IP Library Patent Application 19307742
Patent Application
App. No. 19/307,742

SYSTEM AND METHOD FOR UTILIZATION OF FIREWALL POLICIES FOR NETWORK SECURITY

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/307,742
Abstract

Aspects of the present disclosure involve systems, methods, for encoding a firewall ruleset into one or more bit arrays for fast determination of processing of a received communication packet by a firewall device associated with a network. Through this bitmap, a number of computation operations needed to determine a processing rule for a received packet is significantly reduced compared to the traditional approach of using a hash or a longest prefix match technique. Rather, determining a processing rule for a received packet may include determining a bit value within one or more arrays. In one implementation, a firewall rule may be encoded into a 64-bit array of bit values in which each bit of the array corresponds to a particular processing rule for a particular network address. The firewall rule may be encoded into a bitmap array of bit values by asserting a particular bit within the array.

Claims (40)

1 . A method for providing a firewall service, the method comprising:

encoding a firewall ruleset into a new array comprising a string of bits, wherein each bit of the new array corresponds to one processing rule of the firewall ruleset;

determining a bit value from the new array based on a portion of a network address included in a received communication packet; and

processing the received communication packet based on the bit value from the new array.

2 . The method of claim 1 wherein a number of bits of the new array is the same as a number of bits of one of a plurality of arrays encoded from the firewall ruleset.

3 . The method of claim 1 further comprising:

storing the new array at a firewall device, wherein storing the new array consumes less memory space than a storing of a plurality of arrays encoded from the firewall ruleset.

4 . The method of claim 1 further comprising:

combining a plurality of arrays encoded from the firewall ruleset into the new array including determining a union set of a blacklist array and a threatlist array, the blacklist array corresponding to a block processing rule of the firewall ruleset and the threatlist array corresponding to a re-direct processing rule of the firewall ruleset.

5 . The method of claim 4 wherein combining the plurality of arrays into the new array further comprises:

determining a difference set of the union set and a whitelist array, the whitelist array corresponding to an allow processing rule of the firewall ruleset.

6 . The method of claim 5 wherein combining the plurality of arrays into the new array further comprises: setting the difference set as the new array.

7 . The method of claim 1 wherein the network address is an Internet Protocol (IP) address and the portion comprises a first twenty-six bits of the network address.

8 . The method of claim 2 wherein encoding the firewall ruleset comprises:

asserting a bit of the string of bits of the new array at a first bit position, the first bit position corresponding to a value equal to a second portion of the network address.

9 . The method of claim 8 wherein the second portion comprises a last six bits of the network address.

10 . The method of claim 1 wherein the new array of a string of bits comprises 64 bits.

11 . The method of claim 1 wherein processing the received communication packet comprises:

blocking the received communication to a destination address if the bit value from the new array is asserted.

12 . The method of claim 1 wherein processing the received communication packet comprises:

transmitting the received communication to a destination address if the bit value from the new array is de-asserted.

13 . A network firewall device comprising:

a processing device;

at least one interface receiving communication packets; and

a non-transitory computer-readable medium encoded with instructions, when executed by the processing device, cause the processing device to perform the operations of:

encoding a firewall ruleset into a new array comprising a string of bits, wherein each bit of the new array corresponds to one processing rule of the firewall ruleset;

determining a bit value from the new array based on a portion of a network address included in a received communication packet; and

processing the received communication packet based on the bit value from the new array.

14 . The network firewall device of claim 13 wherein a number of bits of the new array is the same as a number of bits of one of a plurality of arrays encoded from the firewall ruleset.

15 . The network firewall device of claim 13 wherein the instructions, when executed by the processing device, further cause the processing device to perform the operations of:

storing the new array in the non-transitory computer-readable medium, wherein storing the new array consumes less memory space than a storing of a plurality of arrays encoded from the firewall ruleset.

16 . The network firewall device of claim 13 wherein the instructions, when executed by the processing device, further cause the processing device to perform the operation of:

combining a plurality of arrays encoded from the firewall ruleset into the new array including determining a union set of a blacklist array and a threatlist array, the blacklist array corresponding to a block processing rule of the firewall ruleset and the threatlist array corresponding to a re-direct processing rule of the firewall ruleset.

17 . The network firewall device of claim 16 wherein combining the plurality of arrays into the new array further comprises:

determining a difference set of the union set and a whitelist array, the whitelist array corresponding to an allow processing rule of the firewall ruleset.

18 . The network firewall device of claim 17 wherein combining the plurality of arrays into the new array further comprises: setting the difference set as the new array.

19 . The network firewall device of claim 12 wherein the instructions, when executed by the processing device, further cause the processing device to perform the operations of:

determining, based on the network address including the received communication packet, an identifier of a receiving network; and

selecting the data structure from a plurality of data structures as corresponding to the identifier of the receiving network.

20 . The network firewall device of claim 19 wherein the new array of a string of bits comprises 64 bits.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2025
From: WHELTON, ROBERT
To: LEVEL 3 COMMUNICATIONS, LLC
Reel/Frame 072102/0652 →