IP Library Granted Patent US 12,267,300
Granted Patent B2
US 12,267,300 · App. 18/472,050 · Granted Apr 1, 2025

Intelligent firewall policy processor

Inventors: Raja Kommula (Cupertino, CA); Rahul Gupta (Kanpur, IN); Ganesh Byagoti Matad Sunkada (Bengaluru, IN); Tarun Banka (Milpitas, CA); Thayumanavan Sridhar (Sunnyvale, CA); Raj Yavatkar (Los Gatos, CA)
Assignee: Juniper Networks, Inc.
H04L63/0263G06N5/022G06N20/20H04L41/14H04L41/16H04L41/5009H04L43/0811H04L43/0888H04L63/0236H04L63/0245H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,300
App. No.
18/472,050
Granted
Apr 1, 2025
Kind
B2
Abstract

An example network system includes processing circuitry and one or more memories coupled to the processing circuitry. The one or more memories are configured to store instructions which cause the system to obtain telemetry data, the telemetry data being associated with a plurality of applications running on a plurality of hosts. The instructions cause the system to, based on the telemetry data, determine a subset of applications of the plurality of applications that run on a first host of the plurality of hosts. The instructions cause the system to determine a subset of firewall policies of a plurality of firewall polices, each of the subset of firewall policies applying to at least one respective application of the subset of applications. The instructions cause the system to generate an indication of the subset of firewall policies and send the indication to a management plane of a distributed firewall.

Claims (43)

1. A network system comprising:

processing circuitry;

one or more memories coupled to the processing circuitry and configured to store instructions which, when executed by the processing circuitry, cause the network system to:

obtain telemetry data, the telemetry data being associated with a plurality of applications running on a plurality of hosts;

based on the telemetry data, determine which applications of the plurality of applications run on a first host of the plurality of hosts, the determined applications comprising a subset of applications of the plurality of applications;

determine which firewall policies of a plurality of firewall polices apply to the subset of applications, the determined firewall policies comprising a subset of firewall policies of the plurality of firewall policies, each of the subset of firewall policies applying to at least one respective application of the subset of applications;

generate an indication identifying the subset of firewall policies; and

send the indication to a management plane of a distributed firewall.

2. The network system of claim 1 , wherein the processing circuitry is configured to execute a machine learning model to determine at least one of which applications run on the first host or which firewall policies apply to the determined applications.

3. The network system of claim 2 , wherein the machine learning model is an unsupervised machine learning model.

4. The network system of claim 1 , wherein the first host comprises a network interface card (NIC), the NIC comprising NIC processing circuitry.

5. The network system of claim 1 , wherein an instance of a control plane and a data plane of the distributed firewall runs on the first host.

6. The network system of claim 1 , wherein the instructions further cause the network system to:

receive, by the management plane, the indication;

prune, by the management plane, a firewall policy set corresponding to the plurality of firewall policies based on the indication, to generate a pruned firewall policy set, the pruned firewall policy set corresponding to the subset of firewall policies; and

send, by the management plane and to a control plane of an instance of the distributed firewall executing on the first host, the pruned firewall policy set.

7. The network system of claim 6 , wherein the instructions further cause the network system to apply only the pruned firewall policy set to a first packet of a new flow.

8. The network system of claim 7 , wherein as part of applying only the pruned firewall policy set to the first packet of the new flow, the instructions cause the network system to apply each policy of the pruned firewall policy set to the first packet of the new flow and refrain from applying any policy of the firewall policy set that is not a part of the pruned firewall policy set.

9. A method comprising:

obtaining telemetry data, the telemetry data being associated with a plurality of applications running on a plurality of hosts;

based on the telemetry data, determining which applications of the plurality of applications run on a first host of the plurality of hosts, the determined applications comprising a subset of applications of the plurality of applications;

determining which firewall policies of a plurality of firewall polices apply to the subset of applications, the determined firewall policies comprising a subset of firewall policies of the plurality of firewall policies, each of the subset of firewall policies applying to at least one respective application of the subset of applications;

generating an indication identifying the subset of firewall policies; and

sending the indication to a management plane of a distributed firewall.

10. The method of claim 9 , further comprising executing a machine learning model to determine at least one of which applications run on the first host or which firewall policies apply to the determined applications.

11. The method of claim 10 , wherein the machine learning model is an unsupervised machine learning model.

12. The method of claim 9 , wherein the first host comprises a network interface card (NIC), the NIC comprising NIC processing circuitry.

