Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

33 results about "Network security policy" patented technology

A network security policy (NSP) is a generic document that outlines rules for computer network access, determines how policies are enforced and lays out some of the basic architecture of the company security/ network security environment. The document itself is usually several pages long and written by a committee. A security policy goes far beyond the simple idea of "keep the bad guys out". It's a very complex document, meant to govern data access, web-browsing habits, use of passwords and encryption, email attachments and more. It specifies these rules for individuals or groups of individuals throughout the company.

Intelligent network security policy optimization system based on SPF algorithm

The invention discloses a network security policy intelligent optimization system based on an improved SPF algorithm, and belongs to the technical field of network security. According to the system, by constructing a network security topological graph, network assets, services and users are defined as nodes of the graph, and potential access relations are defined as edges. A multi-dimensional and dynamically quantized'security risk index 'is provided as a weight of an edge, and the index integrates multiple dimensions. An improved SPF algorithm is adopted, and a lowest risk path from any source node to a target node is calculated. And according to the calculated optimal path, a refined access control strategy is automatically generated and issued, and redundancy analysis and optimization suggestion are carried out on the existing strategy. According to the method, the problems that a traditional security policy is complex in configuration, prone to errors and incapable of adapting to dynamic risk changes are solved, conversion from static and passive access control to dynamic and active risk path optimization is achieved, and the intelligent level and overall security of network security defense are remarkably improved.
Owner:INNER MONGOLIA AUTONOMOUS REGION METEOROLOGICAL INFORMATION CENT (INNER MONGOLIA AUTONOMOUS REGION AGRI & ANIMAL HUSBANDRY ECONOMIC INFORMATION CENT) (INNER MONGOLIA AUTONOMOUS REGION METEOROLOGICAL ARCHIVES)

Network security policy full-life-cycle self-adaptive tuning system based on intelligent calculation driving

PendingCN121750370ABiological modelsSecuring communicationAttackNetwork security policy
The invention discloses a network security policy full-life-cycle adaptive tuning system based on intelligent computation driving, relates to the technical field of network security, and is used for solving the problems of policy adaptation and efficiency balance under resource limitation. The method comprises the following steps: firstly, predicting an attack probability and mapping a topological weight by using an LSTM combined with an attention mechanism, and generating a risk prediction vector; then, performing weighted pruning on the rule based on the computing power constraint and the flow priority, and generating an execution state strategy packet; after issuing, monitoring a delay increment and an interception hit rate during operation, and generating a regular degradation instruction for a low-efficiency and high-consumption rule; and finally, regular scanning parameters are adjusted through gradient optimization, a self-adaptive system from risk pre-judgment to closed-loop optimization is constructed, and intelligent support is provided for network security defense.
Owner:广州云峰信息科技有限公司

Industrial internet security operation and maintenance risk assessment method and system

The invention discloses an industrial internet security operation and maintenance risk assessment method and system, and relates to the technical field of data management.The industrial internet security operation and maintenance risk assessment method comprises the steps that initial information collection is conducted on an industrial internet operation environment, risk links are constructed, and primary risk links are further analyzed and screened out; then obtaining dynamic operation data of each primary risk link, performing priority ranking based on the dynamic comprehensive risk score, and dynamically adjusting response triggering measures of the primary risk links at the same time to realize pertinence and timeliness of risk disposal; and finally, through cross validation of multi-level risk links, evaluation of actual effects of each adjustment measure and fine adjustment of a network security policy, potential risks can be effectively identified and quantified, a protection policy can be dynamically adjusted, the high-risk link disposal efficiency can be improved, and the security and stability of the whole system can be ensured. Therefore, the scientificity, controllability and reliability of industrial internet security operation and maintenance are obviously enhanced.
Owner:BEIJING HI TECH TECH

Network traffic multi-level security protection model, system, method, equipment and medium

PendingCN121283684ASecuring communicationDeclarative networkingRate limiting
The invention provides a network flow multi-level security protection model, system, method, equipment and medium. According to the method, a plurality of modularized atomization protection points are constructed through a predefined eBPF program library, and network control capabilities such as matching, speed limiting and state observation are realized. In a system initialization stage, a data plane architecture comprising a plurality of kernel execution layer dispatcher programs is constructed, and persistence of the programs and resource Map is realized through pin operation. The declarative network security policy is received through the SDK module, the policy control module analyzes the declarative network security policy to generate a configuration parameter, and the user mode module loads an eBPF program according to the configuration parameter and mounts the eBPF program to a kernel execution layer. The network flow triggers a protection point according to a path and outputs observation data; and the state aggregation sub-module aggregates the data according to the strategy and feeds information back to the upper-layer application. Therefore, flexible deployment of protection points and strategy dynamic driving can be realized, and the method has good expandability and response capability.
Owner:KYLIN CORP

