Incrementally validating security policy code using information from an infrastructure as code repository

    公开(公告)号:US11977476B2

    公开(公告)日:2024-05-07

    申请号:US17587896

    申请日:2022-01-28

    CPC classification number: G06F11/368 G06F11/3664 G06F11/3692 H04L63/20

    Abstract: In an example, an apparatus may include a validation module configured to identify a security policy update from a security as code repository, wherein the identified security policy update is a candidate for deployment to a production environment having a plurality of attributes defined by an infrastructure as code repository; identify, from the plurality of attributes and using the infrastructure as code repository, individual attributes that correspond to the identified security policy update, wherein the identified individual attributes are identical to a subset of the plurality of attributes; generate a test environment based on the identified individual attributes; following deployment of the identified security policy update to the test environment, check for security exceptions or availability exceptions using the test environment; and output validation results based on a result of the checking.

    AUTOMATION OF CLOUD NETWORK SECURITY POLICY ANALYSIS AND DEPLOYMENT

    公开(公告)号:US20220086193A1

    公开(公告)日:2022-03-17

    申请号:US17248529

    申请日:2021-01-28

    Abstract: Disclosed are examples of systems, apparatus, methods and computer program products for automation of network security policy analysis and deployment. A server system can obtain a system input comprising two versions of a policy output. The system can generate a severity characteristic that indicates a severity of deploying the second version of the policy output. The system can then determine whether to deploy the second version of the policy output based on the severity characteristic. The system can then, in response to determining that the second version of the policy output is to be deployed, deploy the second version of the policy output to one of a plurality of clouds.

Patent Agency Ranking