IP Library Granted Patent US 10,904,216
Granted Patent B2
US 10,904,216 · App. 16/524,968 · Granted Jan 26, 2021

Intelligent firewall access rules

Inventors: Bikram Kumar Gupta (Sunnyvale, CA); Ananth Raman (San Jose, CA); Manuel Nedbal (Santa Clara, CA); Elanthiraiyan A. Anbalagan (Sunnyvale, CA)
Assignee: McAfee, LLC
H04L63/0263G06F16/282H04L43/12H04L63/10H04L63/1408H04L67/1095
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,904,216
App. No.
16/524,968
Granted
Jan 26, 2021
Kind
B2
Abstract

Example firewalls disclosed herein populate a first dynamic object of a firewall rule with first information to identify a first updateable set of devices that satisfy a first one of a plurality of conditions associated with the firewall rule, the first information based on first data obtained from an appliance that monitors communication traffic in at least a portion of a network. Disclosed example firewalls also populate a second dynamic object of the firewall rule with second information to identify a second updateable set of devices that satisfy a second one of the conditions associated with the firewall rule, the second information based on second data obtained from an external data source. Disclosed example firewalls further determine, based on the first dynamic object and the second dynamic object, whether the firewall rule is to apply to first network traffic associated with a first device in communication with the network.

Claims (46)

1. A computer readable storage device or storage disk comprising computer readable instructions that, when executed, cause a processor to at least:

populate a first dynamic object of a firewall rule with first information to identify a first updateable set of devices that satisfy a first one of a plurality of conditions associated with the firewall rule, the first information based on first data obtained from an appliance that is to monitor communication traffic in at least a portion of a network;

populate a second dynamic object of the firewall rule with second information to identify a second updateable set of devices that satisfy a second one of the plurality of conditions associated with the firewall rule, the second information based on second data obtained from an external data source;

determine, based on the first dynamic object and the second dynamic object, whether the firewall rule is to apply to first network traffic associated with a first device in communication with the network; and

when the firewall rule is to apply to the first network traffic, at least one of block, permit, rate limit, quarantine or capture the first network traffic in accordance with the firewall rule.

2. The computer readable storage device or storage disk of claim 1 , wherein the instructions, when executed, cause the processor to:

request the first data from the appliance when the first dynamic object is to be evaluated; and

analyze the first data to identify the first updateable set of devices.

3. The computer readable storage device or storage disk of claim 2 , wherein the first information is to identify respective network addresses of the first updateable set of devices, at least some of the first updateable set of devices in communication with the network.

4. The computer readable storage device or storage disk of claim 1 , wherein the instructions, when executed, cause the processor to obtain the second data from the data source according to a synchronization schedule.

5. The computer readable storage device or storage disk of claim 4 , wherein the instructions, when executed, cause the processor to implement a user interface to specify the synchronization schedule.

6. The computer readable storage device or storage disk of claim 4 , wherein the instructions, when executed, cause the processor to:

query the data source for third data according to the synchronization schedule; and

update the second information based on the third data.

7. The computer readable storage device or storage disk of claim 1 , wherein the instructions, when executed, cause the processor to cause a user interface to specify whether at least one of the first dynamic object or the second dynamic object corresponds to a source attribute or a destination attribute of the firewall rule.

8. A firewall apparatus comprising:

memory including computer readable instructions; and

a processor to execute the computer readable instructions to at least:

populate a first dynamic object of a firewall rule with first information to identify a first updateable set of devices that satisfy a first one of a plurality of conditions associated with the firewall rule, the first information based on first data obtained from an appliance that is to monitor communication traffic in at least a portion of a network;

populate a second dynamic object of the firewall rule with second information to identify a second updateable set of devices that satisfy a second one of the plurality of conditions associated with the firewall rule, the second information based on second data obtained from an external data source;

determine, based on the first dynamic object and the second dynamic object, whether the firewall rule is to apply to first network traffic associated with a first device in communication with the network; and

when the firewall rule is to apply to the first network traffic, at least one of block, permit, rate limit, quarantine or capture the first network traffic in accordance with the firewall rule.

9. The firewall apparatus of claim 8 , wherein the processor is to:

request the first data from the appliance when the first dynamic object is to be evaluated; and

analyze the first data to identify the first updateable set of devices.

10. The firewall apparatus of claim 9 , wherein the first information is to identify respective network addresses of the first updateable set of devices, at least some of the first updateable set of devices in communication with the network.

11. The firewall apparatus of claim 8 , wherein the processor is to obtain the second data from the data source according to a synchronization schedule.

12. The firewall apparatus of claim 11 , wherein the processor is to implement a user interface to specify the synchronization schedule.

13. The firewall apparatus of claim 11 , wherein the processor is to:

query the data source for third data according to the synchronization schedule; and

update the second information based on the third data.

14. The firewall apparatus of claim 8 , wherein the processor is to cause a user interface to specify whether at least one of the first dynamic object or the second dynamic object corresponds to a source attribute or a destination attribute of the firewall rule.

15. A method comprising:

populating, by executing an instruction with a processor, a first dynamic object of a firewall rule with first information to identify a first updateable set of devices that satisfy a first one of a plurality of conditions associated with the firewall rule, the first information based on first data obtained from an appliance that is to monitor communication traffic in at least a portion of a network;

populating, by executing an instruction with the processor, a second dynamic object of the firewall rule with second information to identify a second updateable set of devices that satisfy a second one of the plurality of conditions associated with the firewall rule, the second information based on second data obtained from an external data source;

determining, by executing an instruction with the processor, whether the firewall rule is to apply to first network traffic associated with a first device in communication with the network, the determining based on the first dynamic object and the second dynamic object; and

when the firewall rule is to apply to the first network traffic, at least one of blocking, permitting, rate limiting, quarantining or capturing the first network traffic in accordance with the firewall rule.

16. The method of claim 15 , further including:

requesting the first data from the appliance when the first dynamic object is to be evaluated; and

analyzing the first data to identify the first updateable set of devices.

17. The method of claim 16 , wherein the first information is to identify respective network addresses of the first updateable set of devices, at least some of the first updateable set of devices in communication with the network.

18. The method of claim 15 , further including obtaining the second data from the data source according to a synchronization schedule.

19. The method of claim 18 , further including:

querying the data source for third data according to the synchronization schedule; and

updating the second information based on the third data.

20. The method of claim 18 , further including specifying whether at least one of the first dynamic object or the second dynamic object corresponds to a source attribute or a destination attribute of the firewall rule.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2019
From: GUPTA, BIKRAM KUMAR; RAMAN, ANANTH; NEDBAL, MANUEL; ANBALAGAN, ELANTHIRAIYAN A.
To: MCAFEE, INC.
Reel/Frame 050536/0247 →
CHANGE OF NAME Recorded Sep 28, 2019
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 050581/0448 →
Continuity (2)
Continuation 15038388
Related Publication 20190349335A1 · Nov 14, 2019