Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

70 results about "Network security policy" patented technology

A network security policy (NSP) is a generic document that outlines rules for computer network access, determines how policies are enforced and lays out some of the basic architecture of the company security/ network security environment. The document itself is usually several pages long and written by a committee. A security policy goes far beyond the simple idea of "keep the bad guys out". It's a very complex document, meant to govern data access, web-browsing habits, use of passwords and encryption, email attachments and more. It specifies these rules for individuals or groups of individuals throughout the company.

System and method for policy management in cloud computing environments

A system and method for cybersecurity policy management in a computing environment is presented. The method includes receiving a selection of a first cybersecurity policy of a digital security platform of a computing environment; applying the first cybersecurity policy to generate a first measurement; generating a second cybersecurity policy based on the first cybersecurity policy and a result of the first measurement; applying the second cybersecurity policy to generate a second measurement; generating a third cybersecurity policy based on a result of the second measurement and the second cybersecurity policy; and applying the third cybersecurity policy on the computing environment.
Owner:CYERA LTD

Biological monitoring equipment fault-tolerant control method based on network security policy

The invention discloses a biological monitoring equipment fault-tolerant control method based on a network security policy, and relates to the technical field of medical equipment management, and the method comprises the steps: S1, obtaining a historical operation log monitored by biological monitoring equipment, extracting a service life, combining with a time sequence data sequence and fault history, fusing long-term dependence capture, and forming an initial data set; s2, processing the initial data set through a long short-term memory network, capturing a time sequence dependency relationship between performance degradation and fault history by applying a forgetting gate mechanism and input gate control, obtaining a quantization vector of a change trend by utilizing output gate adjustment and cell state updating, and fusing hidden state output; according to the biological monitoring equipment fault-tolerant control method based on the network security policy, the reliability and the fault-tolerant capability of wetland zone micro algae monitoring equipment are remarkably improved, the service life of the equipment is prolonged, and the maintenance cost is reduced.
Owner:NANJING INST OF ENVIRONMENTAL SCI MINIST OF ECOLOGY & ENVIRONMENT OF THE PEOPLES REPUBLIC OF CHINA

Network security policy optimization method and system

The invention relates to the technical field of network security, and provides a network security policy optimization method and system, and the method comprises the steps: obtaining a detection sensitivity adjustment record of a process of adjusting and managing a network communication mode through a self-adaptive network security system, and carrying out the optimization of a network security policy based on the detection sensitivity adjustment record; identifying a communication mode in which the detection sensitivity is continuously reduced; performing multi-dimensional risk re-assessment on the communication mode to obtain a multi-dimensional risk re-assessment result; the multi-dimensional risk re-assessment comprises the steps of performing association analysis on the communication mode and a preset abnormal behavior to obtain association analysis information; obtaining the current state and operation logic of the industrial production process; verifying the rationality of the communication mode in the industrial control system in combination with the current state and the operation logic to obtain rationality verification information; and according to a multi-dimensional risk re-assessment result, adjusting and optimizing a security policy, and generating and sending alarm information. The method has the effect of improving the network security protection level of the industrial control system.
Owner:ZHICHENG TECH CO LTD

Intelligent network security policy optimization system based on SPF algorithm

The invention discloses a network security policy intelligent optimization system based on an improved SPF algorithm, and belongs to the technical field of network security. According to the system, by constructing a network security topological graph, network assets, services and users are defined as nodes of the graph, and potential access relations are defined as edges. A multi-dimensional and dynamically quantized'security risk index 'is provided as a weight of an edge, and the index integrates multiple dimensions. An improved SPF algorithm is adopted, and a lowest risk path from any source node to a target node is calculated. And according to the calculated optimal path, a refined access control strategy is automatically generated and issued, and redundancy analysis and optimization suggestion are carried out on the existing strategy. According to the method, the problems that a traditional security policy is complex in configuration, prone to errors and incapable of adapting to dynamic risk changes are solved, conversion from static and passive access control to dynamic and active risk path optimization is achieved, and the intelligent level and overall security of network security defense are remarkably improved.
Owner:INNER MONGOLIA AUTONOMOUS REGION METEOROLOGICAL INFORMATION CENT (INNER MONGOLIA AUTONOMOUS REGION AGRI & ANIMAL HUSBANDRY ECONOMIC INFORMATION CENT) (INNER MONGOLIA AUTONOMOUS REGION METEOROLOGICAL ARCHIVES)

