IP Library Granted Patent US 10,484,334
Granted Patent B1
US 10,484,334 · App. 15/487,327 · Granted Nov 19, 2019

Distributed firewall security system that extends across different cloud computing networks

Inventors: Jaushin Lee (Saratoga, CA); Hung Chuen Jason Lee (Palo Alto, CA)
Assignee: Zentera Systems, Inc.
H04L63/0263H04L63/0218H04L63/0245H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,484,334
App. No.
15/487,327
Granted
Nov 19, 2019
Kind
B1
Abstract

An application profile is provided to manage security of an application deployed across two or more cloud computing networks. A user can define in the application profile first and second server groups, a cloud chamber as including the first and second server groups, and a computing flow to the cloud chamber. A firewall rule is generated based on the computing flow. The firewall rule is distributed to the first server group of the cloud chamber. A copy of the firewall rule is distributed to the second server group of the cloud chamber. The first server group is in a first cloud computing network that is provided by a first cloud provider. The second server group is in a second cloud computing network that is provided by a second cloud provider, different from the first cloud provider.

Claims (79)

1. A method comprising:

providing an application profile to manage security of an application deployed across two or more cloud computing networks;

allowing a user to define in the application profile a first server group, a second server group, a cloud chamber as including the first and second server groups, and a computing flow to the cloud chamber;

generating a firewall rule based on the computing flow to the cloud chamber;

distributing the firewall rule to the first server group of the cloud chamber; and

distributing a copy of the firewall rule to the second server group of the cloud chamber, wherein the first server group is in a first cloud computing network of the two or more cloud computing networks, the second server group is in a second cloud computing network of the two or more cloud computing networks, and

wherein the first cloud computing network is provided by a first cloud provider, and the second cloud computing network is provided by a second cloud provider, different from the first cloud provider.

2. The method of claim 1 comprising:

receiving, at a first endpoint in the first server group of the cloud chamber, a first data packet specifying a particular destination port;

evaluating the firewall rule distributed to the first server group to determine whether the first data packet should be denied or accepted;

receiving, at a second endpoint in the second server group of the cloud chamber, a second data packet specifying the same particular destination port; and

evaluating the copy of the firewall rule distributed to the second server group to determine whether the second data packet should be denied or accepted.

3. The method of claim 1 comprising:

receiving, at a first endpoint in the first server group of the cloud chamber, a first data packet specifying a particular protocol;

evaluating the firewall rule distributed to the first server group to determine whether the first data packet should be denied or accepted;

receiving, at a second endpoint in the second server group of the cloud chamber, a second data packet specifying the same particular protocol; and

evaluating the copy of the firewall rule distributed to the second server group to determine whether the second data packet should be denied or accepted.

4. The method of claim 1 comprising:

programming the firewall rule distributed to the first server group into an operating system (OS) of an endpoint in the first server group;

monitoring the firewall rule programmed into the OS to detect tampering;

detecting tampering of the firewall rule programmed into the OS; and

upon detecting the tampering, replacing the tampered firewall rule with the firewall rule distributed to the first server group.

5. The method of claim 4 comprising:

calculating a frequency of the tampering;

determining whether the frequency exceeds a threshold frequency; and

if the frequency exceeds the threshold frequency, generating an alert to add the endpoint to a listing of quarantined endpoints.

6. The method of claim 1 comprising:

programming the firewall rule distributed to the first server group into an operating system (OS) of an endpoint in the first server group;

maintaining, in memory at the endpoint, a separate copy of the firewall rule that was programmed into the OS;

periodically comparing the firewall rule programmed into the OS against the separate copy of the firewall rule maintained in the memory of the endpoint to detect tampering of the firewall rule programmed into the OS; and

upon detecting tampering, copying back into the OS the separate copy of the firewall rule maintained in memory at the endpoint, and issuing an alert to a central security controller that is connected with the endpoint.

7. The method of claim 1 wherein the computing flow is a first computing flow and the method comprises:

allowing the user to define in the application profile a second computing flow from the cloud chamber;

generating a second firewall rule based on the second computing flow from the cloud chamber;

distributing the second firewall rule to the first server group of the cloud chamber; and

distributing a copy of the second firewall rule to the second server group of the cloud chamber.

8. A method comprising:

providing an application profile to manage security of an application deployed across a first cloud computing network, and a second cloud computing network, the first and second cloud computing networks being connected by the Internet;

allowing a user to define in the application profile a first server group, a second server group, a cloud chamber as including the first and second server groups, and a computing flow from the cloud chamber;

generating a firewall rule based on the computing flow from the cloud chamber;

distributing the firewall rule to the first server group of the cloud chamber; and

distributing a copy of the firewall rule to the second server group of the cloud chamber, wherein the first server group is in the first cloud computing network, and the first cloud computing network belongs to a first cloud provider, and

wherein the second server group is in the second cloud computing network, and the second cloud computing network belongs to a second cloud provider, different from the first cloud provider.

9. The method of claim 8 wherein the firewall rule distributed to the first server group specifies a particular destination Internet Protocol (IP) address, a particular destination port, a particular protocol, and a particular action to be performed when parameters of a data packet to be sent from the first server group matches the particular destination IP address, particular destination port, and particular protocol, and

wherein the copy of the firewall rule distributed to the second server group specifies the same particular destination IP address, particular destination port, particular protocol, and particular action.

