US2004039942A1PendingUtilityA1

Policy generator tool

Priority: Jun 16, 2000Filed: Jun 15, 2001Published: Feb 26, 2004
Est. expiryJun 16, 2020(expired)· nominal 20-yr term from priority
H04L 41/0894H04L 43/062H04L 41/22H04L 63/1408H04L 63/1433H04L 43/18H04L 63/1425H04L 43/0811H04L 63/0227H04L 43/00H04L 63/0263H04L 63/083H04L 63/0823H04L 43/06H04L 41/0604H04L 43/067H04L 69/22H04L 63/166H04L 41/069H04L 41/5012H04L 41/0893
44
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and apparatus for generating an initial policy specification file is provided. A level of abstraction over a policy language is used, simplifying creating the file based on gross character characteristics of a network at the IP level, such as policy domains, communities of hosts, subnets, and firewalls.

Claims

exact text as granted — not AI-modified
1 . An apparatus for translating desired network security policy into a policy specification file, wherein said file is interpretable and implementable by a policy monitor mechanism, said apparatus comprising: 
 a plurality of policy domains, wherein network traffic is monitored;    a plurality of communities of hosts; and    a plurality of rules for applying to said network traffic between said plurality of communities over a plurality of protocol services.    
     
     
         2 . The apparatus of  claim 1 , wherein said each of said plurality of policy domains is as small as required by traffic monitoring limitations associated with said network traffic, and as large as specification of said plurality of rules allow.  
     
     
         3 . The apparatus of  claim 1 , wherein each of said plurality of rules applies to network traffic anywhere within a particular of said plurality of policy domains.  
     
     
         4 . The apparatus of  claim 1 , further comprising: 
 at least one perimeter element having a MAC address, whereby nodes visible through said at least one perimeter element are known, and whereby said MAC address is used to detect IP spoofing and to detect rogue routers.    
     
     
         5 . The apparatus of  claim 1 , wherein communities comprise any of, but are not limited to the following: 
 sets of IP addresses;    ranges of addresses;    subnet masks;    other communities;    included elements; and    excluded elements.    
     
     
         6 . The apparatus of  claim 1 , wherein said rules are defined in terms of the following: 
 initiator communities;    target communities; and    services allowed.    
     
     
         7 . The apparatus of  claim 6 , wherein said services comprise, but are not limited to: 
 a set of port numbers; and    indicators of whether TCP or UDP protocols are used.    
     
     
         8 . A method for translating desired network security policy into a policy specification file, wherein said file is interpretable and implementable by a policy monitor mechanism, said method comprising: 
 providing a plurality of policy domains, wherein network traffic is monitored;    providing a plurality of communities of hosts; and    providing a plurality of rules for applying to said network traffic between said plurality of communities.    
     
     
         9 . The method of  claim 8 , wherein said each of said plurality of policy domains is as small as required by traffic monitoring limitations associated with said network traffic, and as large as specification of said plurality of rules allow.  
     
     
         10 . The method of  claim 8 , wherein each of said plurality of rules applies to network traffic anywhere within a particular of said plurality of policy domains.  
     
     
         11 . The method of  claim 8 , further comprising: 
 providing at least one perimeter element having a MAC address, whereby nodes visible through said at least one perimeter element are known, and whereby said MAC address is used to detect IP spoofing and to detect rogue routers.    
     
     
         12 . The method of  claim 8 , wherein communities comprise any of, but are not limited to the following: 
 sets of IP addresses;    ranges of addresses;    subnet masks;    other communities;    included elements; and    excluded elements.    
     
     
         13 . The method of  claim 8 , wherein said rules are defined in terms of the following: 
 initiator communities;    target communities; and    services allowed.    
     
     
         14 . The method of  claim 13 , wherein said services comprise, but are not limited to: 
 a set of port numbers; and    indicators of whether TCP or UDP protocols are used.    
     
     
         15 . A method for using a policy generator to generate a formal policy specification file compatible with a policy monitoring system, said method comprising: 
 providing a front end for entering and/or editing an initial policy;    upon satisfaction of said edited initial policy, writing said entered and/or edited initial policy to an intermediate file;    back end processing said intermediate file to said formal policy specification file.    
     
     
         16 . The method of  claim 15 , wherein said initial policy is entered from a file.  
     
     
         17 . The method of  claim 15 , said editing further comprising: 
 editing policy domains, communities, services, and rules.    
     
     
         18 . The method of  claim 15 , further comprising: 
 allowing simultaneously opening of a plurality of instances of editing processes.    
     
     
         19 . The method of  claim 18 , wherein data changed in one instance of said plurality of instances is reflected in other instances of said plurality of instances.  
     
     
         20 . The method of  claim 15 , wherein an editing entity is used before being fully defined.  
     
     
         21 . An apparatus for generating a formal policy specification file, said apparatus comprising: 
 predefined rules, credentials, and dispositions;    explicit rules and credentials; and    implicit rules and credentials.    
     
     
         22 . The apparatus of  claim 21 , wherein said predefined rules comprise, but are not limited to any of the following: 
 rules that do not conform to user-defined policy; and    rules for handling common network events not covered by said user-defined policy.    
     
     
         23 . The apparatus of  claim 21 , whereby associated with each of said predefined disposition is a disposition code and severity usable in a query tool for filtering network events.  
     
     
         24 . The apparatus of  claim 21 , wherein said predefined credentials are combined with dynamically generated credentials and used in said implicit rules, and wherein said predefined credentials are named in a way ensuring uniqueness.  
     