Network security policy full-life-cycle self-adaptive tuning system based on intelligent calculation driving

The invention discloses a network security policy full-life-cycle adaptive tuning system based on intelligent computation driving, relates to the technical field of network security, and is used for solving the problems of policy adaptation and efficiency balance under resource limitation. The method comprises the following steps: firstly, predicting an attack probability and mapping a topological weight by using an LSTM combined with an attention mechanism, and generating a risk prediction vector; then, performing weighted pruning on the rule based on the computing power constraint and the flow priority, and generating an execution state strategy packet; after issuing, monitoring a delay increment and an interception hit rate during operation, and generating a regular degradation instruction for a low-efficiency and high-consumption rule; and finally, regular scanning parameters are adjusted through gradient optimization, a self-adaptive system from risk pre-judgment to closed-loop optimization is constructed, and intelligent support is provided for network security defense.
Owner:广州云峰信息科技有限公司

Multimodal content interpretation of digital assets

A method of managing a computer network includes: receiving, at a network port, a stream of multimodal data; obtaining, from the multimodal data, a subset of the multimodal data that corresponds to a modality; determining, using a large-language model (LLM) agent, a semantic context of the subset of the multimodal data; determining, based on the semantic context and among a plurality of network policies, a network security policy corresponding to the subset of the multimodal data; and directing the subset of the multimodal data according to the network security policy.
Owner:AURASCAPE INC

Automation of cloud network security policy analysis and deployment

Disclosed are examples of systems, apparatus, methods and computer program products for automation of network security policy analysis and deployment. A server system can obtain a system input comprising two versions of a policy output. The system can generate a severity characteristic that indicates a severity of deploying the second version of the policy output. The system can then determine whether to deploy the second version of the policy output based on the severity characteristic. The system can then, in response to determining that the second version of the policy output is to be deployed, deploy the second version of the policy output to one of a plurality of clouds.
Owner:SALESFORCE INC

Self-adaptive dynamic network security policy intelligent regulation and control method

The invention relates to the technical field of network security, and particularly discloses a self-adaptive dynamic network security policy intelligent regulation and control method, which comprises the following steps of: respectively extracting a communication link abnormal characteristic value and a channel disturbance characteristic value by monitoring a quantum bit error rate and communication channel signal strength in network traffic in real time; wherein high-sensitivity identification of quantum noise interference is realized based on Bayesian reasoning, and robustness of external interference detection is improved based on Haar wavelet transform; fusing the two types of features into a comprehensive security risk feature vector, inputting the comprehensive security risk feature vector into a gradient boosting tree model for training, outputting a network security score by taking minimization of a prediction score error as a target, and dividing threat levels according to the network security score; the system automatically adjusts the protection strategy according to the security level, and forms closed-loop optimization control through continuous feedback, thereby improving the adaptability and active defense capability of the network system, and solving the problems of security response lagging and inaccurate strategy adjustment in a complex environment in the prior art.
Owner:HEFEI TANOVO INFORMATION SECURITY TECH CO LTD

Industrial internet security operation and maintenance risk assessment method and system

