IP Library Granted Patent US 11,159,574
Granted Patent B2
US 11,159,574 · App. 16/942,231 · Granted Oct 26, 2021

Securely managing network connections

Inventors: James Calvin Armstrong (Foster City, CA); Jonathan Claybaugh (San Francisco, CA)
Assignee: Snowflake Inc.
H04L63/20G06F21/566G06F21/57G06F21/6218H04L41/0604H04L41/22H04L43/00H04L43/026H04L43/062H04L43/0811H04L47/10H04L63/0263H04L63/102H04L63/104H04L63/1408H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,159,574
App. No.
16/942,231
Granted
Oct 26, 2021
Kind
B2
Abstract

The disclosure relates generally to methods, systems, and apparatuses for managing network connections. A system for managing network connections includes a storage component, a decoding component, a rule manager component, and a notification component. The storage component is configured to store a list of expected connections for a plurality of networked machines, wherein each connection in the list of expected connections defines a start point and an end point for the connection. The decoding component is configured to decode messages from the plurality of networked machines indicating one or more connections for a corresponding machine. The rule manager component is configured to identify an unexpected presence or absence of a connection on at least one of the plurality of network machines based on the list of expected connections. The notification component is configured to provide a notification or indication of the unexpected presence or absence.

Claims (54)

1. A method comprising:

storing a master connection file comprising a list of desired connections among a plurality of networked resources, wherein each desired connection in the master connection file defines a first networked resource and a second networked resource between which the desired connection exists;

detecting, by one or more processors, one or more differences between the master connection file and a first connection indication file of the first networked resource and a second connection indication file of the second networked resource, wherein the first connection indication file indicates actual connections maintained among the first networked resource and the plurality of networked resources and the second connection indication file indicates actual connections maintained among the second networked resource and the plurality of networked resources, the actual connections defined by one or more network rules for the first networked resource and the second networked resource; and

adding or removing, by the one or more processors, one or more network rules to the first and second connection indication files based on the one or more differences between the master connection file and the first and second connection indication files to align the actual connections with the desired connections.

2. The method of claim 1 , further comprising obtaining, for each of one or more of the plurality of networked resources, a connection indication file indicating one or more actual connections maintained by the networked resource.

3. The method of claim 1 , further comprising providing a notification of the detected one or more differences between the master connection file and the actual connections maintained among the plurality of networked resources, wherein each detected difference indicates an unauthorized connection or an inaccuracy of the master connection file.

4. The method of claim 3 , wherein the notification is provided to one or more of a log file, a notification area of a user interface, an email address, a text message, or as part of another message.

5. The method of claim 1 , wherein the one or more differences comprise:

a number of the actual connections among the plurality of networked resources that do not have a corresponding desired connection in the master connection file; and

a number of the desired connections from the master connection file that are missing a corresponding actual connection.

6. The method of claim 5 , wherein each of the one or more detected differences indicates an unauthorized connection or an inaccuracy of the master connection file.

7. The method of claim 5 , wherein comparing a particular desired connection in the master connection file comprises determining whether the particular desired connection has a matching actual connection among the actual connections indicated by the first connection indication file of the first networked resource and the second connection indication file of the second networked resource between which the particular desired connection exists.

8. The method of claim 1 , wherein each of the actual connections among the plurality of networked resources comprises a protocol, a port number, a port number range, or a security group.

9. The method of claim 1 , wherein the master connection file is stored in human readable data-serialization language format.

10. The method of claim 1 , further comprising providing version tracking and control of the master connection file.

11. A system comprising:

a memory to store a master connection file comprising a list of desired connections among a plurality of networked resources, wherein each desired connection in the master connection file defines a first networked resource and a second networked resource between which the desired connection exists; and

one or more processors operatively coupled to the memory, the one or more processors to:

detect one or more differences between the master connection file and a first connection indication file of the first networked resource and a second connection indication file of the second networked resource between, wherein the first connection indication file indicates actual connections maintained among the first networked resource and the plurality of networked resources and the second connection indication file indicates actual connections maintained among the second networked resource and the plurality of networked resources, the actual connections defined by one or more network rules for the first networked resource and the second networked resource; and

add or remove one or more network rules to the first and second connection indication files based on the one or more differences between the master connection file and the first and second connection indication files to align the actual connections with the desired connections.

12. The system of claim 11 , wherein the one or more processors are further to:

obtain, for each of one or more of the plurality of networked resources, a connection indication file indicating one or more actual connections maintained by the networked resource.

