发明名称 |
CONTEXT-AWARE DISTRIBUTED FIREWALL |
摘要 |
A context-aware distributed firewall scheme is provided. A firewall engine tasked to provide firewall protection for a set of network addresses applies a reduced set of firewall rules that are relevant to the set of addresses associated with the machine. A hypervisor implements a search structure that allows each virtual machine's filter to quickly identify relevant rules from all of the received rules. The search structure is constructed as a binary prefix tree, each node corresponding to an IP CIDR (Classless Inter-Domain Routing) block. A query for relevant rules traverses nodes of the search structure according to a queried IP address and collect all rules that are associated with the traversed nodes. |
申请公布号 |
WO2016089441(A1) |
申请公布日期 |
2016.06.09 |
申请号 |
WO2015US27632 |
申请日期 |
2015.04.24 |
申请人 |
NICIRA, INC. |
发明人 |
ZHOU, JINGMIN;SENGUPTA, ANIRBAN |
分类号 |
H04L29/06;G06F9/455 |
主分类号 |
H04L29/06 |
代理机构 |
|
代理人 |
|
主权项 |
|
地址 |
|