IP Library › Granted Patent US 11,882,095
Granted Patent B2
US 11,882,095 · App. 17/228,927 · Granted Jan 23, 2024

Firewall insights processing and machine learning

Inventors: Firat Kalaycilar (San Jose, CA); Xiang Wang (Mountain View, CA); Gregory Lee Slaughter (Palo Alto, CA)
Assignee: Google LLC
H04L63/0263G06F18/214G06N20/00H04L43/06H04L63/0236H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,882,095
App. No.
17/228,927
Granted
Jan 23, 2024
Kind
B2
Abstract

A computer-implemented method causes data processing hardware to perform operations for training a firewall utilization model. The operations include receiving firewall utilization data for firewall connection requests during a utilization period. The firewall utilization data includes hit counts for each sub-rule associated with at least one firewall rule. The operations also include generating training data based on the firewall utilization data. The training data includes unused sub-rules corresponding to sub-rules having no hits during the utilization period and hit sub-rules corresponding to sub-rules having more than zero hits during the utilization period. The operations also include training a firewall utilization model on the training data. The operations further include, for each sub-rule associated with the at least one firewall rule, determining a corresponding sub-rule utilization probability indicating a likelihood the sub-rule will be used for a future connection request.

Claims (87)

1. A computer-implemented method when executed on data processing hardware causes the data processing hardware to perform operations for training a firewall utilization model, the operations comprising:

obtaining firewall utilization data for connection requests received by a firewall during a utilization period, the firewall utilization data including hit counts during the utilization period for each sub-rule of a set of sub-rules associated with at least one firewall rule;

filtering the firewall utilization data based on a filter criteria, the filter criteria based on information associated with the connection requests;

generating training data based on the filtered firewall utilization data, the training data including unused sub-rules corresponding to sub-rules having zero hits during the utilization period and hit sub-rules corresponding to sub-rules having more than zero hits during the utilization period;

training a firewall utilization model on the training data; and

for each sub-rule of the set of sub-rules associated with the at least one firewall rule, determining, using the trained firewall utilization model, a corresponding sub-rule utilization probability indicating a likelihood the sub-rule will be used for a future connection request.

2. The computer-implemented method of claim 1 , wherein the operations further comprise:

determining firewall attribute groupings for the at least one firewall rule, each of firewall attribute groupings including at least one firewall attribute; and

determining a first set of the sub-rules associated with the at least one firewall rule based on the firewall attribute groupings.

3. The computer-implemented method of claim 2 , wherein filtering the firewall utilization data based on a filter criteria comprises:

receiving a plurality of firewall logs associated with connection requests received by the firewall during the utilization period;

determining a second set of sub-rules associated with the plurality of firewall logs; and

generating the firewall utilization data based on the first set of sub-rules and the second set of sub-rules.

4. The computer-implemented method of claim 2 , wherein the firewall attribute groupings include at least three of a source attribute grouping, a target attribute grouping, a port range, or an internet protocol (IP).

5. The computer-implemented method of claim 4 , wherein:

the firewall attribute groupings comprise the source attribute grouping; and

the source attribute grouping comprises:

source IP ranges;

source tags; and

source service accounts.

6. The computer-implemented method of claim 4 , wherein:

the firewall attribute groupings comprise the target attribute grouping; and

the target attribute grouping comprises:

target tags; and

target service accounts.

7. The computer-implemented method of claim 1 , wherein the operations further comprise:

receiving firewall reachability insights from a reachability module;

generating firewall utilization insights based on the corresponding sub-rule utilization probability determined for each sub-rule;

aggregating the firewall reachability insights and the firewall utilization insights; and

generating firewall configuration recommendations based on the aggregated firewall reachability insights and firewall utilization insights.

8. The computer-implemented method of claim 1 , wherein the operations further comprise:

determining unused firewall rule attributes during the utilization period;

for every unused firewall rule attribute, aggregating the sub-rule utilization probabilities for all sub-rules including the unused firewall rule attribute; and

determining a probability that a firewall attribute will be hit in the future based on aggregated sub-rule probabilities.

9. A system for training a firewall insights model, the system comprising:

data processing hardware; and

memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed by the data processing hardware cause the data processing hardware to perform operations comprising:

obtaining firewall utilization data for connection requests received by a firewall during a utilization period, the firewall utilization data including hit counts during the utilization period for each sub-rule of a set of sub-rules associated with at least one firewall rule;

filtering the firewall utilization data based on a filter criteria, the filter criteria based on information associated with the connection requests;

generating training data based on the filtered firewall utilization data, the training data including unused sub-rules corresponding to sub-rules having zero hits during the utilization period and hit sub-rules corresponding to sub-rules having more than zero hits during the utilization period;

training a firewall utilization model on the training data; and

for each sub-rule of the set of sub-rules associated with the at least one firewall rule, determining, using the trained firewall utilization model, a corresponding sub-rule utilization probability indicating a likelihood the sub-rule will be used for a future connection request.

10. The system of claim 9 , wherein the operations further comprise:

determining firewall attribute groupings for the at least one firewall rule, each of firewall attribute groupings including at least one firewall attribute; and

determining a first set of the sub-rules associated with the at least one firewall rule based on the firewall attribute groupings.

11. The system of claim 10 , wherein filtering the firewall utilization data based on a filter criteria comprises:

receiving a plurality of firewall logs associated with connection requests received by the firewall during the utilization period;

determining a second set of sub-rules associated with the plurality of firewall logs; and

generating the firewall utilization data based on the first set of sub-rules and the second set of sub-rules.

12. The system of claim 10 , wherein the firewall attribute groupings include at least three of a source attribute grouping, a target attribute grouping, a port range, or an internet protocol (IP).

13. The system of claim 12 , wherein:

the firewall attribute groupings comprise the source attribute; and

the source attribute grouping comprises:

source IP ranges;

source tags; and

source service accounts.

14. The system of claim 12 , wherein:

the firewall attribute groupings comprise the target attribute grouping; and

the target attribute grouping comprises:

target tags; and

target service accounts.

15. The system of claim 9 , wherein the operations further comprise:

receiving firewall reachability insights from a reachability module;

generating firewall utilization insights based on the corresponding sub-rule utilization probability determined for each sub-rule;

aggregating the firewall reachability insights and the firewall utilization insights; and

generating firewall configuration recommendations based on the aggregated firewall reachability insights and firewall utilization insights.

16. The system of claim 9 , wherein the operations further comprise:

determining unused firewall rule attributes during the utilization period;

for every unused firewall rule attribute, aggregating the sub-rule utilization probabilities for all sub-rules including the unused firewall rule attribute; and

determining a probability that a firewall attribute will be hit in the future based on aggregated sub-rule probabilities.

17. A computer program product encoded on a non-transitory computer readable storage medium comprising instructions that when executed by a data processing apparatus cause the data processing apparatus to perform operations comprising:

obtaining firewall utilization data for connection requests received by a firewall during a utilization period, the firewall utilization data including hit counts during the utilization period for each sub-rule of a set of sub-rules associated with at least one firewall rule;

filtering the firewall utilization data based on a filter criteria, the filter criteria based on information associated with the connection requests;

generating training data based on the filtered firewall utilization data, the training data including unused sub-rules corresponding to sub-rules having zero hits during the utilization period and hit sub-rules corresponding to sub-rules having more than zero hits during the utilization period;

using the training data, determining a sub-rule utilization probability for each sub-rule of the at least one firewall rule, the sub-rule utilization probability indicating a likelihood the sub-rule will be used for a connection request in the future; and

generating firewall utilization insights based on the sub-rule utilization probability.

18. The computer program product of claim 17 , wherein the operations further comprise:

determining firewall attribute groupings for the at least one firewall rule, each of firewall attribute groupings including at least one firewall attribute; and

determining a first set of sub-rules associated with the at least one firewall rule based on the firewall attribute groupings.

19. The computer program product of claim 18 , wherein filtering the firewall utilization data based on a filter criteria comprises:

receiving a plurality of firewall logs associated with connection requests received by the firewall during the utilization period;

determining a second set of sub-rules associated with the plurality of firewall logs; and

generating the firewall utilization data based on the first set of sub-rules and the second set of sub-rules.

20. The computer program product of claim 17 , wherein the operations further comprise:

determining unused firewall rule attributes during the utilization period;

for every unused firewall rule attribute, aggregating the sub-rule utilization probabilities for all sub-rules including the unused firewall rule attribute; and

determining a probability that a firewall attribute will be hit in the future based on aggregated sub-rule probabilities.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE INVENTOR NAME FROM FIRAT KALAYCLIAR TO FIRAT KALAYCILAR PREVIOUSLY RECORDED ON REEL 056014 FRAME 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 1, 2021
From: KALAYCILAR, FIRAT; WANG, XIANG; SLAUGHTER, GREGORY LEE
To: GOOGLE LLC
Reel/Frame 057393/0971 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2021
From: KALAYCLIAR, FIRAT; WANG, XIANG; SLAUGHTER, GREGORY LEE
To: GOOGLE LLC
Reel/Frame 056014/0408 →
Continuity (2)
Provisional Application 63009297 · Apr 13, 2020
Related Publication 20210320903A1 · Oct 14, 2021