-
公开(公告)号:US20230262087A1
公开(公告)日:2023-08-17
申请号:US18306947
申请日:2023-04-25
Applicant: Amazon Technologies, Inc.
Inventor: Catherine Dodge , Nikhil Reddy Cheruku , John Byron Cook , Temesghen Kahsai Azene , William Jo Kocik , Sean McLaughlin , Mark Edward Stalzer , Blake Whaley , Yiwen Wu
IPC: H04L9/40 , H04L41/0866 , H04L41/12 , H04L41/22 , H04L43/06
CPC classification number: H04L63/1433 , H04L41/0866 , H04L41/12 , H04L41/22 , H04L43/06 , H04L63/0272 , H04L63/1441
Abstract: Methods, systems, and computer-readable media for automated packetless network reachability analysis are disclosed. An analysis is performed of network configuration data for a network comprising a host computer. Based at least in part on the analysis, one or more ports at the host computer that are reachable from another computer are determined. Based at least in part on the analysis, one or more routes to the one or more ports are determined. A report is generated that is descriptive of the one or more ports and the one or more routes.
-
公开(公告)号:US11616800B2
公开(公告)日:2023-03-28
申请号:US16985954
申请日:2020-08-05
Applicant: Amazon Technologies, Inc.
Inventor: John Cook , Neha Rungta , Catherine Dodge , Jeff Puchalski , Carsten Varming
IPC: H04L9/40 , H04L41/0869 , H04L41/22 , G06F21/55 , G06F21/57 , G06F21/60 , H04L41/0893
Abstract: Security policies may be utilized to grant or deny permissions related to the access of computing resources. Two or more security policies may be compared to determine whether the policies are equivalent, whether one security is more permissive than another, and more. In some cases, it may be possible to identify whether there exists a security permission that is sufficient to determine two security policies lack equivalency. Propositional logics may be utilized in the evaluation of security policies.
-
公开(公告)号:US11108805B2
公开(公告)日:2021-08-31
申请号:US16020865
申请日:2018-06-27
Applicant: Amazon Technologies, Inc.
Inventor: Catherine Dodge , Nikhil Reddy Cheruku , John Byron Cook , Temesghen Kahsai Azene , William Jo Kocik , Sean McLaughlin , Mark Edward Stalzer , Blake Whaley , Yiwen Wu
IPC: G06F21/00 , H04L29/06 , G06F16/2455 , H04L12/24 , H04L12/26
Abstract: Methods, systems, and computer-readable media for automated packetless network reachability analysis are disclosed. An analysis is performed of network configuration data for a network comprising a host computer. Based at least in part on the analysis, one or more ports at the host computer that are reachable from another computer are determined. Based at least in part on the analysis, one or more routes to the one or more ports are determined. A report is generated that is descriptive of the one or more ports and the one or more routes.
-
公开(公告)号:US11017107B2
公开(公告)日:2021-05-25
申请号:US15913741
申请日:2018-03-06
Applicant: Amazon Technologies, Inc.
Inventor: Neha Rungta , Pauline Virginie Bolignano , Catherine Dodge , Carsten Varming , John Cook , Rajesh Viswanathan , Daryl Stephen Cooke , Santosh Kalyankrishnan
Abstract: A security assessment system of a computing resource service provider performs security analyses of virtual resource instances, such as virtual machine instances and virtual data store instances, to verify that certain invariable security requirements are satisfied by the instances' corresponding configurations; these analyses are performed before the instances are provisioned and deployed. If the security checks, which can be selected by the administrator of the resources, fail, the requested resources are denied deployment. Notifications identifying the faulty configuration(s) may be send to the administrative user. A template for launching virtual resource instances may be transformed into an optimized template for performing the pre-deployment security checks, such as by storing information needed to perform the checks within the optimized template itself.
-
公开(公告)号:US20200067785A1
公开(公告)日:2020-02-27
申请号:US16672120
申请日:2019-11-01
Applicant: Amazon Technologies, Inc.
