Invention Grant
- Patent Title: Methods and systems for orchestrating physical and virtual switches to enforce security boundaries
-
Application No.: US14677827Application Date: 2015-04-02
-
Publication No.: US09973472B2Publication Date: 2018-05-15
- Inventor: Marc Woolward , Choung-Yaw Shieh
- Applicant: vArmour Networks, Inc.
- Applicant Address: US CA Mountain View
- Assignee: vArmour Networks, Inc.
- Current Assignee: vArmour Networks, Inc.
- Current Assignee Address: US CA Mountain View
- Agency: Carr & Ferrell LLP
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Some embodiments include methods comprising: writing entries in a forwarding table of a switch through an application programming interface (API) of the switch, such that first data packets from a first host and directed to a second host are forwarded by the switch to an enforcement point; receiving the first data packets; forwarding the first data packets to the enforcement point using the forwarding table; determining whether the first data packets violate a high-level security policy using a low-level rule set; configuring the forwarding table through the API such that second data packets are forwarded by the switch to the second host, in response to determining the first data packets do not violate the security policy; configuring the forwarding table through the API such that the second data packets are dropped or forwarded to a security function by the switch, in response to the determining.
Public/Granted literature
- US20160294774A1 METHODS AND SYSTEMS FOR ORCHESTRATING PHYSICAL AND VIRTUAL SWITCHES TO ENFORCE SECURITY BOUNDARIES Public/Granted day:2016-10-06
Information query