Automatically generating rules for connection security
    2.
    发明授权
    Automatically generating rules for connection security 有权
    自动生成连接安全性规则

    公开(公告)号:US08490153B2

    公开(公告)日:2013-07-16

    申请号:US13292018

    申请日:2011-11-08

    IPC分类号: H04L29/06

    CPC分类号: H04L63/0263 H04L63/20

    摘要: A method and system for creating security policies for firewall and connection policies in an integrated manner is provided. The security system provides a user interface through which a user can define a security rule that specifies both a firewall policy and a connection policy. After the security rule is specified, the security system automatically generates a firewall rule and a connection rule to implement the security rule. The security system provides the firewall rule to a firewall engine that is responsible for enforcing the firewall rules and provides the connection rule to an IPsec engine that is responsible for enforcing the connection rules.

    摘要翻译: 提供了以综合方式为防火墙和连接策略创建安全策略的方法和系统。 安全系统提供用户界面,用户可以通过该界面定义指定防火墙策略和连接策略的安全规则。 指定安全规则后,安全系统自动生成防火墙规则和连接规则,实现安全规则。 安全系统向防火墙引擎提供防火墙规则,该引擎负责执行防火墙规则,并向负责执行连接规则的IPsec引擎提供连接规则。

    AUTOMATICALLY GENERATING RULES FOR CONNECTION SECURITY
    3.
    发明申请
    AUTOMATICALLY GENERATING RULES FOR CONNECTION SECURITY 有权
    自动生成连接安全规则

    公开(公告)号:US20120054825A1

    公开(公告)日:2012-03-01

    申请号:US13292018

    申请日:2011-11-08

    IPC分类号: G06F21/00

    CPC分类号: H04L63/0263 H04L63/20

    摘要: A method and system for creating security policies for firewall and connection policies in an integrated manner is provided. The security system provides a user interface through which a user can define a security rule that specifies both a firewall policy and a connection policy. After the security rule is specified, the security system automatically generates a firewall rule and a connection rule to implement the security rule. The security system provides the firewall rule to a firewall engine that is responsible for enforcing the firewall rules and provides the connection rule to an IPsec engine that is responsible for enforcing the connection rules.

    摘要翻译: 提供了以综合方式为防火墙和连接策略创建安全策略的方法和系统。 安全系统提供用户界面,用户可以通过该界面定义指定防火墙策略和连接策略的安全规则。 指定安全规则后,安全系统自动生成防火墙规则和连接规则,实现安全规则。 安全系统向防火墙引擎提供防火墙规则,该引擎负责执行防火墙规则,并向负责执行连接规则的IPsec引擎提供连接规则。

    Automatically generating rules for connection security
    4.
    发明授权
    Automatically generating rules for connection security 有权
    自动生成连接安全性规则

    公开(公告)号:US08056124B2

    公开(公告)日:2011-11-08

    申请号:US11183317

    申请日:2005-07-15

    IPC分类号: G06F9/00 G06F15/16 G06F17/00

    CPC分类号: H04L63/0263 H04L63/20

    摘要: A method and system for creating security policies for firewall and connection policies in an integrated manner is provided. The security system provides a user interface through which a user can define a security rule that specifies both a firewall policy and a connection policy. After the security rule is specified, the security system automatically generates a firewall rule and a connection rule to implement the security rule. The security system provides the firewall rule to a firewall engine that is responsible for enforcing the firewall rules and provides the connection rule to an IPsec engine that is responsible for enforcing the connection rules.

    摘要翻译: 提供了以综合方式为防火墙和连接策略创建安全策略的方法和系统。 安全系统提供用户界面,用户可以通过该界面定义指定防火墙策略和连接策略的安全规则。 指定安全规则后,安全系统自动生成防火墙规则和连接规则,实现安全规则。 安全系统向防火墙引擎提供防火墙规则,该引擎负责执行防火墙规则,并向负责执行连接规则的IPsec引擎提供连接规则。

    ACCESS CONTROL TO SECURED APPLICATION FEATURES USING CLIENT TRUST LEVELS
    5.
    发明申请
    ACCESS CONTROL TO SECURED APPLICATION FEATURES USING CLIENT TRUST LEVELS 有权
    使用客户信任级别访问对安全应用程序的功能

