首页> 外国专利> MULTI-STAGE DEFENSE-AWARE SECURITY MODULES PLACEMENT IN THE CLOUD

MULTI-STAGE DEFENSE-AWARE SECURITY MODULES PLACEMENT IN THE CLOUD

机译:云中的多阶段防御-警觉安全模块放置

摘要

Providing security for one or more network flows may include a security deployment node decomposing one or more virtual security appliances (265) of a logical security architecture (255) into security modules (310). The security deployment node orders the security modules (310) into a sequence (320) that implements a selected workflow pattern (400). The selected workflow pattern (400) may be selected from a workflow pattern database, and may define the security to be provided for a flow, for example, according to known best practices. The sequence (320) is then divided into segments (330), and the segments (330) are assigned to different groups (220) of network nodes (230) in a network (200). For each segment (330), an assignment of each security module (310) in the segment (330) to a network node (230) within the group (220) to which the segment (330) is assigned is computed. The network (200) is then configured according to the assignments.
机译:为一个或多个网络流提供安全性可以包括安全性部署节点,该安全性部署节点将逻辑安全性体系结构(255)的一个或多个虚拟安全性设备(265)分解成安全性模块(310)。安全部署节点将安全模块(310)排序为实现选定工作流模式(400)的序列(320)。可以从工作流模式数据库中选择所选的工作流模式(400),并且可以例如根据已知的最佳实践来定义要为流提供的安全性。然后将序列(320)划分为段(330),并且将段(330)分配给网络(200)中的网络节点(230)的不同组(220)。对于每个分段(330),计算分段(330)中的每个安全模块(310)对分配了分段(330)的组(220)内的网络节点(230)的分配。然后根据分配配置网络(200)。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号