Container Microsegmentation via Declarative Policy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems, including firewalls, face challenges in managing large sets of firewall rules and effectively preventing lateral movement within internal networks, allowing attackers to breach and exploit critical assets.

Innovation Solution

Implementing microsegmentation in data networks through a computer-implemented method that receives a high-level declarative policy, generates metadata from an orchestration layer, and configures virtual switches to enforce low-level firewall rules, thereby restricting communications between specific groups of containers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional hardware firewalls are used to control network traffic, then network security boundaries are established, but the complexity of managing firewall rules increases and lateral movement prevention is ineffective

Engineering Contradiction:
Improvenetwork securityVSAvoidfirewall rule management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the internal network into multiple isolated microsegments using virtual switches and enforcement points. Each container or group of containers is placed in its own security segment, allowing granular control over network communications. This segmentation approach replaces traditional perimeter-based firewalling with fine-grained, workload-specific security zones, effectively preventing lateral movement while simplifying rule management through automated policy generation.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If traditional firewalls are used to secure internal networks, then perimeter security is maintained, but attackers can still move laterally across the network to reach critical assets

Engineering Contradiction:
Improvelateral movement preventionVSAvoidsecurity policy enforcement
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements security policies at the local level of individual containers and workloads rather than applying uniform perimeter security. Each microsegment receives security enforcement tailored to its specific requirements through declarative policies that define allowed communications. This local quality approach ensures that even if one segment is compromised, attackers cannot move laterally to other segments, while the system remains easy to operate through high-level policy definitions.

Inventive Principle:
Principle #3Local quality

3Reliability

If granular security policies are implemented for each container, then lateral movement is prevented, but the complexity of policy management increases

Engineering Contradiction:
Improvesecurity segmentationVSAvoidpolicy management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables the system to automatically generate, enforce, and update security policies without manual intervention. The security fabric monitors container communications and autonomously configures virtual switches and enforcement points based on declarative policy definitions. This self-service capability allows granular security segmentation to be maintained while eliminating the operational complexity of manual policy management, as the system adapts automatically to changing network conditions and container deployments.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9560081B1Data network microsegmentation
Publication Date: 2017.01.31 GRYPHO5 LLC
  • US9560081B1 patent drawing
  • US9560081B1 patent drawing
  • US9560081B1 patent drawing

AI summary

Methods and systems for microsegmentation of data networks are provided herein. Exemplary methods include: receiving a high-level declarative policy; getting metadata associated with a plurality of containers from an orchestration layer; determining a low-level firewall rule set using the high-level declarative policy and the metadata; and configuring by a plurality of enforcement points a respective virtual switch of a plurality of virtual switches to process packets in accordance with the low-level firewall ruleset, the virtual switches being collectively communicatively coupled to the plurality of containers, such that network communications between a first group of containers and a second group of containers of the plurality of containers are not permitted, and communications between containers of the first group of containers are permitted.