US2008209504A1PendingUtilityA1

Generalized network security policy templates for implementing similar network security policies across multiple networks

Assignee: BONN DAVID WAYNEPriority: May 6, 1999Filed: Oct 17, 2007Published: Aug 28, 2008
Est. expiryMay 6, 2019(expired)· nominal 20-yr term from priority
H04L 9/40H04L 63/105H04L 63/1425Y10S707/99939H04L 63/20H04L 63/0263
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present invention is directed to a facility for adapting a network security policy model for use in a particular network. The facility retrieves the network security policy model, which comprises network security rules each specified with respect to one or more aliases. Each alias represents a role in a network for one or more network elements. The facility receives, for each alias included in the network security policy model, a list of one or more network elements in the network serving the role represented by the alias. The facility replaces each alias in the network security policy model with the received list of network security devices specified for the alias to produce a network security policy adapted for use in a network.

Claims

exact text as granted — not AI-modified
1 - 13 . (canceled) 
     
     
         14 . A method in a computer system for adapting a generalized network security policy to a particular network, comprising:
 retrieving the generalized network security policy comprising a plurality of network security rules each specified with respect to aliases each representing a role for one or more network elements in a network;   providing a user interface for specifying, for each alias included in the generalized network security policy, a list of one or more network elements in the network serving the role represented by the alias; and   replacing each alias in the generalized network security policy with the list of network elements specified for the alias using the user interface to produce a network security policy adapted to the network.   
     
     
         15 . The method of  claim 14 , further comprising the step of selecting the generalized network security policy from among a plurality of alternative generalized network security policies based upon the nature of the network. 
     
     
         16 . The method of  claim 14 , further comprising implementing the produced network security policy in the network to provide network security services in the network in accordance with the generalized network security policy. 
     
     
         17 . The method of  claim 14 , further comprising:
 providing a user interface for specifying additional rules relating to the network; and   merging the additional rules specified using the user interface into the network security policy.   
     
     
         18 . A computer-readable medium whose contents cause a computer system to adapt a network security policy model for use in a particular network, comprising:
 retrieving the network security policy model, which comprises a plurality of network security rules each specified with respect to one or more aliases each representing a role in a network for one or more network elements;   receiving, for each alias included in the network security policy model, a list of one or more network elements in the network serving the role represented by the alias; and   replacing each alias in the network security policy model with the received list of network elements specified for the alias to produce a network security policy adapted for use in the network.   
     
     
         19 . The computer-readable medium of  claim 18  wherein the contents of the computer-readable medium further cause the computer system to select the retrieved network security policy model from among a plurality of alternative network security policy models in response to user input. 
     
     
         20 . The method of  claim 18  wherein the contents of the computer-readable medium further cause the computer system to implement the produced network security policy in the network to provide network security services in the network in accordance with the network security policy model. 
     
     
         21 - 23 . (canceled) 
     
     
         24 . A computer memory storing a security policy template data structure, the data structure comprising a plurality of computer security directives specifying action to be taken in connection with network traffic between pairs of network nodes, the nodes of each pair being specified in terms of the roles of the nodes rather than in terms of the identity of the nodes, such that, for a subject computer network, the identities of the nodes in the subject computer network having the roles contained in the policy template data structure can be substituted for roles contained in the policy template data to produce a network security policy adapted to the subject network. 
     
     
         25 . A computer memory storing a network security policy data structure for a protected network, the data structure comprising one or more network security rules, each rule expressed in terms of specific network elements of the protected network, each rule having been converted from a model rule expressed in terms of types of network elements by substituting in the model rule for each type of network element a network element of the protected network of that type, such that the network security policy data structure may be implemented to provide networks security services in the protected network. 
     
     
         26 . A data transmission network conveying a network security policy data structure for a protected network to a security device for the protected network, the data structure comprising one or more network security rules, each rule expressed in terms of specific network elements of the protected network, each rule having been converted from a model rule expressed in terms of types of network elements by substituting in the model rule for each type of network element a network element of the protected network of that type, such that the network security policy data structure may be implemented to provide networks security services in the protected network. 
     
     
         27 . A method in a computer system for obtaining information usable to produce a network security policy for a network comprising:
 displaying a plurality of network element aliases used in a network security policy template;   with respect to each of the displayed network element aliases, receiving user input specifying one or more network addresses of network elements within the network; and   storing the specified network addresses.   
     
     
         28 . A computer-readable medium whose contents cause a computer system to perform a method for producing network security policy for a network the method comprising:
 displaying a plurality of network element aliases used in a network security policy template; with respect to each of the displayed network element aliases, receiving user input specifying one or more network addresses of network elements within the network; and   storing the specified network addresses.   
     
     
         29 . The method of  claim 27 , further comprising:
 with respect to each of the displayed network element aliases, substituting for occurrences of the network element alias in a network security policy the network addresses specified for the network element alias; and   after the substitution, persistently storing the network security policy.   
     
     
         30 . The computer-readable medium of  claim 28  wherein the method further comprises:
 with respect to each of the displayed network element aliases, substituting for occurrences of the network element alias in a network security policy the network addresses specified for the network element alias; and   after the substitution, persistently storing the network security policy.

Join the waitlist — get patent alerts

Track US2008209504A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.