The invention discloses an industrial internet security operation and maintenance risk assessment method and system, and relates to the technical field of data management.The industrial internet security operation and maintenance risk assessment method comprises the steps that initial information collection is conducted on an industrial internet operation environment, risk links are constructed, and primary risk links are further analyzed and screened out; then obtaining dynamic operation data of each primary risk link, performing priority ranking based on the dynamic comprehensive risk score, and dynamically adjusting response triggering measures of the primary risk links at the same time to realize pertinence and timeliness of risk disposal; and finally, through cross validation of multi-level risk links, evaluation of actual effects of each adjustment measure and fine adjustment of a network security policy, potential risks can be effectively identified and quantified, a protection policy can be dynamically adjusted, the high-risk link disposal efficiency can be improved, and the security and stability of the whole system can be ensured. Therefore, the scientificity, controllability and reliability of industrial internet security operation and maintenance are obviously enhanced.
Owner:BEIJING HI TECH TECH

Online check network security implementation of multi-part file transfer

On the granularity of a single application layer session, sensing and flow processing of multi-part file transmission of different application programs are separated, and efficient network security implementation on multi-part file transmission is promoted. A protocol-based multi-part file transfer regulator ("regulator") determines a per-session message handling action to prevent completion of the multi-part file transfer based on the protocol of the application identified for the session until a network security analysis can be performed. The regulator then communicates the message handling action to a network component that supports the session. The regulator maintains information and file chunks for active sessions in a data store and uses the data store to determine whether conditions requesting network security analysis for multi-part file transfers are satisfied. Upon obtaining a network security analysis decision, the regulator provides the decision or decision-based instructions to the network component, which ensures that the multi-part file transfer conforms to the network security policy (s).
Owner:PALO ALTO NETWORKS INC

Software-defined network flow rule security detection and tracing method and device

The present application relates to a method and device for security detection and tracing of software-defined network flow rules, wherein the method includes: intercepting the current network top-level security policy, forwarding rules and flow rules stored in the data plane from a preset software-defined network controller, and converting the security policy into a concrete security rule based on a preset conversion rule; encoding and storing the security rules, forwarding rules and flow rules based on a preset data structure, and calculating the actual scope of each rule; simulating the actual behavior of data packets in the network and the security behavior that meets the security policy requirements through a pre-established network topology-hardware device-logical function network behavior model, identifying unsafe network behavior, and tracing it back to the unsafe network rules that caused the behavior. Thus, the technical problem that it is difficult to verify the consistency of network behavior with network security policy, and that the general verification tools used are slow and not timely, is solved, thereby improving the user experience.
Owner:BEIHANG UNIV

Network traffic multi-level security protection model, system, method, equipment and medium

PendingCN121283684ASecuring communicationDeclarative networkingRate limiting
The invention provides a network flow multi-level security protection model, system, method, equipment and medium. According to the method, a plurality of modularized atomization protection points are constructed through a predefined eBPF program library, and network control capabilities such as matching, speed limiting and state observation are realized. In a system initialization stage, a data plane architecture comprising a plurality of kernel execution layer dispatcher programs is constructed, and persistence of the programs and resource Map is realized through pin operation. The declarative network security policy is received through the SDK module, the policy control module analyzes the declarative network security policy to generate a configuration parameter, and the user mode module loads an eBPF program according to the configuration parameter and mounts the eBPF program to a kernel execution layer. The network flow triggers a protection point according to a path and outputs observation data; and the state aggregation sub-module aggregates the data according to the strategy and feeds information back to the upper-layer application. Therefore, flexible deployment of protection points and strategy dynamic driving can be realized, and the method has good expandability and response capability.
Owner:KYLIN CORP

Network device optimization method and apparatus, computer device and storage medium

The application discloses a network device optimization method and device, computer equipment and a storage medium, the method comprises the following steps: obtaining the network security policy table of a target network device; determining the network security policy group with a policy relationship in the network security policy table based on the policy action, the policy virtual wall and the communication five tuple information; performing optimization processing on the network security policy table based on the policy relationship of the network security policy group, to obtain an optimized network security policy table; and performing optimization processing on the target network device based on the optimized network security policy table, to obtain an optimized target network device. The network security policy table after optimization can effectively sort out and optimize the network security policy of the target network device, and since no human intervention is required throughout the process, the management efficiency is effectively improved while ensuring the accuracy of management.
Owner:ASPIRE TECH (SHENZHEN) LTD

