security system uses a universal syntax to map and translate connectivity policies, addressing inefficiencies in managing complex network environments by simplifying the configuration of vendor-specific security devices.
Patent Information
- Application Number
- JP2023512270
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-04-30
- Filing Date
- 2021-05-26
- Publication Date
- 2025-10-22
- Estimated Expiration
- 2041-05-26
AI Technical Summary
Managing connectivity policies in complex network environments is inefficient due to the need for manual configuration of vendor-specific security devices and unclear device configurations, especially as networks become more intricate.
A network security system generates a network topology mapping using a universal syntax to represent connectivity policies, identifying security domains and paths, and translates these policies into device-specific representations to configure security devices.
This approach enables efficient and unified management of connectivity policies across diverse security devices, simplifying the configuration process and ensuring clear implementation in complex network environments.
Smart Images

Figure 0007758729000001 
Figure 0007758729000002 
Figure 0007758729000003
Abstract
Description
[Technical Field]
[0001] The present invention relates generally to computer networking, and more particularly to managing connection policies in a network environment. [Background technology]
[0002]
[0003] Computer network environments, such as enterprise network environments, are configured to connect various network environment entities (e.g., computing devices, virtual machines, subnetworks, etc.) according to one or more connectivity policies. Implementing connectivity policies in a network environment generally involves individually configuring various security devices, such as firewalls, along routes between network entities to allow or prevent connections. Different security devices within a network environment may have device-specific protocols for implementing connectivity policies. For example, security devices manufactured by different vendors may use vendor-specific syntax to express and implement connectivity policies. Thus, manually configuring individual security devices to satisfy the network environment's network connectivity policies is a demanding and inefficient process. Furthermore, especially as network environments become more complex, it may not be clear to network administrators what security devices can or should be configured to implement one or more connectivity policies. Therefore, an improved system for managing connectivity policies in a network environment is needed. Summary of the Invention
[0003] A method, system, and computer-readable storage medium are disclosed for universal management of connectivity policies for a network environment. A network security system generates a network topology mapping of the network environment to implement the connectivity policies for the network environment. The network security system can generate the mapping of the network topology of the network environment and implement the connectivity policies using the network topology mapping. The network topology mapping represents the network environment as security domains, security devices, and a set of domain paths between security domains via one or more security devices. The network security system generates a universal representation of the connectivity policies for the network environment using a universal syntax (e.g., a language for expressing connectivity policies). Using the network topology mapping, the security system identifies network paths between security domains to implement the connectivity policies. To implement the connectivity policies in the network environment, the network security system configures the security devices along the identified domain paths by translating some or all of the universal representation of the connectivity policies into device-specific representations in the native syntax of the security devices.
[0004] In one embodiment, a network security system receives a connectivity policy for a network environment including a plurality of network addresses, the connectivity policy corresponding to a source network address and a destination network address. The network security system generates a universal representation of the network connectivity policy in the security system's universal syntax. Using the network topology mapping, the network security system identifies security devices in the network environment along a network domain path between a security domain including the source network address and a security domain including the destination network address. From the universal representation, the security system generates a native representation of the network connectivity policy in a native syntax associated with the identified security devices. The network security system uses the generated native representation to configure the security devices to enable communication between the source network address and the destination network address.
[0005] In one embodiment, the network security system identifies routing information for one or more security devices that describes a set of routes to one or more network addresses that the one or more security devices are configured to use. Using the routing information, the network security system determines multiple security regions of the network environment, each including one or more network addresses. Furthermore, using the routing information, the network security system determines a set of possible region paths for the network environment, each connecting one or more network addresses of a pair of security regions of the multiple security regions via one or more security devices. The set of possible region paths includes an active region path, which includes one or more security devices that are authorized to enable communication between one or more network addresses connected by the active region path. The set of region paths also includes an alternate region path, which includes one or more security devices that are authorized to enable communication between one or more network addresses connected by the alternate region path if the active region path is unavailable. Using the set of possible region paths, the network security system generates a network topology mapping for the network environment.
[0006] In one embodiment, a client device receives a network topology mapping of a network environment from a network security system. The network topology mapping includes security realms connected by realm paths through one or more security devices. The client device receives a connection policy for the network environment based on interaction between the client device and a user, the connection policy specifying a source network address within a first security realm of a plurality of security realms and a destination network address within a second security realm of a second security realm of the plurality of security realms. The client device provides the connection policy to the network security system. The client device receives a notification from the network security system indicating that one or more security devices along one or more realm paths from the source network address and the destination network address have been configured based on the connection policy. [Brief explanation of the drawings]
[0007] [Figure 1] FIG. 1 illustrates a computing environment for managing network environment connection policies, according to one embodiment. [Figure 2] 1 is a block diagram illustrating a network security system, according to one embodiment. [Figure 3] FIG. 2 is a block diagram illustrating a client system, according to one embodiment. [Figure 4A] FIG. 2 illustrates a first stage of generating a network topology mapping for a network environment, according to one embodiment. [Figure 4B] FIG. 2 illustrates a second stage of generating a network topology mapping for a network environment, according to one embodiment. [Figure 4C] FIG. 10 illustrates a third stage of generating a network topology mapping for a network environment, according to one embodiment. [Figure 4D]FIG. 10 illustrates a fourth stage of generating a network topology mapping for a network environment, according to one embodiment. [Figure 4E] FIG. 10 illustrates a fifth stage of generating a network topology mapping for a network environment, according to one embodiment. [Figure 5] 1 is a flowchart illustrating a method for implementing network connection policies using universal and native representations of connection policies, according to one embodiment. [Figure 6] 1 is a flowchart illustrating a method for generating a network topology mapping of a network environment, according to one embodiment. [Figure 7] 1 is a flowchart illustrating a method for generating a network topology mapping of a network environment, according to one embodiment. [Figure 8] FIG. 1 is a block diagram illustrating a computer system, according to one embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0008] Reference will now be made to several embodiments, examples of which are illustrated in the accompanying figures. It should be noted that, wherever practicable, like or similar reference numerals will be used in the figures to indicate like or similar functionality. Also, where like elements are identified by a reference numeral followed by a letter, reference to the numeral alone in the following description may refer to all such elements, any one such element, or any combination of such elements. Those skilled in the art will readily recognize from the following description that alternative embodiments of structures and methods may be employed without departing from the principles described.
[0009] System environment 1 illustrates one embodiment of a computing environment 100 for managing network environment connection policies. In the illustrated embodiment, computing environment 100 includes a network security system 110, a network environment 120, a client system 130, and a network 140. In other embodiments, computing environment 100 may include different or additional elements. Furthermore, functionality may be distributed among elements in ways different from that described.
