JP2009502052A - 接続セキュリティのためのルールの自動生成 - Google Patents
接続セキュリティのためのルールの自動生成 Download PDFInfo
- Publication number
- JP2009502052A JP2009502052A JP2008521620A JP2008521620A JP2009502052A JP 2009502052 A JP2009502052 A JP 2009502052A JP 2008521620 A JP2008521620 A JP 2008521620A JP 2008521620 A JP2008521620 A JP 2008521620A JP 2009502052 A JP2009502052 A JP 2009502052A
- Authority
- JP
- Japan
- Prior art keywords
- security
- connection
- suite
- rules
- rule
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 238000000034 method Methods 0.000 claims abstract description 41
- 238000010586 diagram Methods 0.000 description 22
- 238000012545 processing Methods 0.000 description 18
- 101100217298 Mus musculus Aspm gene Proteins 0.000 description 7
- 238000013475 authorization Methods 0.000 description 2
- 230000005540 biological transmission Effects 0.000 description 2
- 238000004891 communication Methods 0.000 description 2
- 238000005516 engineering process Methods 0.000 description 2
- 230000003190 augmentative effect Effects 0.000 description 1
- 230000015572 biosynthetic process Effects 0.000 description 1
- 238000001914 filtration Methods 0.000 description 1
- ZXQYGBMAQZUVMI-GCMPRSNUSA-N gamma-cyhalothrin Chemical compound CC1(C)[C@@H](\C=C(/Cl)C(F)(F)F)[C@H]1C(=O)O[C@H](C#N)C1=CC=CC(OC=2C=CC=CC=2)=C1 ZXQYGBMAQZUVMI-GCMPRSNUSA-N 0.000 description 1
- 238000012795 verification Methods 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0227—Filtering policies
- H04L63/0263—Rule management
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F15/00—Digital computers in general; Data processing equipment in general
- G06F15/16—Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/20—Network architectures or network communication protocols for network security for managing network security; network security policies in general
Landscapes
- Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Software Systems (AREA)
- General Business, Economics & Management (AREA)
- Computing Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
- Storage Device Security (AREA)
Abstract
Description
ESPプロトコルは機密性、データ起点認証およびコネクションレスの保全性を提供するために使用することができる。AHとESPのプロトコルは、データが計算機間で安全に送信されることを可能にする。IPsecプロトコルは、1ペアの通信するデバイス間の切換キーに「インターネット鍵交換プロトコル」とタイトルをつけられたIETFのRFC 2409を使用することがある。
ドメイン・プロフィール・プロパティ・ボタン112および標準プロファイルプロパティ・ボタン114は、デフォルト・プロフィール行為を修正するために表示ページへのアクセスを提供する。セキュリティ保護ポリシエリアは接続セキュリティ領域121およびファイアウォール・セキュリティ領域122を含んでいる。接続セキュリティ領域は、ユーザが接続セキュリティ規則の生成で使用されるセキュリティ・スイートを定義し、カスタム接続セキュリティ規則を作成することを可能にする。ファイアウォール・セキュリティ領域は、ユーザが認証されたファイアウォール規則を定義することを可能にする。それは、ドメイン・プロフィール・エリアあるいは標準プロファイルエリアで指定されるようなデフォルトポリシの例外を指定する。
Claims (20)
- コンピュータ・システムにおいて、ファイアウォール・ポリシと接続ポリシとのためのセキュリティ・ポリシを作成する方法であって、
ファイアウォール・ポリシと接続ポリシとに関係するセキュリティ・ルールをユーザが特定することができるユーザ・インターフェースを提供するステップと、
前記特定されたセキュリティ・ルールからファイアウォール・ルールと接続ルールとを自動生成するステップと、
を含むことを特徴とする方法。 - 請求項1記載の方法において、接続ルールはIPセキュリティ・プロトコルの振る舞いを特定することを特徴とする方法。
- 請求項1記載の方法において、接続ルールは鍵交換とデータ保護と接続と関連する認証とを特定することを特徴とする方法。
- 請求項3記載の方法において、データ保護は暗号化及び保全性技術を特定することを特徴とする方法。
- 請求項1記載の方法において、セキュリティ・ルールは、条件と、前記条件が満たされるときになすべきアクションと、前記条件を満足するデータに対する認証及び暗号化の振る舞いとを特定することを特徴とする方法。
- 請求項1記載の方法において、ファイアウォール・ルールは条件と前記条件が満たされるときになすべきアクションとを含み、前記条件は接続セキュリティ情報に基づきうることを特徴とする方法。
- 請求項1記載の方法において、ユーザは前記ユーザ・インターフェースを通じてIPセキュリティ・プロトコルのメイン・モードとクイック・モードとに対するセキュリティ・スイートを特定することができることを特徴とする方法。
