发明名称 Policy enforcement based on dynamically attribute-based matched network objects
摘要 A policy that includes an address group is received. The policy is compiled into a set of one or more rules. The compiling is performed at least in part by determining members of the address group. The compiling can further include substituting one or more IP addresses of the members for the address group. At least one rule included in the set of rules is enforced.
申请公布号 US9537891(B1) 申请公布日期 2017.01.03
申请号 US201314137718 申请日期 2013.12.20
申请人 Palo Alto Networks, Inc. 发明人 Walter Martin;Fitz-Gerald Jeffrey
分类号 G06F15/173;H04L29/06;H04L29/12 主分类号 G06F15/173
代理机构 Van Pelt, Yi & James LLP 代理人 Van Pelt, Yi & James LLP
主权项 1. A system, comprising: a processor configured to: receive a policy that includes an address group object, wherein the address group object abstracts a set of computing assets;compile the policy into a set of one or more rules, at least in part by substituting, for the address group object, a set of one or more IP addresses of computing assets determined to be members of an address group corresponding to the address group object, wherein determining the members of the address group includes querying a set of one or more repositories of computing asset information using a set of match criteria, wherein at least one criterion in the set of match criteria pertains to a characteristic of a computing asset;determine, based at least in part on a detected change to the address group, that at least one rule included in the set of rules should be recompiled;in response to the determination, perform a recompilation, including by substituting a first IP address in an out-of-date rule for a second IP address to create an updated rule; andenforce the updated rule at least one rule; and a memory coupled to the processor and configured to provide the processor with instructions.
地址 Santa Clara CA US