INTENT-BASED NETWORK SECURITY POLICY MODIFICATION

    公开(公告)号:US20190007453A1

    公开(公告)日:2019-01-03

    申请号:US15637789

    申请日:2017-06-29

    Abstract: A device may receive first information associated with a set of security rules. The first information may identify a set of security actions a device is to implement when the set of security rules applies to traffic. The device may determine a manner in which the set of security rules is to apply using the first information. The device may determine whether the manner in which the set of security rules is to apply and an intent of a network security policy or a manner in which a set of previously defined security rules is to apply match to determine whether the set of security rules conflicts with the network security policy or whether the set of security rules and the set of previously defined security rules are related. The device may perform an action.

    TRACKING HOST THREATS IN A NETWORK AND ENFORCING THREAT POLICY ACTIONS FOR THE HOST THREATS

    公开(公告)号:US20190297103A1

    公开(公告)日:2019-09-26

    申请号:US16024319

    申请日:2018-06-29

    Abstract: A device receives network segment information identifying network segments associated with a network, and receives endpoint host session information identifying sessions associated with endpoint hosts communicating with the network. The device generates, based on the network segment information and the endpoint host session information, a data structure that includes information associating the network segments with the sessions associated with the endpoint hosts. The device updates the data structure based on changes in the sessions associated with the endpoint hosts and based on changes in locations of the endpoint hosts within the network segments, and identifies, based on the data structure, a particular endpoint host, of the endpoint hosts, that changed locations within the network segments. The device determines a threat policy action to enforce for the particular endpoint host, and causes the threat policy action to be enforced, by the network, for the particular endpoint host.

    DYNAMIC IMPLEMENTATION OF A SECURITY RULE
    4.
    发明申请

    公开(公告)号:US20190007454A1

    公开(公告)日:2019-01-03

    申请号:US15637806

    申请日:2017-06-29

    Abstract: A device may receive information identifying a set of conditions related to controlling implementation of a set of security rules. The set of conditions may be associated with a set of security actions that a device is to perform based on whether the set of conditions is satisfied. The device may determine the set of security rules that is to be controlled by the set of conditions using information related to the set of security rules. The device may modify information related to the set of security rules to cause the implementation of the set of security rules to be controlled by the set of conditions. The modification to cause the device to process the set of security rules to dynamically implement the set of security actions based on satisfaction of the set of conditions. The device may perform an action after modifying the information.

    ENFORCING THREAT POLICY ACTIONS BASED ON NETWORK ADDRESSES OF HOST THREATS

    公开(公告)号:US20210099472A1

    公开(公告)日:2021-04-01

    申请号:US17247461

    申请日:2020-12-11

    Abstract: A device receives information identifying a specific host threat to a network, where the information includes a list of network addresses associated with the specific host threat. The device identifies network elements, of the network, associated with the specific host threat to the network, and determines a network control system associated with the identified network elements. The device determines a policy enforcement group of network elements, of the identified network elements, that maps to the list of network addresses associated with the specific host threat, where the network control system is associated with the policy enforcement group of network elements. The device determines a threat policy action to enforce for the specific host threat, and causes, via the network control system, the threat policy action to be enforced by the policy enforcement group of network elements.

    ENFORCING MICRO-SEGMENTATION POLICIES FOR PHYSICAL AND VIRTUAL APPLICATION COMPONENTS IN DATA CENTERS

    公开(公告)号:US20190007456A1

    公开(公告)日:2019-01-03

    申请号:US15639366

    申请日:2017-06-30

    CPC classification number: H04L63/20 H04L63/0263 H04L63/0272 H04L63/102

    Abstract: A device may receive policy information associated with a first application group and a second application group. The device may receive network topology information associated with a network. The device may generate a first policy based on the policy information and the network topology information, and generate a second policy based on the policy information and the network topology information. The device may provide, to the virtual network device, information associated with the first policy to permit the virtual network device to implement the first policy in association with network traffic transferred between the first application group and the second application group. The device may provide, to the physical network device, information associated with the second policy to permit the physical network device to implement the second policy in association with network traffic transferred between the first application group and the second application group.

    ENFORCING THREAT POLICY ACTIONS BASED ON NETWORK ADDRESSES OF HOST THREATS

    公开(公告)号:US20190297094A1

    公开(公告)日:2019-09-26

    申请号:US16024308

    申请日:2018-06-29

    Abstract: A device receives information identifying a specific host threat to a network, where the information includes a list of network addresses associated with the specific host threat. The device identifies network elements, of the network, associated with the specific host threat to the network, and determines a network control system associated with the identified network elements. The device determines a policy enforcement group of network elements, of the identified network elements, that maps to the list of network addresses associated with the specific host threat, where the network control system is associated with the policy enforcement group of network elements. The device determines a threat policy action to enforce for the specific host threat, and causes, via the network control system, the threat policy action to be enforced by the policy enforcement group of network elements.

Patent Agency Ranking