Automated Microsegmentation for Serverless Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions struggle with efficiently implementing microsegmentation in serverless computing environments, where users lack control over the platform and manual processes are complex, time-consuming, and costly, making it difficult to secure workloads effectively.

Innovation Solution

The use of machine learning techniques to automate microsegmentation by learning network behavior, generating policies for communication, and managing Access Control Lists (ACLs) to limit host and application access, with software identity-based technology that adapts to environmental changes without requiring underlying network changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual network segmentation is implemented using legacy virtual firewalls, then security risk is reduced, but deployment time, complexity, and cost increase significantly

Engineering Contradiction:
Improvesecurity risk reductionVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically discovering network workloads, analyzing communication patterns, and generating segmentation policies without requiring manual configuration. The automated policy generation engine creates microsegmentation rules based on observed network behavior, eliminating the need for security professionals to manually craft hundreds or thousands of fine-grained rules.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual process of creating and managing segmentation rules with an automated system that uses machine learning and behavioral analysis. Instead of humans manually understanding big data and writing interacting rules, the system automatically analyzes network traffic patterns and generates policies, substituting human cognitive tasks with computational processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual network segmentation is implemented using legacy virtual firewalls, then security risk is reduced, but deployment time increases

Engineering Contradiction:
Improvesecurity risk reductionVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously monitoring and learning normal network behavior patterns before threats occur. It proactively establishes baseline communication patterns between workloads, enabling it to quickly generate segmentation policies when needed without starting from scratch during deployment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated policy generation engine operates continuously, constantly analyzing network traffic and updating segmentation policies in real-time. This continuous operation eliminates the need for periodic manual interventions and maintains security posture without interruption, reducing overall deployment and maintenance time.

Inventive Principle:
Principle #20Continuity of useful action

3Manufacturing precision

If fine-grained segmentation rules are created manually, then access control precision is improved, but the difficulty of understanding and managing rules increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidrule management difficulty
Core Design Contradiction:
Manufacturing precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The system introduces an intermediary automated policy generation engine that translates complex network communication patterns into manageable segmentation rules. This intermediary layer processes the complexity of fine-grained access requirements and presents simplified, standardized policies to administrators, making them easier to understand and manage while maintaining precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms that continuously monitor rule effectiveness and provide insights into network behavior. This feedback loop allows administrators to understand the impact of segmentation rules, validate their correctness, and make informed adjustments, reducing the difficulty of managing fine-grained access control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11792194B2Microsegmentation for serverless computing
Publication Date: 2023.10.17 ZSCALER INC
  • US11792194B2 patent drawing
  • US11792194B2 patent drawing
  • US11792194B2 patent drawing

AI summary

Systems and methods include obtaining a set of policies to in the serverless computing system, wherein the set of policies specify which applications are authorized for communication with the serverless computing system; and modifying rules in a network Access Control List (ACL) associated with the serverless computing system based on the set of policies, wherein the network ACL includes rules that specify allowing and blocking communication. The serverless computing system includes having underlying hardware abstracted therefrom. The network ACL is provided by a cloud provider that hosts the serverless computing system.