Patent attributes
A pluggable cloud security system includes a plurality of nodes. Each node has a memory and a processor. At least one memory is configured to store rules indicating criteria for allowing communication between user applications and a hosted application executed by a cloud infrastructure. At least one processor is configured to receive data to be communicated to the cloud application, determine a source of the received data as a first user application, determine a channel used to transmit the received data, and determine, using the rules, whether the source and the channel satisfy criteria for allowing communication between the first user application and the hosted application. If it is determined that the source satisfies the first criteria, transmission of the data is allowed. Otherwise, transmission of the data is prevented.