Inventor: John Cook , Catherine Dodge , Sean McLaughlin
Abstract: A virtual network verification service for provider networks that leverages a declarative logic programming language to allow clients to pose queries about their virtual networks as constraint problems; the queries may be resolved using a constraint solver engine. Semantics and logic for networking primitives of virtual networks in the provider network environment may be encoded as a set of rules according to the logic programming language; networking security standards and/or client-defined rules may also be encoded in the rules. A description of a virtual network may be obtained and encoded. A constraint problem expressed by a query may then be resolved for the encoded description according to the encoded rules using the constraint solver engine; the results may be provided to the client.
-
公开(公告)号:US20200007569A1
公开(公告)日:2020-01-02
申请号:US16020865
申请日:2018-06-27
Applicant: Amazon Technologies, Inc.
Inventor: Catherine Dodge , Nikhil Reddy Cheruku , John Byron Cook , Temesghen Kahsai Azene , William Jo Kocik , Sean McLaughlin , Mark Edward Stalzer , Blake Whaley , Yiwen Wu
Abstract: Methods, systems, and computer-readable media for automated packetless network reachability analysis are disclosed. An analysis is performed of network configuration data for a network comprising a host computer. Based at least in part on the analysis, one or more ports at the host computer that are reachable from another computer are determined. Based at least in part on the analysis, one or more routes to the one or more ports are determined. A report is generated that is descriptive of the one or more ports and the one or more routes.
-
公开(公告)号:US10469324B2
公开(公告)日:2019-11-05
申请号:US15359500
申请日:2016-11-22
Applicant: Amazon Technologies, Inc.
Inventor: John Cook , Catherine Dodge , Sean McLaughlin
Abstract: A virtual network verification service for provider networks that leverages a declarative logic programming language to allow clients to pose queries about their virtual networks as constraint problems; the queries may be resolved using a constraint solver engine. Semantics and logic for networking primitives of virtual networks in the provider network environment may be encoded as a set of rules according to the logic programming language; networking security standards and/or client-defined rules may also be encoded in the rules. A description of a virtual network may be obtained and encoded. A constraint problem expressed by a query may then be resolved for the encoded description according to the encoded rules using the constraint solver engine; the results may be provided to the client.
-
公开(公告)号:US20190007418A1
公开(公告)日:2019-01-03
申请号:US15637238
申请日:2017-06-29
Applicant: Amazon Technologies, Inc.
Inventor: John Cook , Neha Rungta , Catherine Dodge , Jeff Puchalski , Carsten Varming
IPC: H04L29/06
Abstract: Requests of a computing system may be monitored. A request associated with the application of a policy may be identified and a policy verification routine may be invoked. The policy verification routine may detect whether the policy of the request is more permissive than a reference policy and perform a mitigation routine in response to determining that the policy of the request is more permissive than the reference policy. Propositional logics may be utilized in the evaluation of policies.
-
公开(公告)号:US20250016057A1
公开(公告)日:2025-01-09
申请号:US18892128
申请日:2024-09-20
Applicant: Amazon Technologies, Inc.
Inventor: John Cook , Catherine Dodge , Sean McLaughlin
Abstract: A virtual network verification service for provider networks that leverages a declarative logic programming language to allow clients to pose queries about their virtual networks as constraint problems; the queries may be resolved using a constraint solver engine. Semantics and logic for networking primitives of virtual networks in the provider network environment may be encoded as a set of rules according to the logic programming language; networking security standards and/or client-defined rules may also be encoded in the rules. A description of a virtual network may be obtained and encoded. A constraint problem expressed by a query may then be resolved for the encoded description according to the encoded rules using the constraint solver engine; the results may be provided to the client.
-
公开(公告)号:US20210377126A1
公开(公告)日:2021-12-02
申请号:US17400057
申请日:2021-08-11
Applicant: Amazon Technologies, Inc.
Inventor: John Cook , Catherine Dodge , Sean McLaughlin
Abstract: A virtual network verification service for provider networks that leverages a declarative logic programming language to allow clients to pose queries about their virtual networks as constraint problems; the queries may be resolved using a constraint solver engine. Semantics and logic for networking primitives of virtual networks in the provider network environment may be encoded as a set of rules according to the logic programming language; networking security standards and/or client-defined rules may also be encoded in the rules. A description of a virtual network may be obtained and encoded. A constraint problem expressed by a query may then be resolved for the encoded description according to the encoded rules using the constraint solver engine; the results may be provided to the client.
-
-
-
-
-
-
-
-
-