10. The method of claim 8 wherein the first and second cloud computing networks are remote from each other.

11. The method of claim 8 wherein the firewall rule is received by an agent at an endpoint in the first server group, and

wherein the agent programs the firewall rule into an operating system (OS) at the endpoint, maintains a separate copy of the firewall rule in memory at the endpoint, and monitors the firewall rule programmed into the OS using the separate copy of the firewall rule maintained in the memory at the endpoint.

12. The method of claim 8 wherein the firewall rule is a first firewall rule and the method comprises:

allowing the user to define in the application profile a second computing flow to the cloud chamber;

generating a second firewall rule based on the second computing flow to the cloud chamber;

distributing the second firewall rule to the first server group of the cloud chamber; and

distributing a copy of the second firewall rule to the second server group of the cloud chamber.

13. The method of claim 8 comprising:

receiving the firewall rule at an endpoint in the first server group;

programming the firewall rule into an operating system (OS) at the endpoint;

maintaining, in memory at the endpoint, an independent copy of the firewall rule programmed into the OS;

monitoring the firewall rule programmed into the OS using the independent copy of the firewall rule maintained in the memory at the endpoint to detect tampering of the firewall rule programmed into the OS; and

upon detection of tampering, replacing the tampered firewall rule with the independent copy of the firewall rule maintained in the memory at the endpoint.

14. A method comprising:

storing an application profile to manage security of an application deployed across a first cloud computing network, and a second cloud computing network, the first and second cloud computing networks being connected by the Internet;

allowing a user to define in the application profile a first server group as being in the first cloud computing network, a second server group as being in the second cloud computing network, a cloud chamber as including the first and second server groups, a first computing flow to the cloud chamber, and a second computing flow from the cloud chamber;

generating a first firewall rule based on the first computing flow to the cloud chamber;

transmitting the first firewall rule to the first server group;

transmitting a copy of the first firewall rule to the second server group;

generating a second firewall rule based on the second computing flow from the cloud chamber;

transmitting the second firewall rule to the first server group; and

transmitting a copy of the second firewall rule to the second server group, wherein the first cloud computing network is owned by a first cloud provider, and the second cloud computing network is owned by a second cloud provider, different from the first cloud provider.

15. The method of claim 14 wherein the first firewall rule is received by an agent at an endpoint in the first server group, and

wherein the agent programs the first firewall rule into an operating system (OS) at the endpoint,

maintains, in memory at the endpoint, a copy of the first firewall rule programmed into the OS, and

upon detecting tampering of the first firewall rule programmed into the OS, replaces the tampered first firewall rule with the copy of the first firewall rule maintained in the memory at the endpoint.

16. The method of claim 14 comprising:

receiving the first and second firewall rules at an endpoint in the first server group;

inserting the first and second firewall rules into an operating system (OS) at the endpoint for enforcement;

monitoring the first and second firewall rules inserted into the OS to detect tampering;

calculating a frequency of the tampering;

determining whether the frequency exceeds a threshold frequency; and

if the frequency exceeds the threshold frequency, generating an alert to place the endpoint into quarantine.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2017
From: LEE, JAUSHIN; LEE, HUNG CHUEN JASON
To: ZENTERA SYSTEMS, INC.
Reel/Frame 042005/0140 →
Continuity (3)
Continuation In Part 14817874 · Aug 4, 2015
Continuation 14190019 · Feb 25, 2014
Provisional Application 61769713 · Feb 26, 2013
Cited By (92)
US 12,197,583 US 12,197,590 US 12,199,951 US 12,219,360 US 12,225,022 US 12,225,039 US 12,231,252 US 12,231,433 US 12,238,145 US 12,238,177 US 12,242,520 US 12,243,294 US 12,244,617 US 12,244,637 US 12,245,036 US 12,254,340 US 12,255,817 US 12,255,877 US 12,266,209 US 12,267,304 US 12,267,355 US 12,273,392 US 12,278,845 US 12,282,545 US 12,284,206 US 12,284,222 US 12,299,117 US 12,301,605 US 12,301,629 US 12,309,119 US 12,309,192 US 12,315,231 US 12,316,632 US 12,316,647 US 12,326,957 US 12,341,680 US 12,342,159 US 12,348,494 US 12,355,816 US 12,355,817 US 12,361,680 US 12,363,075 US 12,363,172 US 12,373,240 US 12,375,497 US 12,381,849 US 12,381,890 US 12,386,972 US 12,388,711 US 12,395,534 US 12,413,629 US 12,417,253 US 12,425,371 US 12,425,464 US 12,430,429 US 12,432,176 US 12,432,179 US 12,445,451 US 12,452,310 US 12,470,602 US 12,483,384 US 12,489,734 US 12,500,940 US 12,506,784 US 12,513,073 US 12,519,754 US 12,519,857 US 12,537,838 US 12,537,871 US 12,542,812 US 12,556,512 US 12,561,620 US 12,572,651 US 12,580,945 US 12,580,960 US 12,587,535 US 12,592,959 US 12,593,210 US 12,596,804 US 12,598,216 US 12,609,910 US 12,615,242 US 12,632,572 US 12,647,362 US 12,647,441 US 12,652,312 US 12,676,890 US 12,676,908 US 12,684,018 US 12,695,765 US 12,712,781 US 12,712,920