Container Microsegmentation via Declarative Policy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems, including firewalls, face challenges in managing large sets of firewall rules and effectively preventing lateral movement within internal networks, allowing attackers to breach and exploit critical assets.
Innovation Solution
Implementing microsegmentation in data networks through a computer-implemented method that receives a high-level declarative policy, generates metadata from an orchestration layer, and configures virtual switches to enforce low-level firewall rules, thereby restricting communications between specific groups of containers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional hardware firewalls are used to control network traffic, then network security boundaries are established, but the complexity of managing firewall rules increases and lateral movement prevention is ineffective
Solution Approach 1:
The patent divides the internal network into multiple isolated microsegments using virtual switches and enforcement points. Each container or group of containers is placed in its own security segment, allowing granular control over network communications. This segmentation approach replaces traditional perimeter-based firewalling with fine-grained, workload-specific security zones, effectively preventing lateral movement while simplifying rule management through automated policy generation.
2Object-affected harmful factors
If traditional firewalls are used to secure internal networks, then perimeter security is maintained, but attackers can still move laterally across the network to reach critical assets
Solution Approach 1:
The patent implements security policies at the local level of individual containers and workloads rather than applying uniform perimeter security. Each microsegment receives security enforcement tailored to its specific requirements through declarative policies that define allowed communications. This local quality approach ensures that even if one segment is compromised, attackers cannot move laterally to other segments, while the system remains easy to operate through high-level policy definitions.
3Reliability
If granular security policies are implemented for each container, then lateral movement is prevented, but the complexity of policy management increases
Solution Approach 1:
The patent enables the system to automatically generate, enforce, and update security policies without manual intervention. The security fabric monitors container communications and autonomously configures virtual switches and enforcement points based on declarative policy definitions. This self-service capability allows granular security segmentation to be maintained while eliminating the operational complexity of manual policy management, as the system adapts automatically to changing network conditions and container deployments.
Data Source
AI summary
Methods and systems for microsegmentation of data networks are provided herein. Exemplary methods include: receiving a high-level declarative policy; getting metadata associated with a plurality of containers from an orchestration layer; determining a low-level firewall rule set using the high-level declarative policy and the metadata; and configuring by a plurality of enforcement points a respective virtual switch of a plurality of virtual switches to process packets in accordance with the low-level firewall ruleset, the virtual switches being collectively communicatively coupled to the plurality of containers, such that network communications between a first group of containers and a second group of containers of the plurality of containers are not permitted, and communications between containers of the first group of containers are permitted.