- 請求項7記載の方法において、メイン・モードのための前記セキュリティ・スイートは認証方法と暗号化スイートとを含むことを特徴とする方法。
- 請求項7記載の方法において、クイック・モードのための前記セキュリティ・スイートは暗号化スイートを含むことを特徴とする方法。
- 請求項7記載の方法において、接続ルールはデフォルトのセキュリティ・スイートに基づいて自動生成されることを特徴とする方法。
- コンピュータ・システムを制御して接続ルールを生成する命令を含むコンピュータ可読な媒体であって、
セキュリティ・ルールのローカル及びリモートなアドレス情報に基づいて前記接続ルールのためのエンドポイント情報を確立するステップと、
前記セキュリティ・ルールの条件を前記接続ルールにコピーできるかどうかに基づいて前記接続ルールのためのアクションを確立するステップと、
デフォルトのセキュリティ・スイートに基づいて前記接続ルールのための接続セキュリティ・スイートを確立するステップと、
を含む方法によって、接続ルールを生成する命令を含むコンピュータ可読な媒体。 - 請求項11記載のコンピュータ可読な媒体において、前記デフォルトのセキュリティ・スイートは認証方法と暗号化スイートとのためのメイン・モードとクイック・モードとを含むことを特徴とするコンピュータ可読な媒体。
- 請求項11記載のコンピュータ可読な媒体において、前記セキュリティ・スイートの確立は、一致するエンドポイント情報を用いて接続ルールに対して既に確立されたセキュリティ・スイートに基づくことを特徴とするコンピュータ可読な媒体。
- 請求項11記載のコンピュータ可読な媒体において、前記セキュリティ・ルールのすべての条件をコピーできるときには、安全な接続を確立することができないときにアクションは失敗することを指示することを特徴とするコンピュータ可読な媒体。
- 請求項11記載のコンピュータ可読な媒体において、前記セキュリティ・ルールのすべての条件をコピーできるとは限らないときには、安全な接続を確立できないときに安全でない接続を確立することを指示するアクションを確立するステップを更に含むことを特徴とするコンピュータ可読な媒体。
- 請求項11記載のコンピュータ可読な媒体において、前記エンドポイントの確立は、前記セキュリティ・ルールのローカル・アドレスが特定されていないときには、ローカルな計算機を指示するように前記ローカル・エンドポイント情報を設定することを含むことを特徴とするコンピュータ可読な媒体。
- 請求項11記載のコンピュータ可読な媒体において、前記エンドポイントの確立は、前記セキュリティ・ルールのリモート・アドレスが特定されていないときには、任意のリモートな計算機を指示するように前記リモート・エンドポイント情報を設定することを含むことを特徴とするコンピュータ可読な媒体。
- ファイアウォール・アクションと、
方向とローカル・アプリケーションとローカル・サービスとローカル・アドレスとリモート・アドレスとローカル・ポートとリモート・ポートとを含む条件と、
前記条件を満たすデータが伝送される接続に適用されるセキュリティを指示する接続セキュリティと、
を含むデータ構造を含むコンピュータ可読な媒体。 - 請求項18記載のコンピュータ可読な媒体において、前記接続セキュリティは認証と暗号化とを特定することを特徴とするコンピュータ可読な媒体。
- 請求項18記載のコンピュータ可読な媒体において、認証方法と暗号化スイートとを更に含むことを特徴とするコンピュータ可読な媒体。
Applications Claiming Priority (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US11/183,317 | 2005-07-15 | ||
US11/183,317 US8056124B2 (en) | 2005-07-15 | 2005-07-15 | Automatically generating rules for connection security |
PCT/US2006/027263 WO2007011673A2 (en) | 2005-07-15 | 2006-07-13 | Automatically generating rules for connection security |
Publications (3)
Publication Number | Publication Date |
---|---|
JP2009502052A true JP2009502052A (ja) | 2009-01-22 |
JP2009502052A5 JP2009502052A5 (ja) | 2009-07-23 |
JP4892554B2 JP4892554B2 (ja) | 2012-03-07 |
Family
ID=37663064
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
JP2008521620A Expired - Fee Related JP4892554B2 (ja) | 2005-07-15 | 2006-07-13 | 接続セキュリティのためのルールの自動生成 |
Country Status (7)
Country | Link |
---|---|
US (2) | US8056124B2 (ja) |
EP (1) | EP1905180A2 (ja) |
JP (1) | JP4892554B2 (ja) |
KR (1) | KR20080026177A (ja) |
CN (1) | CN101238669A (ja) |
TW (1) | TW200713954A (ja) |
WO (1) | WO2007011673A2 (ja) |
Families Citing this family (77)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US8250229B2 (en) * | 2005-09-29 | 2012-08-21 | International Business Machines Corporation | Internet protocol security (IPSEC) packet processing for multiple clients sharing a single network address |
JP4545085B2 (ja) * | 2005-12-08 | 2010-09-15 | 富士通株式会社 | ファイアウォール装置 |
JP4690918B2 (ja) * | 2006-03-14 | 2011-06-01 | 株式会社リコー | ネットワーク機器 |
US8099774B2 (en) * | 2006-10-30 | 2012-01-17 | Microsoft Corporation | Dynamic updating of firewall parameters |
US7954143B2 (en) * | 2006-11-13 | 2011-05-31 | At&T Intellectual Property I, Lp | Methods, network services, and computer program products for dynamically assigning users to firewall policy groups |
