SECURITY POLICY UNIFICATION ACROSS DIFFERENT SECURITY PRODUCTS

    公开(公告)号:US20170230425A1

    公开(公告)日:2017-08-10

    申请号:US15498927

    申请日:2017-04-27

    CPC classification number: H04L63/20 G06F21/604 H04L41/28 H04L63/10 H04L63/102

    Abstract: A management entity generates for display multiple icons, each icon representing an actor or a resource in a networking environment, and defines a generic security policy by receiving user input in the form of a line drawn between a first icon representing an actor and a second icon representing a resource to control abilities between the actor and the resource. The management entity translates the generic security policy to multiple native security policies each of which is based on a corresponding one of multiple native policy models associated with corresponding ones of multiple security devices, and supply data descriptive of the multiple native security policies to the corresponding ones of the security devices to configure the corresponding ones of the security devices to implement the native security policies.

    SECURITY POLICY UNIFICATION ACROSS DIFFERENT SECURITY PRODUCTS
    14.
    发明申请
    SECURITY POLICY UNIFICATION ACROSS DIFFERENT SECURITY PRODUCTS 有权
    安全政策不同的安全产品

    公开(公告)号:US20160212169A1

    公开(公告)日:2016-07-21

    申请号:US14600495

    申请日:2015-01-20

    Abstract: A management entity receives from multiple security devices corresponding native security policies each based on a native policy model associated with the corresponding security device. Each security device controls access to resources by devices associated with the security device according to the corresponding native security policy. The management entity normalizes the received native security policies across the security devices based on a generic policy model, to produce a normalized security policy that is based on the generic policy model and representative of the native security polices.

    Abstract translation: 管理实体从多个安全设备接收对应的本地安全策略,每个基于与相应的安全设备相关联的本地策略模型。 每个安全设备根据相应的本地安全策略控制与安全设备相关联的设备对资源的访问。 管理实体基于通用策略模型,在安全设备之间规范化接收到的本地安全策略,以生成基于通用策略模型并代表本机安全策略的规范化安全策略。

    CREATION OF SECURITY POLICY TEMPLATES AND SECURITY POLICIES BASED ON THE TEMPLATES
    15.
    发明申请
    CREATION OF SECURITY POLICY TEMPLATES AND SECURITY POLICIES BASED ON THE TEMPLATES 有权
    基于模板创建安全政策模板和安全政策

    公开(公告)号:US20160212168A1

    公开(公告)日:2016-07-21

    申请号:US14600473

    申请日:2015-01-20

    Abstract: A management entity generates selectable security policy classifications each identifying security policies that share common security rules. Each of the security policies is applied by a corresponding one of different security devices to control access to a resource. The management entity creates a new policy template that includes all of the security policies identified by selected ones of the policy classification selections and then creates a new security policy based on the new policy template. The management entity applies the new security policy to a security device over a network.

    Abstract translation: 管理实体生成可选择的安全策略分类,每个分类标识共享公共安全规则的安全策略。 每个安全策略由相应的一个不同的安全设备应用来控制对资源的访问。 管理实体创建一个新的策略模板,其中包括由选定的策略分类选择标识的所有安全策略,然后基于新的策略模板创建新的安全策略。 管理实体通过网络将新的安全策略应用于安全设备。

    User interface for low-touch security policy provisioning

    公开(公告)号:US10666683B2

    公开(公告)日:2020-05-26

    申请号:US15663757

    申请日:2017-07-30

    Abstract: In one embodiment, a system includes a processor, and a memory to store data used by the processor, the processor being operative to prepare a first user interface including a security policy selection section, interpret user input data to include performing at least one security policy selection action in the security policy selection section yielding selection of a first security policy for a first device, and update the first user interface yielding an updated first user interface including the first security policy, and a first security policy activation key for inputting into a second user interface to be generated when the first device is installed, the first security policy activation key being associated with providing authentication for downloading the first security policy to the first device.

    SECURITY POLICY EFFICACY VISUALIZATION
    19.
    发明申请

    公开(公告)号:US20170353459A1

    公开(公告)日:2017-12-07

    申请号:US15426702

    申请日:2017-02-07

    CPC classification number: H04L63/10 H04L63/0263 H04L63/20

    Abstract: A management entity communicates over a network with devices on which security rules are configured to control network access. Data that indicates a hit count for each security rule across the devices is repeatedly collected from the devices. The indicated hit counts for each security rule are aggregated over different repeating time intervals to produce repeatedly aggregated hit counts for respective ones of the different repeating time intervals. The security rules are generated for display on a user interface screen as selectable options. Responsive to a selection of one of the security rules, a selected security rule and most recently aggregated hit counts for the different repeating time intervals for the selected security rule are generated for concurrent display on the user interface screen. The display of the most recently aggregated hit counts for the selected security rule is updated as time progresses.

Patent Agency Ranking