Invention Grant
- Patent Title: Conditional declarative policies
-
Application No.: US15151303Application Date: 2016-05-10
-
Publication No.: US09621595B2Publication Date: 2017-04-11
- Inventor: Jia-Jyi Lian , Anthony Paterra , Marc Woolward
- Applicant: vArmour Networks, Inc.
- Applicant Address: US CA Mountain View
- Assignee: vArmour Networks, Inc.
- Current Assignee: vArmour Networks, Inc.
- Current Assignee Address: US CA Mountain View
- Agency: Carr & Ferrell LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L12/24

Abstract:
Methods, systems, and media for producing a firewall rule set are provided herein. Exemplary methods may include receiving a declarative policy associated with a computer network security policy; collecting information from at least one external system of record; generating a firewall rule set using the declarative policy and information, the firewall rule set including addresses to or from which network communications are permitted, denied, redirected or logged, the firewall rule set being at a lower level of abstraction than the declarative policy; and provisioning the firewall rule set to a plurality of enforcement points of a distributed firewall, the firewall selectively policing network communications among workloads using the firewall rule set.
Public/Granted literature
- US20170063795A1 CONDITIONAL DECLARATIVE POLICIES Public/Granted day:2017-03-02
Information query