US7702787B1 (en) * | 2006-12-12 | 2010-04-20 | Emc Corporation | Configurable user management |
US8533789B1 (en) | 2006-12-12 | 2013-09-10 | Emc Corporation | User management for repository manager |
US20080178256A1 (en) * | 2007-01-23 | 2008-07-24 | Brian Perrone | System and method providing policy based control of interaction between client computer users and client computer software programs |
US8392981B2 (en) * | 2007-05-09 | 2013-03-05 | Microsoft Corporation | Software firewall control |
US8166534B2 (en) | 2007-05-18 | 2012-04-24 | Microsoft Corporation | Incorporating network connection security levels into firewall rules |
US8341723B2 (en) | 2007-06-28 | 2012-12-25 | Microsoft Corporation | Filtering kernel-mode network communications |
US8443433B2 (en) * | 2007-06-28 | 2013-05-14 | Microsoft Corporation | Determining a merged security policy for a computer system |
WO2009007985A2 (en) * | 2007-07-06 | 2009-01-15 | Elitecore Technologies Limited | Identity and policy-based network security and management system and method |
US20110238587A1 (en) * | 2008-09-23 | 2011-09-29 | Savvis, Inc. | Policy management system and method |
KR101006721B1 (ko) * | 2009-01-20 | 2011-01-07 | 킹스정보통신(주) | 키보드 입력정보 보안장치 및 그 방법 |
US8214645B2 (en) * | 2009-04-08 | 2012-07-03 | Research In Motion Limited | Systems, devices, and methods for securely transmitting a security parameter to a computing device |
KR100917660B1 (ko) * | 2009-05-11 | 2009-09-18 | (주)비전소프트 | 연계아답터를 이용한 방화벽 단일포트를 통해 내부망과 외부망의 서버들 간의 네트워크 연결 시스템 |
CN101640614B (zh) * | 2009-09-03 | 2012-01-04 | 成都市华为赛门铁克科技有限公司 | 一种配置ipsec安全策略的方法及装置 |
US20110075047A1 (en) * | 2009-09-29 | 2011-03-31 | Sony Corporation | Firewall port selection using atsc tuner signals |
US8806486B2 (en) * | 2010-09-03 | 2014-08-12 | Time Warner Cable Enterprises, Llc. | Methods and systems for managing a virtual data center with embedded roles based access control |
US8914841B2 (en) * | 2010-11-24 | 2014-12-16 | Tufin Software Technologies Ltd. | Method and system for mapping between connectivity requests and a security rule set |
US9191327B2 (en) | 2011-02-10 | 2015-11-17 | Varmour Networks, Inc. | Distributed service processing of network gateways using virtual machines |
US9288234B2 (en) * | 2011-08-04 | 2016-03-15 | International Business Machines Corporation | Security policy enforcement |
US9189636B2 (en) | 2012-07-30 | 2015-11-17 | Hewlett-Packard Development Company, L.P. | Office machine security policy |
IL221975A (en) * | 2012-09-19 | 2015-02-26 | Tufin Software Technologies Ltd | A method and device for managing connectivity between resources in a computer network |
EP2782311A1 (en) * | 2013-03-18 | 2014-09-24 | British Telecommunications public limited company | Methods of testing a firewall, and apparatus therefor |
TW201505411A (zh) | 2013-07-31 | 2015-02-01 | Ibm | 用於規則式安全防護設備之規則解譯方法及設備 |
US10768784B2 (en) * | 2013-12-06 | 2020-09-08 | Vivint, Inc. | Systems and methods for rules-based automations and notifications |
US10367787B2 (en) | 2013-12-20 | 2019-07-30 | Mcafee, Llc | Intelligent firewall access rules |
US9361432B2 (en) | 2014-01-15 | 2016-06-07 | Hewlett-Packard Development Company, L.P. | Configuring a security setting for a set of devices using a security policy |
