ASSESSING NETWORK AND DEVICE COMPLIANCE WITH SECURITY POLICIES
    1.
    发明申请
    ASSESSING NETWORK AND DEVICE COMPLIANCE WITH SECURITY POLICIES 有权
    评估网络和设备遵守安全政策

    公开(公告)号:US20080022357A1

    公开(公告)日:2008-01-24

    申请号:US11776721

    申请日:2007-07-12

    IPC分类号: H04L9/00

    CPC分类号: H04L63/20

    摘要: All of the transit services that each device is expected to provide are determined and contrasted with the transit configuration of each device. Because the transit configuration of each device may be state-dependent, the service items within each application service are processed in sequential order. Sequences of service items are associated with connection groups, and each of the routes associated with each connection group is determined based on the sequential order of the service items. The configuration of each device along each route is processed to determine the services that will be permitted or denied, based on its current configuration. Each desired transit service item is compared to the transit configuration provided by each device to identify any inconsistencies and/or violations

    摘要翻译: 每个设备预期提供的所有过境服务都被确定,并与每个设备的传输配置进行对比。 由于每个设备的传输配置可能与状态有关,因此每个应用服务中的服务项目按顺序进行处理。 服务项目的顺序与连接组相关联,并且基于服务项目的顺序来确定与每个连接组相关联的每个路线。 根据其当前配置,处理每个路由上每个设备的配置,以确定将被允许或拒绝的服务。 将每个期望的中转服务项目与由每个设备提供的传输配置进行比较,以识别任何不一致和/或违规

    Analyzing security compliance within a network
    2.
    发明申请
    Analyzing security compliance within a network 有权
    分析网络中的安全合规性

    公开(公告)号:US20070157286A1

    公开(公告)日:2007-07-05

    申请号:US11505171

    申请日:2006-08-16

    IPC分类号: H04L9/00

    摘要: A security policy database identifies the intended security policies within a network, a traffic generator provides test traffic that is configured to test each defined security policy, and a simulator simulates the propagation of this traffic on a model of the network. The model of the network includes the configuration data associated with each device, and thus, if devices are properly configured to enforce the intended security policies, the success/failure of the simulated test traffic will conform to the intended permit/deny policy of each connection. Differences between the simulated message propagation and the intended security policies are reported to the user, and diagnostic tools are provided to facilitate identification of the device configuration data that accounts for the observed difference. Additionally, if a network's current security policy is unknown, test traffic is generated to reveal the actual policy in effect, to construct a baseline intended security policy.

    摘要翻译: 安全策略数据库标识网络中的预期安全策略,流量生成器提供被配置为测试每个定义的安全策略的测试流量,并且模拟器模拟该流量在网络模型上的传播。 网络模型包括与每个设备相关联的配置数据,因此,如果设备被正确配置以实施预期的安全策略,则模拟测试流量的成功/失败将符合每个连接的预期允许/拒绝策略 。 向用户报告模拟消息传播与预期安全策略之间的差异,并提供诊断工具以便于识别出所观察到的差异的设备配置数据。 此外,如果网络当前的安全策略未知,则生成测试流量以显示实际的实际策略,以构建基准预期的安全策略。

    Identifying and analyzing network configuration differences
    3.
    发明申请
    Identifying and analyzing network configuration differences 有权
    识别和分析网络配置差异

    公开(公告)号:US20070058570A1

    公开(公告)日:2007-03-15

    申请号:US11505228

    申请日:2006-08-16

    IPC分类号: H04L12/28

    CPC分类号: H04L41/0866 H04L41/0859

    摘要: A contextual and semantic analysis of network entities facilitates a mapping and comparison of the entities between network models. The system includes a plurality of refine handler and match handler pairs that use rules that are specific to the type of network entities being analyzed. The refine handler analyzes the network model to identify the entities for which its rules apply, and the match handler processes these identified entities to establish a pairing between corresponding entities in each model. A sequence of refine-match processes are applied to the network models, typically in accordance with a hierarchy of rules until each entity is identified as a matched, added, or removed entity. A difference handler processes the identified pairings to provide a difference analysis that facilitates a meaningful interpretation of the configuration changes, and a user interface provides an interactive environment to view the differences from different perspectives.

    摘要翻译: 网络实体的上下文和语义分析有助于网络模型之间的实体的映射和比较。 该系统包括使用特定于正在分析的网络实体的类型的规则的多个精简处理程序和匹配处理程序对。 精简处理程序分析网络模型以识别其规则适用的实体,匹配处理程序处理这些标识的实体以在每个模型中的对应实体之间建立配对。 精细匹配过程的序列通常根据规则的层次结构应用于网络模型,直到每个实体被识别为匹配的,添加的或移除的实体。 差异处理程序处理识别的配对以提供有助于对配置更改进行有意义的解释的差异分析,并且用户界面提供交互式环境以从不同的角度来查看差异。

    Network path discovery and analysis
    6.
    发明授权
    Network path discovery and analysis 有权
    网络路径发现与分析

    公开(公告)号:US09014012B2

    公开(公告)日:2015-04-21

    申请号:US12900357

    申请日:2010-10-07

    IPC分类号: H04L1/00 H04L12/24

    CPC分类号: H04L41/12 H04L41/0213

    摘要: A network analysis system invokes an application specific, or source-destination specific, path discovery process. The application specific path discovery process determines the path(s) used by the application, collects performance data from the nodes along the path, and communicates this performance data to the network analysis system for subsequent performance analysis. The system may also maintain a database of prior network configurations to facilitate the identification of nodes that are off the path that may affect the current performance of the application. The system may also be specifically controlled so as to identify the path between any pair of specified nodes, and to optionally collect performance data associated with the path.

