首页> 外国专利> METHOD APPARATUS AND COMPUTER PROGRAM FOR TESTING NETWORK SECURITY POLICY

METHOD APPARATUS AND COMPUTER PROGRAM FOR TESTING NETWORK SECURITY POLICY

机译:测试网络安全策略的方法设备和计算机程序

摘要

A method for testing security policy in a software-defined network according to an embodiment of the present invention comprises: a step A of transmitting a TCP SYN packet on a test target security function as a packet out message to a switch connected to the security function in a controller; a step B of determining that a failure has occurred in the security function when receiving an SYN response packet on the TCP SYN packet as a packet in message from the switch in the controller; and a step C of transmitting a temporary measure flow rule directing a packet related to a failure occurrence security function to drop, to the switch in the controller. The method can quickly take a measure on the failure of the security function.
机译:根据本发明的实施例的用于在软件定义的网络中测试安全策略的方法包括:步骤A,将测试目标安全功能上的TCP SYN分组作为分组输出消息发送到连接到该安全功能的交换机。在控制器中当从控制器中的交换机接收到TCP SYN分组上的SYN响应分组作为消息中的分组时,确定安全功能中已经发生故障的步骤B;步骤C,向控制器中的交换机发送临时措施流程规则,该规则措施规则将与故障发生安全功能有关的分组丢弃。该方法可以快速地对安全功能的失败采取措施。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号