US10091238B2 (en) * | 2014-02-11 | 2018-10-02 | Varmour Networks, Inc. | Deception using distributed threat detection |
US10264025B2 (en) | 2016-06-24 | 2019-04-16 | Varmour Networks, Inc. | Security policy generation for virtualization, bare-metal server, and cloud computing environments |
US9973472B2 (en) | 2015-04-02 | 2018-05-15 | Varmour Networks, Inc. | Methods and systems for orchestrating physical and virtual switches to enforce security boundaries |
US20150293862A1 (en) * | 2014-04-10 | 2015-10-15 | Andes Technology Corporation | Hardware configuration apparatus |
AU2015259581A1 (en) * | 2014-05-12 | 2016-11-10 | Michael C. Wood | Firewall security for computers with internet access and method |
US9882877B2 (en) * | 2014-05-12 | 2018-01-30 | Michael C. Wood | Transparent traffic control device and method for securing internet-connected devices |
US9756135B2 (en) * | 2014-07-31 | 2017-09-05 | Ca, Inc. | Accessing network services from external networks |
US9565216B2 (en) | 2014-10-24 | 2017-02-07 | At&T Intellectual Property I, L.P. | Methods, systems, and computer program products for security protocol selection in internet protocol multimedia subsystem networks |
US9438634B1 (en) | 2015-03-13 | 2016-09-06 | Varmour Networks, Inc. | Microsegmented networks that implement vulnerability scanning |
US9467476B1 (en) | 2015-03-13 | 2016-10-11 | Varmour Networks, Inc. | Context aware microsegmentation |
US10178070B2 (en) | 2015-03-13 | 2019-01-08 | Varmour Networks, Inc. | Methods and systems for providing security to distributed microservices |
US9294442B1 (en) | 2015-03-30 | 2016-03-22 | Varmour Networks, Inc. | System and method for threat-driven security policy controls |
US10193929B2 (en) | 2015-03-13 | 2019-01-29 | Varmour Networks, Inc. | Methods and systems for improving analytics in distributed networks |
US10009381B2 (en) | 2015-03-30 | 2018-06-26 | Varmour Networks, Inc. | System and method for threat-driven security policy controls |
US9380027B1 (en) * | 2015-03-30 | 2016-06-28 | Varmour Networks, Inc. | Conditional declarative policies |
US9525697B2 (en) | 2015-04-02 | 2016-12-20 | Varmour Networks, Inc. | Delivering security functions to distributed networks |
US9483317B1 (en) | 2015-08-17 | 2016-11-01 | Varmour Networks, Inc. | Using multiple central processing unit cores for packet forwarding in virtualized networks |
US10191758B2 (en) | 2015-12-09 | 2019-01-29 | Varmour Networks, Inc. | Directing data traffic between intra-server virtual machines |
US9680852B1 (en) | 2016-01-29 | 2017-06-13 | Varmour Networks, Inc. | Recursive multi-layer examination for computer network security remediation |
US9762599B2 (en) | 2016-01-29 | 2017-09-12 | Varmour Networks, Inc. | Multi-node affinity-based examination for computer network security remediation |
US9930029B2 (en) * | 2016-02-25 | 2018-03-27 | Nutanix, Inc. | Hypervisor agnostic bidirectional secure channel for guest agent transport |
US9992233B2 (en) | 2016-03-14 | 2018-06-05 | Michael C. Wood | Enhanced firewall and method for securing internet communications |
US9521115B1 (en) | 2016-03-24 | 2016-12-13 | Varmour Networks, Inc. | Security policy generation using container metadata |