Intent-based policy configuration using natural language

Techniques are described for providing a natural language network security policy assistant for allowing a network administrator to implement network security policies using natural language security policy requests. A natural language request can be received by a user and can be translated using Artificial Intelligence into one or more security policy clauses. If the natural language security policy request leads to ambiguities with regard to intended security policies, one or more clarifying questions can be generated as natural language questions and sent to the user for clarification. One or more security policies can be implemented based on the one or more security policy clauses generated in response to the natural language security policy request and / or the natural language response to the clarifying questions.
Owner:CISCO TECHNOLOGY INC

Service access method and equipment

The invention provides a service access method and equipment. The method is applied to a first device, and the method comprises the following steps: obtaining a first corresponding relationship between a plurality of service names and a plurality of service identities (ID); a first service ID corresponding to the first service name is determined according to the first corresponding relation, and the first service name comprises the service name of the source service and / or the service name of the target service; and sending a first message to a second device where the target service is located, wherein the first message comprises the first service ID. In the technical scheme, when service access is carried out, service information can be directly associated by carrying the service ID in the first message, so that a manager can configure a network security policy based on the service information, and a source service or a target service of service access can be limited to improve network security.
Owner:PETAL CLOUD TECH CO LTD

MAC address management method of MES system

The invention relates to the technical field of industrial control system safety, in particular to an MAC address management method of an MES system. Comprising the following steps: receiving contextual data related to a manufacturing process from a manufacturing execution system in real time, such as a work order state, an equipment operation mode, a bill of materials and operator allocation; the method comprises the following steps of: finding equipment connected to an OT network and a corresponding MAC (Media Access Control) address in a mode of passively monitoring and actively querying a network switch; in a central data storage library, the found MAC address is associated with context data obtained from an MES, and a dynamic identity portrait with rich situations is established for each device; dynamically generating a network access strategy with timeliness and a minimum permission principle for the equipment on the basis of the association relationship; finally, an instruction is sent to the network switch to enforce the policy. According to the method, the network security policy is bound with the actual production plan, so that the security of the industrial network is remarkably improved on the premise of ensuring the production continuity.
Owner:SUZHOU FANGTU INFORMATION TECHNOLOGY CO LTD

Domain name resolution method, system and device based on DNS proxy identity authentication and policy control

The invention provides a domain name resolution method, system and device based on DNS proxy identity authentication and strategy control, and belongs to the technical field of computer network DNS resolution. The method comprises the following steps: receiving a DNS request of a client by a DNS agent, and extracting a query domain name and a client source IP (Internet Protocol); the DNS agent obtains a locally stored device ID, wherein the device ID is a 16-byte global unique identifier; constructing an EDNSOPT record containing a device ID and a timestamp; setting an option code as a private value 0xFF01; the data part comprises a 4-byte UNIX timestamp and a 16-byte equipment ID (Identity); adding the EDNSOPT record to an additional part of the DNS request message, and forwarding the EDNSOPT record to a DNS server; the DNS server executes a dynamic strategy decision; executing strategy matching on the verified request; and returning the DNS response message to the client through the DNS agent. According to the invention, the uniqueness authentication of the equipment is realized, the accuracy of equipment identification is obviously improved, and a solid foundation is provided for the implementation of a network security policy.
Owner:SHANDONG FUTURE NETWORK RES INST (PURPLE MOUNTAIN LAB IND INTERNET INNOVATION APPL BASE)

Creating graphical models of network security policies and displaying on a network topology graph

