首页> 外国专利> DISTRIBUTED FIREWALLS AND VIRTUAL NETWORK SERVICES USING NETWORK PACKETS WITH SECURITY TAGS

DISTRIBUTED FIREWALLS AND VIRTUAL NETWORK SERVICES USING NETWORK PACKETS WITH SECURITY TAGS

机译:使用带有安全标签的网络包的分布式防火墙和虚拟网络服务

摘要

A method, system, and apparatus are provided for a distributed firewall and virtual network services on a network. In one example, the method includes storing a plurality of predefined security groups, wherein each predefined security group has a set of predefined security rules for network packets configured to be transmitted between virtual machines (VMs) within the network; associating each virtual machine (VM) within the network with one or more predefined security groups (SGs); filtering an outgoing network packet from a sending VM to a receiving VM in response to the predefined security rules associated with the predefined SGs associated with the sending VM to validate the communication desired in the outgoing network packet; forming a secured network packet by encapsulating a header, a security tag, and the outgoing network packet together; and transmitting the secured network packet into the network for delivery to the receiving VM.
机译:提供了一种用于网络上的分布式防火墙和虚拟网络服务的方法,系统和装置。在一个示例中,该方法包括存储多个预定义的安全组,其中每个预定义的安全组具有一组预配置的安全规则,用于网络分组,其被配置为在网络内的虚拟机(VM)之间传输;将网络中的每个虚拟机(VM)与一个或多个预定义的安全组(SG)关联;响应于与与发送VM相关联的预定义SG相关联的预定义安全规则,从发送VM到接收VM对输出网络包进行过滤,以验证输出网络包中期望的通信;通过将报头,安全标签和传出网络包封装在一起,形成安全的网络包;将所述安全网络报文发送到所述网络中以传递给所述接收虚拟机。

著录项

  • 公开/公告号US2017118173A1

    专利类型

  • 公开/公告日2017-04-27

    原文格式PDF

  • 申请/专利权人 ATTALA SYSTEMS LLC;

    申请/专利号US201514921873

  • 发明设计人 SUJITH ARRAMREDDY;SAI GADIRAJU;

    申请日2015-10-23

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 13:49:33

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号