Invention Grant
- Patent Title: User interface driven translation, comparison, unification, and deployment of device neutral network security policies
-
Application No.: US14725489Application Date: 2015-05-29
-
Publication No.: US09641540B2Publication Date: 2017-05-02
- Inventor: Yedidya Dotan , Jason M. Perry , Denis Knjazihhin , Zachary D. Siswick , Sachin Vasant
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Edell, Shapiro & Finnan, LLC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F17/30

Abstract:
A method is performed at a management device to manage multiple network security devices over a network. The security devices are configured to control access to network accessible resources. A query is received. In response to the received query, a respective native security rule that references the specific resource is collected from each security device, where each native security rule is based on a respective native rule model associated with the security device from which the native security rule is collected. Each native security rule is translated into a respective normalized rule that is based on a generic rule model. The respective normalized rules are compared to each other to generate compare results. Based on the compare results, an indication of whether each security device allows or blocks access to the specific resource is generated.
Public/Granted literature
Information query