Nova Patents
WO9854644A1

Multilayer firewall system

Abstract

A system provides for establishing security in a network (10) that includes nodes having security functions operating in multiple protocol layers. Multiple network devices, such as remote access equipment (13), routers (14), switches (12), repeaters (16) and network cards (15) having security functions are configured to contribute to implementation of distributed firewall functions in the network. By distributing firewall functionality throughout many layers of the network in a variety of network devices, a pervasive firewall is implemented. The pervasive, multilayer firewall includes a policy definition component (11) that accepts policy data that define how the firewall should behave. The multilayer firewall also includes a collection of network devices that are used to enforce the defined policy. The security functions operating in this collection of network devices across multiple protocol layers are coordinated by the policy definition component so that particular devices enforce that part of the policy pertinent to their part of the network.

WO9854644A1, drawing sheet 1
Sheet 1 of 8

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

71 claims: 4 independent, 67 dependent

  1. 1
    CLAIMS It is claimed:1. A system providing security in a network including nodes of a plurality of types, nodes in a set of the nodes in the network including security functions executing in response to configuration data adapted for the corresponding type of node, comprising: a topology data store, storing information about security functions operating in the set of the nodes in the network, and about interconnection of nodes in the set of the nodes;a configuration interface, coupled to the topology data store, including an input by which to receive security policy statements indicating security policies to be implemented among nodes in the network;and a configuration driver, coupled to the network, the configuration interface, and the topology data store, including resources which translate the security policy statements into configuration data for the plurality of types of nodes in the network, and which conveys the configuration data to the nodes.
  2. 29
    A system providing security in a network including nodes of plurality of types, nodes in a set of the nodes in the network including security functions executing in response to configuration data adapted for the corresponding type of node, comprising:a topology data store, storing information about security functions in the set of the nodes in the network, and about interconnection of nodes in the set of the nodes, the topology data store including data structures providing information for particular nodes, including addresses at one or more protocol layers, whether or not the particular node is trasted to enforce security policy, the type of security policy the particular node is able to enforce, and connections of the particular node to other nodes;a configuration interface, coupled to the topology data store, including an input by which to receive security policy statements indicating security policies to be implemented between source sets of one or more end stations and destination sets of one or more end stations in the network, including a script interpreter which interprets a script language to determine the security policy statements, and the script language includes a syntax for specifying a security policy statement including a source set identifier, a destination set identifier, a communication activity identifier, and a rule for the identified communication activity between the identified source set and the identified destination set;and a configuration driver, coupled to the network, the configuration interface, and the topology data store, including resources which translate the security policy statements into configuration data for various types of nodes in the network, and which send the configuration data to the nodes.
  3. 43
    A method for establishing a firewall system in a network including a set of nodes of a plurality of types, nodes in the set of nodes in the network including security functions executing in response to configuration data adapted for the corresponding node, comprising:providing topology data including information about security functions operating in nodes in the set, and about interconnection of nodes in the set;providing security policy statements indicating security policies to be implemented among end systems in the set;translating, in response to the topology data, the security policy statements into configuration data for security functions operating at nodes in the set;and establishing the configuration data in the security functions at the nodes in the network.
  4. 64
    A method for establishing a firewall system in a network including a set of nodes of a plurality of types, nodes in the set of nodes in the network including security functions executing in response to configuration data adapted for the corresponding node, comprising:providing topology data including information about security functions operating in nodes in the set, and about interconnection of nodes in the set;providing security policy statements indicating security policies to be implemented between a source set of end stations and a destination set of end stations in the set;identifying, in response to the topology data and the security policy statements, a cut vertex set of nodes consisting of nodes capable of enforcing the security policy statements, and which if removed from the network would isolate the source set from the destination set;translating, in response to the identified cut vertex set and the security policy statements, into configuration data for security functions operating at nodes in the cut vertex set;and establishing the configuration data in the security functions at the nodes in the cut vertex set.