    摘要翻译: 网络分析系统调用特定于应用程序或源特定路径的路径发现过程。 应用程序特定路径发现过程确定应用程序使用的路径,从沿着路径的节点收集性能数据,并将该性能数据传达到网络分析系统以进行后续性能分析。 系统还可以维护先前网络配置的数据库,以便于识别可能影响应用的当前性能的路径之外的节点。 还可以特别地控制系统,以便识别任何一对指定节点之间的路径,并且可选地收集与该路径相关联的性能数据。

    Component-based modeling of wireless mac protocols for efficient simulations
    7.
    发明授权
    Component-based modeling of wireless mac protocols for efficient simulations 有权
    基于组件的无线mac协议建模,实现有效的模拟

    公开(公告)号:US07844423B2

    公开(公告)日:2010-11-30

    申请号:US11875900

    申请日:2007-10-20

    摘要: Channel access delays and reception uncertainty are modeled as protocol-independent generic processes that are optimized for improved simulation performance. The generic process components are designed such that each different protocol can be modeled using an arrangement of these components that is specific to the protocol. In this way, speed and/or accuracy improvements to the generic process components are reflected in each of such protocol models. If an accurate analytic model is not available for the generic process component, a prediction engine, such as a neural network, is preferably used. The prediction engine is trained using the existing detailed models of network devices. Once trained, the prediction engine is used to model the generic process, and the protocol model that includes the generic component is used in lieu of the detailed models, thereby saving substantial processing time.

    摘要翻译: 通道访问延迟和接收不确定性被建模为针对改进的仿真性能进行了优化的协议无关的通用进程。 通用过程组件被设计为使得可以使用特定于协议的这些组件的布置来对每个不同的协议进行建模。 以这种方式,通用过程组件的速度和/或精度改进反映在每个这样的协议模型中。 如果准确的分析模型对于通用处理组件不可用,则优选地使用诸如神经网络的预测引擎。 使用现有的网络设备详细模型来训练预测引擎。 一旦被训练,预测引擎用于对通用过程进行建模,并且使用包括通用组件的协议模型来代替详细模型,从而节省大量的处理时间。

    Mapping off-network traffic to an administered network
    8.
    发明授权
    Mapping off-network traffic to an administered network 有权
    将网络外流量映射到管理网络

    公开(公告)号:US07672238B2

    公开(公告)日:2010-03-02

    申请号:US11835130

    申请日:2007-08-07

    IPC分类号: H04L15/00

    摘要: Traffic flows through an administered network from an off-network source and/or to an off-network destination are simulated and analyzed by selecting an ingress and/or egress node within the administered network, the ingress node capable of collecting traffic from an off-network source, and the egress node capable of routing traffic to an off-network destination. Traffic flow is mapped from the source or ingress node through the administered network to the egress node. The traffic flow may be simulated and analyzed. The ingress and/or egress nodes may be selected in a variety of ways.

    摘要翻译: 通过选择管理的网络内的入口和/或出口节点来模拟和分析从网络外的源和/或离网目的地流经管理的网络的流量,所述入口节点能够从离线网络中收集流量, 网络源和能够将流量路由到离网目的地的出口节点。 业务流从源或入节点通过被管理网络映射到出口节点。 可以模拟和分析交通流量。 可以以各种方式来选择入口节点和/或出口节点。

    MODELING AND SIMULATING WIRELESS MAC PROTOCOLS
    9.
    发明申请
    MODELING AND SIMULATING WIRELESS MAC PROTOCOLS 有权
    无线MAC协议的建模与仿真

    公开(公告)号:US20080103738A1

    公开(公告)日:2008-05-01

    申请号:US11875900

    申请日:2007-10-20

    IPC分类号: G06G7/48

    摘要: Channel access delays and reception uncertainty are modeled as protocol-independent generic processes that are optimized for improved simulation performance. The generic process components are designed such that each different protocol can be modeled using an arrangement of these components that is specific to the protocol. In this way, speed and/or accuracy improvements to the generic process components are reflected in each of such protocol models. If an accurate analytic model is not available for the generic process component, a prediction engine, such as a neural network, is preferably used. The prediction engine is trained using the existing detailed models of network devices. Once trained, the prediction engine is used to model the generic process, and the protocol model that includes the generic component is used in lieu of the detailed models, thereby saving substantial processing time.

    摘要翻译: 通道访问延迟和接收不确定性被建模为针对改进的仿真性能进行了优化的协议无关的通用进程。 通用过程组件被设计为使得可以使用特定于协议的这些组件的布置来对每个不同的协议进行建模。 以这种方式,通用过程组件的速度和/或精度改进反映在每个这样的协议模型中。 如果准确的分析模型对于通用处理组件不可用,则优选地使用诸如神经网络的预测引擎。 使用现有的网络设备详细模型来训练预测引擎。 一旦被训练,预测引擎用于对通用过程进行建模,并且使用包括通用组件的协议模型来代替详细模型,从而节省大量的处理时间。