Techniques and architecture are described for abstracting a real physical twin network wherein security policies are mapped as an overlay on a graphical representation of the network topology. The techniques include receiving, at a computing device, a first security policy) for a first network device. The computing device processes the first security policy to generate a plurality of first access control entries. The computing device creates first graph nodes corresponding to the first access control entries. Based at least in part on a processing order of the first security policy on the first network device, the computing device links the first graph nodes into a graph. The computing device displays the graph on a display, wherein the graph is displayed as an overlay on a network topology graph that includes the first network device.
Owner:CISCO TECHNOLOGY INC

Policy and traffic management in an overlay network

Technique or mechanism in which network security policies are applied close to the source or origin associated with policy decisions. For example. the disclosed technology moves dropped flows from a firewall cluster to a leaf switch based on host location.
Owner:GOOGLE LLC

Enterprise data security access management method and system

The invention discloses an enterprise data security access management method and system, and relates to the technical field of security access management, and the method comprises the steps: constructing a broadcast source fingerprint matrix of broadcast data in a target enterprise; constructing a trust mask matrix of an enterprise building broadcast domain based on the network security policy table of the target enterprise, and performing line-by-line mask cutting on the broadcast source fingerprint matrix based on the trust mask matrix to obtain a broadcast source cutting matrix; calculating a bucket-level occupation matrix of broadcast buckets in the enterprise building broadcast domain according to the block aggregation matrix and the broadcast source clipping matrix of the enterprise building broadcast domain; and calculating a delay matrix of the broadcast bucket based on the column cyclic shift matrix and the bucket-level occupancy matrix of the enterprise building broadcast domain. According to the method, the dynamic adaptive capacity and the control closed-loop capacity of the enterprise data security policy are improved.
Owner:SHENZHEN SHENYITONG INFORMATION TECHNOLOGY CO LTD

A self-adaptive deployment method and system for a signal creation heterogeneous environment

The present application relates to the technical field of cloud computing platform automation deployment, and particularly relates to a self-adaptive deployment method and system for a heterogeneous environment of a signal creation, and to three major technical bottlenecks of low multi-CPU architecture adaptation efficiency, frequent software dependency conflicts and complex security baseline configuration in the process of localization, and an intelligent heterogeneous computing resource scheduling engine and a dynamic security policy generation mechanism are innovatively proposed. The method comprises: constructing a heterogeneous resource portrait through hardware feature automatic identification technology, and realizing component installation sequence optimization based on a DAG dependency relationship analysis algorithm and Kahn topological sorting; creating an adaptive network security policy, and realizing real-time perception of the target system firewall state through a probe. Compared with the traditional deployment mode, the present application supports cross-architecture compatibility, solves the problem of dependency conflicts, improves the deployment efficiency, and guarantees the consistency and security of the system.
Owner:TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Network security policy updating method, device, equipment and medium

The invention relates to the technical field of networks, and discloses a network security policy updating method and device, equipment and a medium, and the method comprises the steps: obtaining target communication behavior data of communication between a source environment unit and a target environment unit deployed in a containerized environment in real time, and communication behavior clustering centers, and according to all the communication behavior clustering centers, updating a network security policy according to the target communication behavior data; and analyzing the target communication behavior data to obtain an analysis result, inputting the target communication behavior data and the analysis result into a model subjected to communication behavior classification training to obtain a classification result, and updating a current security policy of communication between the source environment unit and the target environment unit according to the classification result to obtain an updated security policy. The method can be applied to an intelligent inquiry scene in the field of medical health, realizes dynamic updating of the network security policy, and improves the communication security.
Owner:PING AN PAY ELECTRONIC PAYMENT CO LTD

Behavioral graph firewall policy

Techniques and systems described herein relate to a security system for a network or other monitored system of computing devices, such as a firewall system. The techniques and systems provide for generation of behavioral graphs based on observed network and / or system traffic during an observation period and subsequent creation of a network security policy using the behavioral graph as the framework for the network security policy. The techniques and systems additionally provide for manipulation, evaluation, and querying of network security policies through the use of matrix operations on behavioral graphs and plain text inputs and querying of the behavioral graph to form a network security policy.
Owner:CISCO TECHNOLOGY INC

