EP2175603A1

Dynamic access control policy with port restrictions for a network security appliance

Abstract

A network security appliance, commonly referred to as firewall device, supports definition of a security policy to control access to a network. The security policy is defined by match criteria including a layer seven network application, a static port list of layer four ports for a transport-layer protocol, and actions to be applied to packet flows that match the match criteria. A rules engine dynamically identifies a type of layer seven network application associated with the received packet flow based on inspection of application-layer data within payloads of packets of the packet flow without basing the identification solely on a layer four port specified by headers within the packets. The rules engine is configured to apply the security policy to determine whether the packet flow matches the static port lists specified by the match criteria. The network security appliance applies the actions specified by the security policy to the packet flow.

EP2175603A1, drawing sheet 1
Sheet 1 of 5

Term

Projected expiry 3 June 2029.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

15 claims: 13 independent, 2 dependent

  1. 1
    A network security appliance comprising:an interface configured to receive a packet flow;a control unit configured to support definition of a security policy to control access by the packet flow to a network, wherein the security policy specifies: (a) match criteria that include a layer seven network application, and a static port list of one or more layer four ports for a transport-layer protocol, and (b) actions to be applied to packet flows that match the match criteria, a rules engine configured to dynamically identify a type of layer seven network application associated with the received packet flow based on inspection of application-layer data within payloads of packets of the packet flow without basing the identification solely on a layer four port specified by headers within the packets, wherein the rules engine is configured to apply the security policy, after the dynamic identification of the layer seven network application, to determine whether the packet flow matches the static port lists specified by the match criteria, wherein upon the rules engine determining that the packet flow matches the static port lists, the control unit applies the actions specified by the security policy to the packet flow.
  2. 3
    The network security appliance of any of claims 1 and 2, further comprising:a flow analysis module configured to analyze packet headers of packets in the packet flow to identify the layer four ports for a transport layer protocol associated with the packet flow;and a flow table updated by the flow analysis module and the rules engine to store the identified layer seven network application as identified by the rules engine, and layer four ports associated with the packet flow.
  3. 4
    The network security appliance of any of claims 1-3, wherein the match criteria further includes a network source, further comprising a query module that identifies the network source associated with a received packet flow by querying a domain controller with a source Internet Protocol (IP) address associated with the packet flow to obtain one of a username or a user role associated with the source IP address.
  4. 5
    The network security appliance of any of claims 1-4, wherein the match criteria of the security policy further includes a network destination, wherein the network destination is defined as one of:a destination Internet Protocol (IP) address, a set of destination IP addresses, and an output zone that defines a set of output interfaces.
  5. 6
    The network security appliance of any of claims 1-5, wherein the match criteria further includes a network source, wherein the network source of the packet flow is defined by the security policy in terms of one of a user, a user role, a source IP address, a set of source IP addresses, and an input zone that defines a set of input interfaces.
  6. 7
    The network security appliance of any of claims 1-6, wherein the one or more layer four ports for the transport-layer protocol are defined by the security policy as a range of layer four ports.
  7. 8
    The network security appliance of any of claims 1-7, wherein the rules engine dynamically defines a new security policy that allows access by a matching packet flow to the network within a defined time period on a different layer four port than is specified by the specified match criteria of the security policy.
  8. 9
    The network security appliance of any of claims 1-8, wherein the actions specified by the security policy to be applied include logging one or more of:whether a matching packet flow was allowed or denied, the identity of the user that was allowed or denied, what application was being used by the packet flow, what port was being used by the packet flow, and a timestamp indicating when a matching packet flow was detected.
  9. 10
    A method for controlling access to a network with a network security appliance, comprising:receiving configuration information with a user interface of the network security appliance, wherein the configuration information specifies a security policy defined by: (a) match criteria that include a layer seven network application, and a static port list of one or more layer four ports for a transport-layer protocol, and (b) actions to be applied to packet flows that match the match criteria;receiving a packet flow with an interface of the network security appliance;with a rules engine of the network security appliance, dynamically identifying a type of layer seven network application associated with the received packet flow based on inspection of application-layer data within payloads of packets of the packet flow without basing the identification solely on a layer four port specified by headers within the packets;with the rules engine, applying the security policy, after the dynamic identification of the layer seven network application, to determine whether the packet flow matches the static port lists specified by the match criteria;and upon the rules engine determining that the packet flow matches the static port lists, applying the actions specified by the security policy to the packet flow.
  10. 12
    The method of any of claims 10 and 11, wherein the match criteria of the security policy further includes a network destination, wherein the network destination is defined as one of:a destination Internet Protocol (IP) address, a set of destination IP addresses, and an output zone that defines a set of output interfaces.
  11. 13
    The method of any of claims 10-12, wherein the match criteria further includes a network source, wherein the network source of the packet flow is defined by the security policy in terms of one of a user and a user role, further comprising:identifying the network source associated with a received packet flow by querying a domain controller with a source Internet Protocol (IP) address associated with the packet flow to obtain one of a username or a user role associated with the source IP address.
  12. 14
    The method of any of claims 10-13, further comprising dynamically defining, with the rules engine, a new security policy that allows access by a matching packet flow to the network within a defined time period on a different layer four port than is specified by the specified match criteria of the security policy.
  13. 15
    A computer-readable medium comprising instructions for causing a programmable processor to:receive configuration information with a user interface of a network security appliance that controls access to a network, wherein the configuration information specifies a security policy defined by: (a) match criteria that include a layer seven network application, and a static port list of one or more layer four ports for a transport-layer protocol, and (b) actions to be applied to packet flows that match the match criteria;receive a packet flow with an interface of the network security appliance;with a rules engine of the network security appliance, dynamically identify a type of layer seven network application associated with the received packet flow based on inspection of application-layer data within payloads of packets of the packet flow without basing the identification solely on a layer four port specified by headers within the packets;with the rules engine, apply the security policy, after the dynamic identification of the layer seven network application, to determine whether the packet flow matches the static port lists specified by the match criteria;and upon the rules engine determining that the packet flow matches the static port lists, apply the actions specified by the security policy to the packet flow.