Managing Edge Network Protection Services
A computing system simplifies the management of edge network protection services by automatically configuring or reconfiguring them based on customer requests, addressing the complexity and expertise gap for small businesses, ensuring secure access control.
Patent Information
- Application Number
- JP2025541699
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-01-26
- Filing Date
- 2023-12-14
- Publication Date
- 2026-01-29
AI Technical Summary
Small businesses lack the technical expertise to configure edge network protection services and manage unauthorized access to prohibited websites, and the provisioning process is complicated, especially when adding such services after subscribing to Internet service from different providers.
A computing system that automatically configures or reconfigures edge network protection services based on customer requests, allowing users to manage edge network protection services through a customer portal, including options to add, remove, or modify service parameters, even for standalone services from different providers.
Enables efficient management of edge network protection services, simplifying the provisioning process and ensuring secure access control for small businesses, regardless of the network service provider.
Smart Images

Figure 2026503480000001_ABST
Abstract
Description
[Technical Field]
[0001] [CROSS-REFERENCE TO RELATED APPLICATIONS] This application claims the benefit of U.S. Provisional Application No. 63 / 441,331, filed January 26, 2023, entitled "Managing Edge Network Protection Service," which is incorporated herein by reference in its entirety.
[0002] This application may be related to U.S. patent application Ser. No. 18 / 327,953 (the "'953 Application"), filed June 2, 2023, entitled "Efficient Provisioning of Internet Circuit and Secure Domain Name System," the disclosure of which is incorporated herein by reference in its entirety for all purposes.
[0003] The disclosures of each of these applications / patents (collectively referred to herein as the "related applications") are incorporated herein by reference in their entirety for all purposes.
[0004] [Copyright Notice] A portion of the disclosure of this patent document contains material that is subject to copyright protection. The copyright owner has no objection to the exact facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent file or records, but otherwise reserves all copyrights whatsoever.
[0005] The present disclosure relates generally to methods, systems, and apparatus for implementing network provisioning and management functions, and more particularly to methods, systems, and apparatus for implementing management of edge network protection services. [Background technology]
[0006] Many small businesses rely on computing and access to the Internet to compete in the modern marketplace. In addition, protection from unauthorized or inadvertent access to prohibited websites from the company's network is desired. However, many small business owners lack the technical expertise to configure equipment or securely control employees' online activity. Some small business owners also desire to add edge network protection services after already subscribing to Internet service, whether from the same network service provider or a different network service provider. However, the process of provisioning such services can be complicated, especially for such standalone services. Management of such services is also traditionally unavailable to business owners.
[0007] It is with respect to this general technological environment that aspects of the present disclosure are directed. [Brief explanation of the drawings]
[0008] A further understanding of the nature and advantages of particular embodiments may be realized by reference to the remaining portions of the specification and drawings, in which like reference numerals are used to refer to like components. In some instances, a sublabel is associated with a reference numeral to indicate one of multiple similar components. When a reference numeral is referenced without designation to an existing sublabel, it is intended to refer to all such multiple similar components. To indicate multiple components, the suffix "a" through "n" is used, where n indicates any suitable integer and may be either the same or different from the suffix "n" for other components in the same or different figures. For example, for component #1 105a through 105n, the integer value of n in 105n may be the same as or different from the integer value of n in 110n for component #2 110a through 110n, and so on.
[0009] [Figure 1] FIG. 1 is a schematic diagram illustrating a system for implementing management of edge network protection services, according to various embodiments.
[0010] [Figure 2] FIG. 2 is a schematic diagram illustrating a non-limiting example of the provider configuration system of FIG. 1, according to various embodiments.
[0011] [Figure 3] FIG. 2 is a schematic diagram illustrating a non-limiting example of the DNS firewall system of FIG. 1, according to various embodiments.
[0012] [Figure 4A] FIG. 1 is a flow diagram illustrating a method for implementing management of edge network protection services, according to various embodiments. [Figure 4B] FIG. 1 is a flow diagram illustrating a method for implementing management of edge network protection services, according to various embodiments. [Figure 4C] FIG. 1 is a flow diagram illustrating a method for implementing management of edge network protection services, according to various embodiments.
[0013] [Figure 5] FIG. 1 is a block diagram illustrating an example computing environment in which the systems and methods of the present application may be implemented, according to various embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0014] [Summary]
[0015] Various embodiments provide tools and techniques for implementing network provisioning and management functions, and more particularly, methods, systems, and apparatus for implementing management of edge network protection services.
[0016] In various embodiments, a computing system may receive a request from a customer to manage edge network protection services for at least one Internet line, the request including customer information. The computing system may determine, based at least in part on the customer information, whether the customer is already provisioned with any lines capable of implementing edge network protection services. Based on a determination that the customer is provisioned with one or more lines capable of implementing edge network protection services, the computing system may present an option to select one line from the one or more lines for which edge network protection services should be provisioned or managed. When a selection of a first circuit from the one or more circuits is received from the customer, one of the following may be performed: based on a determination that a service instance of the edge network protection service is not provisioned on the selected first circuit, the computing system may automatically configure the selected first circuit to provision the first service instance of the edge network protection service; or based on a determination that the first service instance of the edge network protection service is already provisioned on the selected first circuit, the computing system may automatically reconfigure the selected first circuit to modify the first service instance of the edge network protection service.
[0017] In another aspect, a system may include a computing system having at least one first processor and a first non-transitory computer-readable medium communicatively coupled to the at least one first processor, the first non-transitory computer-readable medium, when executed by the at least one first processor, causing the computing system to: receive a request from a customer to manage edge network protection service for at least one Internet line, the request including customer information; determine, based at least in part on the customer information, whether the customer is already provisioned with any lines capable of implementing edge network protection service; and present, based on a determination that the customer is provisioned with one or more lines capable of implementing edge network protection service, an option to select one line from the one or more lines for which edge network protection service should be provisioned or managed; and when a selection of a first circuit from the one or more circuits is received from the customer, automatically configuring the selected first circuit to provision a first service instance of the edge network protection service based on a determination that a service instance of the edge network protection service has not been provisioned on the selected first circuit; or automatically reconfiguring the selected first circuit to modify the first service instance of the edge network protection service based on a determination that the first service instance of the edge network protection service has already been provisioned on the selected first circuit.
[0018] In yet another aspect, a computing system may receive a request from a customer to manage edge network protection service for at least one Internet line, the request including customer information. The computing system may determine whether the customer is already provisioned with any lines capable of implementing edge network protection service based at least in part on the customer information. Based on a determination that the customer is provisioned with one or more lines capable of implementing edge network protection service, the computing system may present an option to select one line from the one or more lines for which edge network protection service should be provisioned or managed. Upon receiving a selection of a first line from the one or more lines from the customer, the computing system may automatically configure the selected first line to provision a first service instance of the edge network protection service.
[0019] Various embodiments provide edge network protection services that can be ordered or managed by a user or customer via a customer portal, for example, to add, remove, or modify service parameters, even in the case of standalone services (e.g., edge network protection services ordered after Internet service has already been provisioned, or edge network protection services from a network service provider different from the network service provider that has already provisioned the user with Internet service, or the like).
[0020] These and other aspects of edge network protection service management are described in more detail with respect to the figures.
[0021] The following detailed description sets forth some exemplary embodiments in greater detail to enable those skilled in the art to practice such embodiments. The described examples are provided for illustrative purposes and are not intended to limit the scope of the invention.
