Cloud Based Firewall System And Service
Abstract
A cloud-based firewall system and service is provided to protect customer sites from attacks, leakage of confidential information, and other security threats. In various embodiments, such a firewall system and service can be implemented in conjunction with a content delivery network (CDN) having a plurality of distributed content servers. The CDN servers receive requests for content identified by the customer for delivery via the CDN. The CDN servers include firewalls that examine those requests and take action against security threats, so as to prevent them from reaching the customer site. The CDN provider implements the firewall system as a managed firewall service, with the operation of the firewalls for given customer content being defined by that customer, independently of other customers. In some embodiments, a customer may define different firewall configurations for different categories of that customer's content identified for delivery via the CDN.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 .- 51 . (canceled)
52 . A system, comprising:
a plurality of machines operated by a service provider on behalf of content providers, each of the plurality of machines comprising circuitry forming one or more processors coupled to non-transitory computer-readable media storing program code executable by the one or more processors, the program code including code executable to run a server application on the respective machine; the program code further including code executable to cause the respective machine to receive an application layer request from a client via a network interface on the respective machine, and to handle the application layer request with the server application; wherein the application layer request includes a domain name associated with a particular content provider; the program code further including code executable to cause the respective machine to, based on the domain name, identify one or more rules from a security ruleset to apply to the application layer request, wherein rules in the security ruleset function to find security threats in application layer requests; the program code further including code executable to cause the respective machine to apply the one or more rules to the application layer request to determine whether one or more security threats are found in the application layer request, and if any of the one or more security threats are found, take an action against the application layer request.
53 . The system of claim 52 , wherein the server application is a proxy server application.
54 . The system of claim 52 , wherein the server application is an HTTP server application.
55 . The system of claim 52 , wherein the application layer request comprises an HTTP request.
56 . The system of claim 52 , wherein the plurality of machines are distributed across a plurality of end-user access networks.
57 . The system of claim 52 , wherein the plurality of machines are distributed around the Internet.
58 . The system of claim 52 , wherein the system further comprises:
separate from the plurality of machines running the server applications, one or more machines operated by the service provider that comprise circuitry forming one or more processors coupled to non-transitory computer-readable media storing program code executable by the one or more processors, the program code including code executable to cause the one or more machines to provide a user interface, and to receive, via the user interface, rule configurations for content providers that include selections of one or more rules from the security ruleset; the program code further including code executable to cause the one or more machines to deploy the rule configurations for content providers to the plurality of machines running the server applications.
59 . The system of claim 58 , wherein the rule configurations are received from content providers via the user interface.
60 . The system of claim 52 , the program code including code executable to cause the respective machine to process an application layer request with the server application where application of the one or more rules do not find a security threat in the application layer request,
wherein said processing of the application layer request comprises at least one of: (i) applying content handling information to determine how to handle the application layer request with the server application; (ii) retrieving content from a cache, and serving the retrieved content to the client, in response to the application layer request, and (iii) retrieving content from an origin server associated with the particular content provider and serving the retrieved content to the client, in response to the application layer request.
61 . The system of claim 52 , the program code further including code executable to cause the respective machine to receive a second application layer request from a second client via the network interface on the respective machine, and executable to cause the respective machine to handle the application layer request with the server application;
wherein the second application layer request includes a second domain name associated with a second content provider; the program code further including code executable to cause the respective machine to identify a second set of one or more rules from the security ruleset to apply to the application layer request; the program code further including code executable to cause the respective machine to apply the second set of one or more rules to the application layer request to determine whether a second set of one or more security threats are found in the application layer request, and if any of the second set of one or more security threats are found, take an action against the application layer request.
62 . The system of claim 52 , wherein the one or more security threats comprise at least one of: a protocol violation, an HTTP policy violation, a robot, a Trojan, a cross-site scripting attack, an injection attack, a content leakage.
63 . The system of claim 52 , wherein the action is any of the following actions: deny the application layer request, generate an alert about the application layer request, block the application layer request, modify the application layer request, stop processing the application layer request. Para16, original claim 8
64 . A method, comprising:
with a machine operated by a service provider on behalf of content providers that comprises circuitry forming one or more processors coupled to non-transitory computer-readable media storing program code executable by the one or more processors: running a server application on the machine; receiving an application layer request from a client via a network interface on the machine, and handling the application layer request with the server application; wherein the application layer request includes a domain name associated with a particular content provider; based on the domain name, identifying one or more rules from a security ruleset to apply to the application layer request, wherein rules in the security ruleset function to find security threats in application layer requests; applying the one or more rules to the application layer request to determine whether one or more security threats are found in the application layer request, and if any of the one or more security threats are found, taking an action against the application layer request.
65 . The method of claim 64 , wherein the server application is a proxy server application.
66 . The method of claim 64 , wherein the server application is an HTTP server application.
67 . The method of claim 64 , wherein the application layer request comprises an HTTP request.
68 . The method of claim 64 , further comprising processing an application layer request with the server application where application of the one or more rules do not find a security threat in the application layer request,
wherein said processing of the application layer request comprises at least one of: (i) applying content handling information to determine how to handle the application layer request with the server application; (ii) retrieving content from a cache, and serving the retrieved content to the client, in response to the application layer request, and (iii) retrieving content from an origin server associated with the particular content provider and serving the retrieved content to the client, in response to the application layer request.
69 . The method of claim 64 , further comprising receiving a second application layer request from a second client via the network interface on the machine, and handling the application layer request with the server application;
wherein the second application layer request includes a second domain name associated with a second content provider; identifying, based on the second domain name, a second set of one or more rules from the security ruleset to apply to the second application layer request; applying the second set of one or more rules to the application layer request to determine whether a second set of one or more security threats are found in the second application layer request, and if any of the second set of one or more security threats are found, take an action against the second application layer request.
70 . The method of claim 64 , wherein the one or more security threats comprise at least one of: a protocol violation, an HTTP policy violation, a robot, a Trojan, a cross-site scripting attack, an injection attack, a content leakage.
71 . The method of claim 64 , wherein the action is any of the following actions: deny the application layer request, generate an alert about the application layer request, block the application layer request, modify the application layer request, stop processing the application layer request.Join the waitlist — get patent alerts
Track US2013269023A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.