Nova Patents
GB2342020B

Multilayer firewall system

Abstract

A system provides for establishing security in a network that include nodes having security functions operating in multiple protocol layers. Multiple network devices, such as remote access equipment, routers, switches, repeaters and network cards having security functions are configured to contribute to implementation of distributed firewall functions in the network. By distributing firewall functionality throughout many layers of the network in a variety of network devices, a pervasive firewall is implemented. The pervasive, multilayer firewall includes a policy definition component that accepts policy data that defines how the firewall should behave. The policy definition component can be a centralized component, or a component that is distributed over the network. The multilayer firewall also includes a collection of network devices that are used to enforce the defined policy. The security functions operating in this collection of network devices across multiple protocol layers are coordinated by the policy definition component so that particular devices enforce that part of the policy pertinent to their part of the network.

GB2342020B, drawing sheet 1
Sheet 1 of 16

Term

Term ended

Expired 28 May 2018, 8.3 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

70 claims: 4 independent, 66 dependent

  1. 1
    CLAIMS 1. A system providing security across one or more protocol layers in a network including nodes of a plurality of network device types, with nodes in a set of the nodes in the network including security functions executing in response to configuration data adapted for the corresponding type of node in the network, the system comprising:a topology data store, storing information about security functions operating in the set of the nodes in the network, and about interconnection of nodes in the set of the nodes in the network;a configuration interface, coupled to the topology data store, including an input by which to receive security policy statements indicating security policies to be implemented among nodes in the network;and a configuration driver, coupled to the network, the configuration interface, and the topology data store, including resources which translate the security policy statements into configuration data for the plurality of types of nodes in the network, and which conveys the configuration data to the nodes in the set of nodes, wherein the security functions operating in the plurality of network device types across the one or more protocol layers are co-ordinated by the security policy so that particular device types enforce the part of the security policy pertinent to the associated part of the network.
  2. 29
    A system providing security across one or more protocol layers in a network including nodes of a plurality of network device types, with nodes in a set of the nodes in the network including security functions executing in response to configuration data adapted for the corresponding type of node in the network, the system comprising:a topology data store, storing information about security functions in the set of the nodes in the network, and about interconnection of nodes in the set of the nodes in the network, the topology data store including data structures providing information for particular nodes in the set of nodes in the network, including addresses at the one or more protocol layers, whether or not the particular node is trusted to enforce security policy, the type of security policy the particular node is able to enforce, and connections of the particular node to other nodes;a configuration interface, coupled to the topology data store, including an input by which to receive security policy statements indicating security policies ( • * · ’ <'.··;· - · · *..· · to be implemented between source sets of one or more end stations and destination sets of one or more end stations in the network, including a script interpreter which interprets a script language to determine the security policy statements, and the script language includes a syntax for specify ing a security policy statement including a source set identifier, a destination set identifier, a communication activity identifier, and a rule for the identified communication activity between the identified source set and the identified destination set;and a configuration driver, coupled to the network, the configuration interface, and the topology data store, including resources which translate the security policy statements into configuration data for various types of nodes in the network, and which send the configuration data to the nodes in the set of nodes, wherein the security functions operating in the plurality of network device types across the one or more protocol layers are co-ordinated by the security policy so that particular device types enforce the part of the security policy pertinent to the associated part of the network.
  3. 35
    36. The system of claim 35, wherein the security policy statement indicate security policies for communications traversing network links to nodes external to the set of the nodes.
  4. 39
    40. The system of claim 39, wherein the configuration store is coupled with the particular node by a communication link.
  5. 41
    42. The system of claim 41, wherein said cut vertex set consists of a minimal cut vertex set.
  6. 42
    43. A method for establishing a firewall system across one or more protocol layers in a network including a set of nodes of a plurality of types, nodes in the set of nodes in the network including security functions executing in response to configuration data adapted for the comesponding type of node in the network, the method comprising. providing topology data including information about security functions operating in nodes in the set, and about interconnection of nodes in the set;,* •,. « 1 providing security policy statements indicating security policies to be implemented among end systems in the set;translating, in response to the topology data, the security policy statements into configuration data for security functions operating at nodes in the set;and establishing the configuration data in the security functions at the nodes in the network, wherein the security functions operating in the set of nodes of a plurality of types across the one or more protocol layers are co-ordinated by the security policy so that particular types enforce the part of the security policy pertinent to the associated part of the network.
  7. 43
    44. The method of claim 43, wherein the topology data includes data structures providing information for particular nodes, including addresses at the one or more protocol layers, whether or not the particular node is trusted to enforce security policy, the type of security policy the particular node is able to enforce, and connections of the particular node to other nodes.
  8. 45
    46. The method of claim 45, wherein the syntax further includes an identifier of the location at which the rule is to be enforced.
  9. 47
    48. The method of claim 47, wherein for at least one node in the set of nodes, the persistent storage in communication with the node is local to the node, and for at least one other node in the set of nodes the persistent storage in communication with the node is remote from the node. ( 4< * 4· 4 44 4 *« •f 4« iI V V t • • 4 I
  10. 50
    51. The method of claim 50, wherein the topology data includes data indicating nodes coupled to network links to nodes external to the set of nodes.
  11. 51
    52. The method of claim 51, wherein the security policy statements indicate security policies for communications traversing network links to nodes external to the set of the nodes.
  12. 63
    64. A method for establishing a firewall system across one or more protocol layers in a 20 network including a set of nodes of a plurality of types, nodes in the set of nodes in the network including security functions executing in response to configuration data adapted for the corresponding type of node in the network, the method comprising:providing topology data including information about security functions operating in nodes in the set, and about interconnection of nodes in the set;25 providing security policy statements indicating security policies to be implemented between a source set of end stations and a destination set of end stations in the set;identifying, in response to the topology data and the security policy statements, cut vertex set of nodes consisting of nodes capable of enforcing the security policy statements, and which if removed from the network would isolate the source set from the destination set;30 translating, in response to the identified cut vertex set and the security policy statements, into configuration data for security functions operating at nodes in the cut vertex set;and establishing the configuration data in the security functions at the nodes in the cut vertex set;ST I 4 4 «t I 44 «4 1 < f 4 < ff wherein the security functions operating in the nodes in the cut vertex set across the one or more protocol layers are co-ordinated by the security policy so that particular types enforce the part of the security policy pertinent to the associated part of the network.
  13. 64
    65. The method of claim 64, wherein the topology data includes data structures providing information for particular nodes, including addresses, whether or not the particular node is trusted to enforce security policy, the type of security policy the particular node is able to enforce, and connections of the particular node to other nodes.
  14. 67
    68. The method of claim 67, wherein for at least one node in the cut vertex of nodes, the persistent storage in communication with the node is local to the node, and for at least one other node in the cut vertex set of nodes the persistent storage in communication with the node is remote from the node.