     
         25 . The apparatus of  claim 21 , wherein when defining an explicit rule, the following information is provided: 
 zero, one, or more initiator communities;    zero, one, or more service; and    zero, one, or more target communities.    
     
     
         26 . The apparatus of  claim 25 , whereby a plurality of rules are generated for a service when said service serves a corresponding plurality of protocols.  
     
     
         27 . The apparatus of  claim 25 , wherein if more than one of said initiator communities are specified, then a credential combining said communities into a union is generated.  
     
     
         28 . The apparatus of  claim 25 , wherein if more than one of said target communities are specified, then a credential combining said communities into a union is generated.  
     
     
         29 . The apparatus of  claim 25 , wherein if more than one of said services are specified, then said services are combined with said target credentials according to service type.  
     
     
         30 . The apparatus of  claim 25 , wherein no service is specified, then a single target community credential is used to identify a target principal.  
     
     
         31 . The apparatus of  claim 21 , for each policy domain within a policy specification, further comprising: 
 means for generating a set of rules and credentials defining valid IP-level network traffic detected at a monitoring point within said domain;    means for generating a plurality of ICMP rules for handling all intradomain ICMP traffic; and    means for generating a credential for said monitoring point in said each domain.    
     
     
         32 . The apparatus of  claim 31 ,wherein said monitoring point is based on an agent descriptor.  
     
     
         33 . The apparatus of  claim 31 ,wherein all intradomain ICMP traffic is segregated by the use of at least one rule.  
     
     
         34 . The apparatus of  claim 21 ,wherein IP traffic is described by said implicit rules enumerating all valid traffic within a policy domain, between hosts in said domain and external hosts, and between hosts through said policy domain.  
     
     
         35 . The apparatus of  claim 34 , wherein: 
 a first IP rule provisionally allows all intradomain IP traffic;    an intradomain IP rule of said all intradomain IP traffic uses a defining community associated with said policy domain as target principal; and    a second intradomain IP rule is used to segregate broadcast and multicast traffic within an enterprise network.    
     
     
         36 . The apparatus of  claim 34 , wherein if a plurality of external communities exist, said communities associated with at least one perimeter element for which an interface address is not known, a credential combining all said communities in a single union is generated.  
     
     
         37 . The apparatus of  claim 36 , wherein two rules defining traffic between hosts internal to said policy domain and said external communities are generated.  
     
     
         38 . A method for generating a formal policy specification file, said method comprising: 
 providing predefined rules, credentials, and dispositions;    providing explicit rules and credentials; and    providing implicit rules and credentials.    
     
     
         39 . The method of  claim 38 , wherein said predefined rules comprise, but are not limited to any of the following: 
 rules that do not conform to user-defined policy; and    rules for handling common network events not covered by said user-defined policy.    
     
     
         40 . The method of  claim 38 , whereby associated with each of said predefined disposition is a disposition code and severity usable in a query tool for filtering network events.  
     
     
         41 . The method of  claim 38 , wherein said predefined credentials are combined with dynamically generated credentials and used in said implicit rules, and wherein said predefined credentials are named in a way ensuring uniqueness.  
     
     
         42 . The method of  claim 38 , wherein when defining an explicit rule, the following information is provided: 
 zero, one, or more initiator communities;    zero, one, or more service; and    zero, one, or more target communities.    
     
     
         43 . The method of  claim 42 , whereby a plurality of rules are generated for a service when said service serves a corresponding plurality of protocols.  
     
     
         44 . The method of  claim 42 , wherein if more than one of said initiator communities are specified, then a credential combining said communities into a union is generated.  
     
     
         45 . The method of  claim 42 , wherein if more than one of said target communities are specified, then a credential combining said communities into a union is generated.  
     
     
         46 . The method of  claim 42 , wherein if more than one of said services are specified, then said services are combined with said target credentials according to service type.  
     
     
         47 . The method of  claim 42 , wherein no service is specified, then a single target community credential is used to identify a target principal.  
     
     
         48 . The method of  claim 38 , for each policy domain within a policy specification, further comprising: 
 generating a set of rules and credentials defining valid IP-level network traffic detected at a monitoring point within said domain;    generating a plurality of ICMP rules for handling all intradomain ICMP traffic; and    generating a credential for said monitoring point in said each domain.    
     
     
         49 . The method of  claim 48 ,wherein said monitoring point is based on an agent descriptor.  
     
     
         50 . The method of  claim 48 , wherein all intradomain ICMP traffic is segregated by the use of at least one rule.  
     
     
         51 . The method of  claim 38 , wherein IP traffic is described by said implicit rules enumerating all valid traffic within a policy domain, between hosts in said domain and external hosts, and between hosts through said policy domain.  
     
     
         52 . The method of  claim 51 , wherein: 
 a first IP rule provisionally allows all intradomain IP traffic;    an intradomain IP rule of said all intradomain IP traffic uses a defining community associated with said policy domain as target principal; and    a second intradomain IP rule is used to segregate broadcast and multicast traffic within an enterprise network.    
     
     
         53 . The method of  claim 51 , wherein if a plurality of external communities exist, said communities associated with at least one perimeter element for which an interface address is not known, a credential combining all said communities in a single union is generated.  
     
     
         54 . The method of  claim 53 , wherein two rules defining traffic between hosts internal to said policy domain and said external communities are generated.

Join the waitlist — get patent alerts

Track US2004039942A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.