US2022400113A1PendingUtilityA1

Systems and methods for focused learning of application structure and ztna policy generation

Assignee: FORTINET INCPriority: Jun 15, 2021Filed: Jun 15, 2021Published: Dec 15, 2022
Est. expiryJun 15, 2041(~14.9 yrs left)· nominal 20-yr term from priority
H04L 63/101H04L 43/0876
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems, devices, and methods are discussed for determining zero trust network access policy from a policy from a perspective focused on one or more network elements.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for focused development of a zero trust network access policy, the method comprising:
 accessing, by a processing resource, a focus list, wherein the focus list identifies at least one network element;   monitoring, by the processing resource, network activity to yield a set of network traffic;   identifying, by the processing resource, a set of workloads in the set of network traffic that are either sourced from any of the at least one network focus, or destined to any of the at least one network element; and   augmenting, by the processing resource, an access control list to include one or more workload rules allowing the set of workloads.   
     
     
         2 . The method of  claim 1 , wherein the network element is selected from a group consisting of: a network endpoint, a network appliance, an application, and a port of a network appliance. 
     
     
         3 . The method of  claim 1 , wherein the set of network traffic is a first set of network traffic, wherein the set of workloads is a first set of workloads, the method further comprising:
 monitoring, by the processing resource, network activity to yield a second set of network traffic;   identifying, by the processing resource, a second set of workloads in the second set of network traffic that are either sourced from any of the at least one network focus, or destined to any of the at least one network focus;   identifying, by the processing resource, at least one workload in the second set of workloads that is not in the first set of workloads; and   augmenting, by the processing resource, the access control list to include the at least one workload in the second set of workloads that is not in the first set of workloads.   
     
     
         4 . The method of  claim 1 , wherein the network element is a first network element, the method further comprising:
 identifying, by the processing resource, a second network element that is either the source of a workload in the set of workloads or a destination of a workload in the set of workloads; and   augmenting, by the processing resource, the focus list to include the second network element.   
     
     
         5 . The method of  claim 4 , wherein the set of network traffic is a first set of network traffic, wherein the set of workloads is a first set of workloads, the method further comprising:
 monitoring, by the processing resource, network activity to yield a second set of network traffic;   identifying, by the processing resource, a second set of workloads in the second set of network traffic that are either sourced from any of the at least one network focus, or destined to any of the at least one network element; and   identifying, by the processing resource, at least one workload in the second set of workloads that is not in the first set of workloads; and   augmenting, by the processing resource, the access control list to include the at least one workload in the second set of workloads that is not in the first set of workloads.   
     
     
         6 . The method of  claim 1 , the method further comprising:
 identifying, by the processing resource, a first application associated with two or more workloads in the set of workloads, and a second application associated with two or more other workloads in the set of workloads;   wherein augmenting, by the processing resource, the access control list to include one or more workload rules allowing the set of workloads is an incremental modification, and wherein the incremental modification includes:
 augmenting, by the processing device, the access control list to include first workload rules corresponding to the two or more workloads associated with the first application to yield a first augmented access control list; 
 forward testing, by the processing device, the first augmented access control list; 
 subsequent to forward testing the first augmented access control list, augmenting, by the processing device, the first access control list to include second workload rules corresponding to the two or more workloads associated with the second application to yield a second augmented access control list; and 
 forward testing, by the processing device, the second augmented access control list. 
   
     
     
         7 . The method of  claim 6 , wherein the access control list includes a default rule that allows any network traffic between any source and any destination, and wherein the forward testing the first augmented access control list comprises:
 applying the first workload rules; and   applying the default rule after the first workload rules.   
     
     
         8 . The method of  claim 6 , wherein the access control list includes a default rule that allows any network traffic between any source and any destination, and wherein the forward testing the second augmented access control list comprises:
 applying the first workload rules;   applying the second workload rules; and   applying the default rule after applying all of the first workload rules and the second workload rules.   
     
