Outer Rim Archives
Archives · 2019 · 20190273720

Application (pre-grant publication)

FIREWALL RULE REMEDIATION FOR IMPROVED NETWORK SECURITY AND PERFORMANCE

Number
20190273720
Published
2019-09-05
Filed
2018-03-02
Assignee
DISNEY ENTERPRISES, INC.
Inventors
CLOUD; Mark G. et al.
CPC
H04L41/0894; H04L41/0895; H04L63/0236; H04L63/0263; H04L63/20
Verdict
Set aside firewall rule remediation, cybersecurity
Source
Google Patents · FreePatentsOnline

Abstract

A firewall manager periodically accesses a set of servers to identify the various services currently active on each server. The firewall manager also periodically accesses a set of firewalls configured to protect those servers to identify various firewall rules implemented by those firewalls. The firewall manager then compares the services data with the rules data to identify any obsolete firewall rules that are (i) defined based on an IP address not currently allocated to any of the servers or (ii) defined based on a port of an active server that is not associated with any service running on server. Such rules are considered obsolete. Upon identifying any obsolete firewall rules, the firewall manager accesses the firewalls associated with those rules and then removes the obsolete rules.

Background

BACKGROUNDField of the Various Embodiments

The various embodiments relate generally to computer networks, and, more specifically, to firewall rule remediation for improved network security and performance.Description of the Related Art

Conventional computing clouds include networks of virtual machines (VMs) configured to receive and process network traffic. For example, a computing cloud could include a network of VMs that operate as web servers to service hypertext transfer protocol (HTTP) requests. During operation and over time, various VMs may be dynamically instantiated and terminated within computing cloud networks. When a VM is instantiated, various network resources are allocated to the VM to facilitate network communications. Those resources typically include an internet protocol (IP) address and/or a media access control (MAC) address, among others. When the VM is terminated, those network resources are de-allocated and returned to a provisioning pool.

For enhanced security, VMs can be protected by firewalls. A firewall that is configured to protect a given VM implements a set of rules according to what network traffic is selectively forwarded to the VM. For example, a firewall rule could indicate that any transmission control protocol (TCP) traffic targeting port 80 should be forwarded to the IP address associated with the VM. In such implementations, network traffic that is not governed by a specific rule in the set of rules is rejected and not f

Claims

1. A computer-implemented method for remediating obsolete firewall rules within a firewall, the method comprising: generating services data indicating one or more services running on a set of servers included within a network; generating rules data indicating one or more firewall rules implemented by a first firewall included in a set of firewalls; comparing at least a portion of the services data to at least a portion of the rules data to identify a first firewall rule included in the one or more firewall rules that meets at least one remediation criterion; and causing the first firewall to remove the first firewall rule from the one or more firewall rules, wherein removing the first firewall rule from the one or more firewall rules causes the first firewall to prevent at least a portion of network traffic from entering the network. 11. A non-transitory computer-readable medium storing program instructions that, when executed by a processor, cause the processor to remediate obsolete firewall rules within a firewall by performing the steps of: generating services data indicating one or more services running on a set of servers included within a network; generating rules data indicating one or more firewall rules implemented by a first firewall included in a set of firewalls; comparing at least a portion of the services data to at least a portion of the rules data to identify a first firewall rule included in the one or more firewall rules that meets at least one remediation criterion; and causing the first firewall to remove the first firewall rule from the one or more firewall rules, wherein removing the first firewall rule from the one or more firewall rules causes the first firewall to prevent at least a portion of network traffic from entering the network. 20. A system, comprising: a memory storing a firewall manager; and a processor that, upon executing the firewall manager, is configured to perform the steps of: generating services data indicating one or more services running on a set of servers included within a network, generating rules data indicating one or more firewall rules implemented by a first firewall included in a set of firewalls, comparing at least a portion of the services data to at least a portion of the rules data to identify a first firewall rule included in the one or more firewall rules that meets at least one remediation criterion, and causing the first firewall to remove the first firewall rule from the one or more firewall rules, wherein removing the first firewall rule from the one or more firewall rules causes the first firewall to prevent at least a portion of network traffic from entering the network.