Invention Application
- Patent Title: DISTRIBUTED IDENTITY-BASED FIREWALLS
-
Application No.: US17063415Application Date: 2020-10-05
-
Publication No.: US20210036990A1Publication Date: 2021-02-04
- Inventor: Anirban Sengupta , Subrahmanyam Manuguri , Mitchell T. Christensen , Azeem Feroz , Todd Sabin
- Applicant: Nicira, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: Nicira, Inc.
- Current Assignee: Nicira, Inc.
- Current Assignee Address: US CA Palo Alto
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/08 ; G06F9/455

Abstract:
Systems and techniques are described for monitoring network communications using a distributed firewall. One of the techniques includes receiving, at a driver executing in a guest operating system of a virtual machine, a request to open a network connection from a process associated with a user, wherein the driver performs operations comprising: obtaining identity information for the user; providing the identity information and data identifying the network connection to an identity module external to the driver; and receiving, by a distributed firewall, data associating the identity information with the data identifying the network connection from the identity module, wherein the distributed firewall performs operations comprising: receiving an outgoing packet from the virtual machine; determining that the identity information corresponds to the outgoing packet; and evaluating one or more routing rules based at least in part on the identity information.
Public/Granted literature
- US11695731B2 Distributed identity-based firewalls Public/Granted day:2023-07-04
Information query