US2021014200A1PendingUtilityA1

Assessing risk associated with firewall rules

Assignee: AT&T GLOBAL NETWORK SERVICES U K B VPriority: Jul 21, 2016Filed: Jun 24, 2020Published: Jan 14, 2021
Est. expiryJul 21, 2036(~10 yrs left)· nominal 20-yr term from priority
Inventors:Ian Phillips
H04L 63/0236H04L 63/1433H04L 63/0263
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques for assessing risk associated with firewall rules are provided. In one implementation, a method includes receiving a request for the network to apply a firewall policy rule to control traffic to a machine associated with the network, wherein the firewall policy rule comprises information that identifies a remote address from which the traffic can originate and a type of the traffic. The method further includes determining a remote address risk value representative of a first degree of security risk associated with allowing the traffic to access the machine in response to the traffic being determined to originate from the remote address; determining a traffic type risk value representative of a second degree of security risk associated with allowing the type of traffic to access the machine; and determining a total risk value based on a combination of the remote address risk value and the traffic type risk value.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method, comprising:
 determining, by a system comprising a processor, a remote address risk value representative of a first degree of risk associated with a communication of traffic between a machine and a defined remote address associated with a network;   determining, by the system, a traffic type risk value representative of a second degree of risk associated with a defined type of the traffic;   determining, by the system, a security risk score based on a vector determined as a function of the remote address risk value and the traffic type risk value; and   applying, by the device, the security risk score to control the communication.   
     
     
         2 . The method of  claim 1 , wherein the applying comprises enabling the communication of the traffic based on a determination that the security risk score satisfies an acceptability criterion for the security risk score. 
     
     
         3 . The method of  claim 1 , wherein the applying comprises disabling the communication of the traffic based on a determination that the security risk score fails to satisfy an acceptability criterion for the security risk score. 
     
     
         4 . The method of  claim 1 , wherein the communication comprises an ingress communication from the defined remote address to the machine. 
     
     
         5 . The method of  claim 1 , wherein the communication comprises an egress communication from the machine to the defined remote address. 
     
     
         6 . The method of  claim 1 , wherein the machine comprises a virtual machine, wherein the network comprises a virtual network, and wherein the security risk score controls passage of the traffic through a virtual network interface card that connects the virtual machine to network equipment of the virtual network. 
     
     
         7 . The method of  claim 1 , wherein determining the remote address risk value comprises determining the remote address risk value based on a number of subnet addresses associated with the defined remote address, and wherein the remote address risk value increases as the number of the subnet addresses increases. 
     
     
         8 . The method of  claim 1 , wherein determining the remote address risk value comprises:
 identifying the remote address in a data store comprising risk information identifying degrees of security risk respectively associated with known remote addresses; and   determining the remote address risk value based on the risk information.   
     
     
         9 . The method of  claim 1 , wherein the type of traffic corresponds to different protocol and port combinations, wherein determining the traffic type risk value comprises determining the traffic risk value based on a number of the different protocol and port combinations, and wherein the traffic type risk value increases as the number of the different protocol and port combinations increases. 
     
     
         10 . The method of  claim 1 , wherein determining the traffic type risk value comprises:
 identifying the type of traffic in a data store comprising risk information that identifies degrees of security risk respectively associated with known types of traffic; and   determining the traffic type risk value based on the risk information.   
     
     
         11 . A system, comprising:
 a processor; and   a memory that stores executable instructions that, when executed by the processor, facilitate performance of operations, comprising:
 determining a remote address risk metric representative of a first degree of risk associated with communication of traffic via a network between a machine and a defined remote address associated with network equipment; 
 determining a traffic type risk metric representative of a second degree of risk associated with a defined type of the traffic; 
 determining a security risk level based on a vector determined as a function of the remote address risk metric and the traffic type risk metric; and 
 controlling the communication based on the security level. 
   
     
     
         12 . The system of  claim 11 , wherein the controlling comprises enabling the communication of the traffic based on a determination that the security risk level satisfies an acceptability criterion for the security risk level. 
     
     
         13 . The system of  claim 11 , wherein the controlling comprises disabling the communication of the traffic based on a determination that the security risk level fails to satisfy an acceptability criterion for the security risk level. 
     
     
         14 . The system of  claim 11 , wherein the communication comprises ingress communication from the defined remote address associated with the network equipment to the machine. 
     
     
         15 . The system of  claim 11 , wherein the communication comprises egress communication from the machine to the defined remote address associated with the network equipment. 
     
     
         16 . The system of  claim 11 , wherein the machine comprises a virtual machine, wherein the network comprises a virtual network, and wherein the security risk level controls passage of the traffic through a virtual network interface card that connects the virtual machine to the virtual network. 
     
     
         17 . The system of  claim 11 , wherein determining the remote address risk value comprises determining the remote address risk value based on a number of subnet addresses associated with the defined remote address, and wherein the remote address risk value increases as the number of the subnet addresses increases. 
     
     
         18 . The system of  claim 11 , wherein determining the remote address risk value comprises:
 identifying the remote address in a data store comprising risk information identifying degrees of security risk respectively associated with known remote addresses; and   determining the remote address risk value based on the risk information.   
     
     
         19 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processor, facilitate performance of operations, comprising:
 determining a remote address risk measure representative of a first degree of risk associated with communication of traffic between a device and a defined remote address corresponding to network equipment;   determining a traffic type risk measure representative of a second degree of risk associated with a defined type of the traffic;   determining a security risk level based on a vector determined as a function of the remote address risk measure and the traffic type risk measure; and   controlling the communication based on the security level.   
     
     
         20 . The non-transitory machine-readable medium of  claim 19 , wherein the controlling comprises:
 enabling the communication of the traffic based on a first determination that the security risk level satisfies an acceptability criterion for the security risk level; and   disabling the communication of the traffic based on a second determination that the security risk level fails to satisfy the acceptability criterion.

Join the waitlist — get patent alerts

Track US2021014200A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.