Dynamic segmentation in an industrial network based on inventory tags
Abstract
According to one or more embodiments of the disclosure, a service obtains one or more component tags and one or more activity tags that were assigned to an endpoint device in a network based on deep packet inspection of traffic associated with the endpoint device. The service determines an intent of the endpoint device, using the one or more component tags and the one or more activity tags that were assigned to the endpoint device. The service translates the intent of the endpoint device into a network segmentation policy. The service configures a network overlay in the network that implements the network segmentation policy.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
obtaining, by a service, one or more component tags and one or more activity tags that were assigned to an endpoint device in a network based on deep packet inspection of traffic associated with the endpoint device; determining, by the service, an intent of the endpoint device, using the one or more component tags and the one or more activity tags that were assigned to the endpoint device; translating, by the service, the intent of the endpoint device into a network segmentation policy; and configuring, by the service, a network overlay in the network that implements the ii network segmentation policy.
2 . The method as in claim 1 , wherein determining the intent of the endpoint device comprises:
receiving, at the service, an indication of one or more scalable group tags for the endpoint device; and associating, by the service, the one or more scalable group tags with the endpoint device.
3 . The method as in claim 2 , wherein translating the intent of the endpoint device into a network segmentation policy comprises:
generating a security group access control list, based on the one or more scalable group tags associated with the endpoint device; and wherein configuring the network overlay in the network comprises: sending the security group access control list to networking equipment in the network.
4 . The method as in claim 2 , wherein indication of the one or more scalable group tags is received via a user interface.
5 . The method as in claim 1 , wherein the network overlay restricts the endpoint device to communicating only with a subset of senders or receivers via the network, and wherein the network overlay further restricts the endpoint device to sending or receiving only a specific type of application traffic via the network.
6 . The method as in claim 5 , wherein the one or more component tags are indicative of a physical location of the endpoint device, and wherein one or more of the senders or receivers in the subset are also located in that physical location.
7 . The method as in claim 1 , wherein the endpoint device comprises a programmable logic controller (PLC) or variable-frequency drive (VFD).
8 . The method as in claim 1 , wherein the network overlay is implemented as a Virtual Extensible Local Area Network (VxLAN) overlay in the network.
9 . An apparatus, comprising:
one or more network interfaces to communicate with a network; a processor coupled to the one or more network interfaces and configured to execute one or more processes; and a memory configured to store a process that is executable by the processor, the process when executed configured to:
obtain one or more component tags and one or more activity tags that were assigned to an endpoint device in a network based on deep packet inspection of traffic associated with the endpoint device;
determine an intent of the endpoint device, using the one or more component tags and the one or more activity tags that were assigned to the endpoint device;
translate the intent of the endpoint device into a network segmentation policy; and
is configure a network overlay in the network that implements the network segmentation policy.
10 . The apparatus as in claim 9 , wherein the apparatus determines the intent of the endpoint device by:
receiving an indication of one or more scalable group tags for the endpoint device; and associating the one or more scalable group tags with the endpoint device.
11 . The apparatus as in claim 10 , wherein the apparatus translates the intent of the endpoint device into a network segmentation policy by:
generating a security group access control list, based on the one or more scalable group tags associated with the endpoint device; and wherein configuring the network overlay in the network comprises: sending the security group access control list to networking equipment in the network.
12 . The apparatus as in claim 11 , wherein indication of the one or more scalable group tags is received via a user interface.
13 . The apparatus as in claim 9 , wherein the network overlay restricts the endpoint device to communicating only with a subset of senders or receivers via the network, and wherein the network overlay further restricts the endpoint device to sending or receiving only a specific type of application traffic via the network.
14 . The apparatus as in claim 13 , wherein the one or more component tags are indicative of a physical location of the endpoint device, and wherein one or more of the senders or receivers in the subset are also located in that physical location.
15 . The apparatus as in claim 9 , wherein the endpoint device comprises a programmable logic controller (PLC) or variable-frequency drive (VFD).
16 . The apparatus as in claim 9 , wherein the network overlay is implemented as a Virtual Extensible Local Area Network (VxLAN) overlay in the network.
17 . A tangible, non-transitory, computer-readable medium storing program instructions that cause a service to execute a process comprising:
obtaining, by the service, one or more component tags and one or more activity tags that were assigned to an endpoint device in a network based on deep packet inspection of traffic associated with the endpoint device; determining, by the service, an intent of the endpoint device, using the one or more component tags and the one or more activity tags that were assigned to the endpoint device; translating, by the service, the intent of the endpoint device into a network segmentation policy; and configuring, by the service, a network overlay in the network that implements the network segmentation policy.
18 . The computer-readable medium as in claim 17 , wherein determining the intent of the endpoint device comprises:
receiving, at the service, an indication of one or more scalable group tags for the endpoint device; and associating, by the service, the one or more scalable group tags with the endpoint device.
19 . The computer-readable medium as in claim 18 , wherein translating the intent of the endpoint device into a network segmentation policy comprises:
generating a security group access control list, based on the one or more scalable group tags associated with the endpoint device; and wherein configuring the network s overlay in the network comprises: sending the security group access control list to networking equipment in the network.
20 . The computer-readable medium as in claim 19 , wherein the network overlay restricts the endpoint device to communicating only with a subset of senders or receivers via the network, and wherein the network overlay further restricts the endpoint device to sending or receiving only a specific type of application traffic via the network.Join the waitlist — get patent alerts
Track US2021194760A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.