Service oriented software-defined security framework

US2016366184A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016366184-A1
Application numberUS-201615177103-A
CountryUS
Kind codeA1
Filing dateJun 8, 2016
Priority dateJun 12, 2015
Publication dateDec 15, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for service oriented software-defined security framework are disclosed. In one aspect, a system includes a security control device, one or more assets, and a security controller that communicates with the security control device and the one or more assets. The security controller includes a processing engine configured to register the security control device by creating a physical-logical attribute mapping for the security control device, and generating a security service description associated with the security control device. The processing engine is further configured to register the one or more assets by creating a physical-logical attribute mapping for each of the one or more assets, and generating security service requirements for each of the one or more assets. The processing engine is further configured to generate a security service binding based on a request for service.

First claim

Opening claim text (preview).

What is claimed is: 1 . A software defined security system comprising: a security control device; one or more assets; and a security controller that communicates with the security control device and the one or more assets, the security controller including a processing engine configured to: register the security control device by creating a physical-logical attribute mapping for the security control device, and generating a security service description associated with the security control device; register the one or more assets by creating a physical-logical attribute mapping for each of the one or more assets, and generating security service requirements for each of the one or more assets; and generate a security service binding based on a request for service, the processing engine being operable to translate the security service binding into a set of security control commands and communicate the security control commands to the security control device. 2 . The system of claim 1 , wherein the security control device is one of a firewall, an intrusion detection system, and an identity and access management system. 3 . The system of claim 1 , wherein the one or more assets include one of a server, a VPN client and server, an external computing device, and a mobile computing device. 4 . The system of claim 1 , wherein the processing engine is further configured to: receive data identifying a security event; access a playbook that identifies one or more actions for the security controller to perform for the security event; and perform the one or more actions in response to the security event. 5 . The system of claim 4 , wherein the security event comprises an event from an intrusion detection control, a network topology change, or a server failure. 6 . The system of claim 4 , wherein generating the security service binding comprises preforming the one or more actions in response to the security event. 7 . The system of claim 1 , wherein: the physical-logical attribute mapping for the security control device comprises an IP address-hostname mapping for the security control device, and the physical-logical attribute mapping for each of the one or more assets comprises an IP address-hostname mapping for each of the one or more assets. 8 . The system of claim 1 , wherein the processing engine is further configured to: receive data indicating a change to a physical attribute of one of the one or more assets; in response to receiving the data indicating the change to the physical attribute of the one of the one or more assets, identify a security service requirement for the one of the one or more assets; and generate a security service binding for the one of the one or more assets based on the security service requirement for the one of the one or more assets. 9 . The system of claim 8 , wherein the security service binding for the one of the one or more assets is generated automatically and without user input after receiving the data indicating the change to the physical attribute of the one of the one or more assets. 10 . A computer-implemented method comprising: registering, by a security controller that communicates with a security control device and one or more assets, the security control device by creating a physical-logical attribute mapping for the security control device, and generating a security service description associated with the security control device; registering the one or more assets by creating a physical-logical attribute mapping for each of the one or more assets, and generating security service requirements for each of the one or more assets; generating a security service binding based on a request for service; translating the security service binding into a set of security control commands; and communicating the security control commands to the security control device. 11 . The method of claim 10 , wherein the security control device is one of a firewall, an intrusion detection system, and an identity and access management system. 12 . The method of claim 10 , wherein the one or more assets include one of a server, a VPN client and server, an external computing device, and a mobile computing device. 13 . The method of claim 10 , comprising: receiving data identifying a security event; accessing a playbook that identifies one or more actions for the security controller to perform for the security event; and performing the one or more actions in response to the security event. 14 . The method of claim 13 , wherein the security event comprises an event from an intrusion detection control, a network topology change, or a server failure. 15 . The method of claim 13 , wherein generating the security service binding comprises preforming the one or more actions in response to the security event. 16 . The method of claim 10 , wherein: the physical-logical attribute mapping for the security control device comprises an IP address-hostname mapping for the security control device, and the physical-logical attribute mapping for each of the one or more assets comprises an IP address-hostname mapping for each of the one or more assets. 17 . The method of claim 10 , comprising: receiving data indicating a change to a physical attribute of one of the one or more assets; in response to receiving the data indicating the change to the physical attribute of the one of the one or more assets, identifying a security service requirement for the one of the one or more assets; and generating a security service binding for the one of the one or more assets based on the security service requirement for the one of the one or more assets. 18 . The method of claim 17 , wherein the security service binding for the one of the one or more assets is generated automatically and without user input after receiving the data indicating the change to the physical attribute of the one of the one or more assets. 19 . A non-transitory computer-readable medium storing software comprising instructions executable by one or more computers which, upon such execution, cause the one or more computers to perform operations comprising: registering, by a security controller that communicates with a security control device and one or more assets, the security control device by creating a physical-logical attribute mapping for the security control device, and generating a security service description associated with the security control device; registering the one or more assets by creating a physical-logical attribute mapping for each of the one or more assets, and generating security service requirements for each of the one or more assets; generating a security service binding based on a request for service; translating the security service binding into a set of security control commands; and communicating the security control commands to the security control device. 20 . The medium of claim 19 , wherein the security control device is one of a firewall, an intrusion detection system, and an identity and access management system.

Assignees

Inventors

Classifications

  • Filtering policies (mail message filtering H04L51/212) · CPC title

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • for separating internal from external traffic, e.g. firewalls · CPC title

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • Discovery or management of network topologies · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016366184A1 cover?
Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for service oriented software-defined security framework are disclosed. In one aspect, a system includes a security control device, one or more assets, and a security controller that communicates with the security control device and the one or more assets. The security controller includes a proces…
Who is the assignee on this patent?
Accenture Global Solutions Ltd
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Dec 15 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).