Invention Grant
- Patent Title: Security policy generation for virtualization, bare-metal server, and cloud computing environments
-
Application No.: US15201351Application Date: 2016-07-01
-
Publication No.: US10264025B2Publication Date: 2019-04-16
- Inventor: Marc Woolward
- Applicant: vArmour Networks, Inc.
- Applicant Address: US CA Mountain View
- Assignee: vArmour Networks, Inc.
- Current Assignee: vArmour Networks, Inc.
- Current Assignee Address: US CA Mountain View
- Agency: Carr & Ferrell LLP
- Main IPC: G06F17/00
- IPC: G06F17/00 ; H04L29/06 ; G06F9/455

Abstract:
Methods, systems, and media for security in virtualization, bare-metal server, and cloud computing environments are provided herein. Exemplary methods include: receiving network traffic associated with a primary workload; generating first metadata using the network traffic; determining a primary categorization associated with the primary workload, using the first metadata; confirming the primary categorization is reliable; determining a secondary categorization associated with at least one secondary workload, the at least one secondary workload being communicatively coupled to the primary workload; ascertaining the primary categorization and the secondary categorization are consistent with each other and are each stable; producing a model using the primary categorization and the secondary categorization; checking the model for sustained convergence; and generating a high-level declarative security policy associated with the primary workload using the model, the high-level declarative security policy indicating at least an application or service with which the primary workload can communicate.
Public/Granted literature
- US20170374101A1 Security Policy Generation for Virtualization, Bare-Metal Server, and Cloud Computing Environments Public/Granted day:2017-12-28
Information query