[0010] The network security system 110 manages connection policies for the network environment 120. The network security system 110 may include one or more computing devices configured to receive connection policies for the network environment 120 from the client system 130 via the network 140. In an embodiment, the network security system 110 generates a mapping of the network topology of the network environment 120 (i.e., a network topology mapping) and uses the network topology mapping to implement the connection policies received from the client system 130 within the network environment 120. Generating and using the network topology mapping for the network environment 120 is described in more detail below with reference to FIGS. 2 and 4A-E. The network security system 110 may receive or obtain connection policies from the client system 130, a third-party system, or any other system authorized to provide connection policies to the network environment 120. The connection policies may be provided by a human administrator (e.g., via a user interface or other connection policy authorization system) or may be generated automatically based on a process in the network environment 120 (e.g., a new network entity, such as a virtual machine, is added to the network environment 120). Additionally, network security system 110 may implement connection policies that depend on external data (e.g., provided by client system 130 or a third-party system), in which case network security system 110 may request or otherwise obtain the relevant data to implement and update the external data-dependent connection policies. For example, connection policies for network environment 120 may depend on blacklists or whitelists of networks or subnetworks provided by a third party, such as legal authority for certain areas or types of network communications (e.g., the Office of Foreign Assets Control).
[0011] Generally, a network connectivity policy specifies which network entities (e.g., computing devices, virtual machines, applications, etc.) of a network environment (e.g., network environment 120) are allowed to communicate with other network entities. Network entities are identified within network environment 120 based on various identifiers (i.e., network addresses), such as IP addresses or port numbers. As an example, a connectivity policy may specify which IP addresses or subnetworks (e.g., subnetworks within network environment 120) can communicate with other IP addresses or subnetworks, which application ports can communicate with other application ports, and which communication protocols, or any combination thereof, can communicate with. Network security system 110 expresses connectivity policies using a universal syntax (i.e., a universal representation) for network environment 120. The universal syntax describes connectivity policies in a form that applies to all of the elements of network environment 120. Given a connectivity policy expressed in the universal syntax, network security system 110 implements the connectivity policy in the network environment by identifying one or more appropriate security devices 126 and configuring the identified security devices using the universal connectivity policy. In embodiments, network security system 110 configures security device 126 by translating some or all of the universal connectivity policies into the native connectivity policy syntax (i.e., native representation) of security device 126. The native syntax describes the connectivity policies in a format used to implement the connectivity policies on an individual security device 126. The implementation of connectivity policies on security device 126 is described in more detail below with reference to Figures 2-3, 5, and 7. While Figure 1 shows a single element, network security system 110 may include one or more computing devices, such as a server cluster, and the computing devices may be located in one or more physical locations.A network security system may also represent one or more virtual computing instances running using one or more computers in a data center, such as a virtual server farm.
[0012] Network environment 120 is a region of a computer network that connects a set of computing devices over a local or wide area network based on one or more connection policies. Network environment 120 includes security domain 124 and one or more security devices 126. One or more connection policies of network environment 120 specify communication rules for network entities of network environment 120. For example, a connection policy may specify that a computing device with IP address A can or cannot communicate with a computing device with IP address B. In some embodiments, network environment 120 corresponds to a network for an organization, such as an enterprise network. Network environment 120 may be further configured to operate using any combination of the systems and processes described below with respect to network 140.
[0013] A security realm 124 is a logical sub-realm of network environment 120 that includes network entities (e.g., computing devices corresponding to respective IP addresses) whose communications can communicate without passing through one of security devices 126. Thus, security realms 124 are bounded by security devices 126, and communications between network entities in different security realms 124 are transmitted over a network realm path through one or more of security devices 126. In some cases, multiple security realms of a security realm 124 may include the same network entity, such as two security realms 124 that include computing devices corresponding to the same IP address. In some embodiments, one or more entities in a security realm 124 are connected to an external network entity (e.g., a third-party application or system).
[0014] Security device 126 monitors and controls network traffic within network environment 120 according to one or more connection policies. Security device 126 may be any type of device that filters network traffic, such as a packet filter firewall, a circuit-level gateway, a stateful inspection firewall, an application-level gateway / proxy server firewall, or a next-generation firewall. In an embodiment, security device 126 filters network communications between network entities corresponding to different security domains 124 or between entities outside network environment 120. Security device 126 may express connection policies using a native syntax (i.e., native connection policies). The native syntax of a given security device 126 may depend on the particular type of security device or the manufacturer of the security device (i.e., security device vendor). Additionally, security device 126 may include security devices that use different native syntaxes to express native connection policies. Security device 126 has one or more device interfaces for receiving incoming data from network entities and routing outgoing data to network entities.
[0015] Client system 130 is a computing system configured to provide connection policies to network security system 110 for network environment 120. Client system 130 is comprised of one or more computing devices that communicate with network security system 110 over network 140. Exemplary computing devices include a server computer, a laptop computer, a desktop computer, and a mobile device (e.g., a phone or tablet). While client system 130 is depicted as a single element in FIG. 1 , one or more computing devices of client system 130 may operate independently of each other or may provide connection policies to network security system 110 independently of each other. In an embodiment, client system 130 receives or obtains information describing one or more connection policies from client system 130. In particular, the connection policies may be generated and provided by a user of client system 130 (e.g., an administrator of network environment 120) via a user interface (e.g., displayed by a computing device) or a connection policy generation system (e.g., a version-controlled connection policy system). Client system 130 provides the received information to network security system 110. The received information may describe the network connection policy using the universal syntax of network security system 110, or may alternatively describe the connection policy using another format. In the same or a different embodiment, client system 130 receives information from network security system 110 describing network environment 120, such as information contained in network topology, network traffic reports, security alerts, or other network security information. In an alternative embodiment to that shown in FIG. 1, client system 130 may be directly integrated with network security system 110.
[0016] Network 140 may include any combination of local area and / or wide area networks using both wired and / or wireless communication systems. In some embodiments, network 140 includes network environment 120. Network 140 may employ various communication technologies and / or protocols. For example, network 140 may utilize communication technologies such as Ethernet, 802.11, 3G, 4G, Digital Subscriber Line (DSL), etc. Network 140 may also employ network protocols for communicating information. Some exemplary protocols may include Internet Protocol Suite (TCP / IP), Ethernet / Industrial Protocol (EtherNet / IP), Hypertext Transport Protocol Secure (HTTPS), Representational State Transfer (REST), Simple Mail Transfer Protocol (SMTP), File Transfer Protocol (FTP), etc. Data exchanged over network 140 may be represented using any suitable format, such as Hypertext Markup Language (HTML), JavaScript Object Notation (JSON), or Extensible Markup Language (XML). In some embodiments, all or a portion of the communication links of network 140 may be encrypted using any suitable technique or techniques.
