Invention Grant
- Patent Title: Computer network security configuration visualization and control system
-
Application No.: US16463582Application Date: 2017-11-21
-
Publication No.: US11258763B2Publication Date: 2022-02-22
- Inventor: Joseph Cummins , Jonathan Wong
- Applicant: CybernetIQ, Inc.
- Applicant Address: CA Ottawa
- Assignee: CybernetIQ, Inc.
- Current Assignee: CybernetIQ, Inc.
- Current Assignee Address: CA Ottawa
- International Application: PCT/CA2017/051389 WO 20171121
- International Announcement: WO2018/094516 WO 20180531
- Main IPC: H04L12/00
- IPC: H04L12/00 ; H04L29/06 ; G06F9/451 ; H04L41/02 ; H04L41/22

Abstract:
A computing device is configured to retrieve network security configuration information from a computer network and generate a security configuration map which readily enables a user to detect defects in the security configuration with respect to a security policy. The computing device retrieves firewall configurations from security appliances in the network which operate firewalls, and processes the firewall configurations to generate a set of corresponding standardized firewall configurations. These are processed to identify enclaves containing network nodes which are associated with respective security sensitivity values based on the security policy. The computing device monitors and detects inter-node network traffic. The computing device generates a map representing the network nodes and security appliances, the security enclaves, the respective security sensitivity values, and the network traffic flows, thereby rendering readily visible inconsistencies between the actual security configuration and traffic flows, and the security policy.
Public/Granted literature
- US20190319926A1 COMPUTER NETWORK SECURITY CONFIGURATION VISUALIZATION AND CONTROL SYSTEM Public/Granted day:2019-10-17
Information query