×

Elastic Enforcement Layer for Cloud Security Using SDN

  • US 20130332983A1
  • Filed: 06/12/2012
  • Published: 12/12/2013
  • Est. Priority Date: 06/12/2012
  • Status: Active Grant
First Claim
Patent Images

1. A method performed by a controller in a split architecture network to control network connectivity for a cloud computing environment, the split architecture network including a plurality of switches coupled to the controller, wherein the controller manages policy enforcement for network security for a plurality of virtual machines (VMs) including a source VM and a destination VM that execute applications in the cloud computing environment and exchange data via the split architecture network, the method comprising the steps of:

  • receiving by the controller a packet originating from the source VM;

    extracting by the controller an application identifier from the received packet, the application identifier identifying an application running on the source VM;

    determining by the controller a chain of middlebox types based on the application identifier;

    mapping by the controller one or more of the middlebox types in the chain to corresponding one or more middlebox instances based on current availability of resources in the cloud computing environment, wherein one or more of the middlebox instances perform network security operations on the packet; and

    adding by the controller a set of rules to the switches to cause the switches to forward the packet toward the destination VM via the one or more middlebox instances to thereby enforce network security in the cloud computing environment.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×