IP Library Granted Patent US 9,497,165
Granted Patent B2
US 9,497,165 · App. 14/669,277 · Granted Nov 15, 2016

Virtual firewall load balancer

Inventors: Susann M. Keohane (Austin, TX); Gerald F. McBrearty (Austin, TX); Shawn P. Mullen (Buda, TX); Jessica C. Murillo (Round Rock, TX); Johnny M. Shieh (Austin, TX)
Assignee: International Business Machines Corporation
H04L63/0245H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,497,165
App. No.
14/669,277
Granted
Nov 15, 2016
Kind
B2
Abstract

According to one exemplary embodiment, a method for load balancing between a virtual component within a virtual environment and a Host Intrusion Prevention System (HIPS) is provided. The method may include receiving a trusted connection table from the HIPS, wherein the trusted connection table contains a plurality of trusted connection information. The method may also include receiving a network packet from a virtual switch, wherein the network packet has a plurality of connection information. The method may then include determining if the plurality of connection information matches the plurality of trusted connection information. The method may further include sending the network packet to a destination based on determining that the plurality of connection information matches the plurality of trusted connection information. The method may include sending the network packet to the HIPS based on determining that the plurality of connection information does not match the plurality of trusted connection information.

Claims (23)

1. A computer system for load balancing between a virtual component within a virtual environment and a Host Intrusion Prevention System (HIPS), comprising:

one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage medium, and program instructions stored on at least one of the one or more tangible storage medium for execution by at least one of the one or more processors via at least one of the one or more memories, wherein the computer system is capable of performing a method comprising:

receiving a trusted connection table from the HIPS, wherein the trusted connection table contains a plurality of trusted connection information;

receiving a network packet from a virtual switch, wherein the network packet has a plurality of connection information;

determining if the plurality of connection information matches the plurality of trusted connection information;

sending the network packet to a destination based on determining that the plurality of connection information matches the plurality of trusted connection information; and

sending the network packet to the HIPS based on determining that the plurality of connection information does not match the plurality of trusted connection information.

2. The computer system of claim 1 , wherein the virtual environment comprises a virtual input output server (VIOS), a hypervisor and a plurality of virtual Ethernet adapters.

3. The computer system of claim 2 , wherein the virtual component is a trusted firewall running within the VIOS or the trusted firewall running within the hypervisor.

4. The computer system of claim 1 , wherein receiving the trusted connection table from the HIPS comprises the virtual component within the virtual environment receiving a trusted message containing the trusted connection table from the HIPS.

5. The computer system of claim 4 , wherein the trusted message comprises sending a plurality of data according to at least one of a Simple Network Management Protocol version 3 (SNMPv3) and a Network Configuration Protocol (NETCONF).

6. The computer system of claim 1 , wherein the HIPS comprises a physical firewall connected to the virtual environment by a communication network.

7. The computer system of claim 1 , wherein the plurality of connection information comprises a source Internet Protocol (IP) address, a destination IP address, a source port, a destination port, and a protocol.

8. The computer system of claim 7 , wherein the plurality of trusted connection information comprises a trusted source IP address, a trusted destination IP address, a trusted source port, a trusted destination port, and a trusted protocol.

9. The computer system of claim 8 , wherein determining if the plurality of connection information matches the plurality of trusted connection information comprises matching the source IP with the trusted source IP address, matching the destination IP address to the trusted destination IP address, matching the source port to the trusted destination port, matching the destination port to the trusted destination port, and matching the protocol with the trusted protocol.

10. A computer program product for load balancing between a virtual component within a virtual environment and a Host Intrusion Prevention System (HIPS), comprising:

one or more non-transitory computer-readable storage medium and program instructions stored on at least one of the one or more non-transitory computer-readable storage medium, the program instructions executable by a processor, the program instructions comprising:

program instructions to receive a trusted connection table from the HIPS, wherein the trusted connection table contains a plurality of trusted connection information;

program instructions to receive a network packet from a virtual switch, wherein the network packet has a plurality of connection information;

program instructions to determine if the plurality of connection information matches the plurality of trusted connection information;

program instructions to send the network packet to a destination based on determining that the plurality of connection information matches the plurality of trusted connection information; and

program instructions to send the network packet to the HIPS based on determining that the plurality of connection information does not match the plurality of trusted connection information.

11. The computer program product of claim 10 , wherein the virtual environment comprises a virtual input output server (VIOS), a hypervisor and a plurality of virtual Ethernet adapters.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2015
From: KEOHANE, SUSANN M.; MCBREARTY, GERALD F.; MULLEN, SHAWN P.; MURILLO, JESSICA C.; SHIEH, JOHNNY M.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 035262/0156 →
Continuity (1)
Related Publication 20160285828A1 · Sep 29, 2016