US10523635B2 (en) * | 2016-06-17 | 2019-12-31 | Assured Information Security, Inc. | Filtering outbound network traffic |
US10755334B2 (en) | 2016-06-30 | 2020-08-25 | Varmour Networks, Inc. | Systems and methods for continually scoring and segmenting open opportunities using client data and product predictors |
US10673891B2 (en) | 2017-05-30 | 2020-06-02 | Akamai Technologies, Inc. | Systems and methods for automatically selecting an access control entity to mitigate attack traffic |
US10616280B2 (en) | 2017-10-25 | 2020-04-07 | Bank Of America Corporation | Network security system with cognitive engine for dynamic automation |
US10437984B2 (en) | 2017-10-26 | 2019-10-08 | Bank Of America Corporation | Authentication protocol elevation triggering system |
US10686684B2 (en) | 2017-11-02 | 2020-06-16 | Bank Of America Corporation | Individual application flow isotope tagging within a network infrastructure |
TW201926108A (zh) * | 2017-12-04 | 2019-07-01 | 和碩聯合科技股份有限公司 | 網路安全系統及其方法 |
US10909010B2 (en) | 2018-04-10 | 2021-02-02 | Nutanix, Inc. | Efficient data restoration |
CN109255247B (zh) | 2018-08-14 | 2020-08-14 | 阿里巴巴集团控股有限公司 | 多方安全计算方法及装置、电子设备 |
EP3627788A1 (de) * | 2018-09-18 | 2020-03-25 | Siemens Aktiengesellschaft | Verfahren und vorrichtung zum konfigurieren eines zugangsschutzsystems |
US11290494B2 (en) | 2019-05-31 | 2022-03-29 | Varmour Networks, Inc. | Reliability prediction for cloud security policies |
US11863580B2 (en) | 2019-05-31 | 2024-01-02 | Varmour Networks, Inc. | Modeling application dependencies to identify operational risk |
US11310284B2 (en) | 2019-05-31 | 2022-04-19 | Varmour Networks, Inc. | Validation of cloud security policies |
US11711374B2 (en) | 2019-05-31 | 2023-07-25 | Varmour Networks, Inc. | Systems and methods for understanding identity and organizational access to applications within an enterprise environment |
US11290493B2 (en) | 2019-05-31 | 2022-03-29 | Varmour Networks, Inc. | Template-driven intent-based security |
US11575563B2 (en) | 2019-05-31 | 2023-02-07 | Varmour Networks, Inc. | Cloud security management |
US11546301B2 (en) | 2019-09-13 | 2023-01-03 | Oracle International Corporation | Method and apparatus for autonomous firewall rule management |
US11283830B2 (en) * | 2020-03-19 | 2022-03-22 | Cisco Technology, Inc. | Protecting device classification systems from adversarial endpoints |
US11876817B2 (en) | 2020-12-23 | 2024-01-16 | Varmour Networks, Inc. | Modeling queue-based message-oriented middleware relationships in a security system |
US11818152B2 (en) | 2020-12-23 | 2023-11-14 | Varmour Networks, Inc. | Modeling topic-based message-oriented middleware within a security system |
US12050693B2 (en) | 2021-01-29 | 2024-07-30 | Varmour Networks, Inc. | System and method for attributing user behavior from multiple technical telemetry sources |
US11777978B2 (en) | 2021-01-29 | 2023-10-03 | Varmour Networks, Inc. | Methods and systems for accurately assessing application access risk |
US11764958B2 (en) | 2021-04-06 | 2023-09-19 | Capital One Services, Llc | Systems and methods for dynamically encrypting redirect requests |
US11734316B2 (en) | 2021-07-08 | 2023-08-22 | Varmour Networks, Inc. | Relationship-based search in a computing environment |
Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2003018156A (ja) * | 2001-06-28 | 2003-01-17 | Mitsubishi Electric Corp | Vpn運用管理装置 |
Family Cites Families (28)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US5835726A (en) * | 1993-12-15 | 1998-11-10 | Check Point Software Technologies Ltd. | System for securing the flow of and selectively modifying packets in a computer network |
US5950195A (en) * | 1996-09-18 | 1999-09-07 | Secure Computing Corporation | Generalized security policy management system and method |
US5987611A (en) * | 1996-12-31 | 1999-11-16 | Zone Labs, Inc. | System and methodology for managing internet access on a per application basis for client computers connected to the internet |
US6453419B1 (en) * | 1998-03-18 | 2002-09-17 | Secure Computing Corporation | System and method for implementing a security policy |
US6182226B1 (en) * | 1998-03-18 | 2001-01-30 | Secure Computing Corporation | System and method for controlling interactions between networks |
US6304973B1 (en) * | 1998-08-06 | 2001-10-16 | Cryptek Secure Communications, Llc | Multi-level security network system |
US6687353B1 (en) | 1998-12-11 | 2004-02-03 | Securelogix Corporation | System and method for bringing an in-line device on-line and assuming control of calls |
JP3659052B2 (ja) * | 1999-02-23 | 2005-06-15 | 株式会社日立製作所 | ネットワーク管理システム |
JP2000324104A (ja) * | 1999-05-10 | 2000-11-24 | Matsushita Electric Works Ltd | バーチャル通信ネットワークにおけるセキュリティーポリシー設定方法、セキュリティーポリシーマネージャ及びこれを用いたバーチャル通信ネットワークシステム |
US7047288B2 (en) * | 2000-01-07 | 2006-05-16 | Securify, Inc. | Automated generation of an english language representation of a formal network security policy specification |
JP2001298449A (ja) * | 2000-04-12 | 2001-10-26 | Matsushita Electric Ind Co Ltd | セキュリティ通信方法、通信システム及びその装置 |
JP2001358716A (ja) * | 2000-06-12 | 2001-12-26 | Nippon Telegr & Teleph Corp <Ntt> | 論理閉域網管理方法及び装置ならびにプログラムを記録した記録媒体 |
US6826698B1 (en) * | 2000-09-15 | 2004-11-30 | Networks Associates Technology, Inc. | System, method and computer program product for rule based network security policies |
US7546629B2 (en) * | 2002-03-06 | 2009-06-09 | Check Point Software Technologies, Inc. | System and methodology for security policy arbitration |
US7159125B2 (en) * | 2001-08-14 | 2007-01-02 | Endforce, Inc. | Policy engine for modular generation of policy for a flat, per-device database |
US6928553B2 (en) * | 2001-09-18 | 2005-08-09 | Aastra Technologies Limited | Providing internet protocol (IP) security |
WO2003029916A2 (en) * | 2001-09-28 | 2003-04-10 | Bluesocket, Inc. | Method and system for managing data traffic in wireless networks |
GB2380279B (en) * | 2001-10-01 | 2006-05-10 | Soundvoice Ltd | Computer firewall system and method |
EP1634175B1 (en) * | 2003-05-28 | 2015-06-24 | Citrix Systems, Inc. | Multilayer access control security system |
US7328451B2 (en) * | 2003-06-30 | 2008-02-05 | At&T Delaware Intellectual Property, Inc. | Network firewall policy configuration facilitation |
US7461140B2 (en) | 2003-12-19 | 2008-12-02 | Lsi Corporation | Method and apparatus for identifying IPsec security policy in iSCSI |
US20050138416A1 (en) * | 2003-12-19 | 2005-06-23 | Microsoft Corporation | Object model for managing firewall services |
