IP Library Granted Patent US 10,764,332
Granted Patent B1
US 10,764,332 · App. 16/857,174 · Granted Sep 1, 2020

Systems, methods, and devices for securely managing network connections

Inventors: James Calvin Armstrong (Foster City, CA); Jonathan Claybaugh (San Francisco, CA)
Assignee: Snowflake Inc.
H04L63/20G06F21/57H04L41/0604H04L41/22H04L43/00H04L43/026H04L43/062H04L43/0811H04L47/10H04L63/0263H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,764,332
App. No.
16/857,174
Granted
Sep 1, 2020
Kind
B1
Abstract

The disclosure relates generally to methods, systems, and apparatuses for managing network connections. A system for managing network connections includes a storage component, a decoding component, a rule manager component, and a notification component. The storage component is configured to store a list of expected connections for a plurality of networked machines, wherein each connection in the list of expected connections defines a start point and an end point for the connection. The decoding component is configured to decode messages from the plurality of networked machines indicating one or more connections for a corresponding machine. The rule manager component is configured to identify an unexpected presence or absence of a connection on at least one of the plurality of network machines based on the list of expected connections. The notification component is configured to provide a notification or indication of the unexpected presence or absence.

Claims (40)

1. A method comprising:

storing a master connection file comprising a list of desired connections for a plurality of networked resources, wherein each connection in the master connection file defines a first resource and a second resource between which the connection exists;

obtaining, for each of one or more of the plurality of networked resources, a connection indication file indicating one or more actual connections maintained by the networked resource;

detecting one or more differences between the master connection file and the actual connections maintained by the one or more of the plurality of networked resources by comparing at least one entry in the master connection file with the one or more actual connections of each networked resource as indicated by a connection indication file of each networked resource; and

providing a notification of any detected differences between the master connection file and the actual connections maintained by the one or more of the plurality of networked resources indicated by the connection indication file, wherein each detected difference indicates an unauthorized connection or an inaccuracy of the master connection file.

2. The method of claim 1 , wherein the master connection file comprises a file stored based on a data serialization standard.

3. The method of claim 1 , further comprising providing version tracking and control of the master connection file.

4. The method of claim 1 , further comprising determining, based on one or more detected differences between the master connection file and the connection indication file maintained by the one or more of the plurality of networked components, whether the master connection file is inaccurate.

5. The method of claim 1 , further comprising determining, based on one or more detected differences between the master connection file and the connection indication file maintained by the one or more of the plurality of networked components, whether one or more of the actual connections are unauthorized.

6. The method of claim 1 , wherein a connection in the master connection file further comprises one or more of a protocol, a port number, or a port number range for the corresponding connection.

7. The method of claim 1 , wherein one or more of the first resource or the second resource in the master connection file comprises a security group.

8. The method of claim 1 , wherein detecting a difference between the master connection file and the connection indication file comprises determining that one or more of the actual connections maintained by the networked resource have no matching connection in the master connection file.

9. The method of claim 1 , wherein detecting a difference between the master connection file and the actual connections maintained by a networked resource of the plurality of networked resources comprises determining that none of the desired connections in the master connection file have a matching entry in the connection indication file.

10. A system comprising:

a memory to store a master connection file comprising a list of desired connections for a plurality of networked resources, wherein each connection in the connection file defines a first resource and a second resource between which the connection exists; and

a processor, operatively coupled to the memory, the processor to:

obtain, for each of one or more of the plurality of networked resources, a connection indication file indicating one or more actual connections maintained by the networked resource;

detect one or more differences between the master connection file and the actual connections maintained by the one or more of the plurality of networked resources by comparing at least one entry in the master connection file with the one or more actual connections of each networked resource as indicated by a connection indication file of each networked resource; and

provide a notification of any detected differences between the master connection file and the actual connections maintained by the one or more of the plurality of networked resources indicated by the connection indication file, wherein each detected difference indicates an unauthorized connection or an inaccuracy of the master connection file.

