发明名称 SYSTEM AND METHOD FOR MONITORING APPLICATION SECURITY IN A NETWORK ENVIRONMENT
摘要 A method includes determining an application role in a distributed application in a network environment, generating a role profile for the application role from an interaction pattern, mapping the role profile to a virtual machine (VM), and detecting a security breach of the VM. Determining the application role includes obtaining network traces from the distributed application, and analyzing the network traces to extract the application role. In one embodiment, detection of the security breach includes generating an access control policy for the VM from the role profile, and determining an anomaly in traffic based thereon. In another embodiment, detection of the security breach includes inserting the role profile in a port profile of the VM, generating a small state machine from the role profile, running the small state machine on a port associated with the VM, and inspecting, by the small state machine, an application level traffic at the port.
申请公布号 US2013298184(A1) 申请公布日期 2013.11.07
申请号 US201213462110 申请日期 2012.05.02
申请人 ERMAGAN VINA;NELLIKAR SURAJ;SRIDHARA RAO SUDARSHANA KANDACHAR;MAINO FABIO R.;MENARINI MASSIMILIANO;CISCO TECHNOLOGY, INC. 发明人 ERMAGAN VINA;NELLIKAR SURAJ;SRIDHARA RAO SUDARSHANA KANDACHAR;MAINO FABIO R.;MENARINI MASSIMILIANO
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址