Automated Network Security Policy Rendering and Deployment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Manually creating or updating network security policies in cloud computing systems is time-consuming, prone to errors, and can lead to data breaches and network outages, especially in multi-substrate cloud environments where changes across different hosting environments are not adequately accounted for.
Innovation Solution
Implementing a zero-touch automation (ZeTA) policy-as-a-service functionality that uses a declarative user interface to create or update network security policies, which are then automatically rendered into access control lists (ACLs) and deployed across diverse substrates through a rendering and deployment sub-system, decoupling services from the underlying policy implementation process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual creation or updating of network security policies is performed, then policy customization and control are improved, but time consumption and error rates increase significantly
Solution Approach 1:
The system enables self-service automation where the network security policy management system automatically retrieves service instance information, generates ACLs, and deploys policies without requiring manual human intervention. The system serves itself by automatically updating policies when service instances change, eliminating the time-consuming manual processes while maintaining policy control through automated service discovery and ACL generation.
2Ease of operation
If manual creation or updating of network security policies is performed, then policy customization and control are improved, but error rates and security risks increase
Solution Approach 1:
The patent replaces manual mechanical processes with automated computational systems. The system automatically discovers service instances, retrieves their network security settings, generates corresponding ACLs, and deploys policies through API calls. This substitution of manual operations with automated system processes eliminates human errors while maintaining precise policy control through programmatic service instance management and ACL generation.
3Productivity
If automated policy rendering and deployment is implemented, then productivity and speed are improved, but system complexity increases
Solution Approach 1:
The network security policy management system performs multiple functions through a single integrated automated platform: it discovers service instances, retrieves network security settings, generates ACLs, and deploys policies across multiple substrates. This multi-functional approach consolidates what would otherwise require separate manual processes into one unified system, managing complexity through integration while achieving high productivity through automation.
4Reliability
If automated policy rendering and deployment is implemented, then policy consistency across multi-substrate environments is improved, but implementation complexity increases
Solution Approach 1:
The system segments the policy deployment process into distinct automated stages: service instance discovery, network security settings retrieval, ACL generation, and policy deployment to multiple substrates. Each segment handles a specific aspect of policy management, allowing the system to maintain consistency across diverse hosting environments by processing each substrate through the same standardized automated workflow, thereby managing implementation complexity through structured segmentation.
Data Source
AI summary
Methods, systems, and devices for data processing in a computing system are described. The computing system may receive a notification of an update to network security objects hosted in diverse substrates within the computing system. The computing system may retrieve a network security policy for a service instance impacted by the update. The computing system may update the network security policy for the service instance according to a network security configuration of the hosting substrate. The computing system may translate the updated network security policy into access control lists (ACLs) for network entities managing communications between service instances within the computing system. The computing system may store the ACLs in respective data repositories that are accessible to the network entities. The computing system may transmit a notification that the ACLs are available for deployment, thereby causing the network entities to retrieve the ACLs from the respective data repositories.


