Granted patent
Firewall rule remediation for improved network security and performance
- Number
- 11218447
- Published
- 2022-01-04
- Filed
- 2018-03-02
- Assignee
- Disney Enterprises, Inc.
- Inventors
- Cloud; Mark G., Floyd, III; Robert K., Mansukhani; Jeffrey Sol
- CPC
- H04L41/0894; H04L41/0895; H04L63/0236; H04L63/0263; H04L63/20
- Verdict
- Set aside network firewall security, unrelated
- Source
- Google Patents · FreePatentsOnline
Abstract
A firewall manager periodically accesses a set of servers to identify the various services currently active on each server. The firewall manager also periodically accesses a set of firewalls configured to protect those servers to identify various firewall rules implemented by those firewalls. The firewall manager then compares the services data with the rules data to identify any obsolete firewall rules that are (i) defined based on an IP address not currently allocated to any of the servers or (ii) defined based on a port of an active server that is not associated with any service running on server. Such rules are considered obsolete. Upon identifying any obsolete firewall rules, the firewall manager accesses the firewalls associated with those rules and then removes the obsolete rules.
Background
BACKGROUND Field of the Various Embodiments (1) The various embodiments relate generally to computer networks, and, more specifically, to firewall rule remediation for improved network security and performance. Description of the Related Art (2) Conventional computing clouds include networks of virtual machines (VMs) configured to receive and process network traffic. For example, a computing cloud could include a network of VMs that operate as web servers to service hypertext transfer protocol (HTTP) requests. During operation and over time, various VMs may be dynamically instantiated and terminated within computing cloud networks. When a VM is instantiated, various network resources are allocated to the VM to facilitate network communications. Those resources typically include an internet protocol (IP) address and/or a media access control (MAC) address, among others. When the VM is terminated, those network resources are de-allocated and returned to a provisioning pool. (3) For enhanced security, VMs can be protected by firewalls. A firewall that is configured to protect a given VM implements a set of rules according to what network traffic is selectively forwarded to the VM. For example, a firewall rule could indicate that any transmission control protocol (TCP) traffic targeting port 80 should be forwarded to the IP address associated with the VM. In such implementations, network traffic that is not governed by a specific rule in the set of rules is rejected and not forwa