首页> 外国专利> PERFORMING APPID BASED FIREWALL SERVICES ON A HOST

PERFORMING APPID BASED FIREWALL SERVICES ON A HOST

机译:在主机上执行基于APPID的防火墙服务

摘要

Some embodiments of the invention provide a novel architecture for capturing contextual attributes on host computers that execute one or more machines, and for consuming the captured contextual attributes to perform services on the host computers. The machines are virtual machines (VMs) in some embodiments, containers in other embodiments, or a mix of VMs and containers in still other embodiments. Some embodiments execute a guest-introspection (GI) agent on each machine from which contextual attributes need to be captured. In addition to executing one or more machines on each host computer, these embodiments also execute a context engine and one or more attribute-based service engines on each host computer. One of these service engines is a firewall engine. Through the GI agents of the machines on a host, the context engine of that host in some embodiments collects contextual attributes associated with network events and/or process events on the machines. The context engine then provides the contextual attributes to the firewall engine, which, in turn, use these contextual attributes to identify firewall rules to enforce.
机译:本发明的一些实施例提供了一种新颖的体系结构,用于在执行一个或多个机器的主机计算机上捕获上下文属性,并使用所捕获的上下文属性来在主机计算机上执行服务。在一些实施例中,机器是虚拟机(VM),在其他实施例中,机器是容器,或者在其他实施例中,机器是VM和容器的混合。一些实施例在每台机器上执行客户自检(GI)代理,需要从中捕获上下文属性。除了在每个主机上执行一个或多个机器之外,这些实施例还在每个主机上执行上下文引擎和一个或多个基于属性的服务引擎。这些服务引擎之一是防火墙引擎。通过主机上机器的GI代理,在一些实施例中,该主​​机的上下文引擎收集与机器上的网络事件和/或过程事件相关联的上下文属性。然后,上下文引擎将上下文属性提供给防火墙引擎,防火墙引擎又使用这些上下文属性来标识要实施的防火墙规则。

著录项

  • 公开/公告号US2018183761A1

    专利类型

  • 公开/公告日2018-06-28

    原文格式PDF

  • 申请/专利权人 NICIRA INC.;

    申请/专利号US201715847908

  • 申请日2017-12-19

  • 分类号H04L29/06;G06F9/455;

  • 国家 US

  • 入库时间 2022-08-21 12:58:10

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号