[0022] In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of the described embodiments. However, it will be apparent to those skilled in the art that other embodiments of the present invention may be practiced without some of these specific details. In other instances, certain structures and devices are shown in block diagram form. While several embodiments are described herein and various features are attributed to different embodiments, it should be recognized that features described with respect to one embodiment may also be incorporated into other embodiments. Similarly, however, no single feature or features of any described embodiment should be construed as essential to every embodiment of the present invention, as other embodiments of the present invention may omit such features.
[0023] Unless otherwise indicated, all numbers used herein to express quantities, dimensions, and similar uses should be understood as modified in all instances by the term "about." In this application, the use of the singular includes the plural unless specifically stated otherwise, and the use of the terms "and" and "or" means "and / or" unless specifically stated otherwise. Furthermore, the use of the term "including" and other forms such as "includes" and "included" should be considered non-exclusive. Also, terms such as "element" or "component" encompass both elements and components comprising one unit and elements and components comprising more than one unit, unless specifically stated otherwise.
[0024] Various modifications and additions can be made to the embodiments discussed without departing from the scope of the invention. For example, while the embodiments described above refer to particular features, the scope of the invention also includes embodiments having different combinations of features and embodiments that do not include all of the features described above.
[0025] Specific Exemplary Embodiments
[0026] Reference will now be made to the embodiments as illustrated by the drawings. Figures 1-5 illustrate some of the features of methods, systems, and apparatus for implementing network provisioning and management functions, and more particularly, methods, systems, and apparatus for implementing management of edge network protection services, as referenced above. The methods, systems, and apparatus illustrated by Figures 1-5 refer to examples of different embodiments that include various components and steps that may be considered alternatives or may be used in combination with one another in various embodiments. The descriptions of the illustrated methods, systems, and apparatus shown in Figures 1-5 are provided for illustrative purposes and should not be considered to limit the scope of different embodiments.
[0027] Furthermore, the following detailed description refers to the accompanying drawings, which form a part hereof, and in which specific embodiments or examples are shown by way of illustration. These aspects may be combined, other aspects may be utilized, and structural changes may be made without departing from the disclosure. The examples may be embodied as methods, systems, or devices. Thus, the examples may take the form of a hardware implementation, an entirely software implementation, or an implementation combining software and hardware aspects. Additionally, all systems described with reference to the figures may include one or more machines or devices operatively connected to cooperate to provide the described system functionality. Therefore, the following detailed description is not to be taken in a limiting sense, and the scope of the present disclosure is defined by the appended claims and their equivalents.
[0028] Referring now to the drawings, FIG. 1 is a schematic diagram illustrating a system 100 for implementing management of edge network protection services, according to various embodiments.
[0029] As shown in the non-limiting example of Figure 1, provider configuration system 102 may be provided by an Internet service provider or other network provider to enable a customer to arrange network connectivity (e.g., Internet line 103 between customer network 104 and provider edge router 105 on network 101 to allow customer devices 106 operating on or connected to customer network 104 to access a wide area network such as the Internet 109). It will be understood that all connections between systems depicted with respect to Figure 1 may be wired or wireless and may involve various intervening devices and systems.
[0030] The provider configuration system 102 may provide a customer portal including a user interface to enable Internet connectivity to be ordered by and subsequently provisioned for a customer. For example, the provider configuration system 102 may be operatively connected to one or more customer devices 106 (e.g., through a third-party wired or wireless connection prior to the customer Internet line 103 being provisioned). In an example, after the customer Internet line 103 is provisioned, the same or different customer devices 106 may connect to the Internet 109 through the customer network 104, the customer Internet line 103, and the provider edge router 105. In an example, the customer network 104 includes at least one device referred to as customer premises equipment (“CPE”) 107. In an example, CPE 107 may include a network address translation ("NAT") device (or a router with NAT capabilities) that assigns Internet protocol ("IP") addresses to customer devices 106 on customer network 104 and routes messages into and out of customer network 104.
[0031] In an example, provider network 101 may provide a domain name system (“DNS”) firewall system 108. In an example, DNS firewall system 108 may provide DNS firewall services to filter DNS requests from customer networks, such as customer network 104. DNS firewall system 108 may allow or deny customer devices 106 access to particular internet sites (or other network locations). For example, DNS firewall system 108 may maintain customizable configurations for multiple customers (each customer is a tenant of DNS firewall system 108). The configurations may include customer-specific instructions related to categories of internet sites, such as social media, news, sports, entertainment, etc. For example, a first customer may allow customer devices connected to its network to access social media sites, while another customer may choose to prohibit such access from its customer network.
[0032] When a customer device attempts to access the Internet 109 via Internet line 103, a browser on the customer device may issue a DNS request to resolve a domain name (e.g., www.example.com) to a specific IP address so that the desired site can be reached. When DNS firewall system 108 receives a DNS request from customer network 104 to resolve a specific domain name to an IP address, the DNS firewall system may first determine a category for the specific domain name, determine whether that category of domain is permitted to be accessed by that customer network, and either allow the request to be resolved (e.g., by returning an IP address for the domain) or deny the request (if the domain is in a prohibited category for that customer network). DNS firewall system 108 may also be operatively connected to a threat intelligence system 110 and / or one or more separate DNS systems 111, as discussed further herein.
[0033] A non-exhaustive example of a provider configuration system 102 is depicted in Figure 2. In an example provider configuration system 102, an ordering system 202, a customer information system 204, a line information system 206, and a configuration system 208 may be provided. As discussed, any of the systems of the provider configuration system 102 may be combined or distributed across one or many physical devices operably connected by wired or wireless connections in a combined software and hardware implementation.
[0034] In an example, the ordering system 202 may include a customer portal that allows customers of the network 101 to order particular products and services. For example, the ordering system 202 may provide one or more user interfaces for display on a device (such as the customer device 106). In an example, the customer may provide (through such user interfaces) customer information such as the customer's name, the customer's physical location, whether the customer is providing their own customer premises equipment 107 or whether it needs to be delivered to the customer as part of the ordered service, etc. Among other things, the ordering system 202 may collect information needed from the customer to provision a new Internet line 103 between the provider edge router 105 of the network 101 and the customer network 104 (including the CPE 107).
[0035] The customer information system 204 may include one or more data stores that store customer information, such as customer information received through the ordering system 202. In some examples, the customer information stored in the customer information system 204 may be received or retrieved from other computing systems of the provider. For example, if a customer is using the ordering system 202 to order an Internet line 103 from a provider, the customer may already be a customer of other products / services of that provider, and information about the customer may already be stored in or accessible to the customer information system 204. For example, the customer may already have an Internet line but may be ordering an additional Internet line 103. In this case, the ordering system may retrieve the customer information from the customer information system 204 as part of the ordering process for the new Internet line 103 (e.g., based on a previously stored account identifier).
[0036] Circuit information system 206 may be configured to store or retrieve from one or more other network systems information about network 101, including, in examples, existing Internet circuits, available ports on provider edge routers 105, available IP address space for allocation to new Internet circuits 103, etc. Circuit information system 206 may be used by ordering system 202 to provide information regarding the closest available provider edge router 105 for a particular customer (e.g., based on customer information received through ordering system 202). Circuit information system 206 may cooperate with configuration system 208, as described below.