US7441022B1 (en) * | 2004-03-12 | 2008-10-21 | Sun Microsystems, Inc. | Resolving conflicts between network service rule sets for network data traffic in a system where rule patterns with longer prefixes match before rule patterns with shorter prefixes |
CA2467603A1 (en) * | 2004-05-18 | 2005-11-18 | Ibm Canada Limited - Ibm Canada Limitee | Visualization firewall rules in an auto provisioning environment |
US20050268331A1 (en) * | 2004-05-25 | 2005-12-01 | Franck Le | Extension to the firewall configuration protocols and features |
FR2872983A1 (fr) * | 2004-07-09 | 2006-01-13 | Thomson Licensing Sa | Systeme de pare-feu protegeant une communaute d'appareils, appareil participant au systeme et methode de mise a jour des regles de pare-feu au sein du systeme |
US8595347B2 (en) * | 2004-09-30 | 2013-11-26 | Cisco Technology, Inc. | Method and apparatus for device based policy configuration in a network |
US7581241B2 (en) * | 2005-07-15 | 2009-08-25 | Microsoft Corporation | Generating an outbound connection security policy based on an inbound connections security policy |
-
2005
- 2005-07-15 US US11/183,317 patent/US8056124B2/en active Active
-
2006
- 2006-07-13 WO PCT/US2006/027263 patent/WO2007011673A2/en active Application Filing
- 2006-07-13 CN CNA2006800257067A patent/CN101238669A/zh active Pending
- 2006-07-13 EP EP06787203A patent/EP1905180A2/en not_active Withdrawn
- 2006-07-13 KR KR1020087001180A patent/KR20080026177A/ko not_active IP Right Cessation
- 2006-07-13 JP JP2008521620A patent/JP4892554B2/ja not_active Expired - Fee Related
- 2006-07-14 TW TW095125911A patent/TW200713954A/zh unknown
-
2011
- 2011-11-08 US US13/292,018 patent/US8490153B2/en active Active
Patent Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2003018156A (ja) * | 2001-06-28 | 2003-01-17 | Mitsubishi Electric Corp | Vpn運用管理装置 |
Also Published As
Publication number | Publication date |
---|---|
WO2007011673A3 (en) | 2007-09-27 |
US8056124B2 (en) | 2011-11-08 |
CN101238669A (zh) | 2008-08-06 |
EP1905180A2 (en) | 2008-04-02 |
US8490153B2 (en) | 2013-07-16 |
KR20080026177A (ko) | 2008-03-24 |
US20070016945A1 (en) | 2007-01-18 |
US20120054825A1 (en) | 2012-03-01 |
TW200713954A (en) | 2007-04-01 |
WO2007011673A2 (en) | 2007-01-25 |
JP4892554B2 (ja) | 2012-03-07 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
JP4892554B2 (ja) | 接続セキュリティのためのルールの自動生成 | |
US11190489B2 (en) | Methods and systems for establishing a connection between a first device and a second device across a software-defined perimeter | |
US6804777B2 (en) | System and method for application-level virtual private network | |
Bellovin | Distributed firewalls | |
US8776208B2 (en) | Incorporating network connection security levels into firewall rules | |
US7308703B2 (en) | Protection of data accessible by a mobile device | |
US7188365B2 (en) | Method and system for securely scanning network traffic | |
US7536715B2 (en) | Distributed firewall system and method | |
US7581241B2 (en) | Generating an outbound connection security policy based on an inbound connections security policy | |
US20030131245A1 (en) | Communication security system | |
WO2004107646A1 (en) | System and method for application-level virtual private network | |
EP2769514A1 (en) | System and method for host-initiated firewall discovery in a network environment | |
