PER-APPLICATION MICRO-FIREWALL IMAGES EXECUTING IN CONTAINERS ON A DATA COMMUNICATIONS NETWORK
Per-application micro-firewall container images execute in containers on a data communication network. A micro-firewall controller detects that a specific application has been activated. In response, a micro-firewall image corresponding to the specific application is configured and executed in a container.
1 . A computer-implemented method in a firewall device of a data communication system, for executing per-application micro-firewall images in a dedicated container on a data communications network, the method comprising the steps of:
generating application profiles from metadata concerning network applications installed on network devices;
storing the application profiles in an application profile database;
detecting a current execution of a specific network application for transmitting data packets on a network device;
responsive to the detection, retrieving an application profile associated with the specific network application;
spawning a micro-firewall container from an operating system of the firewall, to execute the application profile execution of the specific network application;
executing the application profile to examine network traffic associated with the application;
detecting the specific network application has ceased execution; and
closing the micro-firewall container.
2 . The method of claim 1 , further comprising:
updating metadata of the application profile based on the execution of the application profile.
3 . The method of claim 1 , wherein more than one micro-firewall container is spawned for a specific network applications.
4 . A non-transitory computer-readable media storing instructions that, when executed by a processor, perform a computer-implemented method in a firewall device of a data communication system, for executing per-application micro-firewall images in a dedicated container on a data communications network, the method comprising the steps of:
generating application profiles from metadata concerning network applications installed on network devices;
storing the application profiles in an application profile database;
detecting a current execution of a specific network application for transmitting data packets on a network device;
responsive to the detection, retrieving an application profile associated with the specific network application;
spawning a micro-firewall container from an operating system of the firewall, to execute the application profile execution of the specific network application;
executing the application profile to examine network traffic associated with the application;
detecting the specific network application has ceased execution; and
closing the micro-firewall container.