发明名称 METHOD AND SYSTEM FOR MANAGING SECURITY POLICIES
摘要 A system and method of managing security policies in an information technologies (IT) system are provided. In an example, the method includes receiving an input indicating a high-level security policy for the IT system, the received high-level security policy relating to non-functional system attributes for the IT system and received in a format that is not machine-enforceable at an enforcement entity of the IT system. A functional model for the IT system is determined, where the functional model indicates functional system attributes of the IT system. At least one pre-configured rule template is loaded, and at least one machine-enforceable rule is generated in a manner compliant with the received high-level security policy by iteratively filling the at least one pre-configured rule template with functional system attributes indicated by the functional model. After the generating step, the at least one machine-enforceable rule can be distributed (e.g., to an enforcement entity, an Intrusion Detection System (IDS), etc.). In another example, the receiving, determining, loading, generating and distributing steps can be performed at a policy node within an IT system.
申请公布号 WO2009036896(A4) 申请公布日期 2009.07.16
申请号 WO2008EP07253 申请日期 2008.09.05
申请人 OBJECTSECURITY LTD.;LANG, ULRICH;SCHREINER, RUDOLF 发明人 LANG, ULRICH;SCHREINER, RUDOLF
分类号 H04L29/06;G06F9/45 主分类号 H04L29/06
代理机构 代理人
主权项
地址