首页> 外国专利> ASSURANCE OF SECURITY RULES IN A NETWORK

ASSURANCE OF SECURITY RULES IN A NETWORK

机译:保证网络中的安全规则

摘要

Systems, methods, and computer-readable media for assurance of rules in a network. An example method can include creating a compliance requirement including a first endpoint group (EPG) selector, a second EPG selector, a traffic selector, and a communication operator, the first and second EPG selectors representing sets of EPGs and the communication operator defining a communication condition for traffic associated with the first and second EPG selectors and the traffic selector. The method can include creating, for each distinct pair of EPGs, a first respective data structure representing the distinct pair of EPGs, the communication operator, and the traffic selector; creating a second respective data structure representing a logical model of the network; determining whether the first respective data structure is contained in the second respective data structure to yield a containment check; and determining whether policies on the network comply with the compliance requirement based on the containment check.
机译:用于保证网络中规则的系统,方法和计算机可读介质。示例方法可以包括创建包括第一端点组(EPG)选择器,第二EPG选择器,流量选择器和通信操作员的合规性要求,所述第一和第二EPG选择器表示EPG和所述通信操作员定义通信的通信操作员与第一和第二EPG选择器和流量选择器相关的流量条件。该方法可以包括为每个不同的对EPG创建,第一相应的数据结构表示不同对EPG,通信运营商和流量选择器的第一相应数据结构;创建表示网络逻辑模型的第二相应数据结构;确定第一各个数据结构是否包含在第二相应数据结构中以产生容纳检查;并确定网络上的策略是否符合基于遏制检查的合规要求。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号