Intent-based policy configuration using natural language

Techniques are described for providing a natural language network security policy assistant for allowing a network administrator to implement network security policies using natural language security policy requests. A natural language request can be received by a user and can be translated using Artificial Intelligence into one or more security policy clauses. If the natural language security policy request leads to ambiguities with regard to intended security policies, one or more clarifying questions can be generated as natural language questions and sent to the user for clarification. One or more security policies can be implemented based on the one or more security policy clauses generated in response to the natural language security policy request and / or the natural language response to the clarifying questions.
Owner:CISCO TECHNOLOGY INC

Service access method and equipment

PendingCN121940145Aimprove securityflexible allocationSecuring communicationEngineeringNetwork security policy
The invention provides a service access method and equipment. The method is applied to a first device, and the method comprises the following steps: obtaining a first corresponding relationship between a plurality of service names and a plurality of service identities (ID); a first service ID corresponding to the first service name is determined according to the first corresponding relation, and the first service name comprises the service name of the source service and / or the service name of the target service; and sending a first message to a second device where the target service is located, wherein the first message comprises the first service ID. In the technical scheme, when service access is carried out, service information can be directly associated by carrying the service ID in the first message, so that a manager can configure a network security policy based on the service information, and a source service or a target service of service access can be limited to improve network security.
Owner:PETAL CLOUD TECH CO LTD

Creating graphical models of network security policies and displaying on a network topology graph

Techniques and architecture are described for abstracting a real physical twin network wherein security policies are mapped as an overlay on a graphical representation of the network topology. The techniques include receiving, at a computing device, a first security policy) for a first network device. The computing device processes the first security policy to generate a plurality of first access control entries. The computing device creates first graph nodes corresponding to the first access control entries. Based at least in part on a processing order of the first security policy on the first network device, the computing device links the first graph nodes into a graph. The computing device displays the graph on a display, wherein the graph is displayed as an overlay on a network topology graph that includes the first network device.
Owner:CISCO TECHNOLOGY INC

Policy and traffic management in an overlay network

Technique or mechanism in which network security policies are applied close to the source or origin associated with policy decisions. For example. the disclosed technology moves dropped flows from a firewall cluster to a leaf switch based on host location.
Owner:GOOGLE LLC

A self-adaptive deployment method and system for a signal creation heterogeneous environment

The present application relates to the technical field of cloud computing platform automation deployment, and particularly relates to a self-adaptive deployment method and system for a heterogeneous environment of a signal creation, and to three major technical bottlenecks of low multi-CPU architecture adaptation efficiency, frequent software dependency conflicts and complex security baseline configuration in the process of localization, and an intelligent heterogeneous computing resource scheduling engine and a dynamic security policy generation mechanism are innovatively proposed. The method comprises: constructing a heterogeneous resource portrait through hardware feature automatic identification technology, and realizing component installation sequence optimization based on a DAG dependency relationship analysis algorithm and Kahn topological sorting; creating an adaptive network security policy, and realizing real-time perception of the target system firewall state through a probe. Compared with the traditional deployment mode, the present application supports cross-architecture compatibility, solves the problem of dependency conflicts, improves the deployment efficiency, and guarantees the consistency and security of the system.
Owner:TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Behavioral graph firewall policy

Techniques and systems described herein relate to a security system for a network or other monitored system of computing devices, such as a firewall system. The techniques and systems provide for generation of behavioral graphs based on observed network and / or system traffic during an observation period and subsequent creation of a network security policy using the behavioral graph as the framework for the network security policy. The techniques and systems additionally provide for manipulation, evaluation, and querying of network security policies through the use of matrix operations on behavioral graphs and plain text inputs and querying of the behavioral graph to form a network security policy.
Owner:CISCO TECHNOLOGY INC

Techniques for dynamic compact policy generation for computing environments

PCT designated stageWO2026104923A1Machine learningSecuring communicationNetwork security policyData mining
A system and method for dynamically generating a compact cybersecurity policy based on an original policy is presented. The method includes receiving a cybersecurity policy in a first policy language, the first policy language including a first data format; determining a constraint of a second policy language; generating a context for a generative artificial intelligence (AI) based at least on the determined constraint; configuring the generative AI to generate a second cybersecurity policy in the second policy language based on the determined constraint and the generated context; and applying the generated second cybersecurity policy in a cybersecurity platform configured to utilize the second policy language.
Owner:CYERA LTD

