首页> 外国专利> Declarative language for specifying a security policy

Declarative language for specifying a security policy

机译:用于指定安全策略的声明性语言

摘要

The invention is a declarative language system and comprises a language as a tool for expressing network security policy in a formalized way. It allows the specification of security policy across a wide variety of networking layers and protocols. Using the language, a security administrator assigns a disposition to each and every network event that can occur in a data communications network. The event's disposition determines whether the event is allowed (i.e. conforms to the specified policy) or disallowed and what action, if any, should be taken by a system monitor in response to that event. Possible actions include, for example, logging the information into a database, notifying a human operator, and disrupting the offending network traffic.
机译:本发明是一种声明性语言系统,并且包括一种语言作为用于以形式化方式表达网络安全策略的工具。它允许跨各种网络层和协议指定安全策略。安全管理员使用该语言为数据通信网络中可能发生的每个网络事件分配处置。事件的处置方式确定事件是允许的(即符合指定的策略)还是不允许的,以及系统监视器应针对该事件采取何种操作(如果有)。可能的措施包括,例如,将信息记录到数据库中,通知操作员以及破坏有问题的网络流量。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号