Invention Grant
- Patent Title: Dynamic detection of firewall misconfigurations
-
Application No.: US16414398Application Date: 2019-05-16
-
Publication No.: US10798120B2Publication Date: 2020-10-06
- Inventor: Eric Jason Brandwine
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US WA Seattle
- Assignee: AMAZON TECHNOLOGIES, INC.
- Current Assignee: AMAZON TECHNOLOGIES, INC.
- Current Assignee Address: US WA Seattle
- Agency: Hogan Lovells US LLP
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
An automated scanning service can be configured to dynamically determine potential firewall misconfigurations in a shared resource environment. The scanning service can interrogate one or more application programming interfaces (APIs) to determine the state of the relevant firewall ports. For each firewall port in a permitted state, a test or trace can be run to determine whether the corresponding host port is open. Similarly, information can be obtained indicating which host ports for the allocation are open, and a determination can be made as to whether the corresponding firewall ports are permitted. Once the determinations are made, any mismatch in port state can be reported as a potential misconfiguration.
Public/Granted literature
- US20190273757A1 DYNAMIC DETECTION OF FIREWALL MISCONFIGURATIONS Public/Granted day:2019-09-05
Information query