[0037] The configuration system 208, in an example, may cause services ordered through the ordering system 202 to be provisioned within the network 101. For example, when the ordering system 202 receives a request from a customer for a new Internet line 103, the configuration system 208 may cooperate with the line information system 206 to determine the most advantageous way to provision the new Internet line 103. For example, the configuration system 208, in an example, may identify one or more available ports on an existing provider edge router 105 for the new Internet line 103. In another example, the configuration system 208 may determine that a new provider edge router 105 should be added to the network 101 (either at a new location or an existing location) to accommodate the new Internet line 103. The configuration system 208 may initiate one or more workflows to have a technician design or implement the new Internet line 103. The configuration system 208 may allocate IP address space to the new Internet line 103 (e.g., assign a first IP address in the allocated IP address space to the CPE 107 and a second IP address in the allocated IP address space to the provider edge router 105). In an example, the configuration system 208 may automatically configure the provider edge router 105 to advertise an IP address in the allocated IP address space.
[0038] In some examples, the configuration system 208 may automatically configure the CPE 107. In some examples, the provider of the network 101 also provides the CPE 107 to the customer, and the CPE's identification information (e.g., device type, MAC address, etc.) may be assigned by the configuration system 208 and stored in the customer information system 204. For example, if the provider of the network 101 also provides the customer CPE 107 as part of an order for a new Internet line 103, the CPE 107 may be pre-configured to "call home" to the configuration system 208 to receive configuration information. The configuration information provided to the CPE 107 may include, for example, one or more IP addresses for the CPE 107. The configuration information may include one or more IP addresses for one or more provider edge routers 105 that the CPE 107 will use to route outgoing traffic from the customer network 104 to the network 101. In some examples, the configuration information is stored by the customer information system 204 and / or the line information system 206.
[0039] As discussed, using the ordering system 202, a customer may order a new Internet line 103. The ordering system 202 may be available to automated processes through an application programming interface (“API”). In some examples, the ordering system 202 may provide the customer with a simple option to order DNS firewall service for the new Internet line 103. For example, in the same user interface used to order the Internet line 103 (e.g., a checkbox or other selectable option on the same web page presented to the customer, or a series of related web pages presented to the user, before the order is submitted or an equivalent action is performed through the API-based ordering system), the customer may be allowed to optionally add DNS firewall service. In an example, the DNS firewall service (e.g., provided by the DNS firewall system 108) allows the customer to restrict the domains that the customer device 106 is allowed to access from the customer network 104.
[0040] In an example, combining the process for ordering and provisioning a new Internet line 103 and the DNS firewall system 108 for that line allows efficiencies and functionality not possible using separate ordering / provisioning processes. As a non-exhaustive example, the configuration system 208 may automatically configure the CPE 107 to direct DNS requests from the customer device 106 to the DNS firewall system 108. For example, the CPE 107 may automatically configure the DNS firewall system IP address configuration (e.g., using Dynamic Host Configuration Protocol (DHP)). Protocol: "DHCP" configuration settings) to individual customer devices 106, which will then use the DNS firewall system 108 for DNS resolution. In particular, the CPE 107 may be automatically and remotely configured by the configuration system 208 (e.g., when the CPE 107 "calls home" to receive configuration information) to configure DNS settings in its DHCP configuration, which is then used by the customer device 106 to obtain IP addresses advertised by the DNS firewall system 108. In some examples, remote configuration of the CPE 107 may be achieved by sending a configuration from the configuration system 208 to the CPE 107 using an executable configuration script. The executable configuration script may be specific to the type of device (e.g., manufacturer, model, etc.) that includes the CPE 107, and it may be operable to configure the CPE 107 to apply the correct DNS firewall system IP address configuration to the customer device 106.In some examples, the CPE 107 may be configured by the configuration system 208 to allow DNS requests from the customer device 106 only if such requests are directed to the DNS firewall system 108 for DNS resolution, thereby reducing the risk of some of the techniques used by users of the customer device 106 or malicious actors to circumvent the use of the DNS firewall system 108 for DNS resolution.
[0041] The configuration system 208 may also communicate with the DNS firewall system 108 to automatically configure the customer as a new tenant of the DNS firewall service and alert the DNS firewall system 108 that DNS requests from the IP address space assigned to the new Internet connection 103 should be filtered using the DNS firewall service. In some examples, the configuration system 208 does not directly configure the CPE 107 to direct all DNS requests from the customer devices 106 to the DNS firewall system 108, but instead initiates an automated process in the DNS firewall system 108 to communicate with the CPE 107 to cause such configuration to occur. In other examples, the CPE 107 may not be managed by the provider of the network 101. Thus, the configuration system 208 may instead cause a notification to be sent to the customer with instructions on how to configure the CPE 107 to direct all DNS requests from the customer devices 106 to the DNS firewall system 108.
[0042] An example DNS firewall system 108 (used to provide DNS firewall services) is described with respect to FIG. 3. In some examples, the DNS firewall system is co-located with the provider edge router 105, for example, at an edge computing site of the network 101. In an example, the DNS firewall system may include a filter system 302, a tenant data system 304, a category information system 306, and a DNS server 308. The filter system 302 may be configured, for example, to reject DNS requests that are directed to domains that are not authorized to be accessed by the customer device 106 on the customer network 104. In an example, rejecting the DNS request may include dropping the request (not resolving the domain in the request to an IP address) and returning a notification to the customer device 106 (through the CPE 107) indicating that the domain sought to be reached by the customer device 106 is not authorized according to the rules of the customer network 104. In another example, rejecting the DNS request may include resolving the domain to an IP address for a site that displays such a notification, rather than for the requested site.
[0043] The tenant data system 304 may store or be configured to retrieve from one or more other network systems tenant information regarding tenants of the DNS firewall system 108. In an example, the tenant information may include portions of customer information received from the provider configuration system 102 when a new Internet line 103 is ordered with DNS firewall service. For example, the tenant information stored (or retrievable) by the tenant data system 304 may include the customer name and location, customer contact information, the type of equipment including CPE 107, and the IP address space assigned to the Internet line 103 for that customer and for which the DNS firewall service has been subscribed. The tenant data may also include tenant configuration information for a particular customer regarding domains (or categories of domains) for which DNS requests should be denied (or allowed) by the filter system 302.
[0044] In some examples, the tenant data system 304 receives a request from the provider configuration system 102 when a new Internet line 103 is ordered along with DNS firewall service for that line. In examples, the tenant data system 304 automatically extracts customer information from the received request and automatically provisions the customer as a new tenant (if the customer is not already a tenant of the DNS firewall system 108). In examples, the request from the provider configuration system 102 may include IP address space associated with the new Internet line. The tenant data system 304, in examples, stores the IP address space in association with the newly created tenant (based on the customer information) or with previously stored tenant information (if the customer is already a tenant).
[0045] In addition, the request from the provider configuration system 102 also causes the tenant data system 304 to initiate a configuration process for the DNS firewall service. For example, the tenant data system 304 may use customer contact information included in the request from the provider configuration system to send a message (e.g., an email) to initiate a process in which the customer selects categories of domains for which DNS requests will be rejected by the filter system 302. In an example, the tenant data system 304 will provide a user interface (e.g., selectable via a link in an email to the customer) to turn filtering on or off for particular categories of domains. In another example, such a link may direct the customer to a portal in a control center associated with the DNS firewall system 108. In another example, the customer may separately navigate to such a control center to customize the DNS firewall service configuration. In another example, the customer may utilize an API associated with the DNS firewall system 108 to customize the DNS firewall service configuration. In examples, tenant data system 304 provides a default selection (e.g., based on the preferences of a majority of other DNS firewall service tenants, or otherwise) and will use the default selection in the absence of other instructions from the customer. In some examples, all customers are provided with such a default selection as a starting point in the user interface of tenant data system 304, and the customer can then customize their specific selection for filtering. The user interface presented by tenant data system 304, in examples, may allow a customer to specifically designate particular domains on an access allow list and an access deny list, each of which may override decisions that would otherwise be made on category information. Tenant configuration data stored in tenant data system 304 may specify domains or categories of domains for which DNS requests should be filtered (or allowed).Tenant configuration data may apply for all Internet lines of a tenant, or in other examples, tenant configuration data may be specific to a particular Internet line of a tenant, a group of end users, or an individual end user of a tenant.
