Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

14 results about "Application firewall" patented technology

An application firewall is a form of firewall that controls input, output, and/or access from, to, or by an application or service. It operates by monitoring and potentially blocking the input, output, or system service calls that do not meet the configured policy of the firewall. The application firewall is typically built to control all network traffic on any OSI layer up to the application layer. It is able to control applications or services specifically, unlike a stateful network firewall, which is - without additional software - unable to control network traffic regarding a specific application. There are two primary categories of application firewalls, network-based application firewalls and host-based application firewalls.

Dynamically scalable application firewall deployment for cloud native applications

A configuration of a cloud application exposed via a public IP address is duplicated with modifications to include a private IP address to expose the application internally. The original configuration is updated so that external network traffic sent to the application is redirected to and distributed across agents running on nodes of a cloud cluster by which web application firewalls (WAFs) are implemented. A set of agents for which the respective WAFs should inspect the redirected network traffic are selected based on cluster metrics, such as network and resource utilization metrics. The redirected network traffic targets a port allocated to the agents that is unique to the application, where ports are allocated on a per-application basis so each of the agents can support WAF protection for multiple applications. Network traffic which a WAF allows to pass is directed from the agent to the application via its private IP address.
Owner:PALO ALTO NETWORKS INC

METHOD FOR DISTRIBUTING ELEMENTARY CALCULATIONS

One aspect of the invention relates to a method 100 for distributing elementary calculations, the method 100 comprising the steps of: 101 breaking down a complex calculation into a plurality of elementary calculations via an application; 102 transmitting said elementary calculations to an application firewall; 104 distributing said elementary calculations to a plurality of web browsers via said application firewall; 105 executing one received elementary calculation via each web browser; 106 aggregating the results of elementary calculations obtained from said web browsers via said application firewall; 107 transmitting said aggregated results of elementary calculations to said application. Figure to be published with the abstract: Figure 1
Owner:AMADEUS SAS

Unified scheduling method and system for multi-manufacturer load balancing equipment and storage medium

The invention provides a unified scheduling method and system for multi-manufacturer load balancing equipment and a storage medium, and the unified scheduling system for the multi-manufacturer load balancing equipment comprises a terminal, a cloud end and a plurality of pieces of load balancing equipment. The cloud end is suitable for configuring a first load balancing virtual IP, an application firewall and a second load balancing virtual IP, the first load balancing virtual IP is suitable for receiving flow data and carrying out data interaction with the second load balancing virtual IP, and the application firewall is suitable for filtering and checking data in data interaction; the at least one specified load balancing device is adapted to receive traffic data through the second load balancing virtual IP. Through the setting, when the specified application interacts with the cloud through the external network, the double-layer load balancing virtual IP with the application firewall is adopted, and the safety can be improved.
Owner:太保科技有限公司

An Internet finance intelligent risk control system

The present invention provides an Internet finance intelligent risk control system, which includes a financial platform and a risk control system. A platform access module is provided in the risk control system and is connected to the financial platform through the platform access module. The risk control system includes an outer-end user layer and an inner-end management layer. The outer-end user layer and the inner-end management layer are connected through a firewall. An outer-end application layer is provided between the firewall and the outer-end user layer, and an inner-end application layer is provided between the firewall and the inner-end management layer. The outer-end user layer includes a user module, a user verification module, and a permission management module. This kind of Internet finance intelligent risk control system is established in the form of outer-end - firewall - inner-end, that is, the outer-end user layer, the outer-end application layer, the firewall, the inner-end application layer, and the inner-end management layer. The data of the inner-end is separated from the outer-end through the firewall, thereby improving the security of data access and data storage. And it is connected to the financial platform through the platform access module, making the risk control system and the financial platform independent and separated.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Epsilon machine-based unknown traffic clustering identification method and system, and storage medium

The invention discloses an unknown traffic clustering identification method based on an epsilon machine, and the method comprises the steps: S1, carrying out the adaptive sampling of network traffic, and obtaining a traffic data sample; s2, extracting a feature sequence from the traffic data sample; s3, converting the feature sequence into a symbol sequence; s4, constructing an epsilon machine of the symbol sequence by executing a causal state segmentation reconstruction algorithm on the symbol sequence, and obtaining a causal state set corresponding to the epsilon machine; s5, on the basis of the causal state set, calculating and outputting a feature vector representing a flow mode; s6, calculating the distance between different feature vectors, and recording the distance as a similarity distance; and S7, comparing the similarity distance with a preset threshold value, and judging the type of a flow mode according to a comparison result to complete clustering identification of unknown flow. According to the invention, efficient and accurate identification of unknown traffic can be realized, and the invention also provides an application firewall system and a computer readable storage medium, which also have the above beneficial effects.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Protecting serverless applications

ActiveUS12328329B2Securing communicationApplication firewallServer
A system and methods for protecting a serverless application, the system including: (a) a serverless application firewall configured to inspect input of the serverless function so as to ascertain whether the input contains malicious, suspicious or abnormal data; and (b) a behavioral protection engine configured to monitor behaviors and actions of the serverless functions during execution thereof.
Owner:PALO ALTO NETWORKS INC

A detection method, system, and device for defending against network attacks based on the Netfilter framework.

