IP Library Granted Patent US 11,496,524
Granted Patent B2
US 11,496,524 · App. 17/701,482 · Granted Nov 8, 2022

Securely managing network connections

Inventors: James Calvin Armstrong (Foster City, CA); Jonathan Claybaugh (San Francisco, CA)
Assignee: Snowflake Inc.
H04L63/20G06F21/566G06F21/57G06F21/6218H04L41/0604H04L41/22H04L43/00H04L43/026H04L43/062H04L43/0811H04L47/10H04L63/0263H04L63/102H04L63/104H04L63/1408H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,496,524
App. No.
17/701,482
Granted
Nov 8, 2022
Kind
B2
Abstract

The disclosure relates generally to methods, systems, and apparatuses for managing network connections. A method may include comparing a list of expected connections among a set of endpoints of a network with one or more of the actual connections indicated by configuration files of the set of endpoints to determine one or more differences between the list of expected connections and the actual connections and updating at least one of the configuration files of the set of endpoints to reflect the one or more differences detected between the list of expected connections and the actual connections.

Claims (54)

1. A method comprising:

receiving one or more messages from a plurality of endpoints of a network, the one or more messages comprising information from configuration files of the plurality of endpoints indicating actual connections among the plurality of endpoints of the network;

comparing, by one or more processors, a list of expected connections among a plurality of endpoints of the network with one or more of the actual connections indicated by the configuration files of the plurality of endpoints to determine one or more differences between the list of expected connections and the actual connections, wherein the expected connections are indicated by a connections master file storing information for the plurality of endpoints of the network; and

updating, by the one or more processors, at least one of the configuration files associated with at least one of the plurality of endpoints to reflect the one or more differences detected between the list of expected connections and the actual connections.

2. The method of claim 1 , further comprising:

providing a notification indicating the one or more differences between the list of expected connections and the actual connections among the plurality of endpoints.

3. The method of claim 1 , wherein each expected connection in the list defines a first endpoint and a second endpoint between which the expected connection exists.

4. The method of claim 1 , wherein the one or more differences comprise:

a number of the actual connections among the plurality of endpoints that are missing from the list of expected connections; and

a number of the expected connections from the list of expected connections that are missing a corresponding actual connection.

5. The method of claim 4 , wherein each of the one or more differences indicates an unauthorized connection or an inaccuracy of the list of expected connections.

6. The method of claim 4 , wherein comparing the list of expected connections with the actual connections comprises determining whether each expected connection in the list of expected connections has a matching connection among the one or more actual connections indicated by configuration files of a first endpoint and a second endpoint between which the expected connection exists.

7. The method of claim 1 , wherein each of the actual connections among the plurality of endpoints comprises a protocol, a port number, a port number range, or a security group.

8. The method of claim 1 , wherein the list of expected connections is stored in human readable data-serialization language format.

9. The method of claim 1 , further comprising providing version tracking and control of the list of expected connections.

10. The method of claim 1 , wherein updating the at least one of the configuration files of the plurality of endpoints comprises adding an indication of an actual connection to the at least one of the configuration files or removing an indication of an actual connection from the at least one of the configuration files.

11. A system comprising:

a memory comprising instructions; and

one or more processors operatively coupled to the memory to execute the instructions, wherein the instructions cause the one or more processors to:

receive one or more messages from a plurality of endpoints of a network, the one or more messages comprising information from configuration files of the plurality of endpoints indicating actual connections among the plurality of endpoints of the network;

compare, by one or more processors, a list of expected connections among a plurality of endpoints of the network with one or more of the actual connections indicated by the configuration files of the plurality of endpoints to determine one or more differences between the list of expected connections and the actual connections, wherein the expected connections are indicated by a connections master file storing information for the plurality of endpoints of the network; and

update at least one of the configuration files associated with at least one of the plurality of endpoints to reflect the one or more differences detected between the list of expected connections and the actual connections.

12. The system of claim 11 , wherein the one or more processors are further to:

provide a notification indicating the one or more differences between the list of expected connections and the actual connections among the plurality of endpoints.

13. The system of claim 11 , wherein each expected connection in the list defines a first endpoint and a second endpoint between which the expected connection exists.

