US2019222610A1PendingUtilityA1

User-Based Visibility and Control of a Segmentation Policy

Assignee: ILLUMIO INCPriority: Jan 18, 2018Filed: Jan 18, 2018Published: Jul 18, 2019
Est. expiryJan 18, 2038(~11.5 yrs left)· nominal 20-yr term from priority
H04L 41/22H04L 45/50H04L 63/105H04L 43/028H04L 63/20G06F 16/9024H04L 43/045G06F 17/30958H04L 43/026Y02D30/50
48
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A segmentation server enables user-based management of a segmentation policy. Administrators belonging to different user groups may have different limited visibility into traffic flows controlled by the segmentation policy and may be assigned different privileges with respect to viewing, creating, and modifying rules of the segmentation policy. Thus, the burden of administering the segmentation policy may be distributed between administrators associated with different user groups that each may have responsibility for a different segment.

Claims

exact text as granted — not AI-modified
1 . A method for facilitating creation of a segmentation policy controlling communications between a plurality of workloads, the method comprising:
 identifying a user group associated with an administrator logged into an administrative client accessing a segmentation server;   identifying, from a user group database, a group of label sets associated with the user group;   identifying, from a workload database, a subset of workloads of the plurality of workloads having at least one of the group of label sets associated with the user group;   generating a set of rules for controlling communications associated with the subset of workloads;   generating management instructions for enforcing the set of rules; and   sending the management instructions to respective operating system instances executing the subset of workloads, wherein the respective operating system instances enforce the set of rules based on the management instructions.   
     
     
         2 . The method of  claim 1 , further comprising:
 monitoring traffic flows associated with the subset of workloads;   generating a traffic flow graph based on the monitored traffic flows, the traffic flow graph comprising a plurality of nodes representing the subset of workloads, and a plurality of edges representing the monitored traffic flows between the subset of workloads;   generating a graphical representation of the traffic flow graph; and   outputting the graphical representation of the traffic flow graph to the administrative client.   
     
     
         3 . The method of  claim 1 , wherein generating the set of rules comprises:
 generating a rule permitting any communications between workloads having a same predefined label set.   
     
     
         4 . The method of  claim 1 , wherein generating the set of rules comprises:
 monitoring traffic flows associated with the subset of workloads; and   generating the set of rules based on the monitored traffic flows, the set of rules permitting the monitored traffic flows.   
     
     
         5 . The method of  claim 4 , wherein generating the set of rules comprises:
 detecting traffic flow between a first workload in the subset of workloads and a second workload in the plurality of workloads;   determining a first label set associated with the first workload and a second label set associated with the second workload; and   generating a rule permitting communications between workloads having the first label set and workloads having the second label set.   
     
     
         6 . The method of  claim 4 , wherein generating the set of rules comprises:
 detecting traffic flow between a first workload in the subset of workloads and a second workload in the plurality of workloads;   detecting one or more ports and one or more protocols over which the traffic flow is communicated;   determining a first label set associated with the first workload and a second label set associated with the second workload; and   generating a rule permitting communications using the one or more ports and the one or more protocols between workloads having the first label set and workloads having the second label set.   
     
     
         7 . The method of  claim 1 , wherein generating the rule set comprises:
 determining that the user group has limited ruleset creation privileges; and   generating the rule set to only include rules permitting communications between pairs workloads in the subset of workloads that both have at least one of the group of label sets associated with the user group.   
     
     
         8 . The method of  claim 1 , wherein generating the initial rule set comprises:
 determining that the user group has expanded ruleset creation privileges; and   generating the rule set to include rules permitting communications in which a workload in the subset of workloads having at least one of the group of label sets associated with the user group provides a service to a workload outside the subset of workloads.   
     
     
         9 . The method of  claim 1 , wherein generating the management instructions comprises:
 storing the rules to a rules database;   identifying access of the segmentation server by a provisioner associated with a provisioner user group;   generating a user interface presenting the rules for review; and   generating the management instructions responsive to receiving confirmation from the provisioner via the user interface to implement the rules.   
     
