发明名称 System and method for threat-driven security policy controls
摘要 Methods, systems, and media for a security system are provided herein. Exemplary methods may include: acquiring a firewall security policy from a policy compiler; receiving network traffic originating from a source machine and directed to a destination machine; analyzing the network traffic using the firewall security policy; forwarding or dropping each of the network traffic according to the security policy; accumulating the network traffic and metadata associated with the network traffic; and initiating an update to the firewall security policy by the policy compiler using at least one of the accumulated network traffic and metadata.
申请公布号 US9294442(B1) 申请公布日期 2016.03.22
申请号 US201514673679 申请日期 2015.03.30
申请人 vArmour Networks, Inc. 发明人 Lian Jia-Jyi;Paterra Anthony;Woolward Marc
分类号 H04L29/06 主分类号 H04L29/06
代理机构 Carr & Ferrell LLP 代理人 Carr & Ferrell LLP
主权项 1. A system comprising: a source machine; a destination machine; a policy compiler; and an enforcement point communicatively coupled via a network to the source machine, the destination machine, and the policy compiler, the enforcement point including a processor and a memory communicatively coupled to the processor, the memory storing instructions executable by the processor to perform a method including: acquiring a firewall security policy from the policy compiler;receiving network traffic originating from the source machine and directed to the destination machine;analyzing the network traffic using the firewall security policy;forwarding or dropping the network traffic according to the firewall security policy;accumulating the network traffic and metadata associated with the network traffic; andinitiating an update to the firewall security policy by the policy compiler using at least one of the network traffic and the metadata, the initiating the update to the firewall security policy by the policy compiler comprising:receiving information associated with the source machine and the destination machine from an external system of record;weighting one or more of a redirected network packet, further network traffic, the metadata, and the received information;statistically analyzing the weighted one or more of the redirected network packet, the further network traffic, the metadata, and the received information to calculate an updated risk score; andproviding the updated risk score to the policy compiler, such that the policy compiler produces an updated security policy.
地址 Mountain View CA US