[0046] In an example, the filter system 302 and the tenant data system 304 may cooperate with a category information system 306, which may store current information about domain categories or may be configured to retrieve information from one or more other network systems. For example, the category information system 306 may store a list of known domain names and associate one or more categories with such domain names. For example, the domain "example1.com" may be categorized in the category information system 306 as a social media site, while another domain "example2.com" may be categorized as a video streaming site. In some instances, a particular domain may be associated with multiple categories.
[0047] The category information system 306 may receive (or retrieve) data from third-party services and may be continually updated as new sites are added or discovered. In an example, the category information system 306 may communicate with the threat intelligence system 110. The threat intelligence system 110 may maintain a list of known malicious sites. Such a list may be used separately by the threat intelligence system 110 (e.g., in combination with other network elements of a threat mitigation system) to mitigate the impact of such sites (e.g., by dropping any packets received from source IP addresses associated with such sites). The threat intelligence system 110 may provide its own list of known malicious sites to the category information system 306. If the threat intelligence system 110 identifies a particular domain as participating in malicious activity on the network 101, the category information system 306 may create a category of known malicious domains and associate the domain so identified by the threat intelligence system 110 with that category. The tenant data system 304 may store configuration data that, by default, selects categories of known malicious domains for filtering out (or rejection) by the filter system 302. In some examples, the known malicious domain categories are not deselectable for filtering by customers through a user interface presented by the tenant data system 304. However, as discussed, in some examples, customers may specifically add particular domains to the access permission list (overriding any category determination). In some examples, the tenant data system 304 and / or the category information system 306 may cooperate to alert the threat intelligence system 110 if a certain number or percentage of customers have added domains that appear to be in the known malicious domain category to the access permission list.In some examples, this allows threat intelligence system 110 (via automation or its administrator) to review the site and determine whether it should remain on the known malicious domain list in threat intelligence system 110. In other examples, DNS firewall system 108 may communicate other filtering information to threat intelligence system 110, such as if a certain number or percentage of tenants have added the domain to their access-denied list, log information indicating how often DNS requests are denied (and information about the specific domains or categories for which DNS requests are denied), etc.
[0048] In some examples, the DNS firewall system 108 may include a DNS server 308. For example, the DNS server 308 may operate as a DNS recurser, communicating with DNS root servers, top-level domain servers, and / or authoritative name servers (and associated caches or other devices) to resolve any DNS requests that are not filtered out by the filter system 302. As an example, if a DNS request resolving "www.example.com" is received by the DNS firewall system from the CPE 107 through the provider edge router 105, the filter system 302 may extract the domain (i.e., "example.com") from the DNS request and query the category information system 304 for all of the categories with which "example.com" is associated. The filter system 302 may query the tenant information system to determine (a) whether the IP address space from which the DNS request was received is currently associated with a tenant of the DNS firewall service; and (b) if so, whether the tenant information indicates that domains for any of the identified categories are subject to filtering for the identified tenant. If filter system 302 determines that a DNS request should not be filtered (or rejected), it may pass the request to DNS server 308 for resolution to an IP address for the requested domain. In other examples, DNS firewall system 108 does not include a dedicated DNS server, and filter system 302 may pass any DNS requests that are not rejected to a separate DNS server 111.
[0049] Additionally, in some examples, CPE 107 may be configured to send DNS requests to DNS firewall system 108, but the customer may eventually discontinue the DNS firewall service for a particular Internet line 103. In some examples, tenant data system 304 may communicate with configuration system 208 to automatically reconfigure CPE 107 to address outgoing DNS requests to an IP address that is not associated with DNS firewall system 108. However, in other examples, CPE 107 may not be automatically (or otherwise) reconfigured and may continue to send DNS requests to DNS firewall system 108. In some examples, filter system 302 may (a) receive the request; (b) determine that Internet line 103 is no longer associated with a tenant of the DNS firewall service; and (c) either reject the DNS request or forward the request to a different DNS server, such as DNS server 111. In some examples, filter system 302 may notify the customer that DNS requests are being rejected and that CPE 107 needs to be reconfigured to address DNS requests elsewhere. In some examples, filter system 302 may forward such DNS requests to DNS server 111 only for a specified period of time after termination of DNS firewall service for Internet line 103, after which time such DNS requests may be dropped. In some examples, the customer notification may include the amount of time remaining before such DNS requests will begin to be rejected without CPE 107 being reconfigured to address DNS requests to a different DNS server (such as DNS server 111).
[0050] 1 , a control center ordering system 112 and an inventory system 113 may also be provided in network 101. In some embodiments, system 100 may further be provided to enable customers to order or manage edge network protection services. For example, in operation, provider configuration system 102, DNS firewall system 108, and / or DNS system 111 (each and / or collectively a “computing system” or the like) may present or cause to be presented a platform for ordering or managing edge network protection services. The computing system may receive a request from a customer (e.g., via customer device 106, or the like) to manage edge network protection services for at least one Internet line (e.g., Internet line 103, or the like), the request including customer information (such as customer information as described above, including order and service history, or the like). The computing system may determine whether the customer has already been provisioned with any circuits capable of implementing edge network protection services based at least in part on the customer information, and in some cases by querying records of provisioned circuits such as stored in inventory system 113 or the like. Based on a determination that the customer has been provisioned with one or more circuits (among circuits 103 or the like) capable of implementing edge network protection services, the computing system may present, or cause to be presented, an option to select, from among the one or more circuits, a circuit for which edge network protection services should be provisioned or managed.Upon receiving a selection of a first circuit from the one or more circuits from the customer, the computing system may perform one of: automatically configuring the selected first circuit (e.g., via the provider configuration system 102, or the like) to provision the first service instance of the edge network protection service based on a determination that a service instance of the edge network protection service has not been provisioned on the selected first circuit; or automatically reconfiguring the selected first circuit to modify the first service instance of the edge network protection service based on a determination that the first service instance of the edge network protection service has already been provisioned on the selected first circuit.
[0051] According to some embodiments, presenting or causing to be presented an option to select one or more lines for which edge network protection services should be provisioned or managed may include presenting or causing to be presented an option in one of a user interface (“UI”), software application (“app”), or control portal for the customer to select one or more lines for which edge network protection services should be provisioned or managed. In examples, the computing system may do at least one of: expose a first API to allow programmatic ordering of new edge network protection services, thereby providing programmatic access to an ordering system (e.g., control center ordering system 112 and / or ordering system 202 of provider configuration system 102, or the like) via the first API; expose a second API to allow programmatic management of edge network protection services, thereby providing programmatic access to the provider configuration system via the second API; present a first UI, where the first UI provides user-selectable options for customers to order new edge network protection services; or present a second UI, where the second UI provides user-selectable options for customers to manage edge network protection services; and / or the like.Alternatively, or in addition, the computing system may further perform at least one of: presenting or causing to be presented options for additional security controls for utilizing DNS functionality (e.g., DNS firewall system 108 and / or DNS system 111, or the like); presenting or causing to be presented options for additional threat intelligence functionality for the DNS firewall system (e.g., DNS firewall system 108, or the like); or presenting or causing to be presented options for specific configurations for the DNS firewall system; and / or the like.
