Invention Grant
- Patent Title: Securing network-based compute resources using tags
-
Application No.: US16236826Application Date: 2018-12-31
-
Publication No.: US11184363B2Publication Date: 2021-11-23
- Inventor: Mathias Abraham Marc Scherman , Ben Kliger , Evan Clarke Smith
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agency: Fiala & Weaver P.L.L.C.
- Main IPC: G06F21/00
- IPC: G06F21/00 ; H04L29/06 ; G06N20/00

Abstract:
Embodiments described herein are directed to securing network-based compute resources. The foregoing may be achieved by determining a tag representative of non-malicious network addresses. The tag is determined by analyzing network data traffic received by a plurality of compute resources. Machine-learning based techniques may be used to automatically classify each network address that communicates with a particular compute resource as being malicious or non-malicious. Determined non-malicious network addresses for a particular compute resource are automatically associated with a tag. The tag is used to configure a firewall application to prevent access to a corresponding compute resource by malicious network addresses not represented by the tag. The number of non-malicious network addresses associated with a tag may be expanded by clustering compute resources having a similar set of network addresses that communicate therewith. The non-malicious network addresses determined for the clustered compute resources are combined and associated with a single tag.
Public/Granted literature
- US20200213325A1 SECURING NETWORK-BASED COMPUTE RESOURCES USING TAGS Public/Granted day:2020-07-02
Information query