Realtime synchronization of endpoint and cloud service protection

PendingUS20260189610A1Synchronization networksInternet traffic
Systems, methods, and computer readable medium are disclosed for synchronizing network and endpoint security protocols. synchronizing network and endpoint security protocols includes receiving a device posture from an application running on an edge device; receiving from a server in communication with the edge device, network traffic information associated with the edge device; correlating the device posture and the network traffic information; and implementing a network security policy based on the correlation such that both the device posture from the edge device and the network traffic information from the server are used to enforce the network security policy.
Owner:CATO NETWORKS LTD

Network security policy management

Systems, devices, and techniques are disclosed for network security policy management. A file including code written using a Domain Specific Language (DSL) for network security may be received. A cloud native enforcement artifact may be generated from the code written using DSL in the file. A policy domain model including hierarchical data, relational data, and graph data for a network security policy may be generated from the code written using DSL in the file and the cloud native enforcement artifact. The policy domain model may be stored in a persistent storage.
Owner:SALESFORCE INC

A network access white list generation method, device, equipment and storage medium

ActiveCN115766260BSecuring communicationHigh level techniquesEngineeringNetwork security policy
The application discloses a network access white list generation method, device and equipment and a storage medium. The method is applied to cloud services, and the cloud services include at least one deployable unit, at least one container is arranged in the deployable unit, and the network access policy generation method includes: acquiring dynamic data and static data; determining the call association relationship between the cloud services according to the dynamic data and the static data, wherein the call association relationship between the cloud services includes: identification information of an accessed cloud service, identification information of an accessed cloud service and a destination port; and generating a network access white list according to the identification information of the accessed cloud service, the identification information of the accessed cloud service and the destination port. Through the technical scheme, the network access white list can be generated, and then the network security policy is generated according to the network access white list, so that the omission and deviation are reduced.
Owner:SHANGHAI PUDONG DEVELOPMENT BANK

System and method for policy management in cloud computing environments

PendingUS20260143010A1Securing communicationEvent triggerNetwork security policy
A system and method for cybersecurity policy management. The method includes generating a first measurement based on at least one event which triggers a first cybersecurity policy, wherein the first measurement is defined with respect to at least one triggering of the first cybersecurity policy by the at least one event; generating a second cybersecurity policy based on the first cybersecurity policy and the first measurement; and applying the second cybersecurity policy on the at least one event.
Owner:CYERA LTD

System and method for cybersecurity policy generation for a computing environment

PendingUS20260154302A1Digital data information retrievalTransmissionEngineeringNetwork security policy
A system and method for generating a cybersecurity policy for a computing environment is presented. The method includes generating a representation of a computing environment in a security database having a predefined data schema; receiving a natural language query; matching the natural language query to a preexisting policy of a policy engine, the policy engine configured to apply a policy on the representation; generating a prompt for a large language model (LLM) based on the natural language query and the preexisting policy; applying a first policy to the representation, the first policy extracted from a result of executing the prompt utilizing the LLM.
Owner:WIZ INC

Multimodal content interpretation of digital assets

A method of managing a computer network includes: receiving, at a network port, a stream of multimodal data; obtaining, from the multimodal data, a subset of the multimodal data that corresponds to a modality; determining, using a large-language model (LLM) agent, a semantic context of the subset of the multimodal data; determining, based on the semantic context and among a plurality of network policies, a network security policy corresponding to the subset of the multimodal data; and directing the subset of the multimodal data according to the network security policy.
Owner:AURASCAPE INC

Local area network egress opportunity probing appliance

PendingUS20260254839A1PathPingOutbound communication
A system and method for identifying network security gaps by probing outbound egress opportunities from within a local area network. A probe agent, which may be implemented as a dedicated hardware appliance or software instance deployed behind a firewall, attempts outbound communications to a remote server across a range of virtual network port and protocol combinations and / or network interfaces. The remote server receives successful probe requests and evaluates the associated port and protocol combinations against applicable network security policies. Upon identifying a combination inconsistent with those policies, the remote server generates alerts and transmits notifications to designated recipients. The probe agent and remote server coordinate via DNS-based command and control, ensuring reliable communication even in highly restrictive network environments. Multiple probe agents may be deployed across distinct network segments to identify unauthorized inter-segment communication paths. Detected egress vectors are tracked over time to identify ephemeral or periodic firewall misconfigurations.
Owner:OFFENSIVE CONTEXT LLC

