Automating Security Policy Migration from Legacy Platforms to Cloud-Native Security Controls

Main Article Content

Bharathi Sesha Sai Varanasi

Abstract

Current legacy infrastructures become increasingly incapable of handling challenges created by dynamically changing cloud-native environments. Manual conversion of the policy sets during migrations may cause policy configuration mismatches, semantic discrepancies, and long exposure time windows that negatively affect the security stance of an organization. In this paper, we investigate the concept of automatic migration of legacy firewall policies into cloud-native control constructs through rule extraction, semantic transformation, and formal validation. Various vendor-based configurations were transformed into the same intermediate representation, then converted into cloud-native controls while considering zero-trust microsegmentation principles. The experiment carried out on synthetic multi-cloud hybrid environments revealed 96.4% accuracy of semantic transformation, 96 times faster configuration drift detection, and better coverage for least privilege control of 94% of traffic flows (versus 61%). Automation of discrepancy identification led to a decrease in time needed for remediation by 88%. Testing of scalability showed the linear effectiveness of the process on AWS, Azure, and GCP. Thus, the use of automated, verified migration pipelines is much more efficient than manual translations in terms of accuracy and process speed. Nonetheless, there are certain problems with nested legacy policies and API limitations of different providers. Contribution of the study is the methodology of enterprise security migration to the cloud.

Article Details

Section
Articles