System and method for context aware network filtering
US-2017295031-A1 · Oct 12, 2017 · US
US10320749B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10320749-B2 |
| Application number | US-201615344591-A |
| Country | US |
| Kind code | B2 |
| Filing date | Nov 7, 2016 |
| Priority date | Nov 7, 2016 |
| Publication date | Jun 11, 2019 |
| Grant date | Jun 11, 2019 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Example methods are provided for a network management entity to perform firewall rule creation in a virtualized computing environment. The method may comprise obtaining flow data associated with an application-layer protocol session between a first endpoint and a second endpoint in the virtualized computing environment; and identifying, from the flow data, an association between a control flow and at least one data flow of the application-layer protocol session. The method may also comprise: based on the association, creating a firewall rule that is applicable to both the control flow and at least one data flow; and instructing a first firewall engine associated with the first endpoint, or a second firewall engine associated with the second endpoint, or both, to apply the firewall rule during the application-layer protocol session.
Opening claim text (preview).
We claim: 1. A method for a network management entity to perform firewall rule creation in a virtualized computing environment that includes the network management entity, a first endpoint and a second endpoint, wherein the method comprises: obtaining flow data associated with an application-layer protocol session between the first endpoint and second endpoint; identifying, from the flow data, an association between a control flow and at least one data flow of the application-layer protocol session; based on the association, creating a firewall rule that is applicable to both the control flow and at least one data flow; and instructing a first firewall engine associated with the first endpoint, or a second firewall engine associated with the second endpoint, or both, to apply the firewall rule during the application-layer protocol session, wherein the first firewall engine, or the second firewall engine, or both processes packets in response to the instructing to apply the firewall rule. 2. The method of claim 1 , wherein creating the firewall rule comprises: creating the firewall rule based on the control flow, while ignoring the at least one data flow during firewall rule creation. 3. The method of claim 2 , wherein creating the firewall rule comprises: creating the firewall rule to allow communication via a control port number associated with the control flow, wherein at least one ephemeral data port number is dynamically negotiated for the respective at least one data flow through the control flow. 4. The method of claim 3 , wherein creating the firewall rule comprises: creating the firewall rule to specify an application-layer protocol for which application-layer gateway (ALG) processing is supported by the first firewall engine, the second firewall engine, or both, wherein the ALG processing is to allow communication via the at least one ephemeral data port number based on the firewall rule. 5. The method of claim 1 , wherein identifying the association comprises: traversing a tree structure in the flow data to identify the association based on a parent node and at least one child node linked to the parent node, wherein the parent node represents the control flow and the at least one child node represents respective at least one data flow. 6. The method of claim 1 , wherein obtaining the flow data comprises: obtaining the tree structure from the first firewall engine, the second firewall engine, or both. 7. The method of claim 1 , wherein obtaining the flow data comprises: obtaining the flow data associated with the application-layer protocol session that utilizes one of the following application-layer protocols: File Transfer Protocol (FTP), Remote Procedure Call (RPC), Common Internet File System (CIFS), Transparent Network Substrate (TNS) and Trivial File Transfer Protocol (TFTP). 8. A non-transitory computer-readable storage medium that includes a set of instructions which, in response to execution by a processor of a network management entity, cause the processor to perform a method of firewall rule creation in a virtualized computing environment that includes the network management entity, a first endpoint and a second endpoint, wherein the method comprises: obtaining flow data associated with an application-layer protocol session between the first endpoint and second endpoint; identifying, from the flow data, an association between a control flow and at least one data flow of the application-layer protocol session; based on the association, creating a firewall rule that is applicable to both the control flow and at least one data flow; and instructing a first firewall engine associated with the first endpoint, or a second firewall engine associated with the second endpoint, or both, to apply the firewall rule during the application-layer protocol session, wherein the first firewall engine, or the second firewall engine, or both processes packets in response to the instructing to apply the firewall rule. 9. The non-transitory computer-readable storage medium of claim 8 , wherein creating the firewall rule comprises: creating the firewall rule based on the control flow, while ignoring the at least one data flow during firewall rule creation. 10. The non-transitory computer-readable storage medium of claim 9 , wherein creating the firewall rule comprises: creating the firewall rule to allow communication via a control port number associated with the control flow, wherein at least one ephemeral data port number is dynamically negotiated for the respective at least one data flow through the control flow. 11. The non-transitory computer-readable storage medium of claim 10 , wherein creating the firewall rule comprises: creating the firewall rule to specify an application-layer protocol for which application-layer gateway (ALG) processing is supported by the first firewall engine, the second firewall engine, or both, wherein the ALG processing is to allow communication via the at least one ephemeral data port number based on the firewall rule. 12. The non-transitory computer-readable storage medium of claim 8 , wherein identifying the association comprises: traversing a tree structure in the flow data to identify the association based on a parent node and at least one child node linked to the parent node, wherein the parent node represents the control flow and the at least one child node represents respective at least one data flow. 13. The non-transitory computer-readable storage medium of claim 8 , wherein obtaining the flow data comprises: obtaining the tree structure from the first firewall engine, the second firewall engine, or both. 14. The non-transitory computer-readable storage medium of claim 8 , wherein obtaining the flow data comprises: obtaining the flow data associated with the application-layer protocol session that utilizes one of the following application-layer protocols: File Transfer Protocol (FTP), Remote Procedure Call (RPC), Common Internet File System (CIFS), Transparent Network Substrate (TNS) and Trivial File Transfer Protocol (TFTP). 15. A computer system configured to perform firewall rule creation in a virtualized computing environment, the computer system comprising: a processor; and a non-transitory computer-readable medium having stored thereon instructions that, when executed by the processor, cause the processor to: obtain flow data associated with an application-layer protocol session between a first endpoint and a second endpoint in the virtualized computing environment; identify, from the flow data, an association between a control flow and at least one data flow of the application-layer protocol session; based on the association, create a firewall rule that is applicable to both the control flow and at least one data flow; and instruct a first firewall engine associated with the first endpoint, or a second firewall engine associated with the second endpoint, or both, to apply the firewall rule during the application-layer protocol session, wherein the first firewall engine, or the second firewall engine, or both processes packets in response to the processor instructing to apply the firewall rule. 16. The computer system of claim 15 , wherein instructions for creating the firewall rule cause the processor to: create the firewall rule based on the control flow, while ignoring the at least one data flow during firewall rule creation. 17. The computer system of claim 16 , wherein instructions for creating the firewall rule cause the processor to: create the firewall rule to allow communication via
Filtering by information in the payload · CPC title
Rule management · CPC title
Distributed architectures, e.g. distributed firewalls · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.