[0052] In some embodiments, the selected first circuit may be configured to provision a service instance of the edge network protection service. In such a case, the computing system may create a first edge protection tenant in a control portal (similar to a tenant created for the DNS firewall system 108 as described above, where the tenant information is similarly stored in or retrievable by the tenant data system 304 or the like); and associate the created first edge protection tenant with at least one of the first service instance of the edge network protection service or the IP address space assigned to the selected first circuit. In some instances, the control portal may be accessible by the customer via a single sign-on (“SSO”) feature (similar to a customer portal of the provider configuration system 102 as described above, or the like). In some examples, the computing system may apply distributed denial of service (“DDoS”) protection to destination IP addresses specified on the selected first circuit based on the provisioned first service instance of the edge network protection service. In some examples, the computing system may add a first service instance of an edge network protection service to a first edge protection tenant.
[0053] According to some embodiments, based on the customer's selection of configuring at least one new second circuit from among the one or more circuits, the computing system may determine a first number of circuits the customer has already configured from the total number of circuits ordered by the customer and may update the number of entitlements (e.g., the number of services not yet provisioned from among the ordered services, or the like) to which the customer is assigned based on the determined first number of circuits. In some cases, based on a determination that a third circuit has been selected from among the one or more circuits and already configured or ordered, the computing system may cause the ordering system to communicate with the provider configuration system to perform at least one of incrementing the first number of circuits or decrementing the updated number of entitlements. In some examples, when an instruction is received from the customer to select a fourth circuit from among the one or more circuits to delete a service instance of an edge network protection service, the computing system may cause the provider configuration system to perform at least one of decrementing the first number of circuits or incrementing the updated number of entitlements.
[0054] In some embodiments, the network may include a first network associated with a first network service provider. In such cases, the computing system may present or cause to be presented an option to select at least one third-party line over which edge network protection services should be provisioned or managed, the at least one third-party line being operated and provisioned by a second network service provider different from the first network service provider. The computing system may also present or cause to be presented an option to enter line information for the at least one third-party line.
[0055] According to some embodiments, when a user requests to add an edge network protection service instance, the computing system may query inventory (e.g., inventory system 113, or the like) or a copy of the actual network configuration of eligible Internet services. The user may select the Internet service to which the edge network protection service is to be applied. The computing system may query assigned IP address information for the selected Internet service (or circuit), or may present or have presented IP address blocks associated with the circuit. The user may select an IP address range from the presented list to be associated with the edge network protection service. In some cases, the computing system may ensure that the selected IP address range does not exceed a defined service limit (e.g., the number of available IP addresses in a subnet, such as a / 27 subnet, or the like). In cases where the computing system does not have access to the IP address space associated with the selected Internet service, the user may be presented with a UI option to manually associate an IP address with the Internet service. The computing system may similarly ensure that a manually entered IP address range does not exceed the defined service limit.
[0056] In some embodiments, a user requests to add an edge network protection service to a standalone Internet service (either a first network service provider or a second network service provider, or the like). In this case, the inventory system may not be able to successfully find the desired Internet service to associate the requested edge network protection service with. The user may be presented with a UI option to manually associate an IP address with the standalone Internet service. In some cases, the user may be allowed to add a friendly name for the standalone Internet service. In some instances, the computing system may ensure that a manually entered IP address range (as described above) does not exceed a defined service limit. Once the user selects an existing or standalone Internet service and completes IP address space selection and / or provides IP address space (similar to the case of a standalone Internet service, as described above), the user may click a UI button to submit a request to provision an edge network protection service for that Internet service. This may result in the following actions: the selected IP address space may be associated with the edge protection tenant; the rights to configure a service instance of the edge network protection service in the app may be adjusted (e.g., decreased by one); the user may be notified regarding the progress of the provisioning request and completion of the provisioning process; and / or the user may be notified regarding the steps required to configure DNS configuration on their CPE.
[0057] In some examples, the computing system may configure a first CPE in the first circuit by performing one of: sending a service ticket to an agent of the first service provider to manually configure or update DNS parameters of the first CPE based at least in part on the first service instance of the edge network protection service; automatically configuring or updating DNS parameters of the first CPE based at least in part on the first service instance of the edge network protection service; automatically configuring or updating DNS parameters of the first CPE based at least in part on the first service instance of the edge network protection service by exposing the DNS parameters to the first CPE via a third API; or sending at least one first message to a customer having instructions to manually configure or update DNS parameters of the first CPE based at least in part on the first service instance of the edge network protection service; and / or the like.
[0058] According to some embodiments, the computing system may present or cause a user who configured an edge network protection service instance to be presented with an option to remove or delete such service instance, e.g., using a remove or delete service instance button in the UI, or the like. If the user selects to remove the edge network protection service instance, the UI may present or cause a dialog to be presented to the user in the UI to confirm the removal of the edge network protection service instance. In cases where the first network service provider is unable to perform the service instance removal on the user's behalf, the computing system may notify the user that they will need to reconfigure their DNS parameters to avoid any service interruption. If the user confirms the removal, the user may be notified regarding the required steps to reconfigure the DNS configuration on their CPE (e.g., by changing it to point to "regular DNS" instead of edge network protection service-based DNS, or the like).
[0059] In some examples, a computing system may receive a request to de-provision a second service instance of the edge network protection service from a fifth circuit from the one or more circuits. The computing system may configure a second CPE in the fifth circuit by performing one of: sending a service ticket to an agent of the first service provider to manually configure or update DNS parameters of the second CPE based at least in part on the de-provisioning of the second service instance of the edge network protection service; automatically configuring or updating DNS parameters of the second CPE based at least in part on the de-provisioning of the second service instance of the edge network protection service; automatically configuring or updating DNS parameters of the second CPE based at least in part on the de-provisioning of the second service instance of the edge network protection service by exposing the DNS parameters to the second CPE via a fourth API, by the computing system; or sending, by the computing system, at least one second message to the customer having instructions to manually configure or update DNS parameters of the second CPE based at least in part on the de-provisioning of the second service instance of the edge network protection service; and / or the like. The computing system may send at least one third message to the customer informing the customer regarding the progress of the de-provisioning of the second service instance.
[0060] 4A-4C (collectively, "FIG. 4") are flow diagrams illustrating a method 400 for implementing management of edge network protection services, according to various embodiments. Method 400 in FIG. 4A continues in FIG. 4B following the circular marker designated "A." In some examples, 400 in FIG. 4A continues in FIG. 4C following the circular marker designated "B."
[0061] While techniques and procedures are depicted and / or described in a particular order for illustrative purposes, it should be recognized that certain procedures may be rearranged and / or omitted within various embodiments. Moreover, while the method 400 illustrated by Figure 4 may be implemented by or in conjunction with (and, in some cases, is described below with respect to) the systems, examples, or embodiments 100, 200, and 300 (or components thereof) of Figures 1, 2, and 3, respectively, such methods may be implemented using any suitable hardware (or software) implementation. Similarly, while each of the systems, examples, or embodiments 100, 200, and 300 (or components thereof) of Figures 1, 2, and 3, respectively, can operate according to the method 400 illustrated by Figure 4 (e.g., by executing instructions embodied on a computer-readable medium), each of the systems, examples, or embodiments 100, 200, and 300 of Figures 1, 2, and 3 can also operate according to other modes of operation and / or perform other suitable procedures.