     
         10 . A non-transitory computer-readable storage medium storing instructions executable by one or more processors for facilitating creation of a segmentation policy, the instructions when executed causing the one or more processors to perform steps including:
 identifying a user group associated with an administrator logged into an administrative client accessing a segmentation server;   identifying, from a user group database, a group of label sets associated with the user group;   identifying, from a workload database, a subset of workloads of the plurality of workloads having at least one of the group of label sets associated with the user group;   generating a set of rules for controlling communications associated with the subset of workloads;   generating management instructions for enforcing the set of rules; and   sending the management instructions to respective operating system instances executing the subset of workloads, wherein the respective operating system instances enforce the set of rules based on the management instructions.   
     
     
         11 . The non-transitory computer-readable storage medium of  claim 10 , wherein the instructions when executed further cause the processor to perform steps including:
 monitoring traffic flows associated with the subset of workloads;   generating a traffic flow graph based on the monitored traffic flows, the traffic flow graph comprising a plurality of nodes representing the subset of workloads, and a plurality of edges representing the monitored traffic flows between the subset of workloads;   generating a graphical representation of the traffic flow graph; and   outputting the graphical representation of the traffic flow graph to the administrative client.   
     
     
         12 . The non-transitory computer-readable storage medium of  claim 10 , wherein generating the set of rules comprises:
 generating a rule permitting any communications between workloads having a same predefined label set.   
     
     
         13 . The non-transitory computer-readable storage medium of  claim 10 , wherein generating the set of rules comprises:
 monitoring traffic flows associated with the subset of workloads; and   generating the set of rules based on the monitored traffic flows, the set of rules permitting the monitored traffic flows.   
     
     
         14 . The non-transitory computer-readable storage medium of  claim 13 , wherein generating the set of rules comprises:
 detecting traffic flow between a first workload in the subset of workloads and a second workload in the plurality of workloads;   determining a first label set associated with the first workload and a second label set associated with the second workload; and   generating a rule permitting communications between workloads having the first label set and workloads having the second label set.   
     
     
         15 . The non-transitory computer-readable storage medium of  claim 13 , wherein generating the set of rules comprises:
 detecting traffic flow between a first workload in the subset of workloads and a second workload in the plurality of workloads;   detecting one or more ports and one or more protocols over which the traffic flow is communicated;   determining a first label set associated with the first workload and a second label set associated with the second workload; and   generating a rule permitting communications using the one or more ports and the one or more protocols between workloads having the first label set and workloads having the second label set.   
     
     
         16 . The non-transitory computer-readable storage medium of  claim 10 , wherein generating the rule set comprises:
 determining that the user group has limited ruleset creation privileges; and   generating the rule set to only include rules permitting communications between pairs workloads in the subset of workloads that both have at least one of the group of label sets associated with the user group.   
     
     
         17 . The non-transitory computer-readable storage medium of  claim 10 , wherein generating the initial rule set comprises:
 determining that the user group has expanded ruleset creation privileges; and   generating the rule set to include rules permitting communications in which a workload in the subset of workloads having at least one of the group of label sets associated with the user group provides a service to a workload outside the subset of workloads.   
     
     
         18 . A system for facilitating creation of a segmentation policy, the system comprising:
 one or more processors; and   a non-transitory computer-readable storage medium storing instructions executable by the one or more processors, the instructions when executed causing the one or more processor to perform steps including:
 identifying a user group associated with an administrator logged into an administrative client accessing a segmentation server; 
 identifying, from a user group database, a group of label sets associated with the user group; 
 identifying, from a workload database, a subset of workloads of the plurality of workloads having at least one of the group of label sets associated with the user group; 
 generating a set of rules for controlling communications associated with the subset of workloads; 
 generating management instructions for enforcing the set of rules; and 
 sending the management instructions to respective operating system instances executing the subset of workloads, wherein the respective operating system instances enforce the set of rules based on the management instructions. 
   
     
     
         19 . The system of  claim 18 , wherein the instructions when executed further cause the one or more processors to perform steps including:
 monitoring traffic flows associated with the subset of workloads;   generating a traffic flow graph based on the monitored traffic flows, the traffic flow graph comprising a plurality of nodes representing the subset of workloads, and a plurality of edges representing the monitored traffic flows between the subset of workloads;   generating a graphical representation of the traffic flow graph; and   outputting the graphical representation of the traffic flow graph to the administrative client.   
     
     
         20 . The system of  claim 18 , wherein generating the set of rules comprises:
 monitoring traffic flows associated with the subset of workloads; and   generating the set of rules based on the monitored traffic flows, the set of rules permitting the monitored traffic flows.

Join the waitlist — get patent alerts

Track US2019222610A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.