-
公开(公告)号:US20190104144A1
公开(公告)日:2019-04-04
申请号:US15720553
申请日:2017-09-29
Applicant: Cisco Technology, Inc.
Inventor: Matthew Scott Robertson , Darrin Joseph Miller , Sunil Navinchandra Amin , Paul Wayne Bigbee
Abstract: In one example embodiment, a threat detection server receives metadata of a network flow in a network; a zone definition that correlates the metadata of the network flow with a first zone of network devices in the network and a second zone of network devices in the network, where the network flow was transmitted from the first zone to the second zone; and a security policy for the network flow, where the security policy is enforced on the basis of the first zone and the second zone. Based on the zone definition, the threat detection server annotates a flow record that includes the metadata with an indication of the first zone and the second zone. Based on the annotated flow record and the security policy, the threat detection server determines whether to generate a notification associated with a detection of a security threat associated with the network flow.
-
公开(公告)号:US10855705B2
公开(公告)日:2020-12-01
申请号:US15720553
申请日:2017-09-29
Applicant: Cisco Technology, Inc.
Inventor: Matthew Scott Robertson , Darrin Joseph Miller , Sunil Navinchandra Amin , Paul Wayne Bigbee
Abstract: In one example embodiment, a threat detection server receives metadata of a network flow in a network; a zone definition that correlates the metadata of the network flow with a first zone of network devices in the network and a second zone of network devices in the network, where the network flow was transmitted from the first zone to the second zone; and a security policy for the network flow, where the security policy is enforced on the basis of the first zone and the second zone. Based on the zone definition, the threat detection server annotates a flow record that includes the metadata with an indication of the first zone and the second zone. Based on the annotated flow record and the security policy, the threat detection server determines whether to generate a notification associated with a detection of a security threat associated with the network flow.
-