Assessing risk associated with firewall rules
Abstract
Techniques for assessing risk associated with firewall rules are provided. In one implementation, a method includes receiving a request for the network to apply a firewall policy rule to control traffic to a machine associated with the network, wherein the firewall policy rule comprises information that identifies a remote address from which the traffic can originate and a type of the traffic. The method further includes determining a remote address risk value representative of a first degree of security risk associated with allowing the traffic to access the machine in response to the traffic being determined to originate from the remote address; determining a traffic type risk value representative of a second degree of security risk associated with allowing the type of traffic to access the machine; and determining a total risk value based on a combination of the remote address risk value and the traffic type risk value.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method, comprising:
determining, by a system comprising a processor, a remote address risk value representative of a first degree of risk associated with a communication of traffic between a machine and a defined remote address associated with a network; determining, by the system, a traffic type risk value representative of a second degree of risk associated with a defined type of the traffic; determining, by the system, a security risk score based on a vector determined as a function of the remote address risk value and the traffic type risk value; and applying, by the device, the security risk score to control the communication.
2 . The method of claim 1 , wherein the applying comprises enabling the communication of the traffic based on a determination that the security risk score satisfies an acceptability criterion for the security risk score.
3 . The method of claim 1 , wherein the applying comprises disabling the communication of the traffic based on a determination that the security risk score fails to satisfy an acceptability criterion for the security risk score.
4 . The method of claim 1 , wherein the communication comprises an ingress communication from the defined remote address to the machine.
5 . The method of claim 1 , wherein the communication comprises an egress communication from the machine to the defined remote address.
6 . The method of claim 1 , wherein the machine comprises a virtual machine, wherein the network comprises a virtual network, and wherein the security risk score controls passage of the traffic through a virtual network interface card that connects the virtual machine to network equipment of the virtual network.
7 . The method of claim 1 , wherein determining the remote address risk value comprises determining the remote address risk value based on a number of subnet addresses associated with the defined remote address, and wherein the remote address risk value increases as the number of the subnet addresses increases.
8 . The method of claim 1 , wherein determining the remote address risk value comprises:
identifying the remote address in a data store comprising risk information identifying degrees of security risk respectively associated with known remote addresses; and determining the remote address risk value based on the risk information.
9 . The method of claim 1 , wherein the type of traffic corresponds to different protocol and port combinations, wherein determining the traffic type risk value comprises determining the traffic risk value based on a number of the different protocol and port combinations, and wherein the traffic type risk value increases as the number of the different protocol and port combinations increases.
10 . The method of claim 1 , wherein determining the traffic type risk value comprises:
identifying the type of traffic in a data store comprising risk information that identifies degrees of security risk respectively associated with known types of traffic; and determining the traffic type risk value based on the risk information.
11 . A system, comprising:
a processor; and a memory that stores executable instructions that, when executed by the processor, facilitate performance of operations, comprising:
determining a remote address risk metric representative of a first degree of risk associated with communication of traffic via a network between a machine and a defined remote address associated with network equipment;
determining a traffic type risk metric representative of a second degree of risk associated with a defined type of the traffic;
determining a security risk level based on a vector determined as a function of the remote address risk metric and the traffic type risk metric; and
controlling the communication based on the security level.
12 . The system of claim 11 , wherein the controlling comprises enabling the communication of the traffic based on a determination that the security risk level satisfies an acceptability criterion for the security risk level.
13 . The system of claim 11 , wherein the controlling comprises disabling the communication of the traffic based on a determination that the security risk level fails to satisfy an acceptability criterion for the security risk level.
14 . The system of claim 11 , wherein the communication comprises ingress communication from the defined remote address associated with the network equipment to the machine.
15 . The system of claim 11 , wherein the communication comprises egress communication from the machine to the defined remote address associated with the network equipment.
16 . The system of claim 11 , wherein the machine comprises a virtual machine, wherein the network comprises a virtual network, and wherein the security risk level controls passage of the traffic through a virtual network interface card that connects the virtual machine to the virtual network.
17 . The system of claim 11 , wherein determining the remote address risk value comprises determining the remote address risk value based on a number of subnet addresses associated with the defined remote address, and wherein the remote address risk value increases as the number of the subnet addresses increases.
18 . The system of claim 11 , wherein determining the remote address risk value comprises:
identifying the remote address in a data store comprising risk information identifying degrees of security risk respectively associated with known remote addresses; and determining the remote address risk value based on the risk information.
19 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processor, facilitate performance of operations, comprising:
determining a remote address risk measure representative of a first degree of risk associated with communication of traffic between a device and a defined remote address corresponding to network equipment; determining a traffic type risk measure representative of a second degree of risk associated with a defined type of the traffic; determining a security risk level based on a vector determined as a function of the remote address risk measure and the traffic type risk measure; and controlling the communication based on the security level.
20 . The non-transitory machine-readable medium of claim 19 , wherein the controlling comprises:
enabling the communication of the traffic based on a first determination that the security risk level satisfies an acceptability criterion for the security risk level; and disabling the communication of the traffic based on a second determination that the security risk level fails to satisfy the acceptability criterion.Join the waitlist — get patent alerts
Track US2021014200A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.