Invention Grant
- Patent Title: System and method for migrating to and maintaining a white-list network security model
-
Application No.: US15794908Application Date: 2017-10-26
-
Publication No.: US10587621B2Publication Date: 2020-03-10
- Inventor: Kannan Ponnuswamy , Navneet Yadav , Arvind Chari
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: CISCO TECHNOLOGY, INC.
- Current Assignee: CISCO TECHNOLOGY, INC.
- Current Assignee Address: US CA San Jose
- Agency: Polsinelli PC
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Systems, methods, and computer-readable media for migrating to and maintaining a white-list network security model. Network traffic identified from permit-all access logs can be analyzed to determine whether it should be white-listed, and if so, a specific permit-access, without logging, policy is generated for the identified network traffic. The addition of specific permit-access policies is repeated on permit-all access logs, at which point, permit-all access policy is converted into deny-all access. In some examples, a system or method can obtain hit counts, from both hardware (eg: TCAM) and software tables, for the specific permit-access policy to determine existence of identified network traffic over a period of time. After analyzing hit counts, the specific permit-access policy can either continue to exist or be removed to maintain a white-list network security model.
Public/Granted literature
- US20180367541A1 SYSTEM AND METHOD FOR MIGRATING TO AND MAINTAINING A WHITE-LIST NETWORK SECURITY MODEL Public/Granted day:2018-12-20
Information query