Patent · US Active

Distributed identity-based firewalls

US10798058B2 · kind B2 · utility

10Cited by
39References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJul 20, 2018
Grant dateOct 6, 2020
Priority date
Expiry dateJul 20, 2038

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2009/45595
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Systems and techniques are described for monitoring network communications using a distributed firewall. One of the techniques includes receiving, at a driver executing in a guest operating system of a virtual machine, a request to open a network connection from a process associated with a user, wherein the driver performs operations comprising: obtaining identity information for the user; providing the identity information and data identifying the network connection to an identity module external to the driver; and receiving, by a distributed firewall, data associating the identity information with the data identifying the network connection from the identity module, wherein the distributed firewall performs operations comprising: receiving an outgoing packet from the virtual machine; determining that the identity information corresponds to the outgoing packet; and evaluating one or more routing rules based at least in part on the identity information.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.