首页> 外国专利> Security gateway apparatus for controlling of policy-based network security and its proceeding method

Security gateway apparatus for controlling of policy-based network security and its proceeding method

机译:用于控制基于策略的网络安全的安全网关设备及其处理方法

摘要

PURPOSE: A security gateway device for a policy-based network security control and an operating method therefor are provided to dynamically meet a cyber terror by updating a correspondence policy according to a terror type in a policy cache when the cyber terror is generated and applying the updated policy to a newly generated cyber terror. CONSTITUTION: A CPA(Cyber Patrol Agent)(201) receives a cyber terror detection signal, and transmits the received cyber terror detection signal to a CPCS(Cyber Patrol Control System)(300). A policy receiving unit(202) receives a policy corresponding to the cyber terror detection signal from the CPCS(300). A security policy engine(203) receives the policies from the policy receiving unit(202), and outputs a dynamic security policy among the policies. A QoS(Quality of Service) policy executing engine(206) receives the policies from the policy receiving unit(202), and outputs a dynamic QoS policy among the policies. A security policy cache(204) receives the dynamic security policy from the security policy engine(203), and stores the received dynamic security policy according to the type of a cyber terror by a schema unit. A policy cache(205) receives the dynamic security policy of the schema unit from the security policy cache(204), receives the dynamic QoS policy from the QoS policy executing engine(206), updates policy information, and outputs updated policy information to the policy receiving unit(202) for dynamically corresponding to the cyber terror.
机译:目的:提供一种用于基于策略的网络安全控制的安全网关设备及其操作方法,以通过在生成网络恐怖时根据策略缓存中的恐怖类型更新对应策略来动态地应对网络恐怖,并应用更新了针对新产生的网络恐怖的政策。组成:CPA(网络巡逻代理)(201)接收网络恐怖检测信号,并将接收到的网络恐怖检测信号发送到CPCS(网络巡逻控制系统)(300)。策略接收单元(202)从CPCS(300)接收与网络恐怖检测信号相对应的策略。安全策略引擎(203)从策略接收单元(202)接收策略,并输出这些策略中的动态安全策略。 QoS(服务质量)策略执行引擎(206)从策略接收单元(202)接收策略,并输出这些策略中的动态QoS策略。安全策略高速缓存(204)从安全策略引擎(203)接收动态安全策略,并根据模式单元根据网络恐怖的类型来存储所接收的动态安全策略。策略缓存(205)从安全策略缓存(204)接收模式单元的动态安全策略,从QoS策略执行引擎(206)接收动态QoS策略,更新策略信息,并将更新的策略信息输出到策略接收单元(202),用于动态地对应于网络恐怖。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号