首页> 外国专利> SYSTEM FOR GENERATING SECURITY TOPOLOGY OF CLOUD COMPUTING

SYSTEM FOR GENERATING SECURITY TOPOLOGY OF CLOUD COMPUTING

机译:云计算安全拓扑生成系统

摘要

The present invention is an API communication unit for collecting an API for one VPC (Virtual Private Cloud) corresponding to a first user account by collecting API (Application Programming Interface) communication with a cloud service provider system, and one collected through the API communication unit. An information classification unit that analyzes the API for the VPC and classifies the information included in the API into VPC configuration information and security policy information, and identifies the objects constituting the VPC by analyzing the VPC configuration information, and identifies the relationship between the objects. VPC configuration analysis unit, a basic topology configuration unit that generates a basic security topology expressing the relationship between objects and objects constituting a VPC using information on the relationship between objects analyzed by the VPC configuration analysis unit, the VPC configuration analysis unit and A security policy analysis unit that identifies objects that make up the VPC by interlocking and analyzes the security policy information applied to the VPC to determine whether the network connection status between the objects and the security policy conflict and policy overlap for each virtual server. A connection topology configuration unit that processes and resolves security policy conflicts and policy duplication according to the priority of the set security policy, and creates a final security topology by displaying the network connection status between objects on the basic security topology, and the final security It relates to a cloud security topology generation system including an output unit for transmitting the topology to the outside.
机译:本发明是一种API通信单元,用于通过收集与云服务提供商系统的API(应用编程接口)通信来收集与第一用户账户相对应的一个VPC(虚拟私有云)的API,以及通过API通信单元收集的API 。信息分类单元,其分析用于VPC的API,并且将包括在API中的信息分类为VPC配置信息和安全策略信息,并且通过分析VPC配置信息来识别构成VPC的对象,并且标识对象之间的关系。 VPC配置分析单元,基本拓扑配置单元,其使用关于由VPC配置分析单元,VPC配置分析单元和A安全策略分析的对象之间的关系的信息,生成表达对象和构成VPC的对象之间的关系的基本安全拓扑。分析单元,通过互锁来识别组成VPC的对象,并分析应用于VPC的安全策略信息,以确定对象之间的网络连接状态与每个虚拟服务器的安全策略冲突和策略是否重叠。连接拓扑配置单元,根据设置的安全策略的优先级处理和解决安全策略冲突和策略重复,并通过显示基本安全拓扑上的对象之间的网络连接状态以及最终安全性来创建最终安全拓扑。本发明涉及一种云安全拓扑生成系统,该云安全拓扑生成系统包括用于将拓扑传输到外部的输出单元。

著录项

  • 公开/公告号KR102164915B1

    专利类型

  • 公开/公告日2020-10-13

    原文格式PDF

  • 申请/专利权人 (주)아스트론시큐리티;

    申请/专利号KR20200070623

  • 发明设计人 조근석;이상용;황주연;

    申请日2020-06-11

  • 分类号H04L12/24;H04L29/06;

  • 国家 KR

  • 入库时间 2022-08-21 11:03:36

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号