Outer Rim Archives
Archives · 2022 · 11218447

Granted patent

Firewall rule remediation for improved network security and performance

Number
11218447
Published
2022-01-04
Filed
2018-03-02
Assignee
Disney Enterprises, Inc.
Inventors
Cloud; Mark G., Floyd, III; Robert K., Mansukhani; Jeffrey Sol
CPC
H04L41/0894; H04L41/0895; H04L63/0236; H04L63/0263; H04L63/20
Verdict
Set aside network firewall security, unrelated
Source
Google Patents · FreePatentsOnline

Abstract

A firewall manager periodically accesses a set of servers to identify the various services currently active on each server. The firewall manager also periodically accesses a set of firewalls configured to protect those servers to identify various firewall rules implemented by those firewalls. The firewall manager then compares the services data with the rules data to identify any obsolete firewall rules that are (i) defined based on an IP address not currently allocated to any of the servers or (ii) defined based on a port of an active server that is not associated with any service running on server. Such rules are considered obsolete. Upon identifying any obsolete firewall rules, the firewall manager accesses the firewalls associated with those rules and then removes the obsolete rules.

Background

BACKGROUND Field of the Various Embodiments (1) The various embodiments relate generally to computer networks, and, more specifically, to firewall rule remediation for improved network security and performance. Description of the Related Art (2) Conventional computing clouds include networks of virtual machines (VMs) configured to receive and process network traffic. For example, a computing cloud could include a network of VMs that operate as web servers to service hypertext transfer protocol (HTTP) requests. During operation and over time, various VMs may be dynamically instantiated and terminated within computing cloud networks. When a VM is instantiated, various network resources are allocated to the VM to facilitate network communications. Those resources typically include an internet protocol (IP) address and/or a media access control (MAC) address, among others. When the VM is terminated, those network resources are de-allocated and returned to a provisioning pool. (3) For enhanced security, VMs can be protected by firewalls. A firewall that is configured to protect a given VM implements a set of rules according to what network traffic is selectively forwarded to the VM. For example, a firewall rule could indicate that any transmission control protocol (TCP) traffic targeting port 80 should be forwarded to the IP address associated with the VM. In such implementations, network traffic that is not governed by a specific rule in the set of rules is rejected and not forwa

Claims

1. A computer-implemented method for remediating obsolete firewall rules within a firewall, the method comprising: accessing one or more active servers included within a network; extracting services data from the one or more active servers, wherein the services data indicates a current state of one or more services currently running on the one or more active servers; generating rules data indicating one or more firewall rules implemented by a first firewall included in a set of firewalls; comparing at least a portion of the services data to at least a portion of the rules data to identify a first firewall rule included in the one or more firewall rules that meets at least one remediation criterion; and removing, from the first firewall, the first firewall rule from the one or more firewall rules, wherein removing the first firewall rule from the one or more firewall rules causes the first firewall to prevent at least a portion of network traffic from entering the network. || 11. A non-transitory computer-readable medium storing program instructions that, when executed by a processor, cause the processor to remediate obsolete firewall rules within a firewall by performing the steps of: accessing one or more active servers included within a network; extracting services data from the one or more active servers, wherein the services data indicates a current state of one or more services currently running on the one or more active servers; generating rules data indicating one or more firewall rules implemented by a first firewall included in a set of firewalls; comparing at least a portion of the services data to at least a portion of the rules data to identify a first firewall rule included in the one or more firewall rules that meets at least one remediation criterion; and removing, from the first firewall, the first firewall rule from the one or more firewall rules, wherein removing the first firewall rule from the one or more firewall rules causes the first firewall to prevent at least a portion of network traffic from entering the network. || 20. A system, comprising: a memory storing a firewall manager; and a processor that, upon executing the firewall manager, performs the steps of: accessing one or more active servers included within a network, extracting services data from the one or more active servers, wherein the services data indicates a current state of one or more services currently running on the one or more active servers, generating rules data indicating one or more firewall rules implemented by a first firewall included in a set of firewalls, comparing at least a portion of the services data to at least a portion of the rules data to identify a first firewall rule included in the one or more firewall rules that meets at least one remediation criterion, and removing, from the first firewall, the first firewall rule from the one or more firewall rules, wherein removing the first firewall rule from the one or more firewall rules causes the first firewall to prevent at least a portion of network traffic from entering the network.