Invention Grant
- Patent Title: Method and system for managing security policies
- Patent Title (中): 管理安全策略的方法和系统
-
Application No.: US12126711Application Date: 2008-05-23
-
Publication No.: US09043861B2Publication Date: 2015-05-26
- Inventor: Ulrich Lang , Rudolf Schreiner
- Applicant: Ulrich Lang , Rudolf Schreiner
- Agency: Muncy, Geissler, Olds & Lowe, P.C.
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A system and method of managing security policies in an information technologies (IT) system are provided. In an example, the method includes receiving an input indicating a high-level security policy for the IT system, the received high-level security policy relating to non-functional system attributes for the IT system and received in a format that is not machine-enforceable at an enforcement entity of the IT system. A functional model for the IT system is determined, where the functional model indicates functional system attributes of the IT system. At least one pre-configured rule template is loaded, and at least one machine-enforceable rule is generated in a manner compliant with the received high-level security policy by iteratively filling the at least one pre-configured rule template with functional system attributes indicated by the functional model. After the generating step, the at least one machine-enforceable rule can be distributed (e.g., to an enforcement entity, an Intrusion Detection System (IDS), etc.). In another example, the receiving, determining, loading, generating and distributing steps can be performed at a policy node within an IT system.
Public/Granted literature
- US20090077621A1 METHOD AND SYSTEM FOR MANAGING SECURITY POLICIES Public/Granted day:2009-03-19
Information query