IP Library Granted Patent US 12,418,508
Granted Patent B2
US 12,418,508 · App. 17/643,009 · Granted Sep 16, 2025

Inferring cloud network connectivity as a minimal list of firewall rules

Inventors: Adi Sosnovich (Haifa, IL); Ziv Nevo (Yokneam Ilit, IL); Gil Eliezer Shurek (Haifa, IL); Shai Doron (Kibuz Meggido, IL); Karen Frida Yorav (Haifa, IL)
Assignee: International Business Machines Corporation
H04L63/0263H04L41/22H04L63/0236H04L63/102H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,418,508
App. No.
17/643,009
Granted
Sep 16, 2025
Kind
B2
Abstract

A method, computer system, and a computer program product for determining a cluster connectivity is provided. The present invention may first include receiving as input a connectivity graph. The present invention may then include generating a minimal list of firewall rules from the received connectivity graph by iteratively merging firewall rules with commonality of connectivity attribute.

Claims (26)

1. A method comprising:

receiving as input a connectivity graph that includes a list of peer pairs with a plurality of connection sets generated from a plurality of sets of network policies;

grouping, from the connectivity graph, a first set of peer pairs from the list of peer pairs with a connection set by a pod label expression, wherein a namespace associated with the pod label expression includes the first set of peer pairs and a second set of peer pairs from the list of peer pairs; and

generating a minimal list of firewall rules from the connectivity graph by iteratively merging a set of firewall rules with commonality of connectivity attributes, wherein the minimal list of firewall rules include the grouping of the first set of peer pairs with the connection set by the pod label expression.

2. The method of claim 1 , wherein a firewall rule of the set of firewall rules is generated when a combination of the plurality of sets of network policies define ingress and egress rules for the first set of peer pairs from the list of peer pairs.

3. The method of claim 1 , wherein the connectivity graph is a table representation of a cluster's peer pairs with sets of allowed connections.

4. The method of claim 1 , wherein a list of firewall rules is used as an input for a Kubernetes network configuration.

5. A computer system comprising:

one or more computer-readable storage media; and

program instructions stored on the one or more computer-readable storage media to perform operation comprising:

receiving as input a connectivity graph that includes a list of peer pairs with a plurality of connection sets generated from a plurality of sets of network policies;

grouping, from the connectivity graph, a first set of peer pairs from the list of peer pairs with a connection set by a pod label expression, wherein a namespace associated with the pod label expression includes the first set of peer pairs and a second set of peer pairs from the list of peer pairs; and

generating a minimal list of firewall rules from the connectivity graph by iteratively merging a set of firewall rules with commonality of connectivity attributes, wherein the minimal list of firewall rules include the grouping of the first set of peer pairs with the connection set by the pod label expression.

6. The computer system of claim 5 , wherein a firewall rule of the set of firewall rules is generated when a combination of the plurality of sets of network policies define ingress and egress rules for the first set of peer pairs from the list of peer pairs.

7. The computer system of claim 5 , wherein the connectivity graph is a table representation of a cluster's peer pairs with sets of allowed connections.

8. The computer system of claim 5 , wherein a list of firewall rules is used as an input for a Kubernetes network configuration.

9. A computer program product comprising:

a processor set;

one or more computer-readable storage media; and

program instructions stored on the one or more computer-readable storage media to cause the processor set to perform operations comprising:

receiving as input a connectivity graph that includes a list of peer pairs with a plurality of connection sets generated from a plurality of sets of network policies;

grouping, from the connectivity graph, a first set of peer pairs from the list of peer pairs with a connection set by a pod label expression, wherein a namespace associated with the pod label expression includes the first set of peer pairs and a second set of peer pairs from the list of peer pairs; and

generating a minimal list of firewall rules from the connectivity graph by iteratively merging a set of firewall rules with commonality of connectivity attributes, wherein the minimal list of firewall rules include the grouping of the first set of peer pairs with the connection set by the pod label expression.

10. The computer program product of claim 9 , wherein a firewall rule of the set of firewall rules is generated when a combination of the plurality of sets of network policies define ingress and egress rules for the first set of peer pairs from the list of peer pairs.

11. The computer program product of claim 9 , wherein the connectivity graph is a table representation of a cluster's peer pairs with sets of allowed connections.

12. The computer program product of claim 9 , wherein a list of firewall rules is used as an input for a Kubernetes network configuration.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2021
From: SOSNOVICH, ADI; NEVO, ZIV; SHUREK, GIL ELIEZER; DORON, SHAI; YORAV, KAREN FRIDA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058322/0154 →
Continuity (1)
Related Publication 20230179573A1 · Jun 8, 2023
References Cited (18)
US 10511630B1 · Weiss · 2019 [cited by examiner]
US 10547521B1 · Roy · 2020 [cited by applicant]
US 11303611B1 · Karyampudi · 2022 [cited by examiner]
US 20090178105A1 · Feng · 2009 [cited by examiner]
US 20160094401A1 · Anwar · 2016 [cited by examiner]
US 20200177684A1 · Yu · 2020 [cited by examiner]
US 20200257810A1 · Vrabec · 2020 [cited by applicant]
US 20200382560A1 · Woolward · 2020 [cited by applicant]
US 20220417219A1 · Sheriff · 2022 [cited by examiner]
US 20230022134A1 · Talwar · 2023 [cited by examiner]
US 20230216888A1 · Alaeddini · 2023 [cited by examiner]
Cilium, “Cilium 1.7: Hubble UI, Cluster-wide Network Policies, eBPF-based Direct Server Retum, TLS visibility, New eBPF Go Library, . . . , ” Cllium, Feb. 19, 2020, 18 pgs. [cited by applicant]
Cilium, “Network Policy Editor for Kubernetes,” Cilium.com, [accessed Oct. 4, 2021], 1 pg., Retrieved from the Internet: <https://editor.cilium.lo/>. [cited by applicant]
Fenwick, “Tools for Understanding, Measuring, and Applying Network Policies Effectively in Kubernetes,” GolangRepo.com, Aug. 16, 2021, 19 pages, Retrieved from the Internet <https://golangrepo.com/repo/mattfenwick- cycl… [cited by applicant]
Github, “Tools for Understanding, Measuring, and Applying Network Policies Effectively in Kubernetes,” Github.com, [accessed Oct. 1, 2021], 3 pgs., Retrieved from the Internet: <https://github.com/mattfenwick/cyclonus>. [cited by applicant]
Mell et al., “The NIST Definition of Cloud Computing”, National Institute of Standards and Technology, Special Publication 800-145, Sep. 2011, pp. 1-7. [cited by applicant]
Stackrox, “Red Hat Acquires Kubernetes-Native Security Leader StackRox,” [accessed Oct. 1, 2021], 9 pgs., Retrieved from the Internet: <https://www.stackrox.com/>. [cited by applicant]
Tufin, “Network Policy Viewer,” Tufin, [accessed Oct. 1, 2021], 1 pg., Retrieved from the Internet: <https://orca.tufin.io/netpol>. [cited by applicant]