Unlock instant, AI-driven research and patent intelligence for your innovation.

A security policy adaptive generation management system and method based on SDN

A security policy and management system technology, applied in the field of SDN-based security policy adaptive generation management system, can solve the problems of lack of network security policy management, lack of security device linkage, lack of unified management of multiple policies, etc. The effect of protection

Active Publication Date: 2018-08-03
CHINA ELECTRONICS TECH CYBER SECURITY CO LTD
View PDF5 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0006] 2) The existing policy management methods lack policy management related to network security;
[0007] 3), most of the existing policy management methods are one method for one control method, lack of unified management for multiple strategies at the same time;
[0008] 4) The existing policy control method cannot be combined with the security situation information in the cloud environment for self-adaptive adjustment, and lacks the function of linkage with security devices for on-demand protection

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • A security policy adaptive generation management system and method based on SDN
  • A security policy adaptive generation management system and method based on SDN
  • A security policy adaptive generation management system and method based on SDN

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0062] In order to better understand the present invention, the present invention will be described in detail below in conjunction with the accompanying drawings.

[0063] Such as figure 1 As shown, an SDN-based security policy adaptive generation management system of the present invention, the SDN-based security policy adaptive generation management system is connected with the NFV resource pool and the virtual machine resource pool, and provides security policy self-adaptation for the cloud environment Generate management; the NFV resource pool includes an IDS server, an IPS server, a traffic cleaning server, a load balancing server, and a security protection device; the SDN-based security policy adaptive generation management system includes formulating different detection rules to realize different information collection A safety detection module, a data analysis and decision-making module that performs data analysis and mining on the data collected by the safety detection...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention provides an adaptive generation management system of a security strategy based on SDN. The adaptive generation management system is connected with an NFV resource pool and a virtual machine resource pool for providing adaptive generation management of the security strategy for a cloud environment; the adaptive generation management system comprises a security detection module, a data analysis and decision module, a unified security strategy management module and a switch module; the security detection module comprises a detection rule formulation module, a flow perception module, a packet detection module, a security event data collection module and other detection modules; the security detection module further comprises a detection information acquisition interface module used for providing interfaces for the flow perception module, the packet detection module, the other detection modules and the security event data collection module for acquiring external detection information; and the data analysis and decision module comprises a security strategy template base, a data mining analysis module, a security strategy formulation module, a security strategy storage module, a security strategy transmission module and a security strategy interface module.

Description

technical field [0001] The invention relates to the technical field of virtualization, in particular to an SDN-based security policy self-adaptive generation management system and method. Background technique [0002] The emergence of SDN (Software Defined Networking) has realized the flexible management and control of the network. Through the separation of network forwarding and control, the flexible and programmable network control is achieved, which meets the demand for flexible network changes according to application changes. SDN-based network policy management can be converted into specific control commands through the application software in the SDN application layer, and sent to the actual equipment of the network infrastructure to realize the management and control of the actual equipment. [0003] Based on the flexibility of the SDN control module, various network controls can be realized: for example, after receiving and sending buffer overflow traffic, the SDN sw...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06
CPCH04L63/20H04L63/205
Inventor 齐伟钢白杨杨振宇
Owner CHINA ELECTRONICS TECH CYBER SECURITY CO LTD