Security policy enforcement for additional instances of an application

The disclosure provides an approach for firewall policy management. Embodiments include receiving, at a firewall from a first virtual computing instance (VCI), a registration request comprising a first identifier of the first VCI and a second identifier of a second VCI. Embodiments include determining, at the firewall, based on the second identifier included in the registration request, that the second VCI is associated with a network security policy at the firewall. Embodiments include applying, at the firewall, based on the first identifier included in the registration request, the network policy associated with the second VCI to the first VCI. Additionally, embodiments include allowing or disallowing network activity for the first VCI based on the applied network security policy.
Owner:VMWARE INC

Network security policy optimization method and system based on network topology data flow analysis

The invention discloses a network security policy optimization method and system based on network topology data flow analysis, and belongs to the technical field of network security, and the method comprises the steps: obtaining a configuration state and a data flow transmission demand of each network device in a network topology structure, and generating a network feature set; performing space-time correlation analysis on the cross-security domain data stream, and configuring a strategy priority vector; determining a strategy matching queue configuration parameter and an attack surface risk level through an equipment security level label and a data flow sensitive level identifier in combination with a network feature set and a time delay deviation; generating a control instruction set according to the strategy priority vector, the strategy matching queue configuration parameter and the attack surface risk level; and executing the control instruction set, collecting post attack surface convergence feedback data, generating an equipment policy security thermodynamic diagram, and dynamically adjusting security policy rules of each network equipment in the network topology structure. According to the invention, the cross-security domain data transmission security can be ensured, and the attack surface risk is reduced.
Owner:JILIN ELECTRIC POWER RES INST LTD

Network security policy validity verification and rectification scheme generation system and method

PendingCN121887527AKnowledge representationSecuring communicationAttackNetwork security policy
The invention relates to the technical field of network security, and discloses a network security policy validity verification and rectification scheme generation system and method, and the system comprises an attack surface management module which is used for constructing an attack surface map and a system knowledge base; the double-view attack simulation engine is used for driving an attack simulation model to carry out automatic attack simulation through an AI scheduling algorithm based on the attack surface atlas and the system knowledge base, and generating a verification report; the rectification scheme generation module is used for performing root cause analysis on the risk points in the verification report and matching rectification rules to generate a structured rectification scheme; and the closed-loop management module is used for performing task distribution, progress tracking and effect rechecking on the structured rectification scheme, and feeding back a rechecking result to start a new round of verification. The method corresponds to the system. According to the method and the device, a complete closed loop of continuous and automatic verification and optimization of the effectiveness of the network security policy is realized, and the active defense capability of security operation and maintenance is improved.
Owner:GUANGZHOU ELECTRIC POWER COMM NETWORK LTD

Protecting network data of rugged firewalls during physical intrusions of operational technology (OT) devices

PendingUS20260075428A1TransmissionSecurity arrangementNetwork security policyNetwork data
A rugged firewall of an OT device includes sensitive network data stored on a memory device. A current GPS position of an OT device is determined, and a tolerable deviation in GPS position is received for the OT device from the current GPS position as defined by a network security policy. A violation of the tolerable deviation is detected in the OT device from the current GPS position. In response to the detected violation, a security action involving a self-reset is taken to destroy network data in the rugged firewall of the OT device.
Owner:FORTINET INC

Self healing network security policy management

In some embodiments, a method determines a first functional domain that includes a group of security policies that have been copied from a second functional domain. Network flow data is queried to determine network traffic that is associated with a security policy in the group of security policies in the first functional domain. The method analyzes utilization of the security policy based on the network traffic. Based on the analyzing, a recommendation is generated to change the security policy in the first functional domain.
Owner:SALESFORCE INC

Automated generation of objects for kubernetes services

ActiveUS12684017B2Software engineeringNetwork security policy
Methods and systems for automatic generation of Kubernetes objects based on network security policies are described herein. A computing device may receive a template object file. The template object file may comprise a format for a Kubernetes Ingress object and / or a Kubernetes Custom Resource Definition. The template object file may comprise a template identifier. The computing device may receive an indication of a network security policy. The computing device may identify a Kubernetes service object that comprises the template identifier and generate, based on the template object file and based on the network security policy, a new Kubernetes object. The new Kubernetes object may comprise one or both of a new Kubernetes Ingress object for the Kubernetes service object, or a new CRD for the Kubernetes service object. The computing device may store the new Kubernetes object.
Owner:CITRIX SYSTEMS INC

Network security policy optimization system and method based on artificial intelligence

