IP Library Granted Patent US 11,824,899
Granted Patent B2
US 11,824,899 · App. 18/048,248 · Granted Nov 21, 2023

Securely managing network connections

Inventors: James Calvin Armstrong (Foster City, CA); Jonathan Claybaugh (San Francisco, CA)
Assignee: Snowflake Inc.
H04L63/20G06F21/566G06F21/57H04L41/0604H04L41/22H04L43/00H04L43/026H04L43/062H04L43/0811H04L47/10H04L63/0263H04L63/104H04L63/1408H04L63/1416G06F21/6218H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,824,899
App. No.
18/048,248
Granted
Nov 21, 2023
Kind
B2
Abstract

The disclosure relates generally to methods, systems, and apparatuses for managing network connections. An example method includes receiving one or more messages from a plurality of computing devices connected through a network, the one or more messages indicating actual connections among the plurality of computing devices. The example method further includes comparing, by one or more processors, the actual connections to a list of expected connections indicated by a connections master file that comprises connection information for the plurality of computing devices. The method further includes, responsive to detecting one or more differences between the list of expected connections and the actual connections, providing a notification indicating the one or more differences to a log file or a notification area of a user interface.

Claims (39)

1. A method comprising:

receiving one or more messages from a plurality of computing devices connected through a network, the one or more messages indicating actual connections among the plurality of computing devices;

comparing, by one or more processors, the actual connections to a list of expected connections indicated by a connections master file that comprises connection information for the plurality of computing devices;

responsive to detecting one or more differences between the list of expected connections and the actual connections, providing a notification indicating the one or more differences to a log file or a notification area of a user interface; and

responsive to a determination that one of the actual connections between two computing devices of the plurality of computing devices is an unauthorized connection, pushing a configuration file to each of the two computing devices to delete a rule corresponding to the unauthorized connection.

2. The method of claim 1 , wherein the actual connections are determined from configuration files included in each of the plurality of computing devices.

3. The method of claim 1 , wherein each expected connection in the list defines a first computing device of the plurality of computing devices and a second computing device of the plurality of computing devices between which the expected connection exists.

4. The method of claim 1 , wherein each of the actual connections among the plurality of computing devices comprises a protocol, a port number, a port number range, or a security group.

5. The method of claim 1 , wherein each detected difference indicates an unauthorized connection or an inaccuracy of the master connection file.

6. The method of claim 1 , further comprising determining, based on one or more detected differences between the list of expected connections and the actual connections among the plurality of computing devices, whether the list of expected connections is inaccurate.

7. The method of claim 6 , further comprising, responsive to a determination that the list of expected connections is inaccurate, updating the connections master file.

8. The method of claim 1 , further comprising determining, based on one or more detected differences between the list of expected connections and the actual connections among the plurality of computing devices, whether one or more of the actual connections are unauthorized.

9. A system comprising:

a memory comprising instructions; and

one or more processors operatively coupled to the memory to execute the instructions, wherein the instructions cause the one or more processors to:

receive one or more messages from a plurality of computing devices connected through a network, the one or more messages indicating actual connections among the plurality of computing devices;

compare, by the one or more processors, the actual connections to a list of expected connections indicated by a connections master file that comprises connection information for the plurality of computing devices;

responsive to a detection of one or more differences between the list of expected connections and the actual connections, provide a notification indicating the one or more differences to a log file or a notification area of a user interface; and

responsive to a determination that one of the actual connections between two computing devices of the plurality of computing devices is an unauthorized connection, push a configuration file to each of the two computing devices to delete a rule corresponding to the unauthorized connection.

10. The system of claim 9 , wherein the actual connections are determined from configuration files included in each of the plurality of computing devices.

11. The system of claim 9 , wherein each expected connection in the list defines a first computing device of the plurality of computing devices and a second computing device of the plurality of computing devices between which the expected connection exists.

12. The system of claim 9 , wherein each of the actual connections among the plurality of computing devices comprises a protocol, a port number, a port number range, or a security group.

13. The system of claim 9 , wherein each detected difference indicates an unauthorized connection or an inaccuracy of the master connection file.

14. The system of claim 9 , wherein the one or more processors are further to:

determine, based on one or more detected differences between the list of expected connections and the actual connections among the plurality of computing devices, whether the list of expected connections is inaccurate.

15. The system of claim 14 , wherein the one or more processors are further to, responsive to a determination that the list of expected connections is inaccurate, update the connections master file.

16. The system of claim 9 , wherein the one or more processors are further to determine, based on one or more detected differences between the list of expected connections and the actual connections among the plurality of computing devices, whether one or more of the actual connections are unauthorized.

17. A non-transitory computer readable medium having instructions stored thereon which, when executed by one or more processors, cause the one or more processors to:

receive one or more messages from a plurality of computing devices connected through a network, the one or more messages indicating actual connections among the plurality of computing devices;

compare the actual connections to a list of expected connections indicated by a connections master file that comprises connection information for the plurality of computing devices;

responsive to a detection of one or more differences between the list of expected connections and the actual connections, provide a notification indicating the one or more differences to a log file or a notification area of a user interface; and

responsive to a determination that one of the actual connections between two computing devices of the plurality of computing devices is an unauthorized connection, push a configuration file to each of the two computing devices to delete a rule corresponding to the unauthorized connection.

18. The non-transitory computer readable medium of claim 17 , wherein the actual connections are determined from configuration files included in each of the plurality of computing devices.

19. The non-transitory computer readable medium of claim 17 , wherein each expected connection in the list defines a first computing device of the plurality of computing devices and a second computing device of the plurality of computing devices between which the expected connection exists.

20. The non-transitory computer readable medium of claim 17 , wherein each of the actual connections among the plurality of computing devices comprises a protocol, a port number, a port number range, or a security group.

21. The non-transitory computer readable medium of claim 17 , wherein each detected difference indicates an unauthorized connection or an inaccuracy of the master connection file.

22. The non-transitory computer readable medium of claim 17 , wherein the one or more processors are further to determine, based on one or more detected differences between the list of expected connections and the actual connections among the plurality of computing devices, whether the list of expected connections is inaccurate.

23. The non-transitory computer readable medium of claim 22 , wherein the one or more processors are further to, responsive to a determination that the list of expected connections is inaccurate, update the connections master file.

24. The non-transitory computer readable medium of claim 17 , wherein the one or more processors are further to determine, based on one or more detected differences between the list of expected connections and the actual connections among the plurality of computing devices, whether one or more of the actual connections are unauthorized.

Assignments (2)
CHANGE OF NAME Recorded Jul 21, 2023
From: SNOWFLAKE COMPUTING, INC.
To: SNOWFLAKE INC.
Reel/Frame 064360/0821 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2023
From: ARMSTRONG, JAMES CALVIN; CLAYBAUGH, JONATHAN
To: SNOWFLAKE COMPUTING INC.
Reel/Frame 063937/0603 →
Continuity (5)
Continuation 17701482 · Mar 22, 2022
Continuation 16938902 · Jul 24, 2020
Continuation 16778797 · Jan 31, 2020
Continuation 15079849 · Mar 24, 2016
Related Publication 20230055052A1 · Feb 23, 2023