IP Library Granted Patent US 10,476,843
Granted Patent B2
US 10,476,843 · App. 15/455,510 · Granted Nov 12, 2019

Firewall configured with dynamic membership sets representing machine attributes

Inventors: Debashis Basak (San Jose, CA); Rohit Toshniwal (San Jose, CA); Allwyn Sequeira (Saratoga, CA)
Assignee: VMware, Inc.
H04L63/0218H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,476,843
App. No.
15/455,510
Granted
Nov 12, 2019
Kind
B2
Abstract

A method is provided to control the flow of packets within a system that includes one or more computer networks comprising: policy rules are provided that set forth attribute dependent conditions for communications among machines on the one or more networks; machine attributes and corresponding machine identifiers are obtained for respective machines on the networks; and policy rules are transformed to firewall rules that include machine identifiers of machines having attributes from among the obtained machine attributes that satisfy the attribute dependent policy rules.

Claims (40)

1. A method for implementing a distributed firewall on a host running a plurality of endpoints and a firewall manager, wherein an endpoint of the plurality of endpoints is associated with a virtual machine (VM), wherein the VM has a plurality of attributes and an endpoint identifier associated therewith, and wherein the firewall manager monitors updates to attributes of the VM, the method comprising:

monitoring, by the firewall manager, communications to and from the VM according to a set of firewall rules that are based on the plurality of attributes of the VM, the set of firewall rules comprising a first set of firewall rules and a second set of firewall rules;

determining, by the firewall manager, that an attribute of the plurality of attributes of the VM has been updated;

identifying, by the firewall manager, a policy rule that includes the updated attribute within a condition of the policy rule; and

using the endpoint identifier to transform, by the firewall manager, the identified policy rule to one or more new firewall rules, enabling the one or more new firewall rules to be applied to communications to and from the endpoint, the one or more new firewall rules comprising a third set of firewall rules that are not included in the set of firewall rules.

2. The method of claim 1 , wherein the one or more new firewall rules did not exist prior to the transforming.

3. The method of claim 1 , further comprising:

matching each attribute in a source machine dependent condition of the selected policy rule to an attribute update; and

generate a separate source machine identifier portion of a firewall for each machine that satisfies the source attribute dependent condition of the selected policy rule.

4. The method of claim 1 , wherein policy rules are defined based upon attributes and the endpoint identifier is an Internet Protocol (IP) address.

5. The method of claim 4 , further comprising:

applying, by the firewall manager, the one or more new firewall rules to a second endpoint having a second IP address associated with a second VM.

6. The method of claim 1 , further comprising:

wherein the one or more new firewall rules is an updated firewall rule for the endpoint based on determining one or more attribute conditions within a second policy rule does not match the updated additional attribute of the endpoint.

7. The method of claim 4 , wherein applying the one or more new firewall rules comprises permitting or denying passage of messages between the endpoint and a second endpoint having a second IP address.

8. The method of claim 7 , further comprising determining whether a message includes at least one of the IP address and the second IP address, wherein permitting or denying passage of messages between the endpoint and the second endpoint is based on whether the message includes at least one of the IP address and the second IP address.

9. One or more computer-readable media having computer-executable instructions for implementing a distributed firewall on a host running a plurality of endpoints and a firewall manager, wherein an endpoint of the plurality of endpoints is associated with a virtual machine (VM), wherein the VM has a plurality of attributes and endpoint identifier associated therewith, and wherein the firewall manager monitors updates to attributes of the VM, the computer-executable instructions causing one or more processors to perform operations comprising:

monitoring communications to and from the VM according to a set of firewall rules that are based on the plurality of attributes of the VM, the set of firewall rules comprising a first set of firewall rules and a second set of firewall rules;

determining that an attribute of the plurality of attributes of the VM has been updated;

identifying a policy rule that includes the updated attribute within a condition of the policy rule; and

using the endpoint identifier to transform the identified policy rule to one or more new firewall rules, enabling the one or more new firewall rules to be applied to communications to and from the endpoint, the one or more new firewall rules comprising a third set of firewall rules that are not included in the set of firewall rules.

10. The one or more computer-readable media of claim 9 , wherein the updated attribute is one or more of the following: a software update or a network property update.

11. The one or more computer-readable media of claim 9 , wherein the firewall manager runs on the one or more processors.

12. The one or more computer-readable media of claim 9 , wherein the updated attribute is one of the following: a software that the VM executes, a location of the VM, or a network property of the VM.

13. The one or more computer-readable media of claim 12 , wherein the network property of the VM is the endpoint identifier associated with the VM.

14. A computer system, wherein system software for the computer system is programmed to execute a method for implementing a distributed firewall, the computer system comprising:

a memory storing policy rules;

a host running a plurality of endpoints, wherein an endpoint of the plurality of endpoints is associated with a virtual machine (VM), wherein the VM has a plurality of attributes and an endpoint identifier associated therewith;

a firewall manager running on the host, the firewall manager configured to:

monitor communications to and from the VM according to firewall rules that are based on the plurality of attributes of the VM, the firewall rules comprising a first set of firewall rules and a second set of firewall rules;

determine that an attribute of the plurality of attributes of the VM has been updated;

identify a policy rule stored in the memory includes the updated attribute within a condition of the policy rule; and

use the endpoint identifier to transform the identified policy rule to one or more new firewall rules to the endpoint, enabling the one or more new firewall rules to be applied to communications to and from the endpoint, the one or more new firewall rules comprising a third set of firewall rules that are not included in the set of firewall rules.

15. The computer system of claim 14 , wherein the updated attribute is one of the following: a software that the VM executes, a location of the VM, or a network property of the VM.

16. The computer system of claim 15 , wherein the network property of the VM is the endpoint identifier associated with the VM.

17. The computer system of claim 14 , wherein the endpoint comprises the VM.

18. The computer system of claim 14 , wherein the firewall manager is further configured to apply the one or more new firewall rules to a second endpoint having a second IP address associated with a second VM.

19. The computer system of claim 14 , wherein

wherein the one or more new firewall rules is an updated firewall rule for the endpoint based on determining one or more attribute conditions within a second policy rule stored in the memory does not match the updated additional attribute of the endpoint.

20. The computer system of claim 14 , wherein applying the one or more new firewall rules comprises permitting or denying passage of messages between the endpoint and a second endpoint having a second IP address.

Assignments (1)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
Continuity (2)
Continuation 12490773 · Jun 24, 2009
Related Publication 20170187679A1 · Jun 29, 2017