首页> 外国专利> Flow control device and network configuration method and device security strategy thereof

Flow control device and network configuration method and device security strategy thereof

机译:流量控制设备及其网络配置方法及其设备安全策略

摘要

A method of setting security policy implemented by a control network traffic, comprising: identifying (S101) a source, a destination and a type of applying a flow of input data, wherein the origin indicates a user sending the data stream or a user address from which the data stream is sent, the destination of the data stream indicates a user address, server address or public network address in which he received the data stream, and the application type indicating what kind of application whose data are included in the data stream; if the data stream does not match an existing policy, to match the data stream with a policy of allowing anyone to allow access to all users; executing (S102), based on an organizational structure default enterprise, the first processing ascending screening to obtain a first point upstream traceback and a first point upstream tracking target when the data stream matches the policy allow any, where the first point upstream traceback is a department to which the user belongs indicated by the source when the source indicates a user, the first point upstream traceback is a first network segment to which belongs the user address indicated by the source of the data flow when the origin indicates a user address from which the data stream is sent, the first network segment comprises multiple IP (Internet Protocol) addresses, and the first trace point ascending target is set in any direction when the destination indicates a public network address, the first trace point ascende nte target is set to a server when the destination indicates a server address; the first point upstream tracking target is a second network segment to which the user address in which the data stream is received belongs when the destination indicates a user address in which the data stream is received, the second network segment comprises multiple IP addresses; and generating (S103) a first security policy, where an origin in a condition of coincidence of the first security policy is set to the first point upstream traceback and a destination in the match condition of the first security policy is set to the first point upstream tracking target, and an application condition of coincidence of the first security policy is configured to application type of the data stream, the first security policy is used to match a data stream later.
机译:一种由控制网络流量实现的设置安全策略的方法,包括:识别(S101)应用输入数据流的源,目的地和类型,其中,源指示从中发送数据流的用户或用户地址。数据流发送给哪个,数据流的目的地指示接收数据流的用户地址,服务器地址或公共网络地址,以及应用程序类型指示其数据包含在数据流中的应用程序类型;如果数据流与现有策略不匹配,则将数据流与允许任何人允许访问所有用户的策略进行匹配;基于组织结构默认企业,执行(S102),所述第一处理升序筛选,以在数据流与策略匹配时获得第一点上游回溯和第一点上游跟踪目标,其中第一点上游回溯为当源指示用户时,由源指示用户所属的部门,第一点上游回溯是第一个网段,当源指示用户来源时,数据流源指示的用户地址所属的第一网段发送数据流时,第一网段包括多个IP(Internet协议)地址,并且当目的地指示公共网络地址时,将第一跟踪点上升目标设置为任意方向,将第一跟踪点上升目标设置为当目的地指示服务器地址时的服务器;所述第一点上游跟踪目标为:当所述目的地址指示接收到所述数据流的用户地址时,接收所述数据流的用户地址所属的第二网段,所述第二网段包括多个IP地址;生成(S103)第一安全策略,其中,将第一安全策略一致的条件下的源设置为第一点上游回溯,将第一安全策略的匹配条件下的目的地设置为第一点上游。跟踪目标,并根据数据流的应用类型配置第一安全策略的重合应用条件,第一安全策略用于以后匹配数据流。

著录项

  • 公开/公告号ES2687351T3

    专利类型

  • 公开/公告日2018-10-24

    原文格式PDF

  • 申请/专利权人 HUAWEI TECHNOLOGIES CO. LTD.;

    申请/专利号ES20140875870T

  • 发明设计人 WANG XIANGGUANG;

    申请日2014-11-26

  • 分类号H04L29/06;H04L29/08;

  • 国家 ES

  • 入库时间 2022-08-21 12:48:23

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号