首页> 外国专利> Apparatus, System And Method For Security Management Based On Event Correlation In A Distributed Multi-Layered Cloud Environment

Apparatus, System And Method For Security Management Based On Event Correlation In A Distributed Multi-Layered Cloud Environment

机译:分布式多层云环境中基于事件相关性的安全管理装置,系统和方法

摘要

An apparatus for security management based on event correlation in a distributed multi-layered cloud environment is disclosed, wherein the distributed multi-layered cloud environment comprises at least one first layer cloud service provider, and at least one second layer cloud service provider as a tenant of the first layer cloud service provider, and the apparatus is installed at least on one cloud service provider of the first layer cloud service provider and the second layer cloud service provider, the apparatus comprising: a central processing module configured to: provide correlation as a Service (CORRaaS) to a plurality of tenants as virtualized security appliances or virtualized security functions for the plurality of tenants's lices, generate a second interface for allowing the plurality of tenants to configure the correlation as a Service (CORRaaS), and correlate and process security events from security functions in the plurality of tenants'slices to form processed security event data, and to detect or predict attacks or anomalies or incompliance with security requirements; and a third interface for transferring the processed security event data and/or log data and/or raw data to the plurality of tenants'security management systems and/or to a plurality of cloud service providers'security management systems; and a fourth interface towards a cloud manager of the cloud service provider for causing the cloud manager to mitigate the detected or predicted attacks or anomalies or incompliance with security requirements. A corresponding system and method for security management based on event correlation in a distributed multi-layered cloud environment, as well as a computer readable medium, are also provided.
机译:公开了一种用于基于分布式多层云环境中的事件相关性的安全管理的装置,其中,所述分布式多层云环境包括至少一个第一层云服务提供商和至少一个第二层云服务提供商作为承租人。所述装置至少安装在所述第一层云服务提供者和所述第二层云服务提供者中的一个云服务提供者上,所述装置包括:中央处理模块,被配置为:提供相关性作为提供给多个租户的服务(CORRaaS)作为虚拟化安全设备或多个租户虱子的虚拟化安全功能,生成第二个接口,以允许多个租户将相关性配置为服务(CORRaaS),并关联和处理安全性来自多个租户切片中的安全功能的事件以形成处理后的安全性e释放数据,并检测或预测攻击,异常或不符合安全要求;第三接口,用于将处理后的安全事件数据和/或日志数据和/或原始数据传输到多个租户的安全管理系统和/或多个云服务提供商的安全管理系统;面向云服务提供商的云管理器的第四接口,用于使云管理器减轻检测到的或预测的攻击或异常或不符合安全要求。还提供了用于在分布式多层云环境中基于事件相关性的安全管理的相应系统和方法,以及计算机可读介质。

著录项

  • 公开/公告号US2020344267A1

    专利类型

  • 公开/公告日2020-10-29

    原文格式PDF

  • 申请/专利权人 NOKIA TECHNOLOGIES OY;

    申请/专利号US201716764871

  • 发明设计人 IRIS ADAM;JING PING;STEPHANE MAHIEU;

    申请日2017-11-20

  • 分类号H04L29/06;H04L29/08;G06F21/62;G06F21/57;

  • 国家 US

  • 入库时间 2022-08-21 11:22:29

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号