Multi-tenant cloud-based firewall systems and methods
Abstract
Multi-tenant cloud-based firewall systems and methods are described. The firewall systems and methods can operate overlaid with existing branch office firewalls or routers as well as eliminate the need for physical firewalls. The firewall systems and methods can protect users at user level control, regardless of location, device, etc., over all ports and protocols (not only ports 80/443) while providing administrators a single unified policy for Internet access and integrated reporting and visibility. The firewall systems and methods can eliminate dedicated hardware at user locations, providing a software-based cloud solution. The firewall systems and methods support application awareness to identify application; user awareness to identify users, groups, and locations regardless of physical address; visibility and policy management providing unified administration, policy management, and reporting; threat protection and compliance to block threats and data leaks in real-time; high performance through an in-line cloud-based, scalable system; etc.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A non-transitory computer-readable storage medium having computer readable code stored thereon for programming a processor, in a node of a cloud-based security system, to perform steps of:
receiving one or more packets, the one or more packets being received from a network device external to the node; processing the one or more packets utilizing firewall policies of one or more firewall sessions to determine whether or not to block the one or more packets from transmission over a network; logging information associated with the one or more firewall sessions; and producing a report based on the logging of the one or more firewall sessions, the report including a plurality of fields associated with the one or more packets processed by the one or more firewall sessions.
2 . The non-transitory computer-readable storage medium of claim 1 , wherein the report includes information identifying top destinations traversing the network and top firewall threats detected by the one or more firewall sessions.
3 . The non-transitory computer-readable storage medium of claim 1 , wherein the logging is configured for one of aggregate logging and full logging.
4 . The non-transitory computer-readable storage medium of claim 1 , wherein the report is produced as one of a real-time report generated by compressed stats and an analyze report generated by full session log analysis.
5 . The non-transitory computer-readable storage medium of claim 1 , wherein the steps include producing a plurality of reports, and wherein the plurality of reports are produced for any of a particular user, a particular Internet Protocol (IP) address, or group of IP addresses.
6 . The non-transitory computer-readable storage medium of claim 1 , wherein the steps further include:
providing an interactive display of firewall insights, the display including graphs of usage trends through the one or more firewall sessions.
7 . The non-transitory computer-readable storage medium of claim 1 , wherein the steps further include:
receiving an update based on detection of zero-day/zero-hour threats based on the report; and updating the one or more firewall sessions based on the update.
8 . A node in a cloud-based security system, comprising:
a processor and memory storing instructions that, when executed, cause the processor to:
receive one or more packets, the one or more packets being received from a network device external to the node;
process the one or more packets utilizing firewall policies of one or more firewall sessions to determine whether or not to block the one or more packets from transmission over a network;
log information associated with the one or more firewall sessions; and
produce a report based on the logging of the one or more firewall sessions, the report including a plurality of fields associated with the one or more packets processed by the one or more firewall sessions.
9 . The node of claim 8 , wherein the report includes information identifying top destinations traversing the network and top firewall threats detected by the one or more firewall sessions.
10 . The node of claim 8 , wherein the logging is configured for one of aggregate logging and full logging.
11 . The node of claim 8 , wherein the report is produced as one of a real-time report generated by compressed stats and an analyze report generated by full session log analysis.
12 . The node of claim 8 , wherein the instructions cause the processor to produce a plurality of reports, and wherein the plurality of reports are produced for any of a particular user, a particular Internet Protocol (IP) address, or group of IP addresses.
13 . The node of claim 8 , wherein the instructions further cause the processor to:
provide an interactive display of firewall insights, the display including graphs of usage trends through the one or more firewall sessions.
14 . The node of claim 8 , wherein the instructions further cause the processor to:
receive an update based on detection of zero-day/zero-hour threats based on the report; and update the one or more firewall sessions based on the update.
15 . A method implemented in a node of a cloud-based security system, the method comprising steps of:
receiving one or more packets, the one or more packets being received from a network device external to the node; processing the one or more packets utilizing firewall policies of one or more firewall sessions to determine whether or not to block the one or more packets from transmission over a network; logging information associated with the one or more firewall sessions; and producing a report based on the logging of the one or more firewall sessions, the report including a plurality of fields associated with the one or more packets processed by the one or more firewall sessions.
16 . The method of claim 15 , wherein the report includes information identifying top destinations traversing the network and top firewall threats detected by the one or more firewall sessions.
17 . The method of claim 15 , wherein the logging is configured for one of aggregate logging and full logging.
18 . The method of claim 15 , wherein the report is produced as one of a real-time report generated by compressed stats and an analyze report generated by full session log analysis.
19 . The method of claim 15 , wherein the steps include producing a plurality of reports, and wherein the plurality of reports are produced for any of a particular user, a particular Internet Protocol (IP) address, or group of IP addresses.
20 . The method of claim 15 , wherein the steps further include:
providing an interactive display of firewall insights, the display including graphs of usage trends through the one or more firewall sessions.Join the waitlist — get patent alerts
Track US2023164116A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.