IP Library Granted Patent US 9,088,543
Granted Patent B2
US 9,088,543 · App. 13/908,161 · Granted Jul 21, 2015

Coordinated network security management

Inventors: William A. Lemke (Scarsdale, NY); Neil I. Readshaw (Gold Coast, AU)
Assignee: International Business Machines Corporation
H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,088,543
App. No.
13/908,161
Granted
Jul 21, 2015
Kind
B2
Abstract

A computer-implemented method, computer program product, and computer system for implementing coordinated management of network security controls. The computer system determines a plurality of managed network devices affected by coordinated security policies in a network. The computer system converts the coordinated security policies to firewall rule configuration for each of the managed network devices affected. The computer system adds the firewall rule configuration to a set of firewall rules for the each of the managed network devices affected.

Claims (31)

1. A computer-implemented method for implementing coordinated management of network security controls, the method comprising:

determining, by a firewall management server in an Infrastructure as a Service (IaaS) management network, a plurality of managed network devices affected by a set of coordinated security policies, wherein the plurality of managed network devices are on routes to at least one of a web server, an application server, and a database server on a cloud based Infrastructure as a Service (IaaS) network, wherein the managed network devices are determined by calculating impact of the set of coordinated security policies based on a network topology;

converting, by the firewall management server, the set of the coordinated security policies to a firewall rule configuration for each of the plurality of the managed network devices;

adding, by the firewall management server, the firewall rule configuration to a set of firewall rules for the each of the plurality of the managed network devices; and

wherein the firewall management server in the IaaS management network comprises a first program executable to provide an interface for a system administrator to view and manage the network security policies, a second program executable to implement the coordinated management of the network security controls, a plurality of the third programs responsible for respective ones of the plurality of the managed network devices and executable to translate the set of the coordinated security policies into the firewall rule configuration, and a database of the network topology.

2. The computer-implemented method of claim 1 , further comprising the steps of:

determining, by the firewall management server, whether a rule conflict in the set of the firewall rules exists; and

resolving, by the firewall management server, the rule conflict.

3. The computer-implemented method of claim 1 , further comprising the step of: optimizing, by the firewall management server, the set of firewall rules.

4. The computer-implemented method of claim 1 , wherein the plurality of the managed network devices are at least one of: one or more virtual private network routers, one or more network firewalls, one or more hypervisor based firewalls, one or more server based firewalls, one or more router or switch access control lists, and one or more workstation based firewalls.

5. A computer program product for implementing coordinated management of network security controls, the computer program product comprising a computer readable storage medium having program code embodied therewith, the program code executable to:

determine, by a firewall management server in an Infrastructure as a Service (IaaS) management network, a plurality of managed network devices affected by a set of coordinated security policies, wherein the plurality of managed network devices are on routes to at least one of a web server, an application server, and a database server on a cloud based Infrastructure as a Service (IaaS) network, wherein the managed network devices are determined by calculating impact of the set of coordinated security policies based on a network topology;

convert, by the firewall management server, the set of the coordinated security policies to a firewall rule configuration for each of the plurality of the managed network devices;

add, by the firewall management server, the firewall rule configuration to a set of firewall rules for each of the plurality of the managed network devices; and

wherein the firewall management server in the IaaS management network comprises a first program executable to provide an interface for a system administrator to view and manage the network security policies, a second program executable to implement the coordinated management of the network security controls, a plurality of the third programs responsible for respective ones of the plurality of the managed network devices and executable to translate the set of the coordinated security policies into the firewall rule configuration, and a database of the network topology.

6. The computer program product of claim 5 , the computer program product further comprising the program code executable to:

determine, by the firewall management server, whether a rule conflict in the set of the firewall rules exists; and

resolve, by the firewall management server, the rule conflict.

7. The computer program product of claim 5 , the computer program product further comprising the program code executable to: optimize, by the firewall management server, the set of firewall rules.

8. The computer program product of claim 5 , wherein the plurality of the managed network devices are at least one of: one or more virtual private network routers, one or more network firewalls, one or more hypervisor based firewalls, one or more server based firewalls, one or more router or switch access control lists, and one or more workstation based firewalls.

9. A computer system for implementing coordinated management of network security controls, the computer system comprising:

one or more processors, one or more computer-readable tangible storage devices, and program instructions stored on at least one of the one or more computer-readable tangible storage devices for execution by at least one of the one or more processors, the program instructions executable to:

determine, by a firewall management server in an Infrastructure as a Service (IaaS) management network, a plurality of managed network devices affected by a set of coordinated security policies, wherein the plurality of managed network devices are on routes to at least one of a web server, an application server, and a database server on a cloud based Infrastructure as a Service (IaaS) network, wherein the managed network devices are determined by calculating impact of the set of coordinated security policies based on a network topology;

convert, by the firewall management server, the set of the coordinated security policies to a firewall rule configuration for each of the plurality of the managed network devices;

add, by the firewall management server, the firewall rule configuration to a set of firewall rules for each of the plurality of the managed network devices; and

wherein the firewall management server in the IaaS management network comprises a first program executable to provide an interface for a system administrator to view and manage the network security policies, a second program executable to implement the coordinated management of the network security controls, a plurality of the third programs responsible for respective ones of the plurality of the managed network devices and executable to translate the set of the coordinated security policies into the firewall rule configuration, and a database of the network topology.

10. The computer system of claim 9 , further comprising program instructions executable to:

determine, by the firewall management server, whether a rule conflict in the set of the firewall rules exists; and

resolve, by the firewall management server, the rule conflict.

11. The computer system of claim 9 , further comprising program instructions executable to: optimize, by the firewall management server, the set of firewall rules.

12. The computer system of claim 9 , wherein the plurality of the managed network devices are at least one of: one or more virtual private network routers, one or more network firewalls, one or more hypervisor based firewalls, one or more server based firewalls, one or more router or switch access control lists, and one or more workstation based firewalls.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded May 12, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION
To: GLOBALFOUNDRIES U.S. INC.
Reel/Frame 056987/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 20, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION
To: GLOBALFOUNDRIES INC.
Reel/Frame 054636/0001 →
SECURITY AGREEMENT Recorded Nov 29, 2018
From: GLOBALFOUNDRIES INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 049490/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2015
From: GLOBALFOUNDRIES U.S. 2 LLC; GLOBALFOUNDRIES U.S. INC.
To: GLOBALFOUNDRIES INC.
Reel/Frame 036779/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2015
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: GLOBALFOUNDRIES U.S. 2 LLC
Reel/Frame 036550/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2013
From: LEMKE, WILLIAM A.; READSHAW, NEIL I.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 030532/0112 →
Continuity (1)
Related Publication 20140359693A1 · Dec 4, 2014