[0017] 2 is a block diagram embodiment illustrating network security system 110. In the embodiment shown, network security system 110 includes network topology module 210, connection policy implementation module 220, network topology store 230, and connection policy store 240. In other embodiments, network security system 110 may include different or additional elements. Furthermore, functionality may be distributed among elements in ways different from those described.
[0018] Network topology module 210 generates and maintains a network topology mapping for network environment 120. In an embodiment, network topology module 210 performs an initial discovery process to generate the network topology mapping by discovering security domains 124, security devices 126, and network domain routes of network environment 120. As part of the discovery process, network topology module 210 may analyze routing information provided by security devices 126 (e.g., routing tables of security devices 126) to infer the structure of network environment 120. The initial process of generating the network topology mapping is described in more detail below with reference to FIGS. 4A-4E. Network topology module 210 stores the network topology mapping in network topology store 230. In particular, the network topology mapping includes, but is not limited to, information describing security domains 124 (e.g., network addresses of computing devices within each security domain), security devices 126 (e.g., characteristics of security devices 126 and their connections to security domains 124), and possible paths of communication between security domains 124 via one or more security devices 126 (i.e., domain routes). In some embodiments, the network topology module 210 generates and maintains multiple network topology mappings corresponding to multiple network environments.
[0019] The network topology module 210 can further monitor the network environment 120 for changes to elements of the network environment 120 and update the stored network topology mapping accordingly. In particular, the network topology module 210 can periodically perform some or all of the detection process to identify changes in the network environment 120. For example, the network topology module 210 may regenerate some or all of the network topology mapping periodically (e.g., hourly) or based on information provided by network entities to the network environment 120 (e.g., change logs provided by the security devices 126). In this case, the network topology module 210 compares the regenerated network topology mapping with previously generated network topology mappings stored in the network topology store 230 and updates the stored mappings if differences are identified. Additionally or alternatively, the network topology module 210 can receive information describing changes to the network environment 120 (e.g., from the client systems 130) and update the stored network topology mappings based on the received information. For example, an administrator of network environment 120 may submit a change to the network topology, such as adding a new virtual machine, subnetwork, or other network entity to network environment 120. In one embodiment, network topology module 210 automatically updates the network topology mapping upon detecting the change and then requests the administrator (e.g., at client system 130) to review the changes to determine whether there are any discrepancies. Network topology module 210 may provide information describing the updates to the network topology mapping to connectivity policy implementation module 220 to implement any changes based on the updates, as described below with reference to connectivity policy implementation module 220. Network topology module 210 may further provide information contained in the network topology mapping to client system 130.
[0020] In some embodiments, the network topology mapping includes additional information describing the network environment 120. In one embodiment, the network topology mapping includes network address translation (NAT) rules for the network environment 120. In particular, the network topology mapping associates a particular NAT rule with a device (e.g., a router or security device) along a domain path that translates addresses from one address space to another according to the NAT rule. In the same or a different embodiment, the network topology mapping includes information describing the connections of the network environment 120 to external network entities (e.g., third-party systems or applications, the Internet, etc.). Further, in the same or a different embodiment, the network topology mapping may include tags (e.g., labels) assigned to elements of the network topology mapping (e.g., security domains 124, security devices 126, domain paths, NAT rules, external entities or connections, etc.). Tags are specified by a user of the client system 130 (e.g., an administrator of the network environment 120) and specify user preferences for network traffic logic within the network environment 120. For example, the tag may specify the trust level of the element, the type of element (e.g., external, Internet, etc.), the location of the element within the network environment 120, and any other information that can be used to convey user preferences for the network traffic logic.
[0021] In some embodiments, the network topology mapping generated by the network topology module 210 specifies various types of area routes within the network environment 120. In particular, during the initial process of generating the network topology mapping, the network topology module 210 may identify all possible area routes between the security areas 124 of the network environment 120 (e.g., according to the routing information of the security devices 126). After or during the generation of the network topology mapping, an administrator of the network environment 120 may specify (e.g., via the client system 130) whether an identified area route is permitted to enable communication between the network addresses connected by the area route. For example, the administrator may indicate whether the area route is permitted to be used for communication between security areas (i.e., an active area route), permitted to be used as an alternative when one or more equivalent active area routes are unavailable (i.e., an alternate area route), or not permitted to be used (i.e., a denied area route). The network security system 110 may use the area route designation (e.g., active, alternate, or denied) to determine how the security devices on the area route should be managed or otherwise configured. For example, network security system 110 may configure security device 126 to implement a connectivity policy for one or more active or alternate routes that include security device 126. Similarly, network security system 110 may not take any action to configure security device 126 for rejected routes that include security device 126. Configuration of security device 126 based on the specification of a realm route may be performed by connectivity policy implementation module 220, as described below.
[0022] The connection policy implementation module 220 manages connection policies for the network environment 120. In an embodiment, the connection policy implementation module 220 receives a connection policy from the client system 130 or another connection policy provider (e.g., a third-party system) and configures the network environment 120 to implement the connection policy. The connection policy implementation module 220 can implement any number of connection policies within the network environment 120. The connection policy implementation module 220 represents the connection policy using a universal syntax, as described above with reference to the network security system 110. In some cases, the connection policy is provided to the connection policy implementation module 220 in the universal syntax, and in other cases, the connection policy implementation module 220 translates the connection policy from a client-provided format (i.e., the client connection policy) to the universal syntax. The client connection policy is described in more detail below with reference to FIG. 3. Based on the universal representation of the connection policy, the connection policy implementation module 220 uses a stored network topology mapping to identify one or more network region paths associated with the connection policy. For example, the connection policy implementation module 220 may identify one or more active or alternative realm paths connecting a pair of network addresses (e.g., a source address and a destination address) that correspond to the universal expression of the connection policy. The connection policy implementation module 220 further implements the connection policy by configuring security devices 126 on the identified network realm paths in accordance with the connection policy. For example, the connection policy may specify that a first IP address in security realm A must be able to communicate with a second IP address in security realm B. In this case, the connection policy implementation module 220 can identify one or more network realm paths between security realms A and B and configure security devices 126 on the one or more network realm paths to enable communication between the first IP address and the second IP address.The connectivity policy implementation module 220 configures a particular security device 126 along a network region path by translating a universal connectivity policy into the native connectivity policy of the particular security device 126. The connectivity policy implementation module 220 configures the particular security device 126 using the native connectivity policy. For example, the connectivity policy implementation module 220 may provide the native connectivity policy to the particular security device 126 via the network environment 120. The connectivity policy implementation module 220 further stores one or more representations of the received connectivity policy (e.g., a client policy representation, a universal policy representation, one or more native policy representations, etc.) in the connectivity policy store 240. In some embodiments, the connectivity policy implementation module 220 manages connectivity policies for multiple network environments (e.g., using multiple corresponding network topology mappings stored in the network topology store 230).
