- 专利标题: Context-aware distributed firewall
-
申请号: US14558561申请日: 2014-12-02
-
公开(公告)号: US09692727B2公开(公告)日: 2017-06-27
- 发明人: Jingmin Zhou , Anirban Sengupta
- 申请人: Nicira, Inc.
- 申请人地址: US CA Palo Alto
- 专利权人: NICIRA, INC.
- 当前专利权人: NICIRA, INC.
- 当前专利权人地址: US CA Palo Alto
- 代理机构: Adeli LLP
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; H04L12/753 ; G06F9/455
摘要:
A context-aware distributed firewall scheme is provided. A firewall engine tasked to provide firewall protection for a set of network addresses applies a reduced set of firewall rules that are relevant to the set of addresses associated with the machine. A hypervisor implements a search structure that allows each virtual machine's filter to quickly identify relevant rules from all of the received rules. The search structure is constructed as a binary prefix tree, each node corresponding to an IP CIDR (Classless Inter-Domain Routing) block. A query for relevant rules traverses nodes of the search structure according to a queried IP address and collect all rules that are associated with the traversed nodes.
公开/授权文献
- US20160156591A1 CONTEXT-AWARE DISTRIBUTED FIREWALL 公开/授权日:2016-06-02
信息查询