首页> 外国专利> A method and apparatus for managing a firewall

A method and apparatus for managing a firewall

机译:一种防火墙管理方法及装置

摘要

A method and apparatus are disclosed for managing a firewall. The disclosed firewall manager facilitates the generation of a security policy for a particular network environment, and automatically generates the firewall-specific configuration files from the security policy simultaneously for multiple gateways. The security policy is separated from the vendor-specific rule syntax and semantics and from the actual network topology. Thus, the security administrator can focus on designing an appropriate policy without worrying about firewall rule complexity, rule ordering, and other low-level configuration issues. In addition, the administrator can maintain a consistent policy in the presence of intranet topology changes. The disclosed firewall manager utilizes a model definition language (MDL) and an associated parser to produce an entity relationship model. A model compiler translates the entity-relationship model into the appropriate firewall configuration files. The entity-relationship model provides a framework for representing both the firewall-independent security policy, and the network topology. The security policy is expressed in terms of "roles," which are used to define network capabilities of sending and receiving services. A role may be assumed by different hosts or host-groups in the network. A visualization and debugging tool is provided to transform the firewall-specific configuration files into a graphical representation of the current policy on the actual topology, allowing the viability of a chosen policy to be evaluated. A role-group may be closed to prevent the inheritance of roles.
机译:公开了一种用于管理防火墙的方法和装置。所公开的防火墙管理器促进针对特定网络环境的安全策略的生成,并且同时针对多个网关从安全策略自动生成针对防火墙的特定配置文件。安全策略与特定于供应商的规则语法和语义以及实际的网络拓扑分离。因此,安全管理员可以集中精力设计适当的策略,而不必担心防火墙规则的复杂性,规则顺序和其他低级配置问题。此外,管理员可以在存在Intranet拓扑更改时维护一致的策略。所公开的防火墙管理器利用模型定义语言(MDL)和相关联的解析器来产生实体关系模型。模型编译器将实体关系模型转换为适当的防火墙配置文件。实体关系模型提供了一个框架,用于表示独立于防火墙的安全策略和网络拓扑。安全策略用“角色”表示,该角色用于定义发送和接收服务的网络功能。网络中的不同主机或主机组可以承担角色。提供了可视化和调试工具,可将特定于防火墙的配置文件转换为实际拓扑上当前策略的图形表示,从而可以评估所选策略的可行性。角色组可以关闭以防止角色继承。

著录项

  • 公开/公告号EP1024627A3

    专利类型

  • 公开/公告日2003-09-03

    原文格式PDF

  • 申请/专利权人 LUCENT TECHNOLOGIES INC.;

    申请/专利号EP20000300371

  • 申请日2000-01-19

  • 分类号H04L12/24;H04L29/06;H04L12/22;

  • 国家 EP

  • 入库时间 2022-08-21 23:52:55

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号