IP Library › Granted Patent US 12,155,626
Granted Patent B1
US 12,155,626 · App. 17/405,881 · Granted Nov 26, 2024

Cloud-based egress filtering system

Inventors: Xiaobo Sherry Wei (Palo Alto, CA); Lee-Chik Cheung (Santa Clara, CA)
Assignee: Aviatrix Systems, Inc.
H04L63/0263H04L12/4641H04L63/0227H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,155,626
App. No.
17/405,881
Granted
Nov 26, 2024
Kind
B1
Abstract

In one embodiment, a computing platform features a controller in communication with one or more virtual private cloud networks, including a first virtual private cloud network (VPC). The virtual private cloud network includes at least a first egress filtering gateway configured to filter egress traffic data received from a first gateway and route the filtered egress traffic data to a public network in accordance with a first set of filter rules. The first set of filter rules are included as part of a first security policy provided by the controller.

Claims (25)

1. A computing platform, comprising:

a controller deployed within a cloud computing platform and maintained within a non-transitory storage medium;

a first virtual private cloud network communicatively coupled to the controller, the first virtual private cloud network includes at least a first egress filtering gateway configured to:

filter egress traffic data received from a first gateway; and

route filtered egress traffic data to a public network in accordance with a first set of filter rules included as part of a first security policy provided by the controller,

wherein the controller is configured to enable a discovery mode of operation to access an audit log maintained by the first egress filtering gateway, the audit log comprising information associated with the egress traffic data that has been accepted or precluded from transmission.

2. The computing platform of claim 1 further comprising a first subnetwork included within the first virtual private cloud network, the first subnetwork comprises one or more cloud software instances being a source of the traffic data filtered by the first egress filtering gateway.

3. The computing platform of claim 2 , wherein the first virtual private cloud network corresponds to a spoke virtual private cloud network and the first gateway corresponds a first spoke gateway interposed to communicate with the one or more cloud instances and a plurality of egress filtering gateways including the first egress filtering gateway.

4. The computing platform of claim 1 further comprising:

a second virtual private cloud network communicatively coupled to the controller, the second virtual private cloud network includes at least a second egress filtering gateway configured to filter messages routed from a second gateway in accordance with a second set of filter rules included as part of a second security policy provided by the controller,

wherein the second set of filter rules being different from the first set of filter rules.

5. The computing platform of claim 4 , operating as a multi-cloud computing platform, wherein the first virtual private cloud network being deployed within a first public cloud network and the second virtual private cloud network being deployed within a second public cloud network that is different from the first public cloud network.

6. The computing platform of claim 1 , wherein the first virtual private cloud network corresponds to a transit virtual private cloud network and the first gateway corresponds a first transit gateway communicatively coupled to a plurality of egress filtering gateways including the first egress filtering gateway.

7. The computing platform of claim 1 , wherein the controller is configured to conduct analytics on the information associated with the egress traffic data to generate analytic results for subsequent display by a management console.

8. The computing platform of claim 1 , wherein the egress filtering gateway corresponds to logic conducting Fully Qualified Domain Name (FQDN) filtering.

9. A non-transitory storage medium including one or more egress filtering gateways being software that, upon execution and operability controlled by a controller, performs operations, comprising:

receiving, by a first egress filtering gateway of the one or more egress filtering gateways, a first security policy including a first set of filter rules;

receiving, by the first egress filtering gateway, egress traffic data for routing over a public network;

conducting, by the first egress filtering gateway, Fully Qualified Domain Name (FQDN) filtering of the egress traffic data in accordance with the first set of filter rules of the first security policy provided by the controller, the egress traffic data being received from a first gateway for routing to the public network; and

enabling, by the controller, a discovery mode of operation to access an audit log maintained by the first egress filtering gateway, the audit log comprising information associated with the egress traffic data that has been accepted or precluded from transmission.

10. The non-transitory storage medium of claim 9 , wherein the received egress traffic data originating from a first subnetwork included within a first virtual private cloud network that includes the one or more egress filtering gateways, the first subnetwork comprises one or more cloud software instances being a source of the traffic data filtered by the first egress filtering gateway.

11. The non-transitory storage medium of claim 9 , further comprising;

collecting information associated with the egress traffic data with an audit log associated with the first egress filtering gateway, the information identifying messages associated with a first set of egress traffic data with acceptable FQDNs and messages associated with a second set of egress traffic data with FQDNs precluded from transmission.

12. The non-transitory storage medium of claim 11 further comprising:

conducting analytics on the information associated with the egress traffic data to generate analytic results for subsequent display by a management console.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2022
From: WEI, XIAOBO SHERRY; CHEUNG, LEE-CHIK
To: AVIATRIX SYSTEMS, INC.
Reel/Frame 061340/0915 →
Continuity (3)
Provisional Application 63229919 · Aug 5, 2021
Provisional Application 63218869 · Jul 6, 2021
Provisional Application 63150503 · Feb 17, 2021
Cited By (2)
US 12,556,601 US 12,580,830