[0023] In some embodiments, the connection policy implementation module 220 uses a network topology mapping to translate the received client representation of the connection policy into a universal representation. In particular, the connection policy implementation module 220 may identify network addresses of network entities associated with the client representation of the connection policy (e.g., associated network endpoints), such as subnetworks, computing devices, IP addresses, external connections, application ports, or other network entities. For example, the connection policy implementation module 220 may generate the universal representation of the connection policy (e.g., a connection policy file) by retrieving information from the network topology mapping in the network topology store 230 or by communicating with the client system 130 or a third-party system. As an example, the client representation of the connection policy may specify that a particular group of employees in an organization should be able to connect to a particular server through a particular Transmission Control Protocol (TCP) port. In this case, the connection policy implementation module 220 may use the network topology mapping to identify all network entities associated with the employee group, the protocols used to connect the network entities, the network domain paths used to connect the network entities, and the security devices 126 on the identified domain paths. As another example, the client representation of the connection policy may reference all subnetworks blocked by a third-party system (e.g., a legal agency), in which case the connection policy implementation module 220 may obtain the blocked subnetworks and their internal network entities and use the obtained information to generate a universal connection policy. As yet another example, the client representation of the connection policy may specify a connection between a host name and an IP address, in which case the connection policy implementation module 220 may resolve the host name to an IP address by querying the Domain Name System (DNS) of the network environment 120.
[0024] In some embodiments, connectivity policy implementation module 220 identifies the native syntax of security device 126 and translates the universal representation based on information received or otherwise obtained from security device 126, such as security device type (e.g., firewall device manufacturer) and version (e.g., specific firewall device product). In the same or a different embodiment, connectivity policy implementation module 220 can perform the translation based on information contained in a domain topology mapping or otherwise obtained information indicating whether and how a security device 126 upstream of the associated security device 126 on the domain path has modified connectivity policies, such as adjusting IP address or protocol information (e.g., based on NAT rules).
[0025] In some embodiments, the connectivity policy implementation module 220 receives information describing updates to the implemented connectivity policy. For example, an administrator of the client system 130 may add a new rule to the implemented connectivity policy, remove an existing rule from the implemented connectivity policy, or delete the implemented connectivity policy. In these cases, the connectivity policy implementation module 220 may reconfigure one or more of the security devices 126 according to the connectivity policy updates. In particular, the connectivity policy implementation module 220 may update the universal representation of the connectivity policy based on the received information. Furthermore, the connectivity policy implementation module 220 may use the updated universal connectivity policy to update the corresponding native representation of the connectivity policy of one or more security devices 126 and may use the updated native representation to reconfigure the corresponding security devices 126.
[0026] In the same or a different embodiment, the connectivity policy implementation module 220 receives information describing updates to the network topology mapping from the network topology module 210, as described above. In this case, the connectivity policy implementation module 220 may similarly reconfigure one or more of the security devices 126 according to the updates to the network topology mapping. As described above for connectivity policy updates, the connectivity policy implementation module 220 may update the universal and native representations of the connectivity policy based on the updates to the network topology mapping and reconfigure the associated security devices 126 using the updated native representations. In one embodiment, the connectivity policy implementation module 220 configures the security devices 126 included in an alternate region path based on the received update information. For example, the connectivity policy implementation module 220 may configure one or more security devices 126 in an alternate region path to accommodate the unavailability of an active region path, such as by rerouting network traffic via the alternate region path if the active region fails. In some cases, the connectivity policies implemented by the connectivity policy implementation module 220 may reference elements of the network topology mapping stored in the network topology store 230 (e.g., network addresses, security devices, security regions, region paths, etc.). If the connection policy module receives an update to a referenced element from the network topology module 210 (e.g., if a referenced IP address or application port is removed from the network environment 120), the connection policy implementation module 220 can responsively reconfigure one or more security devices 126 to re-implement the connection policy that references the updated element.As described above, to reconfigure one or more security devices 126 based on information describing connectivity policy updates, the connectivity policy implementation module 220 may remove individual connectivity policy rules or entire connectivity policies from one or more security devices 126 and additionally or alternatively add connectivity policy rules or entire connectivity policies to one or more of the same or different security devices 126.
[0027] In some embodiments, the connectivity policy implementation module 220 takes into account the NAT rules of the network environment 120 when converting the universal representation of the connectivity policy to one or more native representations. For example, the connectivity policy implementation module 220 may apply the NAT rules associated with the security device 126 when generating the native representation of the connectivity policy to configure the security device 126. In addition, the connectivity policy implementation module 220 may use the NAT rules associated with an upstream security device on a given network region path to generate native connectivity policies for one or more downstream security devices on the same network region path. The connectivity policy implementation module 220 may use the NAT rules to generate native representations of the connectivity policy that vary depending on the particular security device (e.g., security device manufacturer) or whether the security device is downstream from the security device associated with the NAT rule on the relevant network region path.
[0028] In some embodiments, the connection policy implementation module 220 provides information describing the implementation of the network connection policy to the client system 130. In particular, the connection policy implementation module 220 may provide information to the client system 130 indicating that the connection policy provided by the client system 130 to the connection policy implementation module 220 was successfully implemented. Additionally, the connection policy implementation module 220 may provide information describing changes to the network topology of the network environment 120 or adjustments to the implementation of the connection policy (e.g., changes in the area routes used, the security devices 126 used, etc.).
[0029] In some embodiments, the connection policy implementation module 220 analyzes the connection policies currently implemented for the network environment 120 in order to implement a newly received connection policy. For example, the connection policy implementation module 220 may receive a connection policy (e.g., from the client system 130) that requests a connection between two network entities via a region route designated as a denied region route in the network topology mapping. In this case, the connection policy module 220 may notify the provider of the connection policy or an administrator of the network environment 120 that the connection policy cannot be implemented. Accordingly, the connection policy request may be reviewed, and the denied region route may be redesignated as an active region route, or the connection policy may not be allowed.
[0030] In some embodiments, the connection policy implementation module 220 combines connection policies received or otherwise obtained from the same or different sources (i.e., connection policy channels) to configure the security device 126. For example, the client system 130 may provide the connection policy to the connection policy implementation module 220 submitted by an administrator via a user interface or provided via an API. Additionally, the connection policy implementation module 220 may receive or obtain a connection policy from the client system 130 or another system via other sources or information informing the connection policy. In these cases, the connection policy implementation module 220 may combine connection policies received from multiple channels to configure the network environment 120 to implement the connection policy. For example, the connection policy implementation module 220 may generate a single universal representation for multiple connection policies received from the same or different connection policy channels. In the same or different embodiments, the connection policy implementation module 220 may attach one or more mandated connection policies to each universal representation of a received connection policy. For example, a legal entity may mandate by law that the network environment 120 cannot communicate with certain network entities. In this case, the connection policy implementation module 220 can add one or more corresponding mandated connection policies to the received universal representation of the connection policy to ensure that these mandated requirements are met.
