【24h】

eGuard

机译:卫士

获取原文
获取原文并翻译 | 示例

摘要

Players on security sector have the forming of the situation picture as the fundamental requirement for successful on scene commanding and in addition to traditional communications device the goal can be supported by using different types of technical instruments. Information produced by different type of device can be transferred into centralized server environment on network layer referenced to OSI-model. A source device, for example IP camera, initiates an IP-based connection while a destination system is an application server that is able to receive incoming encrypted data flow through secured communication tunnel. To secure the data containers produced by different tenants(like independent authors, countries and companies) an essential requirement for the SaaS-application is to be multitenant aware on database, configuration and data warehouse levels hence tenants are required to be isolated from each other. As a potential solution we represent a product called eGuard that would be based on open source products as well as selected parts of commercial products with the goal to offer a functional IP-based entirety for actors on security sector. The application will be planned as a multitenant solution which means an environment where all tenants are isolated from each other by defining access controls lists for all tenants and information flows. Outbound traffic will be controlled by using default tenant-based security groups that have access to outbound data flows and on the other hand when needed it is possible to establish temporary or permanent cross-tenant security groups to offer cross-tenant situational picture when necessary.
机译:安全部门的参与者已经将情况图的形成作为成功完成现场指挥的基本要求,并且除了传统的通信设备外,还可以通过使用不同类型的技术工具来支持该目标。可以将由不同类型的设备产生的信息传输到参考OSI模型的网络层上的集中式服务器环境中。源设备(例如IP摄像机)将启动基于IP的连接,而目标系统是能够通过安全通信隧道接收传入的加密数据流的应用服务器。为了保护由不同租户(例如独立作者,国家和公司)生产的数据容器,SaaS应用程序的基本要求是对多租户了解数据库,配置和数据仓库级别,因此需要将租户彼此隔离。作为一种潜在的解决方案,我们代表一种名为eGuard的产品,该产品将基于开源产品以及商业产品的选定部分,旨在为安全部门的参与者提供基于IP的功能性整体。该应用程序将作为多租户解决方案进行计划,这意味着通过定义所有租户和信息流的访问控制列表将所有租户彼此隔离的环境。出站流量将通过使用可以访问出站数据流的基于默认租户的安全组来控制,另一方面,在需要时可以建立临时或永久性跨租户安全组,以便在必要时提供跨租户的情况。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号