IP Library Granted Patent US 9,648,047
Granted Patent B2
US 9,648,047 · App. 15/143,149 · Granted May 9, 2017

Security device controller

Inventors: Jason A. Kirby (San Jose, CA); John Dominic Belamaric (Bethesda, MD); Francois J. Tur (Edgewater, MD); Christophe Troillard (Drancy, FR)
Assignee: Infoblox Inc.
H04L63/20G06F21/604H04L63/02H04L63/0209
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,648,047
App. No.
15/143,149
Granted
May 9, 2017
Kind
B2
Abstract

In some embodiments, a security device controller (SDC) is provided. In some embodiments, a security device controller includes receiving a configuration policy in a vendor neutral language; and automatically configuring a plurality of security devices on a heterogeneous network based on the configuration policy. For example, the plurality of security devices can include physical, virtual, or software defined network (SDN) based routers and/or firewalls, and the heterogeneous network can include security devices from a plurality of different vendors.

Claims (31)

1. A system for a security device controller, comprising:

a hardware processor; and

a memory coupled with the hardware processor, wherein the memory is configured to provide the processor with instructions which when executed cause the hardware processor to:

receive a configuration policy in a vendor neutral language;

determine whether the configuration policy causes a configuration change to at least one security device of a plurality of security devices that violates a general or higher precedential rule of the configuration policy; and

in the event that the configuration policy does not cause the configuration change to the at least one security device of the plurality of security devices that violates the general or higher precedential rule of the configuration policy, automatically configure the plurality of security devices on a heterogeneous network based on the configuration policy, wherein the heterogeneous network includes different firewall devices from a plurality of different vendors, and wherein a firewall policy defined using the security device controller is automatically translated by the security device controller into a native language for each of the different firewall devices that can be implemented by each of the different firewall devices from each respective vendor of the plurality of different vendors.

2. The system of claim 1 , wherein the plurality of security devices includes physical, virtual, or software defined network (SDN) based routers, firewalls, or both, and wherein the heterogeneous network includes security devices from a plurality of different vendors.

3. The system of claim 1 , wherein the hardware processor is further configured to:

automatically translate the vendor neutral language into a plurality of vendor specific languages for automatically configuring the plurality of security devices on the network based on the configuration policy.

4. The system of claim 1 , wherein the security device controller facilitates provisioning security devices.

5. The system of claim 1 , wherein the security device controller facilitates provisioning security devices, including physical security devices, virtual security devices, software defined networks (SDN) based networks, or any combination thereof.

6. The system of claim 1 , wherein the heterogeneous network includes security devices from a plurality of different vendors, and wherein the hardware processor is further configured to:

generate a report on the configured security devices on the heterogeneous network.

7. A method for a security device controller, comprising:

receiving a configuration policy in a vendor neutral language;

determining whether the configuration policy causes a configuration change to at least one security device of a plurality of security devices that violates a general or higher precedential rule of the configuration policy; and

in the event that the configuration policy does not cause the configuration change to the at least one security device of the plurality of security devices that violates the general or higher precedential rule of the configuration policy, automatically configuring the plurality of security devices on a heterogeneous network based on the configuration policy, wherein the heterogeneous network includes different firewall devices from a plurality of different vendors, and wherein a firewall policy defined using the security device controller is automatically translated by the security device controller into a native language for each of the different firewall devices that can be implemented by each of the different firewall devices from each respective vendor of the plurality of different vendors.

8. The method of claim 7 , wherein the plurality of security devices includes physical, virtual, or software defined network (SDN) based routers, firewalls, or both, and wherein the heterogeneous network includes security devices from a plurality of different vendors.

9. The method of claim 7 , further comprising:

automatically translating the vendor neutral language into a plurality of vendor specific languages for automatically configuring the plurality of security devices on the network based on the configuration policy.

10. The method of claim 7 , wherein the security device controller facilitates provisioning security devices.

11. The method of claim 7 , wherein the security device controller facilitates provisioning security devices, including physical security devices, virtual security devices, software defined networks (SDN) based networks, or any combination thereof.

12. A computer program product for a security device controller, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

receiving a configuration policy in a vendor neutral language;

determining whether the configuration policy causes a configuration change to at least one security device of a plurality of security devices that violates a general or higher precedential rule of the configuration policy; and

in the event that the configuration policy does not cause the configuration change to the at least one security device of the plurality of security devices that violates the general or higher precedential rule of the configuration policy, automatically configuring the plurality of security devices on a heterogeneous network based on the configuration policy, wherein the heterogeneous network includes different firewall devices from a plurality of different vendors, and wherein a firewall policy defined using the security device controller is automatically translated by the security device controller into a native language for each of the different firewall devices that can be implemented by each of the different firewall devices from each respective vendor of the plurality of different vendors.

13. The computer program product recited in claim 12 , wherein the plurality of security devices includes physical, virtual, or software defined network (SDN) based routers, firewalls, or both, and wherein the heterogeneous network includes security devices from a plurality of different vendors.

14. The computer program product recited in claim 12 , further comprising computer instructions for:

automatically translating the vendor neutral language into a plurality of vendor specific languages for automatically configuring the plurality of security devices on the network based on the configuration policy.

15. The computer program product recited in claim 12 , wherein the security device controller facilitates provisioning security devices.

16. The computer program product recited in claim 12 , wherein the security device controller facilitates provisioning security devices, including physical security devices, virtual security devices, software defined networks (SDN) based networks, or any combination thereof.

Assignments (6)
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS (RELEASES RF 040575/0549) Recorded Dec 3, 2020
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: INFOBLOX INC.
Reel/Frame 054585/0914 →
FIRST LIEN SECURITY AGREEMENT Recorded Dec 2, 2020
From: INFOBLOX INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054615/0317 →
SECOND LIEN SECURITY AGREEMENT Recorded Dec 2, 2020
From: INFOBLOX INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054615/0331 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (RELEASES RF 040579/0302) Recorded Oct 23, 2019
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: INFOBLOX, INC.
Reel/Frame 050809/0980 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 8, 2016
From: INFOBLOX INC.
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 040579/0302 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 7, 2016
From: INFOBLOX INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 040575/0549 →
Continuity (3)
Continuation 14092415 · Nov 27, 2013
Provisional Application 61762267 · Feb 7, 2013
Related Publication 20160308908A1 · Oct 20, 2016