Component-Specific Network Security Policies for Containerized Microservices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Container orchestration frameworks face challenges in managing network traffic flow due to the dynamic nature of micro-service based systems, where traditional network controls are inadequate in distinguishing and filtering traffic at the level of individual components, especially with encapsulated traffic and dynamically assigned IP addresses.

Innovation Solution

A method for generating component-specific network security policies by monitoring network traffic, identifying network paths, and creating unique identifiers for components, allowing for precise security policies that respect pre-defined policies and enable different versions of components to co-exist with distinct network requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional network-based firewalls are used for traffic control, then network-level security is maintained, but the ability to distinguish and filter traffic at the component level is lost due to encapsulated traffic and dynamic IP addresses

Engineering Contradiction:
Improvetraffic identification precisionVSAvoidnetwork control complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments network security policies from network-level to component-level by creating version-specific security policies for individual application components. Each component version receives a unique security policy that identifies its specific network paths, allowing precise traffic filtering at the component level despite encapsulated traffic flows.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component that monitors network traffic flows and generates component-specific security policies. This intermediary acts as a mediator between the traditional network firewall and the microservice components, translating network-level traffic control into component-level security without requiring changes to the underlying network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If dynamic IP addressing is used for microservice components, then flexibility and scalability are improved, but the stability required for network security policies deteriorates

Engineering Contradiction:
Improvecomponent deployment flexibilityVSAvoidnetwork address stability
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The patent embraces the dynamic nature of microservice deployment by generating security policies that are specific to each component version rather than relying on static IP addresses. The system adapts to dynamic IP changes by monitoring actual network traffic flows and updating security policies accordingly, allowing flexible component deployment while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the identifying parameter from static IP addresses to version-based identifiers. Each component version is assigned a unique identifier that remains stable regardless of IP address changes, and security policies are based on these version identifiers rather than network addresses, thereby maintaining policy stability in a dynamic environment.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple versions of a component co-exist in the deployed application, then system availability and gradual deployment are improved, but network security management complexity increases due to different network requirements

Engineering Contradiction:
Improvesystem availabilityVSAvoidsecurity policy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security policies by component version, creating distinct security policies for each version that co-exists in the system. This segmentation allows different versions with different network requirements to be managed independently, with each version's security policy tailored to its specific traffic patterns while maintaining overall system availability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a dynamic security policy generation system that automatically creates and updates policies as component versions are deployed or retired. This dynamic approach simplifies management of multiple versions by eliminating manual configuration, allowing the system to adapt security policies automatically as the component version landscape changes.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11539754B2Techniques for generating network security policies for application components deployed in a computing environment
Publication Date: 2022.12.27 ORACLE INT CORP
  • US11539754B2 patent drawing
  • US11539754B2 patent drawing
  • US11539754B2 patent drawing

AI summary

Techniques are disclosed for generating network security policies for different versions of a component of an application deployed in a computing environment where the different versions have potentially different network requirements and the different versions operate together at the same time in the computing environment. The disclosed techniques include capabilities for enabling different versions of a component of a containerized application to co-exist at the same time on different computing nodes in a cluster of nodes in a containerized environment that deploys and executes the application. The techniques additionally include capabilities for enabling different network policies to be generated for the different versions of the component, where each component has potentially different network requirements. The techniques provide a mechanism to create precise, per-component network policies, while respecting the overall coarse-grained policies of the containerized application.