首页> 外国专利> Dynamic network identity and policy management

Dynamic network identity and policy management

机译:动态网络身份和策略管理

摘要

Network policies are managed based at least in-part on user/entity identity information with: a state monitor operable to monitor for state change events in user/entity state and related, network state or in traffic pattern and traffic flow state; an identity manager operable to obtain and validate user credentials; and a policy manager operable in response to a state change event detected by the state monitor (either the identity manager or a defense center) to select a policy based in-part on the user identity obtained by the identity manager or security context obtained by the defense center, and to prompt application of the selected policy. The policies are indicative of user/device authorization entitlements and restrictions to utilization of certain network resources, network services or applications. Dynamic policy selection and targeted responses can be used, for example, against a user who gains network access with stolen user ID and password, and subsequently attempts malicious behavior. In particular, the malicious behavior is detected and identified, and the malicious user can then be restricted from abusing network resources without adversely affecting other users, groups, network devices, and other network services.
机译:至少部分地基于用户/实体身份信息来管理网络策略,其中:状态监视器可用于监视用户/实体状态及相关,网络状态或业务模式和业务流状态中的状态变化事件;身份管理器,用于获取和验证用户凭证;以及响应于状态监视器(身份管理器或防御中心)检测到的状态改变事件而操作的策略管理器,以部分地基于身份管理器获得的用户身份或安全管理器获得的安全上下文来选择策略。防御中心,并提示应用所选策略。该策略指示用户/设备授权权利以及对某些网络资源,网络服务或应用程序的利用的限制。动态策略选择和目标响应可以用于,例如,针对使用窃取的用户ID和密码获得网络访问权并随后尝试进行恶意行为的用户。特别地,恶意行为被检测和识别,然后可以限制恶意用户滥用网络资源,而不会不利地影响其他用户,组,网络设备和其他网络服务。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号