[0062] 4A, method 400 may include causing a computing system of the network to present a platform for ordering or managing edge network protection services, at block 405. In some embodiments, the computing system may include, without limitation, a provider configuration system, a control center ordering system, a server, a Domain Name System (“DNS”) computing system, a DNS firewall system, a cloud computing system, or a distributed computing system, and / or the like.
[0063] At block 410, method 400 may include receiving, by the computing system, a request from a customer to manage edge network protection service for at least one Internet line, the request including customer information. At block 415, method 400 may further include, by the computing system, determining whether the customer is already provisioned with any lines capable of implementing edge network protection service based at least in part on the customer information. Based on a determination that the customer is provisioned with one or more lines capable of implementing edge network protection service, method 400 may further include, by the computing system, presenting an option to select, from among the one or more lines, a line for which edge network protection service should be provisioned or managed (block 420).
[0064] According to some embodiments, presenting an option to select a circuit, from among the one or more circuits, for which edge network protection service should be provisioned or managed may include presenting an option in one of a user interface (“UI”), software application (“app”), or control portal for the customer to select a circuit, from among the one or more circuits, for which edge network protection service should be provisioned or managed. In examples, the computing system may do at least one of: exposing a first application programming interface (“API”) to allow programmatic ordering of new edge network protection services, thereby providing programmatic access to an ordering system via the first API; exposing a second API to allow programmatic management of edge network protection services, thereby providing programmatic access to a provider configuration system via the second API; presenting a first UI, where the first UI provides user-selectable options for the customer to order the new edge network protection service; or presenting a second UI, where the second UI provides user-selectable options for the customer to manage the edge network protection service; and / or the like. Alternatively, or in addition, the computing system may further perform at least one of: presenting options for additional security controls for utilizing Domain Name System (“DNS”) functionality; presenting options for additional threat intelligence functionality for a DNS firewall system; or presenting options for specific configurations for a DNS firewall system; and / or the like.
[0065] In block 425, method 400 may include, upon receiving a selection of a first line from the one or more lines from a customer, performing one of: automatically, by the computing system, configuring the selected first line to provision the first service instance of the edge network protection service based on a determination that a service instance of the edge network protection service has not been provisioned on the selected first line (block 425a); or automatically, by the computing system, reconfiguring the selected first line to modify the first service instance of the edge network protection service based on a determination that the first service instance of the edge network protection service has already been provisioned on the selected first line (block 425b).
[0066] In some examples, method 400 may continue from the process at block 425a or 425b to the process at block 430 in Figure 4B following the circular marker designated "A." In other examples, method 400 may continue from the process at block 425a or 425b to the process at block 455 in Figure 4C following the circular marker designated "B."
[0067] At block 430 in FIG. 4B (following the circular marker designated "A" in FIG. 4A ), method 400 continues by: transmitting, by the computing system, a service ticket to an agent of the first service provider for manually configuring or updating DNS parameters of the first CPE based at least in part on the first service instance of the edge network protection service (block 435); automatically configuring or updating, by the computing system, DNS parameters of the first CPE based at least in part on the first service instance of the edge network protection service (block 436); block 440); automatically configuring or updating, by the computing system, the DNS parameters of the first CPE based at least in part on the first service instance of the edge network protection service by exposing the DNS parameters to the first CPE via a third API (block 445); or sending, by the computing system, at least one first message to the customer having instructions to manually configure or update the DNS parameters of the first CPE based at least in part on the first service instance of the edge network protection service (block 450); and / or the like.
[0068] In some examples, at block 455 in FIG. 4C (following the circular marker designated "B" in FIG. 4A), method 400 may include receiving, by a computing system, a request to deprovision a second service instance of the edge network protection service from a fifth circuit from among the one or more circuits. At block 460, method 400 may include configuring, by the computing system, a second CPE in the fifth circuit by performing one of: sending, by the computing system, a service ticket to an agent of the first service provider to manually configure or update DNS parameters of the second CPE based at least in part on the deprovisioning of the second service instance of the edge network protection service (block 465); automatically configuring or updating, by the computing system, DNS parameters of the second CPE based at least in part on the deprovisioning of the second service instance of the edge network protection service (block 470); automatically configuring or updating, by the computing system, DNS parameters of the second CPE based at least in part on the deprovisioning of the second service instance of the edge network protection service by exposing the DNS parameters to the second CPE via a fourth API (block 475); or sending, by the computing system, at least one second message to the customer having instructions to manually configure or update DNS parameters of the second CPE based at least in part on the deprovisioning of the second service instance of the edge network protection service (block 480); and / or the like. At block 485, the method 400 may include sending, by the computing system, at least one third message to the customer informing the customer regarding the progress of the de-provisioning of the second service instance.
[0069] In some embodiments, the selected first circuit may be configured to provision a service instance of the edge network protection service. In such cases, the computing system may create a first edge protection tenant in a control portal; and associate the created first edge protection tenant with at least one of the first service instance of the edge network protection service or the Internet Protocol (“IP”) address space assigned to the selected first circuit. In some cases, the control portal may be accessible by the customer via a single sign-on (“SSO”) feature. In some examples, the computing system may apply distributed denial of service (“DDoS”) protection to destination IP addresses specified on the selected first circuit based on the provisioned first service instance of the edge network protection service. In some examples, the computing system may add the first service instance of the edge network protection service to the first edge protection tenant.
[0070] According to some embodiments, based on the customer's selection of configuring at least one new second circuit from among the one or more circuits, the computing system may determine a first number of circuits already configured by the customer from the total number of circuits ordered by the customer and may update the number of entitlements allocated to the customer based on the determined first number of circuits. In some cases, based on a determination that a third circuit has been selected and already configured or ordered from among the one or more circuits, the computing system may cause the ordering system to communicate with the provider configuration system to perform at least one of incrementing the first number of circuits or decrementing the updated number of entitlements. In some examples, when an instruction is received from the customer to select a fourth circuit from among the one or more circuits to delete a service instance of an edge network protection service, the computing system may cause the provider configuration system to perform at least one of decrementing the first number of circuits or incrementing the updated number of entitlements.
[0071] In some embodiments, the network may include a first network associated with a first network service provider. In such a case, the computing system may present an option to select at least one third-party line over which edge network protection services should be provisioned or managed, the at least one third-party line being operated and provisioned by a second network service provider different from the first network service provider. The computing system may also present an option to input line information for the at least one third-party line.
[0072] Example System and Hardware Implementation
[0073] FIG. 5 is a block diagram illustrating the physical components (i.e., hardware) of a computing device 500 with which examples of the present disclosure may be implemented. The computing device components described below may be suitable for a client device that embeds the provider configuration system 102, the DNS firewall system 108, or one or more of the other components of FIGS. 1-3. In a basic configuration, the computing device 500 may include at least one processing unit 502 and a system memory 504. The processing unit (e.g., a processor) may be referred to as a processing system. Depending on the configuration and type of computing device, the system memory 504 may include, but is not limited to, volatile storage (e.g., random access memory), non-volatile storage (e.g., read-only memory), flash memory, or any combination of such memory. The system memory 504 may include an operating system 505 and one or more program modules 506 suitable for executing software applications 550 to implement one or more of the systems described above with respect to FIGS. 1-3.