13. The system of claim 11 , wherein the one or more processors are further to:

provide a notification of the detected one or more differences between the master connection file and the actual connections maintained among the plurality of networked resources, wherein each detected difference indicates an unauthorized connection or an inaccuracy of the master connection file.

14. The system of claim 13 , wherein the one or more processors provide the notification to one or more of a log file, a notification area of a user interface, an email address, a text message, or as part of another message.

15. The system of claim 11 , wherein the one or more differences comprise:

a number of the actual connections among the plurality of networked resources that do not have a corresponding desired connection in the master connection file; and

a number of the desired connections from the master connection file that are missing a corresponding actual connection.

16. The system of claim 15 , wherein each of the one or more detected differences indicates an unauthorized connection or an inaccuracy of the master connection file.

17. The system of claim 15 , wherein to compare a particular desired connection in the master connection file, the one or more processors are to:

determine whether the particular desired connection has a matching actual connection among the actual connections indicated by the first connection indication file of the first networked resource and a second connection indication file of the second networked resource between which the particular desired connection exists.

18. The system of claim 11 , wherein each of the actual connections among the plurality of networked resources comprises a protocol, a port number, a port number range, or a security group.

19. The system of claim 11 , wherein the master connection file is stored in human readable data-serialization language format.

20. The system of claim 11 , wherein the one or more processors are further to:

provide version tracking and control of the master connection file.

21. A non-transitory computer-readable medium having instructions stored thereon which, when executed by one or more processors, cause the one or more processors to:

store a master connection file comprising a list of desired connections among a plurality of networked resources, wherein each desired connection in the master connection file defines a first networked resource and a second networked resource between which the desired connection exists; and

detect, by the one or more processors, one or more differences between the master connection file and a first connection indication file of the first networked resource and a second connection indication file of the flail second networked resource, wherein the first connection indication file indicates actual connections maintained among the first networked resource and the plurality of networked resources and the second connection indication file indicates actual connections maintained among the second networked resource and the plurality of networked resources, the actual connections defined by one or more network rules for the first networked resource and the second networked resource; and

add or remove one or more network rules to the first and second connection indication files based on the one or more differences between the master connection file and the first and second connection indication files to align the actual connections with the desired connections.

22. The non-transitory computer-readable medium of claim 21 , wherein the one or more processors are further to:

obtain, for each of one or more of the plurality of networked resources, a connection indication file indicating one or more actual connections maintained by the networked resource.

23. The non-transitory computer-readable medium of claim 21 , wherein the one or more processors are further to:

provide a notification of the detected one or more differences between the master connection file and the actual connections maintained among the plurality of networked resources, wherein each detected difference indicates an unauthorized connection or an inaccuracy of the master connection file.

24. The non-transitory computer-readable medium of claim 23 , wherein the one or more processors provide the notification to one or more of a log file, a notification area of a user interface, an email address, a text message, or as part of another message.

25. The non-transitory computer-readable medium of claim 21 , wherein the one or more differences comprise:

a number of the actual connections among the plurality of networked resources that do not have a corresponding desired connection in the master connection file; and

a number of the desired connections from the master connection file that are missing a corresponding actual connection.

26. The non-transitory computer-readable medium of claim 25 , wherein each of the one or more detected differences indicates an unauthorized connection or an inaccuracy of the master connection file.

27. The non-transitory computer-readable medium of claim 25 , wherein to compare a particular desired connection in the master connection file, the one or more processors are to:

determine whether the particular desired connection has a matching actual connection among the actual connections indicated by the first connection indication file of the first networked resource and the second connection indication file of the second networked resource between which the particular desired connection exists.

28. The non-transitory computer-readable medium of claim 21 , wherein each of the actual connections among the plurality of networked resources comprises a protocol, a port number, a port number range, or a security group.

29. The non-transitory computer-readable medium of claim 21 , wherein the master connection file is stored in human readable data-serialization language format.

30. The non-transitory computer-readable medium of claim 21 , wherein the one or more processors are further to:

provide version tracking and control of the master connection file.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2020
From: ARMSTRONG, JAMES CALVIN; CLAYBAUGH, JONATHAN
To: SNOWFLAKE COMPUTING, INC.
Reel/Frame 053455/0411 →
CHANGE OF NAME Recorded Aug 11, 2020
From: SNOWFLAKE COMPUTING, INC.
To: SNOWFLAKE INC.
Reel/Frame 054146/0347 →
Continuity (3)
Continuation 16857174 · Apr 23, 2020
Continuation 15079849 · Mar 24, 2016
Related Publication 20200358828A1 · Nov 12, 2020