Workload Tag-Based Security Policy Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems require manual customization and maintenance of security settings and policies based on virtual machine IP addresses, network connectivity, and other factors, which is time-consuming and inefficient, especially as virtual machine operations change.

Innovation Solution

Implementing a security system that uses tags associated with workloads to dynamically apply security settings and policies, allowing security orchestrators to automatically detect and enforce security configurations based on workload properties without requiring detailed knowledge of the virtual machine's location or connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual customization and maintenance of security settings and policies is used, then security can be applied to virtual machines, but the process is time-consuming and inefficient

Engineering Contradiction:
Improvesecurity applicationVSAvoidtime for customization and maintenance
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service by automatically detecting workload properties and applying appropriate security settings and policies without requiring manual intervention. The security orchestrator autonomously monitors virtual machine operations, identifies security requirements based on workload characteristics, and enforces corresponding security configurations, thereby eliminating the time-consuming manual customization process while maintaining reliable security protection.

Inventive Principle:
Principle #25Self-service

2Reliability

If security settings are based on virtual machine IP addresses and network connectivity, then security policies can be enforced, but the system requires detailed knowledge of virtual machine location and connectivity

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms the basis for security policy enforcement from network-centric parameters (IP addresses, connectivity) to workload-centric parameters (workload properties, operational characteristics). By changing the fundamental parameter used for security determination, the system maintains reliable policy enforcement while reducing complexity, as workload properties are inherently associated with the virtual machine regardless of its network location or connectivity changes.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If conventional security systems are used, then security monitoring can be performed, but the systems cannot rapidly adapt to changing virtual machine environments and operations

Engineering Contradiction:
Improvesecurity monitoringVSAvoidadaptation to changing environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements dynamics by continuously monitoring virtual machine operations and automatically adjusting security settings in real-time based on changing workload properties. Rather than relying on static security configurations, the security orchestrator dynamically evaluates current operational states and applies appropriate security policies, enabling the system to adapt rapidly to environmental changes while maintaining consistent security monitoring and protection.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11120148B2Dynamically applying application security settings and policies based on workload properties
Publication Date: 2021.09.14 FORTINET INC
  • US11120148B2 patent drawing
  • US11120148B2 patent drawing
  • US11120148B2 patent drawing

AI summary

Systems, methods, and apparatuses enable a security orchestrator to detect a virtual machine deployed in a virtual environment. The virtual machine includes a tag storing information associated with the virtual machine. The security orchestrator determines that the tag contains one or more security elements, the security elements indicating information for determining security settings and policies to be applied to the virtual machine. The security orchestrator determines the security settings and policies associated with the one or more security elements. The security orchestrator then assigns or applies the security settings and policies for the virtual machine based on values of the one or more security elements.