The invention discloses a network security policy optimization system and method based on artificial intelligence, and relates to the technical field of network security, and the method comprises the steps: obtaining network multi-source data, and building an event data model and a dynamic behavior relation graph; obtaining an attack evidence accumulation score of the suspicious security behavior for the network subject; obtaining a potential behavior attack chain, and identifying a key path and a key cut point of the development of the potential behavior attack chain; establishing a multi-level security policy set, and forming different policy candidate sets for the attack chain; and determining an optimal strategy combination and executing the optimal strategy combination. According to the method, the multi-source network data is adopted as initial data, data unification and structural processing are carried out, event behaviors are converted into structured evidences, and evidence accumulation is carried out, so that the attack evidence accumulation score is obtained, the problem that fragmented attacks and latent low abnormal behaviors are difficult to discover and defend by a network strategy is solved, and the security of the network strategy is improved. And the network security defense effect is improved.
Owner:GUANGDONG POWER GRID CO LTD +1

Security rating method and system based on cross-chain interaction of blockchain

The application discloses a security rating method and system based on cross-chain interaction of blockchains, and belongs to the technical field of security rating. The method specifically comprises the following steps: collecting transaction data, node behavior data, and delay and abnormal characteristics of a cross-chain communication link of each blockchain network in a cross-chain interaction process, generating a cross-chain security entropy index, generating and managing reputation tokens through a smart contract based on the cross-chain security entropy index, dynamically rating the cross-chain interaction security of each blockchain according to generation, circulation and historical records of the reputation tokens, and recording the security rating results in a layered form in a blockchain account book. When an abnormal cross-chain security entropy index is detected, the value of the reputation tokens is automatically adjusted, a preset game mechanism is triggered, and the security strategy of the blockchain network is optimized. The application comprehensively analyzes cross-chain transactions, smart contract vulnerabilities and abnormal behaviors under the premise of ensuring privacy, and effectively improves the risk perception ability in the financial cross-chain interaction scene.
Owner:JIANGSU JINNONG

System and method for applying multi-source cybersecurity policy on computing environments

PendingUS20260143016A1Securing communicationNetwork security policyData mining
A system and method for generating multi-source cybersecurity policies is presented. The method includes generating a first normalized cybersecurity policy based on a first received cybersecurity policy in a first policy format. A second normalized cybersecurity policy is generated based on a second received cybersecurity policy in a unique second policy format. A first generated cybersecurity policy is generated utilizing the second policy format and based on the first normalized cybersecurity policy. A second generated cybersecurity policy is generated utilizing the first policy format and based on the second normalized cybersecurity policy. The first generated cybersecurity policy is applied by a first cybersecurity platform which utilizes the second policy format. The second generated cybersecurity policy is applied by a second cybersecurity platform which utilizes the first policy format.
Owner:CYERA LTD

An industrial internet security operation and maintenance risk assessment method and system

The application discloses an industrial internet security operation and maintenance risk assessment method and system, relates to the technical field of data management, and collects initial information of an industrial internet operation environment, constructs various risk links, and further analyzes and screens various primary risk links; then, dynamic operation data of the various primary risk links are acquired, priority is sorted based on dynamic comprehensive risk scores of the various primary risk links, response trigger measures of the primary risk links are dynamically adjusted, the pertinence and timeliness of risk disposal are realized; finally, the actual effects of the various adjustment measures are evaluated through cross verification of multistage risk links, network security strategies are finely adjusted, potential risks can be effectively identified and quantified, protection strategies can be dynamically adjusted, high-risk link disposal efficiency can be improved, and the overall system safety and stability are ensured, so that the scientificity, controllability and reliability of industrial internet security operation and maintenance are significantly enhanced.
Owner:BEIJING HI TECH TECH

Information security protection method and device, equipment and storage medium

PendingCN121194186ASecurity arrangementNetwork security policyInformation security
The invention discloses an information security protection method and device, equipment and a storage medium, and relates to the technical field of information security. The method comprises the following steps: performing association analysis on an access signaling and a risk signaling of an access subject to obtain an analysis result, and obtaining access information when the access subject accesses a mobile communication network and / or a computer network according to the analysis result; judging whether the access of the access subject is safe or not according to the access information to obtain a judgment result; and adjusting the security level of the access subject according to the judgment result to obtain a target security level, and controlling the access response speed of the access subject according to the target security level. According to the technical scheme provided by the embodiment of the invention, the network security policy and the management and control mechanism are established in the existing network access link, and the information security of converged communication is managed in an active protection mode, so that timely and effective network risk prevention and control are realized.
Owner:中国移动通信集团云南有限公司 +1