IP Library Granted Patent US 11,082,401
Granted Patent B2
US 11,082,401 · App. 16/266,335 · Granted Aug 3, 2021

Cloud based firewall system and service

Inventors: John A. Dilley (Los Altos, CA); Prasanna Laghate (Santa Clara, CA); John F. Summers (Newton, MA); Thomas Devanneaux (Los Altos, CA)
Assignee: Akamai Technologies, Inc.
H04L63/0263H04L63/0218H04L63/0227H04L63/16H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,082,401
App. No.
16/266,335
Granted
Aug 3, 2021
Kind
B2
Abstract

A cloud-based firewall system and service is provided to protect customer sites from attacks, leakage of confidential information, and other security threats. In various embodiments, such a firewall system and service can be implemented in conjunction with a content delivery network (CDN) having a plurality of distributed content servers. The CDN servers receive requests for content identified by the customer for delivery via the CDN. The CDN servers include firewalls that examine those requests and take action against security threats, so as to prevent them from reaching the customer site. The CDN provider implements the firewall system as a managed firewall service, with the operation of the firewalls for given customer content being defined by that customer, independently of other customers. In some embodiments, a customer may define different firewall configurations for different categories of that customer's content identified for delivery via the CDN.

Claims (29)

1. A method of content delivery in a content delivery network (CDN) operated by a content delivery network service provider (CDNSP) on behalf of a plurality of participating content providers, wherein the plurality of participating content providers have content delivered via the CDN, the CDN having a plurality of CDN servers deployed around the Internet at an edge, the edge being any of in and adjacent to an end user access network, the method comprising:

the CDNSP providing a user interface through which a particular participating content provider any of: creates and selects a first firewall instance for the plurality of CDN servers, which are deployed around the Internet at the edge, to apply to network traffic associated with the particular participating content provider, the network traffic comprising requests for content of the particular participating content provider, the content to be delivered via the CDN;

the user interface further enabling the particular participating content provider to any of: create and select a second firewall instance for the plurality of CDN servers, which are deployed around the Internet at the edge, to apply to network traffic associated with the particular participating content provider, the network traffic comprising requests for content of the particular participating content provider, the content to be delivered via the CDN;

the first firewall instance comprising:

(i) a first application layer control, which comprises one or more security criteria to be checked against a request and an action to take if an attack is identified;

(ii) a first network layer control, which comprises one or more IP-layer restrictions to apply to requests from particular IP addresses; and

(iii) a designation of a first set of one or more of the plurality of CDN servers to which the first firewall instance will apply;

the second firewall instance comprising:

(i) a second application layer control, which comprises one or more security criteria to be checked against a request and an action to take if an attack is identified;

(ii) a second network layer control, which comprises one or more IP-layer restrictions to apply to requests from particular IP addresses; and,

(iii) a designation of a second set of one or more of the plurality of CDN servers to which the second firewall instance will apply, the second set being different than the first set.

2. The method of claim 1 , wherein the one or more security criteria in the first application layer control comprise any of: one or more selected rules from a ruleset, and, a rule authored by a user with a Boolean expression.

3. The method of claim 1 , wherein the one or more security criteria comprises: a rule authored by a user with a Boolean expression.

4. The method of claim 1 , wherein one or more the IP-layer restrictions comprises any of: a whitelist, a blacklist.

5. A system comprising a content delivery network (CDN) operated by a content delivery network service provider (CDNSP) on behalf of a plurality of participating content providers, wherein the plurality of participating content providers have content delivered via the CDN, the CDN having a plurality of CDN servers deployed around the Internet at an edge, the edge being any of in and adjacent to an end user access network, the system further comprising:

the plurality of CDN servers; and,

a user interface through which a particular participating content provider any of: creates and selects a first firewall instance for the plurality of CDN servers, which are deployed around the Internet at the edge, to apply to network traffic associated with the particular participating content provider, the network traffic comprising requests for content of the particular participating content provider, the content to be delivered via the CDN;

the user interface further enabling the particular participating content provider to any of: create and select a second firewall instance for the plurality of CDN servers, which are deployed around the Internet at the edge, to apply to network traffic associated with the particular participating content provider, the network traffic comprising requests for content of the particular participating content provider, the content to be delivered via the CDN;

the first firewall instance comprising:

(i) a first application layer control, which comprises one or more security criteria to be checked against a request and an action to take if an attack is identified;

(ii) a first network layer control, which comprises one or more IP-layer restrictions to apply to requests from particular IP addresses; and

(iii) a designation of a first set of one or more of the plurality of CDN servers to which the first firewall instance will apply;

the second firewall instance comprising:

(i) a second application layer control, which comprises one or more security criteria to be checked against a request and an action to take if an attack is identified;

(ii) a second network layer control, which comprises one or more IP-layer restrictions to apply to requests from particular IP addresses; and,

(iii) a designation of a second set of one or more of the plurality of CDN servers to which the second firewall instance will apply, the second set being different than the first set.

6. The system of claim 5 , wherein the one or more security criteria in the first application layer control comprise any of: one or more selected rules from a ruleset, and, a rule authored by a user with a Boolean expression.

7. The system of claim 5 , wherein the one or more security criteria comprises: a rule authored by a user with a Boolean expression.

8. The system of claim 5 , wherein one or more the IP-layer restrictions comprises any of: a whitelist, a blacklist.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2019
From: DILLEY, JOHN; LAGHATE, PRASANNA; SUMMERS, JOHN; DEVANNEAUX, THOMAS
To: AKAMAI TECHNOLOGIES, INC.
Reel/Frame 048274/0450 →
Continuity (5)
Continuation 14998187 · Dec 24, 2015
Continuation 13896995 · May 17, 2013
Continuation 12965188 · Dec 10, 2010
Provisional Application 61285958 · Dec 12, 2009
Related Publication 20200007506A1 · Jan 2, 2020