Patent · US Active

Context based firewall services for data message flows for multiple concurrent users on one machine

US11032246B2 · kind B2 · utility

7Cited by
57References
18Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 10, 2017
Grant dateJun 8, 2021
Priority date
Expiry dateApr 3, 2038

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/104
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Some embodiments of the invention provide a novel architecture for capturing contextual attributes on host computers that execute one or more machines, and for consuming the captured contextual attributes to perform services on the host computers. The machines are virtual machines (VMs) in some embodiments, containers in other embodiments, or a mix of VMs and containers in still other embodiments. Some embodiments execute a guest-introspection (GI) agent on each machine from which contextual attributes need to be captured. In addition to executing one or more machines on each host computer, these embodiments also execute a context engine and one or more attribute-based service engines on each host computer. One of these service engines is a firewall engine. Through the GI agents of the machines on a host, the context engine of that host in some embodiments collects contextual attributes associated with network events and/or process events on the machines. The context engine then provides the contextual attributes to the firewall engine, which, in turn, use these contextual attributes to identify firewall rules to enforce.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.