13. The method of claim 9 , wherein an instance of a control plane and a data plane of the distributed firewall runs on the first host.

14. The method of claim 9 , further comprising:

receiving, by the management plane, the indication;

pruning, by the management plane, a firewall policy set corresponding to the plurality of firewall policies based on the indication, to generate a pruned firewall policy set, the pruned firewall policy set corresponding to the subset of firewall policies; and

sending, by the management plane and to a control plane of an instance of the distributed firewall executing on the first host, the pruned firewall policy set.

15. The method of claim 14 , further comprising applying only the pruned firewall policy set to a first packet of a new flow.

16. The method of claim 15 , wherein applying only the pruned firewall policy set to the first packet of the new flow comprises applying each policy of the pruned firewall policy set to the first packet of the new flow and refraining from applying any policy of the firewall policy set that is not a part of the pruned firewall policy set.

17. Non-transitory computer-readable storage media storing instructions, which, when executed, cause processing circuitry to:

obtain telemetry data, the telemetry data being associated with a plurality of applications running on a plurality of hosts;

based on the telemetry data, determine which applications of the plurality of applications run on a first host of the plurality of hosts, the determined applications comprising a subset of applications of the plurality of applications;

determine which firewall policies of a plurality of firewall polices apply to the subset of applications, the determined firewall policies comprising a subset of firewall policies of the plurality of firewall policies, each of the subset of firewall policies applying to at least one respective application of the subset of applications;

generate an indication identifying the subset of firewall policies; and

send the indication to a management plane of a distributed firewall.

18. The non-transitory computer-readable storage media of claim 17 , the instructions cause the processing circuitry to execute a machine learning model to determine at least one of which applications run on the first host or which firewall policies apply to the determined applications.

19. The non-transitory computer-readable storage media of claim 18 , wherein the machine learning model is an unsupervised machine learning model.

