Adaptive network security policies

US2016205143A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016205143-A1
Application numberUS-201314912665-A
CountryUS
Kind codeA1
Filing dateAug 19, 2013
Priority dateAug 19, 2013
Publication dateJul 14, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method and system for dynamic identification of network security policies are provided. The method comprises inspecting network traffic using a number of network inspection technologies; executing a first network security system to implement a first number of security policies to respond to a first number of threats identified by the number of network inspection technologies; executing a second network security system to implement a second number of security policies to respond to a second number of threats identified by the number of network inspection technologies; obtaining security intelligence from the first and second network security system; and adaptively reassessing the first and second number of security policies based on the security intelligence.

First claim

Opening claim text (preview).

What is claimed: 1 . A non-transitory computer-readable medium storing a set of instructions executable by a processing resource to: monitor network traffic using a number of inspection technologies; assign a number of risk values to security intelligence associated with the network traffic; adaptively calculate a weighted risk value using the number of risk values; and identify a number of security policies to implement based on the weighted risk value. 2 . The medium of claim 1 , further storing instructions executable to store the security intelligence associated with the network traffic in a historical database. 3 . The medium of claim 1 , further storing instructions executable to implement the number of security policies in a dynamic feedback loop, wherein the number of security policies to implement are identified based on a user-configurable threshold weighted risk value. 4 . A system for adapting network traffic flows, the system comprising: a processing resource; a memory resource coupled to the processing resource to implement: an inspection engine to inspect network traffic using a first network security system; a risk assessment engine to assign a first risk value to first security intelligence obtained using the first network security system; a security intelligence engine to record the first security intelligence; and an enforcement and control engine to select a number of security policies to implement based on the first security intelligence and the first risk value. 5 . The system of claim 4 , wherein: the inspection engine inspects network traffic using a second network security system; the risk assessment engine assigns a second risk value to second security intelligence obtained using the second network security system; and the enforcement and control engine selects a number of security policies to be implemented by the first network security system based on the second security intelligence and the second risk value. 6 . The system of claim 4 , wherein: the inspection engine inspects network traffic using a second network security system; and the enforcement and control engine selects a number of security policies to be implemented by the second network security system based on the first security intelligence and the first risk value. 7 . The system of claim 4 , wherein: the inspection engine inspects network traffic using a second network security system and a third network security system; the risk assessment engine: assigns a second risk value to second security intelligence obtained using the second network security system; assigns a third risk value to third security intelligence obtained using the third network security system; and the enforcement and control engine selects a number of security policies to be implemented by the third network security system based on the first and second security intelligence. 8 . The system of claim 7 , wherein: the risk assessment engine calculates a weighted risk value based on the first, second, and third risk values; and the enforcement and control engine selects a number of security policies to be implemented based on the weighted risk value. 9 . The system of claim 8 , wherein the enforcement and control engine selects a number of security policies to be implemented, based on a user configurable risk tolerance. 10 . The system of claim 7 , wherein the first network security system is a firewall, the second network security system is an application identification system, and the third network security system is an intrusion prevention system. 11 . A method for dynamic identification of network security policies comprising: inspecting network traffic using a number of network inspection technologies; executing a first network security system to implement a first number of security policies to respond to a first number of threats identified by the number of network inspection technologies; executing a second network security system to implement a second number of security policies to respond to a second number of threats identified by the number of network inspection technologies; obtaining security intelligence from the first and second network security systems; and adaptively reassessing the first and second number of security policies based on the security intelligence. 12 . The method of claim 11 , further including updating a historical database to include the security intelligence, in response to receiving the security intelligence from the first and second network security system. 13 . The method of claim 11 , further including: determining revised security intelligence using a historical database and the security intelligence; and sending the revised security intelligence to the first and second network security systems. 14 . The method of claim 11 , further including: selecting a third number of security policies to be executed by a third network security system, in response to obtaining security intelligence from the first and second network security systems. 15 . The method of claim 11 , wherein adaptively reassessing includes continuous, transmission of security policy results from a network security system to a progressive policy engine and back to the number of network security systems.

Assignees

Inventors

Classifications

  • for separating internal from external traffic, e.g. firewalls · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • H04L63/205Primary

    involving negotiation or determination of the one or more network security mechanisms to be used, e.g. by negotiation between the client and the server or between peers or by selection according to the capabilities of the entities involved (negotiation of communication capabilities H04L69/24) · CPC title

  • Vulnerability analysis · CPC title

  • Risk-dependent, e.g. selecting a security level depending on risk profiles · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016205143A1 cover?
A method and system for dynamic identification of network security policies are provided. The method comprises inspecting network traffic using a number of network inspection technologies; executing a first network security system to implement a first number of security policies to respond to a first number of threats identified by the number of network inspection technologies; executing a seco…
Who is the assignee on this patent?
Hewlett Packard Entpr Dev Lp
What technology area does this patent fall under?
Primary CPC classification H04L63/205. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jul 14 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).