- 专利标题: System And Method For Securing Virtualized Networks
-
申请号: US13842695申请日: 2013-03-15
-
公开(公告)号: US20140123211A1公开(公告)日: 2014-05-01
- 发明人: Kelly Wanser , Andreas Markos Antonopoulos
- 申请人: Kelly Wanser , Andreas Markos Antonopoulos
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
A method and apparatus that secures a dynamic virtualized network is described. In an exemplary embodiment, a device learns a current network policy of the dynamic virtualized network, where the dynamic virtualized network is a virtualized layer 2 network that is overlaid on a layer 3 physical network. In addition, the current network policy includes multiple network policy elements, where each of the multiple network policy elements identifies an authorized endpoint in the dynamic virtualized network. Furthermore, the layer 3 physical network includes multiple network access devices. The device further determines a network security policy for the dynamic virtualized network from the current network policy. The network security policy includes one or more second network policy elements that are a different network policy element than one of the multiple network policy elements of the current network policy. In addition, each of the one or more second network policy network elements adds an additional policy on how network traffic is processed in the dynamic virtualized network by a port of one of the plurality of network access devices. The device further applies the network security policy to each network access device that is affected by the network security policy.
公开/授权文献
- US08931046B2 System and method for securing virtualized networks 公开/授权日:2015-01-06
信息查询