20. The non-transitory computer-readable storage media of claim 17 , wherein the first host comprises a network interface card (NIC), the NIC comprising NIC processing circuitry.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2025
From: YAVATKAR, RAJENDRA SHIVARAM
To: JUNIPER NETWORKS, INC.
Reel/Frame 073226/0029 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2023
From: KOMMULA, RAJA; GUPTA, RAHUL; SUNKADA, GANESH BYAGOTI MATAD; BANKA, TARUN; SRIDHAR, THAYUMANAVAN; YAVATKAR, RAJ
To: JUNIPER NETWORKS, INC.
Reel/Frame 064988/0980 →
Priority Claims (1)
IN 202241069004 · Nov 30, 2022 · national
Continuity (1)
Related Publication 20240179124A1 · May 30, 2024
References Cited (108)
US 7363203B2 · Hines · 2008 [cited by applicant]
US 9424121B2 · Kushnir et al. · 2016 [cited by applicant]
US 9571394B1 · Sivaramakrishnan et al. · 2017 [cited by applicant]
US 9961571B2 · Yang et al. · 2018 [cited by applicant]
US 10171335B2 · Maheshwari et al. · 2019 [cited by applicant]
US 10235231B2 · Zhang et al. · 2019 [cited by applicant]
US 10257055B2 · Li et al. · 2019 [cited by applicant]
US 10263833B2 · Maheshwari et al. · 2019 [cited by applicant]
US 10289473B2 · Mendes et al. · 2019 [cited by applicant]
US 10373094B2 · Naous et al. · 2019 [cited by applicant]
US 10574512B1 · Mermoud et al. · 2020 [cited by applicant]
US 10616043B2 · Wang et al. · 2020 [cited by applicant]
US 10855548B2 · Garvey et al. · 2020 [cited by applicant]
US 10897389B2 · Thampy et al. · 2021 [cited by applicant]
US 11061393B2 · Abe et al. · 2021 [cited by applicant]
US 11082439B2 · Salunke et al. · 2021 [cited by applicant]
US 11138163B2 · Mdini et al. · 2021 [cited by applicant]
US 11165631B1 · Chitalia et al. · 2021 [cited by applicant]
US 11238129B2 · Jalal et al. · 2022 [cited by applicant]
US 11265336B2 · Hild · 2022 [cited by applicant]
US 11323312B1 · Banka et al. · 2022 [cited by applicant]
US 11323327B1 · Chitalia et al. · 2022 [cited by applicant]
US 11422882B1 · Chhabra · 2022 [cited by applicant]
US 11500757B2 · Ambichl et al. · 2022 [cited by applicant]
US 11616682B2 · Thampy et al. · 2023 [cited by applicant]
US 11636090B2 · Li et al. · 2023 [cited by applicant]
US 11645293B2 · Pelloin · 2023 [cited by applicant]
US 11658874B2 · Banka et al. · 2023 [cited by applicant]
US 11675799B2 · Pierri et al. · 2023 [cited by applicant]
US 11765014B2 · Banka et al. · 2023 [cited by applicant]
US 11809267B2 · Gusat et al. · 2023 [cited by applicant]
US 11816178B2 · Jalal et al. · 2023 [cited by applicant]
US 11887015B2 · Fahmy et al. · 2024 [cited by applicant]
US 20040088730A1 · Gopalan et al. · 2004 [cited by applicant]
US 20040268149A1 · Aaron · 2004 [cited by applicant]
US 20050276228A1 · Yavatkar et al. · 2005 [cited by applicant]
US 20080262990A1 · Kapoor et al. · 2008 [cited by applicant]
US 20090055684A1 · Jamjoom et al. · 2009 [cited by applicant]
US 20110214157A1 · Korsunsky et al. · 2011 [cited by applicant]
US 20130298184A1 · Ermagan et al. · 2013 [cited by applicant]
US 20140157405A1 · Joll et al. · 2014 [cited by applicant]
US 20160112443A1 · Grossman et al. · 2016 [cited by applicant]
US 20160182373A1 · Wang et al. · 2016 [cited by applicant]
US 20160308734A1 · Feller et al. · 2016 [cited by applicant]
US 20170075749A1 · Ambichl et al. · 2017 [cited by applicant]
US 20170288991A1 · Ganesh · 2017 [cited by applicant]
US 20170330096A1 · Gupta et al. · 2017 [cited by applicant]
US 20180103052A1 · Choudhury · 2018 [cited by examiner]
US 20180115470A1 · Huang et al. · 2018 [cited by applicant]
US 20180131675A1 · Sengupta · 2018 [cited by examiner]
US 20190068693A1 · Bernat · 2019 [cited by applicant]
US 20190141015A1 · Nellen · 2019 [cited by applicant]
US 20190196894A1 · Cherbakov et al. · 2019 [cited by applicant]
US 20200028771A1 · Wong · 2020 [cited by examiner]
US 20200136973A1 · Rahman et al. · 2020 [cited by applicant]
US 20200272973A1 · Hongtan et al. · 2020 [cited by applicant]
US 20200278892A1 · Nainar et al. · 2020 [cited by applicant]
US 20210044623A1 · Bosch et al. · 2021 [cited by applicant]
US 20210117242A1 · Van De Groenendaal et al. · 2021 [cited by applicant]
US 20210135967A1 · Iorga et al. · 2021 [cited by applicant]
US 20210160262A1 · Bynum et al. · 2021 [cited by applicant]
US 20210320875A1 · Guim Bernat et al. · 2021 [cited by applicant]
US 20210367830A1 · Jain et al. · 2021 [cited by applicant]
US 20210390423A1 · Latapie et al. · 2021 [cited by applicant]
US 20210406091A1 · Thyagaturu et al. · 2021 [cited by applicant]
US 20220006783A1 · Hassanzadeh · 2022 [cited by examiner]