[0031] 3 is a block diagram embodiment illustrating client system 130. In the embodiment shown, client system 130 includes a network topology analysis module 310 and a client connection policy module 320. In other embodiments, network security system 110 may include different or additional elements. Furthermore, functionality may be distributed among elements in ways different from those described.
[0032] The network topology analysis module 310 receives and processes information describing the network topology mapping of the network environment 120. In embodiments, the network topology analysis module 310 provides an interface for display by the computing device of the client system 130, including elements of the network topology mapping, such as a visualization of the network topology mapping. In particular, the network topology analysis module 310 may provide an interface that identifies the network regions 124, network devices 126, network region routes, or other elements of the network environment 120 included in the network topology mapping. In one embodiment, the interface provided by the network topology analysis module 310 displays the region routes of the network environment 120 included in the network topology and may further identify whether the region routes are active, alternate, or rejected. The interface provided for display may further enable a user of the computing device to interact with various other elements of the network topology mapping to configure the network environment 120 or otherwise process the information included in the network topology mapping. Additionally, the network topology analysis module 310 may allow a user of a computing device to submit tags for elements of the network topology mapping to the network security system 110 (e.g., for storage with the network topology mapping in the network topology store 230). By providing tags, the user of the computing device can change how the network security system structures the network topology mapping and implements connectivity policies within the network environment 120. For example, if a network entity is included in multiple security domains 124, the user may submit a metadata tag for one of the multiple security domains 124 to restrict the security domain used for the network entity and, consequently, the domain path used to implement the network entity's connectivity policies.In the above case, the network topology analysis module 310 communicates with the network security system 110 to perform any configuration or reconfiguration of the network environment 120 .
[0033] In some embodiments, network topology analysis module 310 receives notifications from network security system 110 describing changes to network environment 120. For example, a system administrator or other individual may install a new security device 126 or add a new computing device to one or more security domains 124. In this case, network topology analysis module 310 may receive a notification describing the new security device 126 or the new computing device. In the same or a different embodiment, network topology analysis module 310 provides the received notifications to client connectivity policy module 320 to identify any appropriate adjustments to one or more current connectivity policies based on the notifications, as described in more detail below.
[0034] The client connection policy module 320 communicates with the network security system 110 to implement the client representation of the connection policy. In embodiments, the client connection policy module 320 receives input from a user of the client system 130 specifying one or more parameters of the connection policy (e.g., which network entities in the network environment 120 are allowed to connect) and provides the client representation of the connection policy to the network security system 110. The connection policy received by the client connection policy module 320 may further include tags for elements of the network topology mapping (e.g., as provided by the network topology analysis module 310). The client connection policy module 320 may provide an interface for submitting the connection policy or for displaying the current connection policy of the network environment 120, such as a user interface or application programming interface (API) for display by the client system 130. For example, the client connection policy module 320 may retrieve the connection policy stored by the network security system 110 in the connection policy store 240. In some embodiments, the client connection policy module 320 facilitates both the implementation of new connection policies and the updating of existing connection policies in the network environment 120. The client connection policy module 320 may communicate with the network security system using a generic application programming interface (API) associated with the network security system 110 .
[0035] In some embodiments, client system 130 displays one or more interfaces that include information describing elements of the network topology mapping (e.g., provided by network topology analysis module 310, as described above) and enables a user of client system 130 to submit a connection policy (e.g., using client connection policy module 320, as described above). For example, the one or more interfaces may enable a user of client system 130 to specify and submit a connection policy for implementation within network environment 120 by interacting with the information included in the network topology mapping.
[0036] 4A-4E illustrate an embodiment of a process for discovering elements of network environment 120 and generating network topology mapping 400 that includes several stages. In the illustrated embodiment, the discovery process for generating the network topology mapping is performed as a sequential series of stages. Broadly speaking, the stages of the discovery process can be categorized as 1) discovering security domains of network environment 120 based on routes identified by routing information associated with security devices (e.g., security device 126), 2) determining external entities connected to network environment 120, and 3) identifying domain paths for the network topology mapping. While FIGS. 4A-4E illustrate the discovery and generation process as a sequential series of stages for illustrative purposes, in other embodiments, the same or different stages may be performed in other orders or simultaneously.
[0037] In the embodiment shown in FIGS. 4A-4E, the network security system 110 receives information describing the characteristics of the network environment 120, which is used to perform the discovery process shown in FIGS. 4A-4E. For example, the network security system 110 may be provided with information describing the characteristics of the network environment 120 from the client system 130. In particular, the information describing the security device 126 may include the interfaces of the security device (e.g., Ethernet ports on a firewall device) through which data is received and transmitted. The information describing the security device 126 may further include tags assigned to the device or those device interfaces. Additionally, the information describing the characteristics of the network environment 120 may include other information, such as NAT rules or the external connectivity of the network environment 120. In the same or different embodiment as that shown in FIGS. 4A-4E, the network security system 110 communicates with an administrator of the network environment 120 (e.g., via the client system 130) during the discovery process to accurately determine or infer the structure of the network environment 120. For example, the administrator may submit tags of elements discovered during some or all stages of the discovery process to assist the network security system 110 in generating the network topology mapping 400.
[0038] 4A illustrates an embodiment of a first stage of generating a network topology mapping 400 of network environment 120 by network security system 110. In the illustrated embodiment, the first stage includes discovering a set of routes that can be identified from routing information associated with security device 410 to network addresses within security regions accessible via a set of routes. For example, network security system 110 may identify network addresses stored by security device 410 in a network routing table. Network security system 110 can analyze the paths of the set of routes identified from security device 410's routing information through some or all of the security regions traversed by the routes to further infer the structure of network environment 120. As shown, security device 410's routing information identifies a path to network address A.1 via a first interface of device interface 415 and paths to network addresses B.1 and B.2 via a second interface of device interface 415. In the first step, network security system 110 determines that network address A.1 belongs to newly detected security realm A, and that network addresses B.1 and B.2 belong to newly detected security realm B.
[0039] 4B illustrates an embodiment of a second stage of generating network topology mapping 400 for network environment 120 by network security system 110. In the illustrated embodiment, the second stage includes detecting a set of routes identifiable from routing information associated with security device 420 to network addresses within security regions accessible via the set of routes. Similar to security device 110, network security system 110 can analyze the paths of the set of routes identified from security device 420's routing information through some or all of the security regions traversed by the routes to further infer the structure of network environment 120. As shown, security device 420's routing information includes routes to network addresses A.1 and A.2 via a first interface of device interface 425, and a route to network address C.1 via a second interface of device interface 425. During the second stage, network security system 110 determines that network address A.2 belongs to previously detected security region A and that network address C.1 belongs to newly detected security region C. In one embodiment, network security system 110 determines that a new network address (e.g., network address A.2) belongs to a previously discovered security realm (e.g., security realm A) by verifying that a connection exists from the new network address to another security device (e.g., security device 410) that is bounded by the previously discovered security realm.