11. The system of claim 10 , wherein the master connection file comprises a file stored based on a data serialization standard.

12. The system of claim 10 , wherein the processor is further to provide version tracking and control of the master connection file.

13. The system of claim 10 , wherein the processor is further to determine, based on one or more detected differences between the master connection file and the connection indication file maintained by the one or more of the plurality of networked components, whether the master connection file is inaccurate.

14. The system of claim 10 , wherein the processor is further to determine, based on one or more detected differences between the master connection file and the connection indication file maintained by the one or more of the plurality of networked components, whether one or more of the actual connections are unauthorized.

15. The system of claim 10 , wherein a connection in the master connection file further comprises one or more of a protocol, a port number, or a port number range for the corresponding connection.

16. The system of claim 10 , wherein one or more of the first resource or the second resource in the master connection file comprises a security group.

17. The system of claim 10 , wherein to detect a difference between the master connection file and the connection indication file the processor is to determine that one or more of the actual connections maintained by the networked resource have no matching connection in the master connection file.

18. The system of claim 10 , wherein to detect a difference between the master connection file and the actual connections maintained by a networked resource of the plurality of networked resources the processor is to determine that none of the desired connections in the master connection file have a matching entry in the connection indication file.

19. A non-transitory computer readable medium having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to:

store a master connection file comprising a list of desired connections for a plurality of networked resources, wherein each connection in the connection file defines a first resource and a second resource between which the connection exists;

obtain, for each of one or more of the plurality of networked resources, a connection indication file indicating one or more actual connections maintained by the networked resource;

detect one or more differences between the master connection file and the actual connections maintained by the one or more of the plurality of networked resources by comparing at least one entry in the master connection file with the one or more actual connections of each networked resource as indicated by a connection indication file of each networked resource; and

provide a notification of any detected differences between the master connection file and the actual connections maintained by the one or more of the plurality of networked resources indicated by the connection indication file, wherein each detected difference indicates an unauthorized connection or an inaccuracy of the master connection file.

20. The non-transitory computer readable medium of claim 19 , wherein the master connection file comprises a file stored based on a data serialization standard.

21. The non-transitory computer readable medium of claim 19 , wherein the processor is further to provide version tracking and control of the master connection file.

22. The non-transitory computer readable medium of claim 19 , wherein the processor is further to determine, based on one or more detected differences between the master connection file and the connection indication file maintained by the one or more of the plurality of networked components, whether the master connection file is inaccurate.

23. The non-transitory computer readable medium of claim 19 , wherein the processor is further to determine, based on one or more detected differences between the master connection file and the connection indication file maintained by the one or more of the plurality of networked components, whether one or more of the actual connections are unauthorized.

24. The non-transitory computer readable medium of claim 19 , wherein a connection in the master connection file further comprises one or more of a protocol, a port number, or a port number range for the corresponding connection.

25. The non-transitory computer readable medium of claim 19 , wherein one or more of the first resource or the second resource in the master connection file comprises a security group.

26. The non-transitory computer readable medium of claim 19 , wherein to detect a difference between the master connection file and the connection indication file the processor is to determine that one or more of the actual connections maintained by the networked resource have no matching connection in the master connection file.

27. The non-transitory computer readable medium of claim 19 , wherein to detect a difference between the master connection file and the actual connections maintained by a networked resource of the plurality of networked resources the processor is to determine that none of the desired connections in the master connection file have a matching entry in the connection indication file.

Assignments (2)
CHANGE OF NAME Recorded Jun 3, 2021
From: SNOWFLAKE COMPUTING, INC.
To: SNOWFLAKE INC.
Reel/Frame 056476/0277 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2021
From: ARMSTRONG, JAMES CALVIN; CLAYBAUGH, JONATHAN
To: SNOWFLAKE COMPUTING, INC.
Reel/Frame 056418/0721 →
Continuity (2)
Continuation 16778797 · Jan 31, 2020
Continuation 15079849 · Mar 24, 2016