Inferential analysis using feedback for extracting and combining cyber risk information

Inferential analysis includes: assessing risk of a cyber security failure in a computer network of an entity, using a computer agent configured to collect information from at least one accessible Internet elements, automatically determining, based on the assessed risk, a change or a setting to at least one element of policy criteria of a cyber security policy; and automatically recommending, based on the assessed risk, a computer network change to reduce the assessed risk.
Owner:GUIDEWIRE SOFTWARE INC

Techniques for dynamic compact policy generation for computing environments

A system and method for dynamically generating a compact cybersecurity policy based on an original policy is presented. The method includes receiving a cybersecurity policy in a first policy language, the first policy language including a first data format; determining a constraint of a second policy language; generating a context for a generative artificial intelligence (AI) based at least on the determined constraint; configuring the generative AI to generate a second cybersecurity policy in the second policy language based on the determined constraint and the generated context; and applying the generated second cybersecurity policy in a cybersecurity platform configured to utilize the second policy language.
Owner:CYERA LTD

Realtime synchronization of endpoint and cloud service protection

Systems, methods, and computer readable medium are disclosed for synchronizing network and endpoint security protocols. synchronizing network and endpoint security protocols includes receiving a device posture from an application running on an edge device; receiving from a server in communication with the edge device, network traffic information associated with the edge device; correlating the device posture and the network traffic information; and implementing a network security policy based on the correlation such that both the device posture from the edge device and the network traffic information from the server are used to enforce the network security policy.
Owner:CATO NETWORKS LTD

Network security policy management

Systems, devices, and techniques are disclosed for network security policy management. A file including code written using a Domain Specific Language (DSL) for network security may be received. A cloud native enforcement artifact may be generated from the code written using DSL in the file. A policy domain model including hierarchical data, relational data, and graph data for a network security policy may be generated from the code written using DSL in the file and the cloud native enforcement artifact. The policy domain model may be stored in a persistent storage.
Owner:SALESFORCE INC

A network access white list generation method, device, equipment and storage medium

The application discloses a network access white list generation method, device and equipment and a storage medium. The method is applied to cloud services, and the cloud services include at least one deployable unit, at least one container is arranged in the deployable unit, and the network access policy generation method includes: acquiring dynamic data and static data; determining the call association relationship between the cloud services according to the dynamic data and the static data, wherein the call association relationship between the cloud services includes: identification information of an accessed cloud service, identification information of an accessed cloud service and a destination port; and generating a network access white list according to the identification information of the accessed cloud service, the identification information of the accessed cloud service and the destination port. Through the technical scheme, the network access white list can be generated, and then the network security policy is generated according to the network access white list, so that the omission and deviation are reduced.
Owner:SHANGHAI PUDONG DEVELOPMENT BANK

System and method for policy management in cloud computing environments

A system and method for cybersecurity policy management. The method includes generating a first measurement based on at least one event which triggers a first cybersecurity policy, wherein the first measurement is defined with respect to at least one triggering of the first cybersecurity policy by the at least one event; generating a second cybersecurity policy based on the first cybersecurity policy and the first measurement; and applying the second cybersecurity policy on the at least one event.
Owner:CYERA LTD

System and method for cybersecurity policy generation for a computing environment

A system and method for generating a cybersecurity policy for a computing environment is presented. The method includes generating a representation of a computing environment in a security database having a predefined data schema; receiving a natural language query; matching the natural language query to a preexisting policy of a policy engine, the policy engine configured to apply a policy on the representation; generating a prompt for a large language model (LLM) based on the natural language query and the preexisting policy; applying a first policy to the representation, the first policy extracted from a result of executing the prompt utilizing the LLM.
Owner:WIZ INC