Customer-Network Traffic Tagging for Target-Service Egress Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud environments lack effective mechanisms to enforce egress traffic policies, particularly in multi-tenant scenarios, leading to risks of data exfiltration and unauthorized data transfer.
Innovation Solution
Implementing egress traffic policy enforcement at a target service by tagging traffic with network location information, such as identifiers and IP addresses, and using a policy evaluator to determine and enforce customer-defined actions based on these tags.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If egress traffic policy enforcement is implemented at target service, then data security and compliance are improved, but system complexity increases due to tagging and policy evaluation mechanisms
Solution Approach 1:
The network location tags traffic with network location information (such as gateway identifiers) in advance before the traffic reaches the target service. This preliminary tagging action enables the target service to enforce egress policies without needing to implement complex evaluation logic, thereby improving data security while minimizing the increase in system complexity.
Solution Approach 2:
The patent introduces a policy evaluator as an intermediary component that receives policy evaluation requests from target services and returns enforcement decisions. This intermediary handles the complex policy matching and evaluation logic centrally, allowing target services to enforce policies simply by querying the evaluator, thus improving security enforcement while containing system complexity in a dedicated component.
2Measurement precision
If network location tagging is performed on all egress traffic, then policy enforcement accuracy is improved, but processing overhead increases
Solution Approach 1:
The network location tags traffic with identifying information at the point of egress (at the gateway) before the traffic traverses the network to reach the target service. This preliminary tagging ensures that when the target service receives the traffic, the network location information is already available for immediate policy enforcement without requiring additional processing or querying, thereby achieving high policy enforcement accuracy while minimizing processing overhead at the target service.
Data Source
AI summary
Techniques for enforcing an egress policy at a target service are described. In an example, traffic is generated for a customer, where the traffic is generated by a customer network of the customer, such as a customer tenancy or an on-premise network. The traffic can be destined to the target service. The traffic can be tagged by the customer network (e.g., by a gateway of the customer network). The customer network can be associated with the egress policy. The target service can determine the egress policy based on the information tagged to the traffic and can enforce the egress policy on the traffic that the target service is receiving.