US 20220029929A1 · Jain et al. · 2022 [cited by applicant]
US 20220038471A1 · Sugarbaker et al. · 2022 [cited by applicant]
US 20220058042A1 · Vanjare et al. · 2022 [cited by applicant]
US 20220103431A1 · Singh et al. · 2022 [cited by applicant]
US 20220114032A1 · Bernat et al. · 2022 [cited by applicant]
US 20220116478A1 · Biederman et al. · 2022 [cited by applicant]
US 20220210028A1 · Chen et al. · 2022 [cited by applicant]
US 20220224121A1 · Jha et al. · 2022 [cited by applicant]
US 20220337555A1 · Gol · 2022 [cited by examiner]
US 20220417117A1 · Tayeb et al. · 2022 [cited by applicant]
US 20220417323A1 · Julien et al. · 2022 [cited by applicant]
US 20230262093A1 · Gupta · 2023 [cited by examiner]
US 20230300059A1 · Rodriguez Natal et al. · 2023 [cited by applicant]
US 20230388346A1 · Kulshreshtha et al. · 2023 [cited by applicant]
US 20240007342A1 · Gupta et al. · 2024 [cited by applicant]
CN 113206761B · 2021 [cited by applicant]
EP 3889777A1 · 2021 [cited by applicant]
WO 2013184846A1 · 2013 [cited by applicant]
WO 2022020336A1 · 2022 [cited by applicant]
“Amazon SageMaker—Developer Guide,” retrieved from https://docs.aws.amazon.com/sagemaker/latest/dg/randomcutforest.html on Feb. 15, 2024, 6167 pp. [cited by applicant]
“CSRX Container Firewall,” retrieved from https://www.juniper.net/us/en/products/security/srx-series/csrx-containerized-firewall.html, on Feb. 15, 2024, 2 pp. [cited by applicant]
“Emerging Technologies: Adoption Growth Insights—Function Accelerator Cards Cards(Next-Gen SmartNICs, DPUs, IPUs),” Gartner Research, Sep. 14, 2021, 6 pp. [cited by applicant]
“Granger Causality,” Wikipedia, Last Updated Sep. 28, 2023, 14 pp. [cited by applicant]
“NVIDIA BlueField Networking Platform,” retrieved from https://www.nvidia.com/en-us/networking/products/data-processing-unit/, on Feb. 15, 2024, 7 pp. [cited by applicant]
“PageRank,” Wikipedia, Last Updated Oct. 19, 2023, 22 pp. [cited by applicant]
“The Istio Service Mesh,” retrieved from https://istio.io/latest/about/service-mesh/, on Feb. 15, 2024, 5 pp. [cited by applicant]
Extended Search Report from counterpart European Application No. 23211541.0 dated Feb. 5, 2024, 7 pp. [cited by applicant]
Kim et al., “A Case for SmartNIC-accelerated Private Communication,” APNet '20: Proceedings of the 4th Asia-Pacific Workshop on Networking, Aug. 2020, 8 pp. [cited by applicant]
Liu et al., “MicroHECL: High-Efficient Root Cause Localization in Large-Scale Microservice Systems,” 2021 IEEE/ACM 43rd International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP), May… [cited by applicant]
Liu et al., “Offloading Distributed Applications onto SmartNICs using iPipe,” in Proceedings of the ACM Special Interest Group on Data Communication (SIGCOMM '19), Aug. 19-23, 2019, 16 pp. [cited by applicant]
Liu et al., “Performance Characteristics of the BlueField-2 SmartNIC,” arXiv:2105.06619, May 14, 2021, 13 pp. [cited by applicant]
Meng et al., “Localizing Failure Root Causes in a Microservice through Causality Inference,” 2020 IEEE/ACM 28th International Symposium on Quality of Service (IWQoS), Jun. 2020, 10 pp. [cited by applicant]
Moro et al., “FOP4: Function Offloading Prototyping in Heterogeneous and Programmable Network Scenarios,” 2019 IEEE Conference on Network Function Virtualization and Software Defined Network, Nov. 2019, 6 pp. [cited by applicant]
Soldani et al., “Anomaly Detection and Failure Root Cause Analysis in (Micro) Service-Based Cloud Applications: A Survey,” arXiv:2105.12378, May 26, 2021, 36 pp. [cited by applicant]
Tanenbaum et al., “Distributed Systems: Principles and Paradigms,” Second Edition, Prentice-Hall, (Applicant points out, in accordance with MPEP 609.04(a), that the year of publication, 2007, is sufficiently earlier tha… [cited by applicant]
U.S. Appl. No. 18/472,042, filed Sep. 21, 2023, by Kommula et al. [cited by applicant]
U.S. Appl. No. 18/472,059, filed Sep. 21, 2023, by Kommula et al. [cited by applicant]
U.S. Appl. No. 18/472,092, filed Sep. 21, 2023, by Kommula et al. [cited by applicant]
U.S. Appl. No. 18/472,111, filed Sep. 21, 2023, by Kommula et al. [cited by applicant]
U.S. Appl. No. 18/472,123, filed Sep. 21, 2023, by Kommula et al. [cited by applicant]
Wu et al., “MicroRCA: Root Cause Localization of Performance Issues in Microservices,” IEEE/IFIP Network Operations and Management Symposium (NOMS), Apr. 2020, 10 pp. [cited by applicant]
Response to Extended Search Report dated Feb. 6, 2024, from counterpart European Application No. 23211541.0 filed Dec. 2, 2024, 11 pp. [cited by applicant]
Cited By (1)
US 12,647,394