     
         9 . The method of  claim 1 , wherein the access control list includes a default rule that allows any network traffic between any source and any destination. 
     
     
         10 . The method of  claim 9 , the method further comprising:
 modifying, by the processing resource, the default rule to block any network traffic between any source and any destination.   
     
     
         11 . A network appliance, the network appliance comprising:
 a processing resource;   a non-transitory computer-readable medium, coupled to the processing resource, having stored therein instructions that when executed by the processing resource cause the processing resource to:   access a focus list, wherein the focus list identifies at least one network element;   monitor network activity to yield a set of network traffic;   identify a set of workloads in the set of network traffic that are either sourced from any of the at least one network focus, or destined to any of the at least one network element; and   augment an access control list to include one or more workload rules allowing the set of workloads.   
     
     
         12 . The network appliance of  claim 11 , wherein the network element is selected from a group consisting of: a network endpoint, a network appliance, an application, and a port of a network appliance. 
     
     
         13 . The network appliance of  claim 11 , wherein the set of network traffic is a first set of network traffic, wherein the set of workloads is a first set of workloads, and wherein the instructions that when executed by the processing resource cause the processing resource further to:
 monitor network activity to yield a second set of network traffic;   identify a second set of workloads in the second set of network traffic that are either sourced from any of the at least one network focus, or destined to any of the at least one network focus;   identify at least one workload in the second set of workloads that is not in the first set of workloads; and   augment the access control list to include the at least one workload in the second set of workloads that is not in the first set of workloads.   
     
     
         14 . The network appliance of  claim 11 , wherein the network element is a first network element, and wherein the instructions that when executed by the processing resource cause the processing resource further to:
 identify a second network element that is either the source of a workload in the set of workloads or a destination of a workload in the set of workloads; and   augment the focus list to include the second network element.   
     
     
         15 . The network appliance of  claim 11 , wherein the set of network traffic is a first set of network traffic, wherein the set of workloads is a first set of workloads, and wherein the instructions that when executed by the processing resource cause the processing resource further to:
 monitor network activity to yield a second set of network traffic;   identify a second set of workloads in the second set of network traffic that are either sourced from any of the at least one network focus, or destined to any of the at least one network element;   identify at least one workload in the second set of workloads that is not in the first set of workloads; and   augment the access control list to include the at least one workload in the second set of workloads that is not in the first set of workloads.   
     
     
         16 . The network appliance of  claim 11 , wherein the access control list includes a default rule that allows any network traffic between any source and any destination. 
     
     
         17 . The network appliance of  claim 16 , and wherein the instructions that when executed by the processing resource cause the processing resource further to:
 modify the default rule to block any network traffic between any source and any destination.   
     
     
         18 . A non-transitory computer-readable storage medium embodying a set of instructions, which when executed by a processing resource, causes the processing resource to:
 access a focus list, wherein the focus list identifies at least one network element;   monitor network activity to yield a set of network traffic;   identify a set of workloads in the set of network traffic that are either sourced from any of the at least one network focus, or destined to any of the at least one network element; and   augment an access control list to include one or more workload rules allowing the set of workloads.   
     
     
         19 . The non-transitory computer-readable storage medium of  claim 18 , wherein the network element is selected from a group consisting of: a network endpoint, a network appliance, an application, and a port of a network appliance. 
     
     
         20 . The non-transitory computer-readable storage medium of  claim 18 , wherein the set of network traffic is a first set of network traffic, wherein the set of workloads is a first set of workloads, and wherein the instructions that when executed by the processing resource cause the processing resource further to:
 monitor network activity to yield a second set of network traffic;   identify a second set of workloads in the second set of network traffic that are either sourced from any of the at least one network focus, or destined to any of the at least one network focus;   identify at least one workload in the second set of workloads that is not in the first set of workloads; and   augment the access control list to include the at least one workload in the second set of workloads that is not in the first set of workloads.

Join the waitlist — get patent alerts

Track US2022400113A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.