US2002093527A1PendingUtilityA1
User interface for a security policy system and method
Priority: Jun 16, 2000Filed: Apr 5, 2001Published: Jul 18, 2002
Est. expiryJun 16, 2020(expired)· nominal 20-yr term from priority
Inventors:Kieran Gerard SherlockGeoffrey CooperLuis ValenteJose J AmadorPaul X. WangRobert ShawKevin Cornwall
H04L 41/0894H04L 69/22H04L 43/062H04L 63/166H04L 41/5012H04L 63/083H04L 63/1425H04L 43/0811H04L 43/06H04L 43/18H04L 43/00H04L 41/069H04L 41/22H04L 63/1433H04L 63/0823H04L 41/0604H04L 43/067H04L 41/0893H04L 63/0263H04L 63/0227H04L 63/1408
39
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A user interface for a network security policy monitoring system and method that performs network and security assessments based on system-wide policy, whereby real network traffic is analyzed to identify abnormalities, vulnerabilities, and incorrect configurations by listening on a network, logging events, and taking action.
Claims
exact text as granted — not AI-modified1 . A user interface for displaying processed and analyzed network data to an end user, comprising:
a system dashboard kept up to date with current monitoring information from a monitored network, said dashboard comprising:
a network status console area;
a network events viewing area; and
a trend viewing area.
2 . The user interface of claim 1 , wherein said network status console area further comprises:
an alerts area comprising a FIFO queue of critical alerts; and a health monitor area showing a percentage of network traffic that does not violate current traffic and over a predetermined amount of time.
3 . The user interface of claim 1 , further comprising:
a tear off status console window for said end user to keep console window open on a desktop to monitor network status.
4 . The user interface of claim 1 , using a web page paradigm.
5 . The user interface of claim 2 , wherein said user alerts are updated on a real-time basis.
6 . The user interface of claim 2 , wherein any of said user alerts links to corresponding alert details information.
7 . The user interface of claim 2 , wherein the underlying traffic data of said health monitor is updated automatically at a regular interval.
8 . The user interface of claim 2 , wherein severity alerts levels are distinguished by color codes.
9 . The user interface of claim 1 , wherein said network events viewing area further comprises links to any of the following:
summary information; information on all events; and policy history information; wherein a configurable time period is set.
10 . The user interface of claim 9 , wherein said configurable time period comprises any of:
a user selected date and time range; last two hours; today; last 24 hours; yesterday; last seven days; this month; last month; and last three months.
11 . The user interface of claim 1 , further comprising any of:
conformance events summary information containing a count of violations for each rule/disposition pair; violator events summary information containing a count of the number of violations for each violating ip-address; and target events summary information containing a count of the number of violations for each top destination ip-address.
12 . The user interface of claim 11 , wherein event summary information links to network event details information containing details on events making up said count.
13 . The user interface of claim 1 , wherein user defined and configurable query and report settings are stored.
14 . The user interface of claim 1 , wherein said trend viewing area further comprises links to network events summary information.
15 . The user interface of claim 1 , wherein said trend viewing area further comprises a QuickWeek section, containing any of:
a predetermined number of most frequent rule/disposition combinations during a past predetermined number of days; a predetermined number of most frequent violator ip-addresses versus count during said past predetermined number of days; and a predetermined number of most frequent target ip-addresses versus count during said past predetermined number of days.
16 . The user interface of claim 1 , wherein the trend viewing area is user customizable.
17 . The user interface of claim 1 , further comprising embeddable trend charts into details information, said trend over a time range dynamically configurable by said end user.
18 . The user interface of claim 17 , wherein said trend charts comprise any of:
policy effectiveness; number of policy changes over time; event summary; network event details; and all conformance counts.
19 . The user interface of claim 12 , wherein said network event details information further comprises any of:
monitoring point; disposition name; rule name; disposition code; severity; source ip-address; source port; destination ip-address; destination port; ip protocol; event time; and application data.
20 . The user interface of claim 19 , wherein said application data comprises any of, but not limited to:
ICMP action code; HTTP-URL; FTP-Filename; SSL-Ciphersuite, Issuer and Subject's certificate CommonName, Certificate Status; SSH-Authentication handshake status; and application status code.
21 . The user interface of claim 1 , further comprising protocol event details information in context of a particular network event to a database from which said information is retrieved on an as-needed basis.
22 . The user interface of claim 21 , wherein said protocol event details information further comprises data from attributes.
23 . The user interface of claim 22 , wherein said data attributes comprise any of, but not limited to:
initiator credential name; target credential name; rule name for said protocol event; and disposition name for said protocol event.
24 . The user interface of claim 1 , further comprising alert event details information, said information comprising any of:
details of network event that caused alert; rule and disposition name that triggered alert; log comment from corresponding disposition; time at which alert was generated; initiator ip address of the corresponding non-conformant traffic; target ip address of the corresponding non-conformant traffic; an icon that links to the network event details page describing the non-conformant network event; and checkbox to clear alert;
25 . The user interface of claim 1 , further comprising a policy update information area showing each time a new policy is installed, said information comprising:
date of policy information; description of policy; and link to English representation of said newly installed policy.
26 . The user interface of claim 2 , further comprising means for each of said alerts to generate an alert email, said alert email comprising any of, but not limited to:
time said alert occurred; rule and disposition name that triggered alert; log description from said corresponding disposition; initiator ip address of corresponding non-conformant traffic; target ip address of corresponding non-conformant traffic; and a link to network event detail, said detail describing said non-conformant network event.
27 . The user interface of claim 26 , further comprising a customer information area allowing said end user to configure a list of email addresses to receive said alert email.
28 . The user interface of claim 1 , further comprising means for ad-hoc querying by said end user.
29 . The user interface of claim 28 , wherein means for ad-hoc querying further comprises filtering results by, but not limited to any or all of:
protocol of rule name; policy rule name; regular expression within rule name; disposition name of violation; regular expression within disposition name; source ip-address; regular expression with source ip-address; target ip-address; regular expression within target ip-address; target port; and regular expression within target port.
30 . The user interface of claim 28 , wherein means for ad-hoc querying further comprises an advanced search feature.
31 . The user interface of claim 30 , wherein said advanced search feature is implemented using a dialog box.
32 . The user interface of claim 1 , further comprising informational aids, said information aids comprising any of:
English language representation of policy; rule and disposition descriptions; and copyright information.
33 . The user interface of claim 32 , wherein said informational aids are linked to by said end user when said end user places a cursor over an appropriate field thereby displaying a tooltip of corresponding descriptions of said fields.
34 . The user interface of claim 33 , wherein said descriptions are any of but not limited to:
rule descriptions; disposition descriptions; and Resolved DNS names for ip-addresses; and TCP and UDP service names.
35 . The user interface of claim 33 , wherein said informational aids further comprise any of:
context sensitive help;
36 . The user interface of claim 1 , further comprising a link to generate a printer friendly printed page.
37 . The user interface of claim 1 , further comprising displaying time information in a predetermined time zone.Join the waitlist — get patent alerts
Track US2002093527A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.