-
公开(公告)号:CA2729898A1
公开(公告)日:2010-01-07
申请号:CA2729898
申请日:2009-06-30
Applicant: IBM
Inventor: GOTTIMUKKALA SIVARAM , HUYNH LAP THIET , JOSEPH DINAKARAN , OVERBY JR LINWOOD HUGH , DEVINE WESLEY MCMILLAN , BEHRENDT MICHAEL , BREITER GERD
Abstract: A computer- implemented method (400) is provided for updating network security- policy rules when network resources are provisioned in a service landscape instance. The method includes categorizing network resources in a service landscape instance based on a service landscape model (404). The method further includes responding to the provisioning of a network resource by automatically generating one or more security policy rules for a newly- provisioned network resource (406). Additionally, the method includes updating security policy rules of pre-existing network resources in the service landscape instance that are determined to be eligible to communicate with the newly-provisioned network resource so as to include the newly-provisioned network resource as a remote resource based on the service landscape model (408).
-
公开(公告)号:CA2729898C
公开(公告)日:2017-04-11
申请号:CA2729898
申请日:2009-06-30
Applicant: IBM
Inventor: GOTTIMUKKALA SIVARAM , HUYNH LAP THIET , JOSEPH DINAKARAN , OVERBY JR LINWOOD HUGH , DEVINE WESLEY MCMILLAN , BEHRENDT MICHAEL , BREITER GERD
Abstract: A computer-implemented method (400) is provided for updating network security-policy rules when network resources are provisioned in a service landscape instance. The method includes categorizing network resources in a service landscape instance based on a service landscape model (404). The method further includes responding to the provisioning of a network resource by automatically generating one or more security policy rules for a newly-provisioned network resource (406). Additionally, the method includes updating security policy rules of pre-existing network resources in the service landscape instance that are determined to be eligible to communicate with the newly-provisioned network resource so as to include the newly-provisioned network resource as a remote resource based on the service landscape model (408).
-