IP Library Granted Patent US 10,367,787
Granted Patent B2
US 10,367,787 · App. 15/038,388 · Granted Jul 30, 2019

Intelligent firewall access rules

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,367,787
App. No.
15/038,388
Granted
Jul 30, 2019
Kind
B2
Abstract

A firewall provides improved network security by allowing the use of dynamic objects in firewall rules, where the dynamic objects evaluate to a variable set of devices. The dynamic objects may be updated from real-time data sources and non-real time inventories of data. Dynamic objects may be used for either or both of source and destination in a firewall rule. Where the dynamic object includes non-real time data, the dynamic object may be synchronized with the non-real time data inventory on a configurable basis. By using dynamic objects, the firewall can provide flexibility in the rules to allow control over user-owned and controlled devices.

Claims (68)

1. A machine readable storage device or storage disk comprising instructions that, when executed, cause a firewall device to at least:

create a dynamic object for a firewall rule, the dynamic object to define a variable set of devices that satisfy a plurality of conditions included in the dynamic object, the dynamic object to be created by:

accessing device data from a real-time data source external to the firewall device;

analyzing the device data from the real-time data source to determine information identifying a first set of devices that satisfy a first one of the plurality of conditions included in the dynamic object; and

populating the dynamic object with the information identifying the first set of devices that satisfy the first one of the plurality of conditions;

evaluate the dynamic object for a first device associated with first network traffic to determine whether to apply the firewall rule to the first network traffic, the dynamic object to be evaluated for the first device based on the information populated in the dynamic object;and

when the firewall rule is to apply to the first network traffic, at least one of block, permit, rate limit, quarantine or capture the first network traffic in accordance with the firewall rule.

2. The machine readable storage device or storage disk of claim 1 , wherein the instructions, when executed, cause the firewall device to request the device data from a network security device monitoring a network.

3. The machine readable storage device or storage disk of claim 1 , wherein the instructions, when executed, cause the firewall device to:

access second device data from a non-real time data inventory; and

populate the dynamic object based on the received device data.

4. The machine readable storage device or storage disk of claim 3 , wherein the instructions, when executed, cause the firewall device to:

synchronize the dynamic object with the non-real time data inventory.

5. The machine readable storage device or storage disk of claim 3 , wherein the instructions, when executed, cause the firewall device to:

query the non-real time data inventory for the second device data.

6. The machine readable storage device or storage disk of claim 1 , wherein the instructions, when executed, cause the firewall device to:

provide a user interface to define dynamic objects and to define rules that employ the dynamic objects.

7. The machine readable storage device or storage disk of claim 1 , wherein the dynamic object is to evaluate to the variable set of devices.

8. A method to provide a firewall for a network, the method comprising:

defining, by executing an instruction with a processor, a firewall rule that employs a dynamic object, the dynamic object to define a variable set of devices that satisfy a plurality of conditions included in the dynamic object;

creating the dynamic object by:

accessing device data from a real-time data source;

analyzing the device data from the real-time data source to determine information identifying a first set of devices that satisfy a first one of the plurality of conditions included in the dynamic object; and

populating the dynamic object with the information identifying the first set of devices that satisfy the first one of the plurality of conditions;

matching, by executing an instruction with the processor, a first device corresponding to first network traffic against the information populated in the dynamic object to determine whether to apply the firewall rule to the first network traffic; and

when the firewall rule is to apply to the first network traffic, at least one of blocking, permitting, rate limiting, quarantining or capturing the first network traffic in accordance with the firewall rule.

9. The method of claim 8 , further including:

synchronizing the dynamic object with a non-real time data inventory of device data.

10. The method of claim 9 , wherein the synchronizing of the dynamic object with the non-real time data inventory of device data includes:

querying the non-real time data inventory; and

updating the dynamic object with results obtained by querying the non-real time data inventory.

11. The method of claim 8 , further including:

obtaining real-time device information; and

populating the dynamic object based on the real-time device information.

12. The method of claim 11 , wherein the obtaining of the real-time device information includes:

obtaining the real-time device information from a device passively monitoring network flow.

13. A firewall apparatus comprising:

a network interface;

a rule evaluator to evaluate firewall rules that include dynamic objects to determine whether to apply the firewall rules to first network traffic associated with a first device, the firewall apparatus to at least one of block, permit, rate limit, quarantine or capture the first network traffic in accordance with the firewall rules when the firewall rules are to apply to the first network traffic;

a dynamic object evaluator to evaluate a first one of the dynamic objects to determine whether the firewall rules apply to the first network traffic, the first one of the dynamic objects to define a variable set of devices that satisfy a plurality of conditions included in the dynamic object;

a real-time data collector to obtain data from a real-time data source;

a non-real time data collector to obtain data from a non-real time data inventory;

a dynamic object creator to create and populate the first one of the dynamic objects based on one or more of the real-time data or the non-real time data by:

analyzing the data from the real-time data source to determine information identifying a first set of devices that satisfy a first one of the plurality of conditions included in the first one of the dynamic objects; and

populating the dynamic object with the information identifying the first set of devices that satisfy the first one of the plurality of conditions; and

a rules data store, at least one of the rule evaluator, the dynamic object evaluator, the real-time data collector, the non-real time data collector, or the dynamic object creator implemented by a logic circuit.

14. The firewall apparatus of claim 13 , further including:

a dynamic object definer to define the dynamic objects included in the firewall rules.

15. The firewall apparatus of claim 13 , wherein the dynamic object creator is to store the dynamic objects in the rules data store.

16. A system to protect a network with a firewall, comprising:

a real-time source of network device data;

a non-real time source of network device data;

a firewall including:

a processor;

a firewall rules data store in communication with the processor; and

memory in communication with the processor, the memory including instructions that, when executed, cause the processor to at least:

create a dynamic object for a firewall rule, the dynamic object to define a variable set of devices that satisfy a plurality of conditions included in the dynamic object, the processor to create the dynamic object by:

analyzing device data from a real-time source of network device data to determine information identifying a first set of devices that satisfy a first one of the plurality of conditions included in the dynamic object; and

populating the dynamic object with the information identifying the first set of devices that satisfy the first one of the plurality of conditions;

evaluate the dynamic object for a first device associated with first network traffic to determine whether to apply the firewall rule to the first network traffic, the dynamic object to be evaluated for the first device based on the information populated in the dynamic object; and

when the firewall rule is to apply to the first network traffic, cause the firewall to at least one of block, permit, rate limit, quarantine or capture the first network traffic in accordance with the firewall rule.

17. The system of claim 16 , wherein the real-time source of network device data includes a network security device passively monitoring a network.

18. The system of claim 16 , wherein the processor is further to populate the dynamic object based on a non-real time source of network device data including a mobile security manager for endpoint devices.

19. The system of claim 16 , wherein the processor is further to populate the dynamic object based on a non-real time source of network device data including a logon collector for a directory service.

20. The system of claim 16 , wherein the processor is to:

provide a user interface to define the dynamic object and to define the firewall rule that includes the dynamic object.

21. The system of claim 16 , wherein the processor to is:

synchronize the dynamic object with a non-real time source of network device data.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2017
From: GUPTA, BIKRAM KUMAR; RAMAN, ANANTH; NEDBAL, MANUEL; ANBALAGAN, ELANTHIRAIYAN A.
To: MCAFEE, INC.
Reel/Frame 043962/0811 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Sep 15, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043969/0057 →