APPARATUS AND METHOD FOR QUANTITATIVELY EVALUATING SECURITY POLICY
    1.
    发明申请
    APPARATUS AND METHOD FOR QUANTITATIVELY EVALUATING SECURITY POLICY 审中-公开
    用于定量评估安全政策的设备和方法

    公开(公告)号:US20120167163A1

    公开(公告)日:2012-06-28

    申请号:US13324482

    申请日:2011-12-13

    IPC分类号: G06F21/00

    CPC分类号: G06F21/577

    摘要: An apparatus for quantitatively evaluating security policy includes: a security policy analyzing unit for analyzing a security policy of a network; an evaluation criterion defining unit for defining an evaluation criterion for categorizing security features and evaluating each of the security features; an evaluation result calculating unit for calculating an evaluation result of each of security components based on the evaluation criterion; an indicator calculating unit for grouping the security components according to a security function and calculating an indicator by considering a security function of each group; and a quantitative evaluating unit for evaluating a security policy of the each group by using the indicator.

    摘要翻译: 一种用于定量评估安全策略的装置包括:安全策略分析单元,用于分析网络的安全策略; 评估标准定义单元,用于定义用于对安全特征进行分类并评估每个安全特征的评估标准; 评估结果计算单元,用于基于评估标准来计算每个安全成分的评估结果; 指示器计算单元,用于根据安全功能对安全组件进行分组,并通过考虑每个组的安全功能来计算指标; 以及通过使用指标来评估每个组的安全策略的定量评估单元。

    APPARATUS FOR SHARING SECURITY INFORMATION AMONG NETWORK DOMAINS AND METHOD THEREOF
    2.
    发明申请
    APPARATUS FOR SHARING SECURITY INFORMATION AMONG NETWORK DOMAINS AND METHOD THEREOF 审中-公开
    用于共享网络域中的安全信息的方法及其方法

    公开(公告)号:US20120110633A1

    公开(公告)日:2012-05-03

    申请号:US13182972

    申请日:2011-07-14

    IPC分类号: G06F17/00 H04L29/06

    CPC分类号: H04L63/0263 H04L63/1408

    摘要: Provided are a security information sharing apparatus capable of sharing security information among network domains and a method thereof. The security information sharing apparatus includes a primitive security information storage unit configured to store primitive security information to be shared with other network domains, an information sharing policy storage unit configured to store an information sharing policy for information to be shared, an information masking policy storage unit configured to store an information masking policy for information not to be opened to the other network domain, a domain selector configured to select the other network domain to receive the shared security information, a shared security information generator configured to generate shared security information for the selected other network domain by applying the information sharing policy to the primitive security information, an information masking unit configured to mask information not to be opened in the generated security information according to the information masking policy, a protocol message generator configured to generate a protocol message for the shared security information subjected to the information masking, to be transmitted, and a protocol message transmitter configured to transmit the protocol message to the selected other network domain.

    摘要翻译: 提供能够在网络域之间共享安全信息的安全信息共享装置及其方法。 安全信息共享装置包括:原始安全信息存储单元,被配置为存储要与其他网络域共享的原始安全信息;信息共享策略存储单元,被配置为存储用于要共享的信息的信息共享策略,信息屏蔽策略存储 被配置为存储用于不被打开的信息的信息屏蔽策略的单元,被配置为选择其他网络域以接收所述共享安全信息的域选择器,被配置为生成所述共享安全信息的共享安全信息生成器, 通过将信息共享策略应用于原始安全信息来选择其他网络域,信息掩蔽单元,被配置为根据信息屏蔽策略屏蔽所生成的安全信息中不被打开的信息;协议消息生成器,被配置为生成 用于被发送的信息屏蔽的共享安全信息的协议消息以及被配置为将协议消息发送到所选择的其他网络域的协议消息发送器。

    Apparatus and method for limiting bandwidths of burst aggregate flows
    4.
    发明授权
    Apparatus and method for limiting bandwidths of burst aggregate flows 失效
    用于限制突发聚合流的带宽的装置和方法

    公开(公告)号:US07417951B2

    公开(公告)日:2008-08-26

    申请号:US10934545

    申请日:2004-09-03

    IPC分类号: H04L12/28

    摘要: Provided are an apparatus and method for limiting bandwidths of burst aggregate flows according to the present invention. The apparatus comprises: a bandwidth measuring unit measuring a bandwidth of at least one input aggregate flow; a grade determining unit determining abnormal grades according to abnormal levels of the input aggregate flows; a bandwidth limit determining unit determining a bandwidth volume and aggregate flow to be limited; a bandwidth limiting unit inputting a result determined by the bandwidth limit determining unit, limiting or releasing a bandwidth of a aggregate flow selected among the input aggregate flows and outputting the selected aggregate flow; and a status information storage unit storing status information including a usage bandwidth, an abnormal grade, and a limited bandwidth volume of the input aggregate flow. Accordingly, the apparatus and method provide an effect of dropping attack aggregate flows corresponding to excessive traffic while not influencing normal aggregate flows.

    摘要翻译: 提供了根据本发明的用于限制突发集束流的带宽的装置和方法。 该装置包括:带宽测量单元,测量至少一个输入聚合流的带宽; 等级确定单元根据输入的总流的异常水平确定异常等级; 带宽限制确定单元,确定要限制的带宽量和聚合流; 带宽限制单元,输入由所述带宽限制确定单元确定的结果,限制或释放在所述输入聚合流中选择的聚合流的带宽并输出所选择的聚合流; 以及状态信息存储单元,其存储包括输入聚合流的使用带宽,异常等级和有限带宽量的状态信息。 因此,该装置和方法提供了在不影响正常聚合流的情况下,减少对应于过多流量的攻击聚合流的效果。