IP Library Granted Patent US 7,376,965
Granted Patent B2
US 7,376,965 · App. 09/861,986 · Granted May 20, 2008

System and method for implementing a bubble policy to achieve host and network security

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,376,965
App. No.
09/861,986
Granted
May 20, 2008
Kind
B2
Abstract

A method of creating a structured access list template, which includes dividing an access list template into a plurality of sections, creating an inbound local rule group for the bubble, creating an outbound local rule group for the bubble, creating an inbound remote rule group for the bubble, and creating an outbound remote rule group for the bubble. A method of creating an access list for each of the plurality of bubble boundary devices, which includes creating an address table that includes a plurality of addresses corresponding to devices in a bubble partition, creating a protocol table that includes a list of network services and whether each of the network services are granted or denied access to the bubble partition, creating an access list template using the address table and the protocol table, generating an access list from the access list template, and providing the access list to one of the plurality of bubble boundary devices.

Claims (29)

1. In a network security system having a plurality of bubbles, where each bubble has a plurality of bubble partitions, a method of creating a structured access list template, the method comprising:

dividing a first access list template into a plurality of sections, where each section includes rules that implement a function;

assigning a first plurality of network devices to a first bubble;

assigning a second plurality of network devices to a second bubble;

creating an inbound local rule group for the first bubble;

creating an outbound local rule group for the first bubble;

creating an inbound remote rule group for the first bubble for use by the second bubble for allowing access from the first plurality of network devices of the first bubble;

creating an outbound remote rule group for the first bubble for use by the second bubble for allowing access to the plurality of network devices of the first bubble;

arranging the inbound local rule group and the outbound local rule group in one of the plurality of sections of the first access list template; and

arranging the inbound remote rule group and the outbound remote rule group in one of the plurality of sections of the first access list template.

2. A method as defined in claim 1 , further comprising arranging the inbound remote rule group and the outbound remote rule group from another bubble access list template in the first access list template.

3. A method as defined in claim 1 , further comprising dividing a second access list template into a plurality of sections, where each section includes rules that implement a function.

4. A method as defined in claim 3 , further comprising arranging the inbound local rule group and the outbound local rule group in the second access list template.

5. A method as defined in claim 3 , further comprising arranging the inbound remote rule group and the outbound remote rule group from another bubble access list template in the second access list template.

6. A method of creating a structured network for providing security comprising:

assigning a first plurality of network devices to a first bubble;

assigning a second plurality of network devices to a second bubble;

providing a first access list template having a plurality of sections, where each section includes rules that implement a function;

providing an inbound local rule group for the first bubble;

providing an outbound local rule group for the first bubble;

providing an inbound remote rule group for the first bubble for use by the second bubble for allowing access from the first plurality of network devices of the first bubble;

providing an outbound remote rule group for the first bubble for use by the second bubble for allowing access to the first plurality of network devices of the first bubble;

arranging the inbound local rule group and the outbound local rule group in one of the plurality of sections of the first access list template;

arranging the inbound remote rule group and the outbound remote rule group in one of the plurality of sections of the first access list template; and

utilizing the first access list template to ensure consistency in implementation of network security policies between the first bubble and the second bubble.

7. A method as defined in claim 6 , further comprising arranging the inbound remote rule group and the outbound remote rule group from another bubble access list template in the first access list template.

8. A method as defined in claim 6 , further comprising providing a second access list template having a plurality of sections, where each section includes rules that implement a function.

9. A method as defined in claim 8 , further comprising arranging the inbound local rule group and the outbound local rule group in the second access list template.

10. A method as defined in claim 8 , further comprising arranging the inbound remote rule group and the outbound remote rule group from another bubble access list template in the second access list template.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2021
From: OT PATENT ESCROW, LLC
To: VALTRUS INNOVATIONS LIMITED
Reel/Frame 056157/0492 →
PATENT ASSIGNMENT, SECURITY INTEREST, AND LIEN AGREEMENT Recorded Jan 26, 2021
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP; HEWLETT PACKARD ENTERPRISE COMPANY
To: OT PATENT ESCROW, LLC
Reel/Frame 055269/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THIRD ASSIGNOR'S NAME FROM PEDERSON, LEIF-BUCH, SERIAL NUMBER FROM 09908602 AND FILING DATE FROM 07/20/2001 PREVIOUSLY RECORDED ON REEL 012485 FRAME 0982. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 26, 2020
From: JEMES, BRIAN L.; BRAWN, JOHN; BUCH-PEDERSON, LEIF
To: HEWLETT-PACKARD COMPANY
Reel/Frame 052496/0472 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →