IP Library Granted Patent US 12,381,849
Granted Patent B2
US 12,381,849 · App. 18/050,516 · Granted Aug 5, 2025

Polymorphic dynamic firewall

Inventors: Satishkumar Sadagopan (Leawood, KS); Mudhakar Srivatsa (White Plains, NY); Dinesh C. Verma (New Castle, NY); Mathews Thomas (Flower Mound, TX); Utpal Mangla (Toronto, CA); Gerald Coon (Durham, NC)
Assignee: International Business Machines Corporation
H04L63/0263H04L63/1425H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,381,849
App. No.
18/050,516
Granted
Aug 5, 2025
Kind
B2
Abstract

A method, computer system, and a computer program product is provided for establishing a dynamically adaptive network firewall. A firewall model is established that identifies resources that can be used and a plurality of nodes that connect to one another to form a network. A set of external rules and policies are provided to each resource. The firewall implemented using the firewall model upon receiving of incoming data and upon traffic flow. The firewall expands or contracts the network by adding or removing resources according to work that needs to be performed. The work includes both tasks to be completed and efforts that has to be taken by the firewall to ensure security by preventing unauthorized access into the network.

Claims (41)

1. A method for constructing a dynamically adaptive network firewall, comprising:

identifying a plurality of nodes and resources connected to one another in a network having a network firewall, through which a data traffic flows;

creating a logical entity of firewall resources and services with a surface area;

establishing a firewall model for providing traffic flow using said logical entity having one or more Internet Protocol addresses or domain name systems and preventing unauthorized access to resources, wherein said firewall model directs said data traffic flow by establishing reference pointers to a set of external rules and rules lists;

using said firewall model, to instantiating resources as needed according to resource capability for handing one or more task completion and/or for providing network security for said network firewall, wherein said firewall grows or contracts according to characteristics of data traffic flow and includes one or more resources provided geographically through one or more cloud providers;

implementing said firewall network using said firewall model using said instantiated resources and dynamically using said model upon receiving data traffic, to expands or contracts said network by said firewall model by adding or removing resources according to work relating to handling said one or more task completion and work related to providing network security so unauthorized access to said network is prevented;

continuously monitoring said network using said firewall model so that unauthorized access to said network is prevented and determining any vulnerabilities to said firewall through said monitoring to modify said firewall and said network as needed.

2. The method of claim 1 , further comprising establishing a vulnerability notification system for said firewall model; said vulnerability notification system prompting changes in said firewall once established.

3. The method of claim 2 , wherein said vulnerability notification includes determining sudden traffic flow increases and decreases into said firewall network and said vulnerability system detecting any unauthorized attempts for access into said network.

4. The method of claim 3 , wherein said vulnerability notification system prompt changes in said firewall make-up by improving preparedness to handle traffic when it does arrive.

5. This method of claim 1 , wherein said resources can include standalone devices or a network of interconnected devices such as those included by a cloud provider.

6. The method of claim 5 , wherein said resources can dispersed geographically.

7. The method of claim 1 , wherein said firewall is established by selecting amongst a plurality of possible different combination of resources, an optimal combination that can select amongst the available resources those that can optimally provide results based on the traffic flows, growth, or other characteristics of the traffic.

8. The method of claim 1 , wherein said firewall include resources that are connected to one or more devices.

9. The method of claim 1 , further comprising implementing said firewall on one or more machines connected to network segments where the nodes reside; and using said one or more resources.

10. The method of claim 1 , wherein further comprising implementing said firewall by automatically instantiating the type of resources best required to handle the traffic.

11. The method of claim 1 , wherein said firewall model establishes reference pointers to said rules for said resources so that once said traffic flow starts, said rules can be used to instantiate resources as needed.

12. The method of claim 1 , wherein resources can be reassigned for work or be put in idle mode depending on traffic flow.

13. A computer system for providing a dynamically adaptive firewall, comprising;

one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage medium, and program instructions stored on at least one of the one or more tangible storage medium for execution by at least one of the one or more processors via at least one of the one or more memories, wherein the computer system is enabled to perform the steps:

identifying a plurality of nodes and resources connected to one another in a network having a network firewall, through which a data traffic flows;

creating a logical entity of firewall resources and services with a surface area;

establishing a firewall model for providing traffic flow using said logical entity having one or more Internet Protocol addresses or domain name systems and preventing unauthorized access to resources, wherein said firewall model directs said data traffic flow by establishing reference pointers to a set of external rules and rules lists,

using said firewall model, to instantiating resources as needed according to resource capability for handing one or more task completion and/or for providing network security for said network firewall, wherein said firewall grows or contracts according to characteristics of data traffic flow and includes one or more resources provided geographically through one or more cloud providers;

using said firewall model, to instantiating resources as needed and according to resource capability for banding one or more task completion and/or for providing network security for said network firewall;

implementing said firewall network using said firewall model using said instantiated resources and dynamically using said model upon receiving data traffic, to expands or contracts said network by said firewall model by adding or removing resources according to work relating to handling said one or more task completion and work related to providing network security so unauthorized access to said network is prevented;

continuously monitoring said network using said firewall model so that unauthorized access to said network is prevented and determining any vulnerabilities to said firewall through said monitoring to modify said firewall and said network as needed.

14. The computer system of claim 13 , further comprising establishing a vulnerability notification system for said firewall model; said vulnerability notification system prompting changes in said firewall once established.

15. The computer system of claim 13 , further comprising implementing said firewall on one or more machines connected to network segments where the nodes reside; and using said one or more resources.

16. The computer system of claim 13 , wherein resources can be reassigned for work or be put in idle mode depending on traffic flow.

17. A computer program product for providing a dynamically adaptive firewall, comprising:

one or more computer-readable storage medium and program instructions stored on at least one of the one or more tangible storage medium, the program instructions executable by a processor, the program instructions comprising:

one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage medium, and program instructions stored on at least one of the one or more tangible storage medium for execution by at least one of the one or more processors via at least one of the one or more memories, wherein the computer system is enabled to perform the steps comprising:

identifying a plurality of nodes and resources connected to one another in a network having a network firewall, through which a data traffic flows; creating a logical entity of firewall resources and services with a surface area;

establishing a firewall model for providing traffic flow using said logical entity having one or more Internet Protocol addresses or domain name systems and preventing unauthorized access to resources, wherein said firewall model directs said data traffic flow by establishing reference pointers to a set of external rules and rules lists;

using said firewall model, to instantiating resources as needed according to resource capability for handing one or more task completion and/or for providing network security for said network firewall, wherein said firewall grows or contracts according to characteristics of data traffic flow and includes one or more resources provided geographically through one or more cloud providers;

implementing said firewall network using said firewall model using said instantiated resources and dynamically using said model upon receiving data traffic, to expands or contracts said network by said firewall model by adding or removing resources according to work relating to handling said one or more task completion and work related to providing network security so unauthorized access to said network is prevented;

continuously monitoring said network using said firewall model so that unauthorized access to said network is prevented and determining any vulnerabilities to said firewall through said monitoring to modify said firewall and said network as needed.

18. The computer program product of claim 17 , further comprising establishing a vulnerability notification system for said firewall model; said vulnerability notification system prompting changes in said firewall once established.

19. The computer program product of claim 17 , further comprising implementing said firewall on one or more machines connected to network segments where the nodes reside; and using said one or more resources.

20. The computer program product of claim 17 , wherein resources can be reassigned for work or be put in idle mode depending on traffic flow.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2022
From: SADAGOPAN, SATISHKUMAR; SRIVATSA, MUDHAKAR; VERMA, DINESH C.; THOMAS, MATHEWS; MANGLA, UTPAL; COON, GERALD
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 061574/0487 →
Continuity (1)
Related Publication 20240146693A1 · May 2, 2024
References Cited (34)
US 5898830A · Wesinger, Jr. · 1999 [cited by applicant]
US 6880089B1 · Bommareddy · 2005 [cited by applicant]
US 7565430B2 · Kortum · 2009 [cited by examiner]
US 7966655B2 · Acharya · 2011 [cited by examiner]
US 8032933B2 · Turley · 2011 [cited by examiner]
US 8856936B2 · Datta Ray · 2014 [cited by examiner]
US 9094449B2 · Brueckner · 2015 [cited by examiner]
US 10484334B1 · Lee · 2019 [cited by examiner]
US 10855700B1 · Jeyaraman · 2020 [cited by examiner]
US 11824897B2 · Kwan · 2023 [cited by examiner]
US 11863528B1 · Chung · 2024 [cited by examiner]
US 20050204402A1 · Turley · 2005 [cited by examiner]
US 20070271453A1 · Pohja · 2007 [cited by examiner]
US 20120054866A1 · Evans · 2012 [cited by examiner]
US 20130269033A1 · Amaya Calvo · 2013 [cited by examiner]
US 20140245423A1 · Lee · 2014 [cited by examiner]
US 20150326532A1 · Grant · 2015 [cited by examiner]
US 20150341377A1 · Kasturi · 2015 [cited by examiner]
US 20160285828A1 · Keohane · 2016 [cited by examiner]
US 20160294772A1 · Padmanabhan · 2016 [cited by examiner]
US 20180026944A1 · Phillips · 2018 [cited by examiner]
US 20180063194A1 · Vaidya · 2018 [cited by examiner]
US 20190020671A1 · Komárek · 2019 [cited by examiner]
US 20190058690A1 · Huang · 2019 [cited by examiner]
US 20190260794A1 · Woodford · 2019 [cited by examiner]
US 20200177550A1 · Valluri · 2020 [cited by examiner]
US 20200403971A1 · Wang · 2020 [cited by examiner]
US 20220116423A1 · Cummins · 2022 [cited by examiner]
US 20220116427A1 · Kwan · 2022 [cited by examiner]
US 20220166756A1 · Gupta · 2022 [cited by examiner]
US 20220292199A1 · Mosko · 2022 [cited by examiner]
US 20240028358A1 · Liu · 2024 [cited by examiner]
Jin et al. “Traffic Engineering of High-Rate Large-Sized Flows.” 2013 IEEE 14th International Conference on High Performance Switching and Routing, IEEE, Downloaded: Aug. 26, 2022, 8 pages. [cited by applicant]
Kiran et al., “Understanding Flows in High-Speed Scientific Networks: A Netflow Data Study.” ScienceDirect, Future Generation Computer Systems, vol. 94, May 2019, 11 pages. [cited by applicant]