[0040] 4C illustrates an embodiment of a third stage of generating network topology mapping 400 for network environment 120 by network security system 110. In the illustrated embodiment, the third stage includes detecting a set of identifiable routes from the routing information of security devices 430 and 440 to network addresses within security regions accessible via the set of routes. As described above for security devices 410 and 420, network security system 110 can analyze the paths of the set of routes identified from the routing information of security devices 430 and 440 through some or all of the security regions traversed by the routes to further infer the structure of network environment 120. As shown, the routing information of security devices 430 and 440 collectively includes a route to network address B.1 via a first interface of device interface 445 and routes to network addresses C.1 and B.2 via a second interface of device interface 445. During the third phase, network security system 110 determines that previously identified network address B.2 belongs to previously detected security realm C, rather than previously detected security realm B, as determined during the first phase. In one embodiment, network security system 110 determines that a previously identified network address (e.g., network address B.2) belongs to a different security realm than the previously determined security realm when one or more security devices, similar to security devices 430 and 440 and device interface 445, are identified as having routing information identifying routes that logically separate security realms and network addresses based on the device interface corresponding to the route.
[0041] 4D illustrates an embodiment of a fourth stage of generating a network topology mapping 400 for network environment 120 by network security system 110. In the illustrated embodiment, the fourth stage includes locating external connections to external entities within network environment 120. As shown, external entity 460 is connected to network environment 120 via security domain A and security domain B. Similarly, external entity 450 is connected to network environment 120 via security domain C.
[0042] FIG. 4E illustrates an embodiment of a fifth stage of generating a network topology mapping 400 for a network environment 120 by the network security system 110. In the illustrated embodiment, the fifth stage involves detecting possible area paths between the security areas A, B, and C identified in the first, second, and third stages described above. As shown, the possible area paths are designated as a set of an active area path 470 (shown using solid arrows), an alternate area path 480 (shown using uniformly dashed arrows), and a rejected area path 490 (shown using non-uniformly dashed arrows). After a possible area path is identified, the network security system 110 may designate it as the active area path by default. As shown in FIG. 4E, at some point after or during the identification of the possible area paths, the network security system 110 receives information designating an area path as an alternate area path (i.e., alternate area path 480) and designating an area path as a rejected area path (i.e., rejected area path 490).
[0043] Using network topology mapping 400, network security system 110 can configure security devices 410, 420, 430, and 440 to implement connectivity policies for network addresses within security domains A, B, and C, as well as for communications with external entities 450 and 460. For example, network security system 110 can configure security device 420 to implement a connectivity policy that connects network address A.1 to network address C.1 using active domain route 470. Furthermore, network security system 110 can configure security devices 410, 420, or 430 to implement the same connectivity policy using alternate domain route 480 if active domain route 470 is unavailable (e.g., due to a network outage).
[0044] In some embodiments, security realms A, B, and C contain overlapping network addresses. For example, network address B.2 may be included in both security realm B and security realm C, such that network entities in both security realm B and security realm C can communicate with network address B.2 without using a realm route.
[0045] Implementing a Connection Policy 5 is a flowchart illustrating a method 500 for implementing network connection policies using universal and native representations of connection policies, according to one embodiment. In the embodiment shown, the steps of FIG. 5 are shown from the perspective of network security system 110 performing method 500. However, some or all of the steps may be performed by other entities or components. In addition, some embodiments may perform steps differently.
[0046] 5, method 500 begins with network security system 110 receiving 510 a network connection policy for source and destination network addresses within a network environment (e.g., network environment 120). For example, connection policy implementation module 220 may receive a client representation of the connection policy from client system 130. Using a network topology mapping of the network environment, network security system 110 generates 520 a universal representation of the connection policy in the universal syntax of network security system 110. For example, connection policy implementation module 220 may identify network addresses of network entities within the network environment associated with the received connection policy based on elements of the network topology mapping stored in network topology store 230, including the source and destination network addresses.
[0047] Using the network topology mapping, the network security system 110 identifies 530 security devices in the network environment along the network area path between the source network address and the destination network address. For example, the connection policy implementation module 220 may identify security devices on the network area path included in the network topology mapping between the security area containing the source network address and the security area containing the destination network address. Using the universal representation, the network security system 110 generates 540 a native representation of the connection policy in a native syntax associated with the identified security device. For example, the connection policy implementation module 220 may convert some or all of the universal representation to a native representation. Using the generated native representation, the network security system 110 configures 550 the security device to enable communication between the source network address and the destination network address in accordance with the connection policy. Thus, the network security system 110 configures the network environment to enable the source network address and the destination network address to communicate via the network area path of the identified security device.
[0048] 6 is a flow chart illustrating an embodiment of a method 600 for generating a network topology mapping of a network environment. In the illustrated embodiment, the steps of FIG. 6 are shown from the perspective of network security system 110 performing method 600. However, some or all of the steps may be performed by other entities or components. In addition, some embodiments may perform steps differently.
[0049] In the embodiment shown in FIG. 6, method 600 begins with network security system 110 identifying 610 routing information for one or more security devices (e.g., security device 126), describing a set of routes to one or more network addresses that the one or more security devices are configured to use. For example, network topology module 210 may obtain routing tables for security devices 126 included in network environment 120. Using the routing information, network security system 110 determines 620 security domains for the network environment, each of which includes one or more network addresses. For example, network topology module 210 may perform the discovery process shown in FIGS. 4A-C to identify security domains. Further, using the routing information, network security system 110 determines 630 a set of possible domain paths for the network environment, each of which connects one or more network addresses of a pair of security domains. In particular, the set of possible domain paths includes an active domain path and an alternate domain path. For example, network topology module 210 may identify possible domain paths between each security domain 124 using the discovery process described in FIGS. 4A-4E. The active area path and the alternate area path may be designated as active and alternate, respectively, by an administrator of the network environment 110 or by a component of the network security system 110. An active area path includes one or more authorized security devices (e.g., based on the active designation) and enables communication between one or more network addresses connected by the active area path. An alternate area path includes one or more authorized security devices (e.g., based on the alternate designation) and enables communication between one or more network addresses connected by the alternate area path when the active area path is unavailable.In other cases, the set of possible region routes may include any other combination of region routes designated as active region routes, alternate region routes, or rejected region routes. Using the set of possible region routes, the network security system 110 generates 640 a network topology mapping for the network environment 120. For example, the network topology module 210 may store elements of the network topology mapping in the network topology store 230.
[0050] 7 is a flow chart illustrating an embodiment of a method 700 for providing a connection policy for implementation in network environment 120. In the illustrated embodiment, the steps of FIG. 7 are shown from the perspective of a client device performing method 700. However, some or all of the steps may be performed by other entities or components. In addition, some embodiments may perform steps differently.
