Invention Grant
- Patent Title: Firewall event reduction for rule use counting
-
Application No.: US13711094Application Date: 2012-12-11
-
Publication No.: US08949418B2Publication Date: 2015-02-03
- Inventor: Rory F. Bray , Cezar P. Grzelak , Jason D. Keirstead
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Lee Law, PLLC
- Agent Christopher B. Lee
- Main IPC: G06F15/16
- IPC: G06F15/16 ; G06F15/173 ; H04L29/06 ; H04L12/26

Abstract:
An illustrative embodiment of a method for firewall rule use counting receives log messages comprising one or more log data sets from each firewall rule in a particular network whose counts are to be tracked in a log collector, generates a network trie for each reference database in a set of databases and a device source trie and a device destination trie for each firewall device in a plurality of devices of the particular network, a source port and protocol list and a destination port and protocol list for each respective device, a unique object for each log data set received; a mapping database comprising an entry for each log data set received associated with the unique object; and feeds each entry in the mapping database through a topology model to also generate a reference to a unique firewall rule on a respective device in the plurality of devices. A count associated with the unique firewall rule is incremented using a count of logs stored associated with the respective unique object and a report is generated.
Public/Granted literature
- US20140164595A1 FIREWALL EVENT REDUCTION FOR RULE USE COUNTING Public/Granted day:2014-06-12
Information query