US20080282313A1 (en) | Multi-profile interface specific network security policies | |
US20080155645A1 (en) | Network-implemented method using client's geographic location to determine protection suite | |
KR20210001728A (ko) | 이더넷 기반의 선박 네트워크 보호를 위한 선박 보안 시스템 | |
Naous et al. | Delegating network security with more information | |
Foltz et al. | Enterprise considerations for ports and protocols | |
US9419800B2 (en) | Secure network systems and methods | |
Cisco | Configuring Internet Key Exchange Security Protocol | |
WO2001091418A2 (en) | Distributed firewall system and method | |
Balogun | Distributed firewalls mechanism for the resolution of packets forwarding problems in computer networks using RSA-CRT technique | |
Bhoi et al. | Exploring The Security Landscape: A Comprehensive Analysis Of Vulnerabilities, Challenges, And Findings In Internet Of Things (Iot) Application Layer Protocols | |
Stephens | Security architecture for aeronautical networks | |
Schmalen | Security Concept for VPN IPsec Site-to-Site Connections to Third Parties | |
WO2022256866A1 (en) | Systems, methods and devices for secure communication |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20090604 |
|
A621 | Written request for application examination |
Free format text: JAPANESE INTERMEDIATE CODE: A621 Effective date: 20090604 |
|
A977 | Report on retrieval |
Free format text: JAPANESE INTERMEDIATE CODE: A971007 Effective date: 20110322 |
|
A131 | Notification of reasons for refusal |
Free format text: JAPANESE INTERMEDIATE CODE: A131 Effective date: 20110401 |
|
A601 | Written request for extension of time |
Free format text: JAPANESE INTERMEDIATE CODE: A601 Effective date: 20110701 |
|
A602 | Written permission of extension of time |
Free format text: JAPANESE INTERMEDIATE CODE: A602 Effective date: 20110708 |
|
A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20110728 |
|
A131 | Notification of reasons for refusal |
Free format text: JAPANESE INTERMEDIATE CODE: A131 Effective date: 20110824 |
|
RD04 | Notification of resignation of power of attorney |
Free format text: JAPANESE INTERMEDIATE CODE: A7424 Effective date: 20110908 |
|
A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20111031 |
|
TRDD | Decision of grant or rejection written | ||
A01 | Written decision to grant a patent or to grant a registration (utility model) |
Free format text: JAPANESE INTERMEDIATE CODE: A01 Effective date: 20111124 |
|
A01 | Written decision to grant a patent or to grant a registration (utility model) |
Free format text: JAPANESE INTERMEDIATE CODE: A01 |
|
A61 | First payment of annual fees (during grant procedure) |
Free format text: JAPANESE INTERMEDIATE CODE: A61 Effective date: 20111219 |
|
R150 | Certificate of patent or registration of utility model |
Free format text: JAPANESE INTERMEDIATE CODE: R150 |
|
FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20141222 Year of fee payment: 3 |
|
LAPS | Cancellation because of no payment of annual fees | ||
S111 | Request for change of ownership or part of ownership |
Free format text: JAPANESE INTERMEDIATE CODE: R313113 |
|
R350 | Written notification of registration of transfer |
Free format text: JAPANESE INTERMEDIATE CODE: R350 |