[0074] Operating system 505 may be suitable, for example, for controlling the operation of computing device 500. Additionally, aspects of the present invention may be implemented in combination with graphics libraries, other operating systems, or any other application programs and are not limited to any particular application or system. This basic configuration is illustrated in FIG. 5 by those components within dashed line 508. Computing device 500 may have additional features or functionality. For example, computing device 500 may include additional data storage devices (which may be removable and / or non-removable), such as, for example, magnetic disks, optical disks, tape, or the like. Such additional storage is illustrated in FIG. 5 by removable storage device 509 and non-removable storage device 510.
[0075] As mentioned above, several program modules and data files may be stored in the system memory 504. While executing on the processing unit 502, the program modules 506 may perform processes including, but not limited to, one or more of the method operations shown in Figures 4A-4C or described with respect to Figures 1-3, or the like. Other program modules may be used in accordance with examples of the invention and may include applications such as email and contact applications, word processing applications, spreadsheet applications, database applications, slide presentation applications, drawing or computer-aided application programs, etc.
[0076] Furthermore, examples of the present invention may be implemented in electrical circuits including discrete electronic elements, packaged or integrated electronic chips including logic gates, circuits utilizing a microprocessor, or a single chip including electronic elements or a microprocessor. For example, examples of the present invention may be implemented via a system-on-a-chip ("SOC") in which each or many of the components shown in FIG. 5 may be integrated into a single integrated circuit. Such an SOC device may include one or more processing units, graphics units, communications units, system virtualization units, and various application functions, all of which may be integrated (or "burned") onto a chip substrate as a single integrated circuit. When operating via an SOC, the functionality described herein, with respect to generating suggested queries, may be operated via application-specific logic integrated with other components of computing device 500 on a single integrated circuit (or chip). Examples of the present disclosure may also be implemented using other technologies capable of performing logical operations such as AND, OR, and NOT, including, for example, but not limited to, mechanical, optical, fluidic, and / or quantum technologies.
[0077] The computing device 500 may have one or more input devices 512, such as a keyboard, mouse, pen, sound input device, and / or touch input device, etc. Output devices 514, such as a display, speakers, and / or printer, etc., may also be included. The above-mentioned devices are examples, and others may be used. The computing device 500 may include one or more communication connections 516 that enable communication with other computing devices 518. Examples of suitable communication connections 516 include, but are not limited to, RF transmitter, receiver, and / or transceiver circuitry; universal serial bus (USB), parallel, and / or serial ports; and / or the like.
[0078] The term computer-readable medium, as used herein, may include computer storage media. Computer storage media may include volatile and nonvolatile, removable and non-removable media implemented in any method or technology for storage of information, such as computer-readable instructions, data structures, or program modules. System memory 504, removable storage device 509, and non-removable storage device 510 are all examples of computer storage media (i.e., memory storage, etc.). Computer storage media may include RAM, ROM, electrically erasable programmable read-only memory (“EEPROM”), flash memory or other memory technology, CD-ROM, digital versatile disk (“DVD”) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other article of manufacture that can be used to store information and that can be accessed by computing device 500. Any such computer storage media may be part of computing device 500. Computer storage media may be non-transitory and tangible and do not include a carrier wave or other propagated data signal.
[0079] Communication media may be embodied by computer-readable instructions, data structures, program modules, or other data in a modulated data signal, such as a carrier wave or other transport mechanism, and includes any information delivery media. The term "modulated data signal" may describe a signal that has one or more characteristics set or changed in such a manner as to encode information in the signal. By way of example, and not limitation, communication media may include wired media such as a wired network or direct-wired connection, and wireless media such as acoustic, radio frequency (RF), infrared and other wireless media.
[0080] Aspects of the present invention are described above with reference to block diagrams and / or operational illustrations of, for example, methods, systems, and computer program products according to aspects of the present invention. The functions / acts noted in the blocks may occur out of the order shown in any flowchart. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending on the functions / acts involved. Furthermore, as used herein and in the claims, the phrase "at least one of element A, element B, or element C" (or any suitable number of elements) is intended to convey any of element A, element B, element C, elements A and B, elements A and C, elements B and C, and / or elements A, B, and C (etc.).
[0081] The description and illustration of one or more aspects provided herein are not intended to limit or restrict the scope of the claimed disclosure in any way. The aspects, examples, and details provided herein are deemed sufficient to convey ownership and to enable others to make and use the best mode of the claimed disclosure. The claimed disclosure should not be construed as limited to any aspect, example, or detail provided herein. Various features (both structural and methodological), whether shown and described in combination or separately, are intended to be selectively rearranged, included, or omitted to produce embodiments with particular sets of features. Given the description and illustrations herein, those skilled in the art may conceive variations, modifications, and alternative embodiments that fall within the spirit of the broader aspects of the general inventive concepts embodied herein without departing from the broader scope of the claimed disclosure.
Claims
1. receiving, by a computing system of the network, a request from a customer to manage edge network protection services for at least one Internet line, wherein said request includes customer information; determining, by the computing system, whether the customer is already provisioned with any lines capable of implementing edge network protection services based at least in part on the customer information; based on a determination that the customer is provisioned with one or more lines capable of implementing edge network protection services, causing the computing system to present an option to select one line from the one or more lines over which edge network protection services should be provisioned or managed; and receiving a selection of a first line from the one or more lines from the customer; based on a determination that a service instance of the edge network protection service is not provisioned on the selected first circuit, automatically configuring the selected first circuit to provision a first service instance of the edge network protection service; or causing the computing system to automatically reconfigure the selected first circuit to modify the first service instance of the edge network protection service based on a determination that the first service instance of the edge network protection service has already been provisioned on the selected first circuit. performing one of the steps A method comprising:
2. 10. The method of claim 1, wherein the computing system comprises a provider configuration system, a control center ordering system, a server, a Domain Name System ("DNS") computing system, a DNS firewall system, a cloud computing system, or a distributed computing system.
3. 3. The method of claim 1 or 2, wherein presenting the option to select one of the one or more lines for which edge network protection services should be provisioned or managed comprises presenting the option in one of a user interface ("UI"), a software application ("app"), or a control portal for the customer to select one of the one or more lines for which edge network protection services should be provisioned or managed.
4. exposing, by the computing system, a first application programming interface ("API") to allow programmatic ordering of new edge network protection services, thereby providing programmatic access to an ordering system via the first API; exposing, by the computing system, a second API to allow programmatic management of edge network protection services, thereby providing programmatic access to a provider configuration system via the second API; causing the computing system to present a first UI, wherein the first UI provides user-selectable options for the customer to order a new edge network protection service; or causing the computing system to present a second UI, wherein the second UI provides user-selectable options for the customer to manage edge network protection services. The method of claim 3 , further comprising at least one of:
5. presenting, by the computing system, options for additional security controls for utilizing Domain Name System ("DNS") functionality; presenting, by the computing system, options for additional threat intelligence features for the DNS firewall system; or presenting, by the computing system, options for specific configurations for the DNS firewall system. The method of claim 1 or 2, further comprising at least one of:
6. adding, by the computing system, in response to adding a first domain to an access permission list and overriding any category determinations, the first domain to the access permission list while overriding any category determinations for the first domain; causing, by the computing system, at least one of a tenant data system or a category information system to alert a threat intelligence system if a certain number or percentage of customers add a second domain to an access permission list that appears to be on a known malicious domain list; In response to being alerted, causing the computing system to cause the threat intelligence system to review the second domain to determine whether it should remain on the known malicious domains list; or causing the computing system to cause at least one of the tenant data system or the category information system to alert the threat intelligence system if a certain percentage of tenants add a third domain to a denied access list; or logging, by the computing system, information indicating the frequency with which DNS requests are rejected, the information including the domains or categories for which DNS requests are rejected; The method of claim 1 or 2, further comprising at least one of:
7. The selected first circuit is configured to provision the service instance of the edge network protection service, and the method includes: causing the computing system to create a first edge protection tenant in a control portal; and associating, by the computing system, the created first edge protection tenant with at least one of the first service instance of the edge network protection service or an Internet Protocol ("IP") address space assigned to the selected first circuit. The method of claim 1 or 2, further comprising:
8. The method of claim 7 , wherein the control portal is accessible by the customer via a single sign-on ("SSO") feature.
