Invention Grant
- Patent Title: Context-aware distributed firewall
-
Application No.: US16248732Application Date: 2019-01-15
-
Publication No.: US10581801B2Publication Date: 2020-03-03
- Inventor: Jingmin Zhou , Anirban Sengupta
- Applicant: Nicira, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: NICIRA, INC.
- Current Assignee: NICIRA, INC.
- Current Assignee Address: US CA Palo Alto
- Agency: Adeli LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L12/753 ; G06F9/455

Abstract:
A context-aware distributed firewall scheme is provided. A firewall engine tasked to provide firewall protection for a set of network addresses applies a reduced set of firewall rules that are relevant to the set of addresses associated with the machine. A hypervisor implements a search structure that allows each virtual machine's filter to quickly identify relevant rules from all of the received rules. The search structure is constructed as a binary prefix tree, each node corresponding to an IP CIDR (Classless Inter-Domain Routing) block. A query for relevant rules traverses nodes of the search structure according to a queried IP address and collect all rules that are associated with the traversed nodes.
Public/Granted literature
- US20190166096A1 CONTEXT-AWARE DISTRIBUTED FIREWALL Public/Granted day:2019-05-30
Information query