SERVICE PROVIDING METHOD AND CONTROL DEVICE
    2.
    发明申请

    公开(公告)号:US20180248846A1

    公开(公告)日:2018-08-30

    申请号:US15890519

    申请日:2018-02-07

    申请人: FUJITSU LIMITED

    IPC分类号: H04L29/06

    摘要: A non-transitory computer-readable recording medium has stored therein a program for causing a computer to execute a process of providing a service for constructing a platform in a cloud and using the constructed platform. The process includes constructing a plurality of platforms in a cloud when definition information on a construction of a platform is received from a plurality of information processing devices via a network, and causing each of the plurality of platforms constructed at the constructing to include a firewall initialized to block accesses excluding one or a plurality of common access sources.

    MICRO-SEGMENTATION OF VIRTUAL COMPUTING ELEMENTS

    公开(公告)号:US20180183757A1

    公开(公告)日:2018-06-28

    申请号:US15790303

    申请日:2017-10-23

    申请人: Nicira, Inc.

    IPC分类号: H04L29/06 G06F9/455

    摘要: The technology disclosed herein enables micro-segmentation of virtual computing elements. In a particular embodiment, a method provides identifying one or more multi-tier applications comprising a plurality of virtual machines. Each application tier of the one or more multi-tier applications comprises at least one of the plurality of virtual machines. The method further provides maintaining information about the one or more multi-tier applications. The information at least indicates a security group for each virtual machine of the plurality of virtual machines. Additionally, the method provides identifying communication traffic flows between virtual machines of the plurality of virtual machines and identifying one or more removable traffic flows of the communication traffic flows based, at least in part, on the information. The method then provides blocking the one or more removable traffic flows.

    COLLECTING FIREWALL FLOW RECORDS OF A VIRTUAL INFRASTRUCTURE

    公开(公告)号:US20180176184A1

    公开(公告)日:2018-06-21

    申请号:US15380934

    申请日:2016-12-15

    申请人: NICIRA, INC.

    IPC分类号: H04L29/06 G06F9/48 H03M7/30

    摘要: In a computer-implemented method for collecting firewall flow records, firewall flow records are received from a plurality of data end nodes of a virtualized infrastructure comprising a distributed firewall according to a collection schedule, wherein the collection schedule defines which data end nodes of the plurality of data end nodes from which firewall flow records are collected, a frequency of collection of firewall flow records from the data end nodes, and an amount of firewall flow records collected from the data end nodes. Firewall flow records received at a firewall flow record collection queue are processed, such that the received firewall flow records are prepared for storage at a flow record data store. The collection schedule is dynamically adapted based at least in part on the processing of the received firewall flow records, such that the firewall flow record collection queue is available for processing firewall flow records prior to receiving additional firewall flow records from the data end nodes.

    PROVIDING SECURITY SERVICE
    8.
    发明申请

    公开(公告)号:US20180007001A1

    公开(公告)日:2018-01-04

    申请号:US15543724

    申请日:2016-04-20

    发明人: Songer Sun

    IPC分类号: H04L29/06

    摘要: In an example, a security service providing system receives a service request for requesting security service for a target flow, determine a security device for providing security service for the target flow and first service configuration information and next-hop information of the security device according to security service information carried in the service request, and configure the first service configuration information and the next-hop information of the security device onto the security device, so that the security device provides security service to the target flow according to the first service configuration information and forwards the target flow according to the next-hop information

    DATA CENTER SYSTEM
    9.
    发明申请
    DATA CENTER SYSTEM 审中-公开

    公开(公告)号:US20170310641A1

    公开(公告)日:2017-10-26

    申请号:US15479192

    申请日:2017-04-04

    摘要: A data center system includes: at least two data center subsystems interconnected through a layer-2 network, each of the data center subsystems comprising a plurality of hosts, a plurality of layer-2 switches connected with the plurality of hosts, a firewall group connected with the layer-2 switches, and a layer-2 extension device connected with the layer-2 switches; wherein the firewall groups of the at least two data center subsystems are configured to transmit synchronization information to each other through a synchronization channel in a first virtual local area network; wherein the layer-2 extension devices of the at least two data center subsystems are configured to transmit service information through a service channel in a second virtual local area network; and wherein the first virtual local area network and the second virtual local area network are implemented in the layer-2 network.