This application provides a detection method, system, and apparatus for defending against network attacks based on the Netfilter framework. The detection method is applied to a defense system between a client and a server to be accessed by the client. The method includes: sending access traffic from the client to an authentication tunnel module via a first detection point for authentication; after successful authentication, the defense system initiates a process to establish a secure communication tunnel with the client; sending data packets destined for the application layer to an application firewall module via a second detection point for web attack detection; the second and first detection points are respectively set on the PREROUTING chain of the Netfilter framework; and sending data packets detected by the application firewall module to a packet filtering module via a third detection point for network layer detection; the third detection point is set on the FORWARD chain of the Netfilter framework.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

Content management systems, methods, and media using an application level firewall

Content management systems, methods, and media using an application level firewall are provided. In accordance with some embodiments of the disclosed subject matter, the system for managing advertisement adjacencies comprises: a firewall component in an application layer comprising a processor and a memory, wherein the firewall component is configured to operate in an advertisement call stack of the application layer and wherein the processor is programmed to: receive an advertisement call for publishing an advertisement in an advertisement server on a web page, wherein a verification tag is inserted in the advertisement call that redirects the advertisement call to the firewall component prior to transmission to the advertisement server; determine whether the web page associated with the advertisement call contains objectionable content; and, in response to determining that the web page does not contain objectionable content, transmit the advertisement call to the advertisement server for publishing the advertisement on the web page.
Owner:INTEGRAL AD SCIENCE INC

Firewall configuration method and apparatus, computer device and storage medium

The application relates to an application firewall configuration method and device, computer equipment and a storage medium. Service traffic obtained by mirroring processing of received traffic from a switch is received, the service traffic is analyzed, network information and load information of a site are obtained, site information for protecting the site is obtained according to the network information, corresponding site protection rules are generated according to the site information for protecting the site, corresponding site resource configuration rules are generated according to the load information, and the application firewall is configured according to the site protection rules and the site resource configuration rules, so that the application firewall does not need to be connected in series to networking, thus the original network result is not changed, and the configuration strategy can be automatically deployed according to the network information and the load condition, so that the flexibility and the configuration efficiency of the application firewall configuration are improved.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Dynamically Scalable Application Firewall Deployment for Cloud-Native Applications

The configuration of a cloud application exposed through a public IP address is replicated with modifications to include a private IP address to expose the application internally. The original configuration is updated so that external network traffic sent to the application is redirected to and distributed among agents running on nodes of a cloud cluster where a web application firewall (WAF) is implemented. The set of agents that each WAF should inspect the redirected network traffic is selected based on cluster metrics, such as network and resource utilization metrics. The redirected network traffic targets ports allocated to the application-specific agents, where ports are allocated per application, and thus each agent can support WAF protection for multiple applications. Network traffic allowed through by the WAF is directed from the agent to the application via its private IP address.
Owner:PALO ALTO NETWORKS INC

Dynamically scalable application firewall deployment for cloud native applications

A configuration of a cloud application exposed via a public IP address is duplicated with modifications to include a private IP address to expose the application internally. The original configuration is updated so that external network traffic sent to the application is redirected to and distributed across agents running on nodes of a cloud cluster by which web application firewalls (WAFs) are implemented. A set of agents for which the respective WAFs should inspect the redirected network traffic are selected based on cluster metrics, such as network and resource utilization metrics. The redirected network traffic targets a port allocated to the agents that is unique to the application, where ports are allocated on a per-application basis so each of the agents can support WAF protection for multiple applications. Network traffic which a WAF allows to pass is directed from the agent to the application via its private IP address.
Owner:PALO ALTO NETWORKS INC

Content management systems, methods, and media using an application level firewall

Content management systems, methods, and media using an application level firewall are provided. In accordance with some embodiments of the disclosed subject matter, the system for managing advertisement adjacencies comprises: a firewall component in an application layer comprising a processor and a memory, wherein the firewall component is configured to operate in an advertisement call stack of the application layer and wherein the processor is programmed to: receive an advertisement call for publishing an advertisement in an advertisement server on a web page, wherein a verification tag is inserted in the advertisement call that redirects the advertisement call to the firewall component prior to transmission to the advertisement server; determine whether the web page associated with the advertisement call contains objectionable content; and, in response to determining that the web page does not contain objectionable content, transmit the advertisement call to the advertisement server for publishing the advertisement on the web page.
Owner:INTEGRAL AD SCIENCE INC

Operation data report generation method and device, electronic equipment and storage medium

The embodiment of the invention discloses an operation data report generation method and device, electronic equipment and a storage medium, historical operation data of a cloud application firewall is obtained by responding to a request for generating an operation data report for the cloud application firewall, the historical operation data is written into a pre-created webpage file, and the operation data report is generated. Executing the webpage file through the headless browser, calling the data analysis module to analyze based on the historical operation data according to the calling path, drawing a result obtained based on the analysis of the historical operation data in the headless browser to obtain a target webpage, converting the target webpage through the headless browser, generating an operation data report, and displaying the operation data report. The running data report is generated in the mode that the headless browser is introduced to process the target webpage, automatic generation of the running data report can be achieved, the generation efficiency of the running data report is effectively improved, and the method and device are widely applied to scenes such as the cloud technology.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Symbolic execution for web application firewall performance

Among other things, this document describes systems, devices, and methods for executing rules in an application layer firewall, including in particular a web application firewall (WAF). An application layer firewall engine employs symbolic execution techniques that result in improved performance and efficiency. In preferred embodiments, an arbitrary firewall rule can be pre-processed to discover and define a set of one or more properties that an input must have in order for the input to have the potential to trigger the rule. By quickly examining an input for these properties, then application layer firewall can conclude that the input cannot trigger and therefore skip full execution of the rule against the input. This can be repeated for many if not all rules in a firewall ruleset. When a high proportion of the inputs have the required properties for rule-skipping, performance can be dramatically improved.
Owner:AKAMAI TECHNOLOGIES INC