    公开(公告)号:US20100319063A1

    公开(公告)日:2010-12-16

    申请号:US12483239

    申请日:2009-06-12

    IPC分类号: H04L29/06 G06F7/04 G06F15/16

    摘要: Architecture that facilitates the conveyance of a trust level when the caller makes a call, the trust level in dependence on the state of the caller system. The callee (call recipient) receives notification of the trust level and can use this information in the communication such as to request verification from the caller and/or initiate other modes of communication. A caller can authenticate the caller identity in different ways to a communication server. Based on that, the server can assign an appropriate server-verified trust level to the caller. Further, an unsecured phone controller can indicate a lower client-side defined trust level. The server verified and client-side trust levels are then sent to the callee, where the callee determines whether to allow caller access to one or more secured features based on the feature values and the trust level imposed by the callee to access those features.

    摘要翻译: 当调用者进行呼叫时,有助于传递信任级别的体系结构,信任级别取决于呼叫者系统的状态。 被叫方(呼叫接收方)接收到信任级别的通知,并且可以在通信中使用该信息,以便从呼叫者请求验证和/或启动其他通信模式。 呼叫者可以以不同的方式向通信服务器认证呼叫者身份。 基于此,服务器可以为呼叫者分配适当的服务器验证的信任级别。 此外,不安全的电话控制器可以指示较低的客户端定义的信任级别。 服务器验证和客户端信任级别然后被发送到被叫方,被叫方根据特征值和被叫方强制访问这些特征的信任级别确定是否允许主叫方访问一个或多个安全特征。

    Access control to secured application features using client trust levels
    9.
    发明授权
    Access control to secured application features using client trust levels 有权
    使用客户端信任级别对安全应用程序功能进行访问控制

    公开(公告)号:US09531695B2

    公开(公告)日:2016-12-27

    申请号:US12483239

    申请日:2009-06-12

    摘要: Architecture that facilitates the conveyance of a trust level when the caller makes a call, the trust level in dependence on the state of the caller system. The callee (call recipient) receives notification of the trust level and can use this information in the communication such as to request verification from the caller and/or initiate other modes of communication. A caller can authenticate the caller identity in different ways to a communication server. Based on that, the server can assign an appropriate server-verified trust level to the caller. Further, an unsecured phone controller can indicate a lower client-side defined trust level. The server verified and client-side trust levels are then sent to the callee, where the callee determines whether to allow caller access to one or more secured features based on the feature values and the trust level imposed by the callee to access those features.

    摘要翻译: 当调用者进行呼叫时,有助于传递信任级别的体系结构,信任级别取决于呼叫者系统的状态。 被叫方(呼叫接收方)接收到信任级别的通知,并且可以在通信中使用该信息,以便从呼叫者请求验证和/或启动其他通信模式。 呼叫者可以以不同的方式向通信服务器认证呼叫者身份。 基于此,服务器可以为呼叫者分配适当的服务器验证的信任级别。 此外,不安全的电话控制器可以指示较低的客户端定义的信任级别。 服务器验证和客户端信任级别然后被发送到被叫方,被叫方根据特征值和被叫方强制访问这些特征的信任级别确定是否允许主叫方访问一个或多个安全特征。

    Multi-profile interface specific network security policies
    10.
    发明授权
    Multi-profile interface specific network security policies 有权
    多配置界面特定的网络安全策略

    公开(公告)号:US08201234B2

    公开(公告)日:2012-06-12

    申请号:US11746478

    申请日:2007-05-09

    IPC分类号: H04L29/06

    摘要: Computer-readable medium having a data structure stored thereon for defining a schema for expressing a network security policy. The data structure includes a first data field including data defining a parameter to be applied based on the network security policy. The network security policy defines at least one of the following: a firewall rule and a connection security rule. The data structure also includes a second data field having data specifying restrictions of the parameter included in the first data field. The parameter in the first data field and the restrictions in the second data field form the schema for expressing the network security policy to be processed. The network security policy manages communications between a computing device and at least one other computing device.

    摘要翻译: 计算机可读介质,其上存储有用于定义表示网络安全策略的模式的数据结构。 数据结构包括第一数据字段,包括基于网络安全策略定义要应用的参数的数据。 网络安全策略定义以下至少一个:防火墙规则和连接安全规则。 数据结构还包括具有指定包含在第一数据字段中的参数的限制的数据的第二数据字段。 第一数据字段中的参数和第二数据字段中的限制形成用于表示要处理的网络安全策略的模式。 网络安全策略管理计算设备与至少一个其他计算设备之间的通信。