[0051] In the embodiment shown in FIG. 7, method 700 begins with a client device (e.g., a computing device of client system 130) receiving 710 a network topology mapping for a network environment from a network security system (e.g., network security system 110). The network topology mapping includes security domains connected by domain paths through one or more security devices. For example, the client device may receive a network topology mapping for network environment 120 from network topology module 210 of network security system 110. The client device receives 720 a connection policy for the network environment based on user interaction with the client device. In particular, the connection policy specifies source network addresses within a first security domain of the network topology mapping and destination network addresses in a second security domain of the network topology mapping. For example, network topology analysis module 310 or client connection policy module 320 may provide an interface for display including information describing some or all of the network topology mapping and may allow a user to interact with the interface to input a client representation of the connection policy. The client device provides 730 the connection policy to the network security system. For example, client connection policy module 320 may provide the client representation of the connection policy to network security system 110. After providing 730 the connection policy to the network security system, the client device receives 740 a notification from the network security system indicating that the connection policy has been implemented in the network environment. In particular, the notification indicates that one or more security devices along one or more area paths between the source network address and the destination network address are configured based on the connection policy. For example, the client device may receive the notification from the connection policy implementation module 220 of the network security system 110. Computer Systems Figure 8 is a block diagram representing a computer system, according to one embodiment. Specifically, Figure 8 shows a diagrammatic representation of a computing device of network security system 110 or client system 130 in the exemplary form of computer system 800. Computer system 800 can be used to execute instructions 824 (e.g., program code or software) that cause the machine to perform any one or more of the methodologies (or processes) disclosed herein. In alternative embodiments, the machine operates as a standalone device or a connected (e.g., networked) device that connects to other machines. In a networked deployment, the machine may operate in the capacity of a server machine or a client machine in a server-client system environment (e.g., environment 100), or as a peer machine in a peer-to-peer (or distributed) system environment.
[0052] The machine may be a server computer, a client computer, a personal computer (PC), a tablet PC, a set-top box (STB), a smartphone, an Internet of Things (IoT) device, a network router, a switch or bridge, or any machine capable of executing instructions 824 (sequential or otherwise) that specify operations to be performed by the machine. Additionally, although only a single machine is shown, the term "machine" shall be taken to include any collection of machines that individually or collectively execute instructions 824 to perform any one or more of the methodologies described herein.
[0053] The exemplary computer system 800 includes one or more processing units (generally, a processor 802). The processor 802 may be, for example, a central processing unit (CPU), a graphics processing unit (GPU), a digital signal processor (DSP), a controller, a state machine, one or more application specific integrated circuits (ASICs), one or more radio frequency integrated circuits (RFICs), or any combination thereof. The computer system 800 also includes a main memory 804. The computer system may include a storage unit 816. The processor 802, the memory 804, and the storage unit 816 communicate via a bus 808.
[0054] Additionally, computer system 800 may include static memory 806, a graphics display (e.g., for driving a plasma display panel (PDP), a liquid crystal display (LCD), or a projector). Computer system 800 may also include an alphanumeric input device 812 (e.g., a keyboard), a cursor control device 814 (e.g., a mouse, trackball, joystick, motion sensor, or other pointing device), a signal generating device 818 (e.g., a speaker), and a network interface device 820, which are also configured to communicate via bus 808.
[0055] Storage unit 816 includes a machine-readable medium 822 on which are stored instructions 824 (e.g., software) that embody any one or more of the methodologies or functions described herein. For example, instructions 824 may include the functions of the modules of network security system 110 described in FIG. 1. Instructions 824 may also reside, completely or at least partially, within main memory 804 or within processor 802 (e.g., within a processor's cache memory) during execution thereof by computer system 800, with main memory 804 and processor 802 also constituting machine-readable media. Instructions 824 may be transmitted or received over a network 826 (e.g., network 140) via network interface device 820.
[0056] Although machine-readable medium 822 is shown as a single medium in an exemplary embodiment, the term "machine-readable medium" is intended to include a single medium or multiple media (e.g., a centralized or distributed database, or associated caches and servers) capable of storing instructions 824. The term "machine-readable medium" is also intended to include any medium capable of storing instructions 824 for execution by a machine, causing the machine to perform any of one or more of the methodologies disclosed herein. The term "machine-readable medium" includes, but is not limited to, data repositories in the form of solid-state memory, optical media, and magnetic media.
[0057] Additional Considerations The foregoing description of embodiments of the present disclosure has been presented for purposes of illustration. It is not intended to be exhaustive or to be limited to the precise form disclosed. Those skilled in the art will recognize that many modifications and variations are possible in light of the above disclosure.
[0058] Some portions of this description will describe embodiments of the present disclosure in terms of algorithms and symbolic representations of operations on information. These algorithmic descriptions and representations are commonly used by those skilled in the data processing arts to effectively convey the substance of their work to others skilled in the art. While these operations are described functionally, computationally, or logically, they will be understood to be implemented by computer programs or equivalent electrical circuits, microcode, or the like. Further, and without loss of generality, it will prove convenient at times to refer to arrangements of these operations as modules. The described operations and their associated modules may be embodied in software, firmware, hardware, or any combination thereof.
[0059] Any step, operation, or process described herein may be performed or implemented using one or more hardware or software modules, alone or in combination with other devices. In one embodiment, a software module is implemented using a computer program product that includes a computer-readable medium containing computer program code, which can be executed by a computer processor to perform any or all of the described steps, operations, or processes.
[0060] Embodiments of the present disclosure may also relate to apparatus for performing the operations herein. The apparatus may be specially constructed for the required purposes and / or may comprise a general-purpose computing device selectively activated or reconfigured by a computer program stored in the computer. Such a computer program may be stored on a tangible computer-readable storage medium, or any type of medium suitable for storing electronic instructions, and coupled to a computer system bus. Furthermore, any computing system referred to herein may include a single processor or may be an architecture employing a multiple processor design to increase computing power.
[0061] Embodiments of the present disclosure may also relate to a computer data signal embodied in a carrier wave, which includes any embodiment of the computer program product or other data combination described herein. A computer data signal is a product presented on a tangible medium or carrier wave, modulated or encoded on a carrier wave that is tangible, and transmitted according to any suitable transmission method.
[0062] Finally, the language used in the specification has been selected primarily for ease of reading and explanation, and may not have been selected to delineate or limit the subject matter of the invention. Accordingly, it is intended that the scope of the disclosure be limited not by this detailed description, but by the claims that issue in an application based thereon. Accordingly, the disclosure of embodiments of the present disclosure is intended to illustrate, but not to limit, the scope of the invention.
