IP Library Granted Patent US 11,483,288
Granted Patent B1
US 11,483,288 · App. 16/570,365 · Granted Oct 25, 2022

Serialization of firewall rules with user, device, and application correlation

Inventors: Justin Dunn (Yadkinville, NC); Artemio V. Meras, III (San Antonio, TX); Brian Schlemmer (Charlotte, NC); Shawn M. Craig (Charlotte, NC); Duncan Molony (New Orleans, LA); Christopher Houser (Mt. Holly, NC); Michael Scott Hopkins (Millstadt, IL); Kerrie Heller (Stanley, NC); Michael Dutilly (Waxhaw, NC); Christy K. Lewis Lester (Brandon, SD); Jonathan Louis Gabel (Charlotte, NC)
Assignee: Wells Fargo Bank, N.A.
H04L63/0263G06F16/22G06F16/258H04L63/0218H04L63/0838H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,483,288
App. No.
16/570,365
Granted
Oct 25, 2022
Kind
B1
Abstract

Distributed firewalls reside at different points across a network. Each distributed firewall can include one or more rules that govern traffic over and/or access to the network. The rules can be discovered, converted into a standardized format, and indexed at a centralized rule database. The rules or data of the rules can be verified. The rules can be certified at the centralized database. The certification process can be based on a direction of traffic to which the rule governs. The certification process may have different levels based on the direction of traffic.

Claims (71)

1. A method for serializing firewall rules, comprising:

discovering, by a processor and using a search algorithm, a firewall rule from at least one firewall over a network;

storing the firewall rule in a rule database remote from the firewall;

parsing one or more objects from the firewall rule, the one or more objects including a portion of function data that is included in the firewall rule;

based on the one or more parsed objects, generating one or more data-tags that identify a publicly accessible application associated with the firewall rule;

classifying the firewall rule based on a direction of traffic;

determining that the data-tag identifies the publicly accessible application of the firewall rule; and

responsive to determining the data-tag that identifies the publicly accessible application of the firewall rule, certifying the firewall rule based on the direction of traffic.

2. The method of claim 1 , the classifying comprising:

determining that the firewall rule allows inbound traffic from an external source, wherein the external source resides on an outside network.

3. The method of claim 2 , comprising:

determining whether the firewall rule has been classified as being associated with the publicly accessible application.

4. The method of claim 3 , the classifying comprising:

creating the data-tag that identifies publicly accessible application for the firewall rule based on the determination that the firewall rule allows inbound traffic; and

requesting a detailed certification of the firewall rule.

5. The method of claim 4 , wherein requesting the detailed certification comprises:

generating and sending a notification for the firewall rule based on the data-tag that identifies the publicly accessible application, wherein the notification requests the detailed certification of the firewall rule.

6. The method of claim 5 , comprising:

determining an owner of the firewall rule; and

requesting and receiving acknowledgement of the data-tag that identifies the publicly accessible application for the firewall rule from the owner.

7. The method of claim 1 , comprising:

receiving approval of the firewall rule from a certification board; and

verifying the firewall rule from an asset of the firewall rule.

8. The method of claim 1 , wherein the certifying comprises:

determining that the firewall rule exclusively allows traffic from internal sources, wherein the internal sources reside within the network; and

verifying the firewall rule from an asset of the firewall rule.

9. The method of claim 8 , wherein the verifying comprises:

generating a 1-time code;

sending, via a transmission server and to a user device, the 1-time code to an owner associated with the asset of the firewall rule;

receiving, via the transmission server and from the user device, the 1-time code back from the owner; and

determining that the sent 1-time code and the received 1-time code match.

10. A system, comprising:

a discovery component that:

discovers, by a processor and using a search algorithm, a firewall rule from at least one firewall over a network,

parses one or more objects from the firewall rule, the one or more objects including a portion of function data that is included in the firewall rule, and

based on the one or more parsed objects, generates one or more data-tags that identify a publicly accessible application associated with the firewall rule;

a classification component that;

classifies the firewall rule based on a direction of traffic, and

determines that the data-tag identifies the publicly accessible application of the firewall rule; and

a certification component that certifies, responsive to determining the data-tag that identifies the publicly accessible application of the firewall rule, the firewall rule based on the direction of traffic.

11. The system of claim 10 , wherein the classification component determines that the firewall rule allows inbound traffic from an external source, wherein the external source resides on an outside network.

12. The system of claim 11 , wherein the classification component determines whether the firewall rule has been tagged as being associated with the publicly accessible application.

13. The system of claim 12 , wherein the classification component creates the data-tag that identifies the publicly accessible application for the firewall rule based on the determination that the firewall rule allows inbound traffic;

the system further comprising a communication component that requests a detailed certification of the firewall rule.

14. The system of claim 13 , wherein the communication component generates and sends a notification for the firewall rule based on the data-tag that identifies the publicly accessible application, wherein the notification requests the detailed certification of the firewall rule.

15. The system of claim 14 , wherein the certification component:

determines an owner of the firewall rule; and

requests and receives acknowledgement of the data-tag that identifies the publicly accessible application for the firewall rule from the owner.

16. The system of claim 15 , wherein the certification component:

receives approval of the firewall rule from a certification board; and

verifies the firewall rule from an asset of the firewall rule.

17. The system of claim 10 , wherein the certification component:

determines that the firewall rule exclusively allows traffic from internal sources, wherein the internal sources reside within the network; and

verifies the firewall rule from an asset of the firewall rule.

18. The system of claim 17 , wherein the certification component:

generates a 1-time code;

sends, via a transmission server and to a user device, the 1-time code to an owner associated with the asset of the firewall rule;

receives, via the transmission server and from the user device, the 1-time code back from the owner; and

determines that the sent 1-time code and the received 1-time code match.

19. A non-transitory computer-readable storage medium storing instructions to control one or more processors, wherein, when executed by the one or more processors, the instructions configure the one or more processors to perform operations comprising:

discovering, by a processor, a firewall rule from at least one firewall over a network using a search algorithm;

storing the firewall rule in a rule database remote from the firewall;

parsing one or more objects from the firewall rule, the one or more objects including a portion of function data that is included in the firewall rule;

based on the one or more parsed objects, generating one or more data-tags that identify a publicly accessible application associated with the firewall rule;

classifying the firewall rule based on a direction of traffic;

determining that the data-tag identifies the publicly accessible application of the firewall rule; and

responsive to determining the data-tag that identifies the publicly accessible application of the firewall rule, certifying the firewall rule based on the direction of traffic.

20. The non-transitory computer-readable storage medium of claim 19 , wherein the instructions configure the one or more processors to perform further operations comprising:

determining that the firewall rule allows inbound traffic from an external source, wherein the external source resides on an outside network;

determining an owner of the firewall rule; and

requesting and receiving acknowledgement of a publicly accessible application data-tag for the firewall rule from the owner.

Assignments (2)
ADDRESS CHANGE Recorded Jun 2, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071769/0158 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2021
From: DUNN, JUSTIN; MERAS, ARTEMIO V., III; SCHLEMMER, BRIAN; CRAIG, SHAWN M.; MOLONY, DUNCAN; HOUSER, CHRISTOPHER; HOPKINS, MICHAEL SCOTT; HELLER, KERRIE; DUTILLY, MICHAEL; LEWIS LESTER, CHRISTY K.; GABEL, JONATHAN LOUIS
To: WELLS FARGO BANK, N.A.
Reel/Frame 055191/0544 →
Continuity (1)
Continuation In Part 15073026 · Mar 17, 2016
Cited By (2)
US 12,425,371 US 12,683,929