14. The system of claim 11 , wherein the one or more differences comprise:

a number of the actual connections among the plurality of endpoints that are missing from the list of expected connections; and

a number of the expected connections from the list of expected connections that are missing a corresponding actual connection.

15. The system of claim 14 , wherein each of the one or more differences indicates an unauthorized connection or an inaccuracy of the list of expected connections.

16. The system of claim 14 , wherein to compare the list of expected connections with the actual connections, the one or more processors are to:

determine whether each expected connection in the list of expected connections has a matching connection among the one or more actual connections indicated by configuration files of a first endpoint and a second endpoint between which the expected connection exists.

17. The system of claim 11 , wherein each of the actual connections among the plurality of endpoints comprises a protocol, a port number, a port number range, or a security group.

18. The system of claim 11 , wherein the list of expected connections is stored in human readable data-serialization language format.

19. The system of claim 11 , further comprising providing version tracking and control of the list of expected connections.

20. The system of claim 11 , wherein to update the at least one of the configuration file of the plurality of endpoints the one or more processors are to:

add an indication of an actual connection to the at least one of the configuration files or remove an indication of an actual connection from the at least one of the configuration files.

21. A non-transitory computer readable medium having instructions stored thereon which, when executed by one or more processors, cause the one or more processors to:

receive one or more messages from a plurality of endpoints of a network, the one or more messages comprising information from configuration files of the plurality of endpoints indicating actual connections among the plurality of endpoints of the network;

compare, by one or more processors, a list of expected connections among a plurality of endpoints of the network with one or more of the actual connections indicated by the configuration files of the plurality of endpoints to determine one or more differences between the list of expected connections and the actual connections, wherein the expected connections are indicated by a connections master file storing information for the plurality of endpoints of the network; and

update at least one of the configuration files associated with at least one of the plurality of endpoints to reflect the one or more differences detected between the list of expected connections and the actual connections.

22. The non-transitory computer readable medium of claim 21 , wherein the one or more processors are further to:

provide a notification indicating the one or more differences between the list of expected connections and the actual connections among the plurality of endpoints.

23. The non-transitory computer readable medium of claim 21 , wherein each expected connection in the list defines a first endpoint and a second endpoint between which the expected connection exists.

24. The non-transitory computer readable medium of claim 21 , wherein the one or more differences comprise:

a number of the actual connections among the plurality of endpoints that are missing from the list of expected connections; and

a number of the expected connections from the list of expected connections that are missing a corresponding actual connection.

25. The non-transitory computer readable medium of claim 24 , wherein each of the one or more differences indicates an unauthorized connection or an inaccuracy of the list of expected connections.

26. The non-transitory computer readable medium of claim 24 , wherein to compare the list of expected connections with the actual connections, the one or more processors are to:

determine whether each expected connection in the list of expected connections has a matching connection among the one or more actual connections indicated by configuration files of a first endpoint and a second endpoint between which the expected connection exists.

27. The non-transitory computer readable medium of claim 21 , wherein each of the actual connections among the plurality of endpoints comprises a protocol, a port number, a port number range, or a security group.

28. The non-transitory computer readable medium of claim 21 , wherein the list of expected connections is stored in human readable data-serialization language format.

29. The non-transitory computer readable medium of claim 21 , further comprising providing version tracking and control of the list of expected connections.

30. The non-transitory computer readable medium of claim 21 , wherein to update the at least one of the configuration file of the plurality of endpoints the one or more processors are to:

add an indication of an actual connection to the at least one of the configuration files or remove an indication of an actual connection from the at least one of the configuration files.

Assignments (3)
CHANGE OF NAME Recorded Oct 24, 2022
From: SNOWFLAKE COMPUTING INC.
To: SNOWFLAKE INC.
Reel/Frame 061752/0019 →
CHANGE OF NAME Recorded Oct 4, 2022
From: SNOWFLAKE COMPUTING INC.
To: SNOWFLAKE INC.
Reel/Frame 061599/0333 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2022
From: ARMSTRONG, JAMES CALVIN; CLAYBAUGH, JONATHAN
To: SNOWFLAKE COMPUTING INC.
Reel/Frame 061237/0950 →
Continuity (4)
Continuation 16938902 · Jul 24, 2020
Continuation 16778797 · Jan 31, 2020
Continuation 15079849 · Mar 24, 2016
Related Publication 20220217180A1 · Jul 7, 2022