Claims
1. 1. A computer-implemented method for configuring a network security device, comprising: receiving, by a network security system, a connection policy for a network environment including a plurality of network addresses, the connection policy corresponding to a first network address and a second network address within the network environment; generating a universal representation of the connectivity policy using a network topology mapping of the network environment, the network topology mapping including a set of possible area paths of the network environment connecting the first network address and the second network address, the set of possible area paths comprising: an active area path that enables communication between the first network address and the second network address; an alternative area route that enables communication between the first network address and the second network address in response to the active area route becoming unavailable; using the network topology mapping to identify security devices within the network environment on a network region path between the first network address and the second network address, the security devices configured to implement connection policies using native syntax; generating a native representation of the connection policy in the native syntax based on the universal representation; configuring the security device to enable communication between the first network address and the second network address using the generated native representation; An implementation method comprising:
2. receiving, by the network security system, an updated access policy; generating an updated universal representation of the updated connectivity policy in a universal syntax for the network environment; generating an updated native representation of the updated connection policy in the native syntax; The method of claim 1 , further comprising: reconfiguring the security device using the updated native representation.
3. identifying a network address translation (NAT) rule associated with the security device; identifying a second security device in the network environment on the network region path between the first network address and the second network address, the second security device configured to implement connections using a second native syntax; generating a second native representation of the connectivity policy in the second native syntax based on the universal representation and using the NAT rules; 2. The method of claim 1, further comprising: configuring the second security device to allow communication between the first network address and the second network address using the second native representation.
4. identifying updates to the network topology mapping for the network environment; generating an updated universal representation of the connectivity policy in a universal syntax for the network environment based on the update of the network topology mapping; generating an updated native representation of the updated connection policy in the native syntax based on the updated universal representation; The method of claim 1 , further comprising: reconfiguring the security device based on the updated native representation.
5. The connection policy references elements of the network topology mapping, and identifying the update to the network topology mapping includes: The method of claim 4 , further comprising determining that the element of the network topology mapping has changed.
6. 5. The method of claim 4, further comprising providing a notification to a client device describing the update to the network topology mapping and the reconfiguration of the security device.
7. The step of receiving the connection policy includes: providing, by the network security system, information describing the network topology mapping to a client system; and receiving the connection policy from the client system.
8. 2. The method of claim 1, wherein the security device bounds a plurality of security realms, and the first and second network addresses are in a first and second security realm of the plurality of security realms, respectively.
9. the connection policy is received via a first connection policy channel; receiving, by the network security system, an additional access policy for the network environment via a second access policy channel; generating a combined universal representation of the connection policy and the additional connection policy in a universal syntax for the network environment; 10. The method of claim 1, further comprising: using the combined universal representation to configure one or more security devices of the network environment to implement the connection policy and the additional connection policy in the network environment.
10. 1. A computer-implemented method for configuring a network security device, comprising: generating a universal representation of a connectivity policy for a network environment using a network topology mapping of the network environment, the network topology mapping including a set of possible area paths of the network environment connecting a first network address and a second network address within the network environment, the set of possible area paths comprising: an active area path that enables communication between the first network address and the second network address; an alternative area route that enables communication between the first network address and the second network address in response to the active area route becoming unavailable; configuring a security device in the network environment to enable communication between the first network address and the second network address using the native representation of the connection policy, the security device being identified using the network topology mapping; An implementation method comprising:
11. receiving an updated connection policy; generating an updated universal representation of the updated connectivity policy in a universal syntax for the network environment; generating an updated native representation of the updated connection policy in native syntax; 11. The method of claim 10, further comprising: reconfiguring the security device using the updated native representation.
12. identifying a network address translation (NAT) rule associated with the security device; identifying a second security device in the network environment on the network region path between the first network address and the second network address, the second security device configured to implement connections using a second native syntax; generating a second native representation of the connectivity policy in the second native syntax based on the universal representation and using the NAT rules; 11. The method of claim 10, further comprising: configuring the second security device to allow communication between the first network address and the second network address using the second native representation.
13. identifying updates to the network topology mapping for the network environment; generating an updated universal representation of the connectivity policy in a universal syntax for the network environment based on the update of the network topology mapping; generating an updated native representation of the updated connection policy in native syntax based on the updated universal representation; The method of claim 10, further comprising: reconfiguring the security device based on the updated native representation.
14. The connection policy references elements of the network topology mapping, and identifying the update to the network topology mapping comprises: The method of claim 13 , further comprising determining that the element of the network topology mapping has changed.
15. 14. The method of claim 13, further comprising providing a notification to a client device describing the update to the network topology mapping and the reconfiguration of the security device.
16. 1. A non-transitory computer-readable storage medium storing instructions that, when executed by a processor, cause the processor to perform operations for generating a network topology mapping, the operations comprising: generating a universal representation of a connectivity policy for a network environment using a network topology mapping of the network environment, the network topology mapping including a set of possible area paths of the network environment connecting a first network address and a second network address within the network environment, the set of possible area paths comprising: an active area path that enables communication between the first network address and the second network address; an alternative region route that enables communication between the first network address and the second network address in response to the active region route becoming unavailable; configuring a security device in the network environment to enable communication between the first network address and the second network address using the native representation of the connection policy, the security device being identified using the network topology mapping; A non-transitory computer-readable storage medium comprising:
17. The operation is receiving an updated connection policy; generating an updated universal representation of the connection policy in a universal syntax for the network environment; generating an updated native representation of the updated connection policy in native syntax; 20. The non-transitory computer-readable storage medium of claim 16, further comprising: reconfiguring the security device using the updated native representation.
18. The operation is Identifying a network address translation (NAT) rule associated with the security device; identifying a second security device in the network environment on a network domain path between the first network address and the second network address, the second security device configured to implement the connection using a second native syntax; generating a second native representation of the connectivity policy in the second native syntax based on the universal representation and using the NAT rules; 17. The non-transitory computer-readable storage medium of claim 16, further comprising: configuring the second security device to enable communication between the first network address and the second network address using the second native representation.
19. The operation is identifying updates to the network topology mapping for the network environment; generating an updated universal representation of the connectivity policy in a universal syntax for the network environment based on the update of the network topology mapping; generating an updated native representation of the updated connection policy in a native syntax based on the updated universal representation; 20. The non-transitory computer-readable storage medium of claim 16, further comprising: reconfiguring the security device based on the updated native representation.
20. The connection policy references elements of the network topology mapping, and identifying the update to the network topology mapping includes:
20. The non-transitory computer-readable storage medium of claim 19, comprising determining that the element of the network topology mapping has changed.
Citation Information
Patent Citations
Method and system to manage firewall
JP2000253066A
Firewall managing apparatus and method
JP2002261788A
System, method and program for security policy management
JP2006040247A
Access control setting support system
JP2008219419A
Chassis controller for converting universal flow
JP2016067008A