9. applying distributed denial of service ("DDoS") protection to a specified destination IP address on the selected first line based on the provisioned first service instance of the edge network protection service. The method of claim 7 further comprising:
10. adding the first service instance of the edge network protection service to the first edge protection tenant; The method of claim 7 further comprising:
11. in response to receiving a DNS request from the customer after the edge network protection service for the customer is disconnected, based on a determination that the selected first circuit is no longer associated with the first edge protection tenant associated with the first service instance of the edge network protection service; rejecting, by the computing system, the DNS request; forwarding, by the computing system, the DNS request to a different server; forwarding, by the computing system, the DNS requests to the different server only for a predetermined period of time after the edge network protection service is disconnected, and rejecting, by the computing system, DNS requests after the predetermined period of time; notifying, by the computing system, the customer that the DNS request is being rejected and that customer premises equipment ("CPE") in the selected first line needs to be configured to address the DNS request elsewhere; or notifying, by the computing system, the customer of the predetermined period before DNS requests will begin to be rejected unless the CPE is configured to address the DNS requests to a different server. performing at least one of the following steps: The method of claim 1 or 2, further comprising:
12. determining, by the computing system, a first number of lines already configured by the customer from a total number of lines ordered by the customer based on the customer's selection of configuring at least one new second line from the one or more lines, and updating, by the computing system, a number of rights allocated to the customer based on the determined first number of lines. The method of claim 1 or 2, further comprising:
13. and, based on a determination that a third line has been selected from among the one or more lines and has already been configured or ordered, causing, by the computing system, an ordering system to communicate with a provider configuration system to perform at least one of incrementing the first number of lines or decrementing the updated number of entitlements. The method of claim 12 further comprising:
14. and causing the computing system to at least one of decrementing the first number of lines or incrementing the updated number of rights when an instruction is received from the customer to select a fourth line from among the one or more lines to delete a service instance of an edge network protection service. The method of claim 12 further comprising:
15. The network includes a first network associated with a first network service provider, and the method includes: causing the computing system to present an option to select at least one third-party line over which edge network protection services should be provisioned or managed, the at least one third-party line being operated and provisioned by a second network service provider different from the first network service provider; and causing the computing system to present an option for entering line information for the at least one third-party line. The method of claim 1 or 2, further comprising:
16. a first customer premises equipment ("CPE") in the first line, sending, by the computing system, a service ticket to an agent of the first service provider to manually configure or update Domain Name System (“DNS”) parameters of the first CPE based at least in part on the first service instance of the edge network protection service; automatically configuring or updating, by the computing system, DNS parameters of the first CPE based at least in part on the first service instance of the edge network protection service; automatically configuring or updating, by the computing system, DNS parameters of the first CPE based at least in part on the first service instance of the edge network protection service by exposing the DNS parameters to the first CPE via a third application programming interface (“API”); or sending, by the computing system, at least one first message to the customer having instructions to manually configure or update DNS parameters of the first CPE based at least in part on the first service instance of the edge network protection service. by performing one of the steps The method of claim 15 further comprising:
17. receiving, by the computing system, a request to deprovision a second service instance of the edge network protection service from a fifth line from the one or more lines; a second CPE in the fifth line by the computing system; sending, by the computing system, a service ticket to an agent of the first service provider to manually configure or update DNS parameters of the second CPE based at least in part on the deprovisioning of the second service instance of the edge network protection service; automatically configuring or updating, by the computing system, DNS parameters of the second CPE based at least in part on the de-provisioning of the second service instance of the edge network protection service; automatically configuring or updating, by the computing system, DNS parameters of the second CPE based at least in part on the de-provisioning of the second service instance of the edge network protection service by exposing the DNS parameters to the second CPE via a fourth API; or sending, by the computing system, at least one second message to the customer having instructions to manually configure or update DNS parameters of the second CPE based at least in part on the deprovisioning of the second service instance of the edge network protection service; and sending, by the computing system, at least one third message to the customer informing the customer regarding the progress of the deprovisioning of the second service instance. The method of claim 15 further comprising:
18. 1. A system comprising:
1. A computing system comprising: at least one first processor; and a first non-transitory computer-readable medium communicatively coupled to the at least one first processor; a computing system having wherein the first non-transitory computer-readable medium, when executed by the at least one first processor, provides the computing system with: receiving a request from a customer to manage edge network protection services for at least one Internet line, wherein the request includes customer information; determining whether the customer is already provisioned with any lines capable of implementing edge network protection services based at least in part on the customer information; based on a determination that the customer is provisioned with one or more lines capable of implementing edge network protection services, presenting the customer with an option to select one line from the one or more lines on which edge network protection services should be provisioned or managed; and receiving a selection of a first line from the one or more lines from the customer; automatically configuring the selected first circuit to provision a first service instance of the edge network protection service based on a determination that a service instance of the edge network protection service is not provisioned on the selected first circuit; or automatically reconfiguring the selected first circuit to modify the first service instance of the edge network protection service based on a determination that the first service instance of the edge network protection service has already been provisioned on the selected first circuit. Steps to perform one of the following: storing computer software including a first set of instructions to cause the system to:
19. The step of presenting the option to select one of the one or more lines for which edge network protection services should be provisioned or managed includes presenting the option in one of a user interface (“UI”), a software application (“app”), or a control portal for the customer to select one of the one or more lines for which edge network protection services should be provisioned or managed, wherein the first set of instructions, when executed by the at least one first processor, causes the computing system to: exposing a first application programming interface ("API") to allow programmatic ordering of new edge network protection services, thereby providing programmatic access to the ordering system via the first API; exposing a second API to allow programmatic management of edge network protection services, thereby providing programmatic access to the provider configuration system via the second API; presenting a first UI, wherein the first UI provides user-selectable options for the customer to order a new edge network protection service; or presenting a second UI, wherein the second UI provides user-selectable options for the customer to manage edge network protection services. The system of claim 18 , further comprising:
20. receiving, by a computing system of the network, a request from a customer to manage edge network protection services for at least one Internet line, wherein said request includes customer information; determining, by the computing system, whether the customer is already provisioned with any lines capable of implementing edge network protection services based at least in part on the customer information; based on a determination that the customer is provisioned with one or more lines capable of implementing edge network protection services, causing the computing system to present an option to select one line from the one or more lines over which edge network protection services should be provisioned or managed; and and automatically configuring, by the computing system, upon receiving a selection of a first line from the one or more lines from the customer, the selected first line for provisioning a first service instance of the edge network protection service. A method comprising: