System for supervising the security of an architecture

US9380075B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9380075-B2
Application numberUS-201314389191-A
CountryUS
Kind codeB2
Filing dateMar 26, 2013
Priority dateMar 29, 2012
Publication dateJun 28, 2016
Grant dateJun 28, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method is provided for supervising security of an architecture having a plurality of interconnected clouds. A cloud includes a plurality of resources and a security supervisor. The plurality of resources forms in the cloud a plurality of groups of resources associated respectively with a security domain. A security controller supervises the resources of the domain, and a plurality of physical machines contains the resources of the plurality of clouds. The method includes: receiving a security event by a security controller of a first cloud, originating from a first resource associated with a first security domain; dispatching said security event to the security supervisor of the first cloud; and dispatching by the security supervisor of the first cloud a security order in reaction to the security event to at least one second security controller of the first cloud and dispatching the security order by the second security controller to a second resource supervised by the second controller.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for supervising security of an architecture, the method comprising: reception of a security event by a first security controller of a first cloud, said first cloud belonging to a plurality of interconnected clouds of the architecture, wherein each cloud of the plurality comprises a plurality of resources and a security supervisor, the plurality of resources forming a plurality of resource groups in the cloud that are respectively associated with a security domain, wherein each security domain comprises a security controller that supervises the resources of the security domain, and a plurality of physical machines comprise resources of the plurality of interconnected clouds, wherein the respective security supervisors of the interconnected clouds comprise a set of security rules forming a security policy, and wherein said security event originates from a first of the resources associated with a first of the security domains, sending said security event to the security supervisor of the first cloud, sending a security order by the security supervisor of the first cloud to at least a second security controller of the first cloud in reaction to the security event, and sending the security order by the second security controller to a second resource supervised by the second security controller, sending, by the security supervisor of the first cloud, information relating to the security event to the other security supervisors of the other interconnected clouds of the plurality of interconnected clouds negotiation of a second security order between the security supervisor of the first cloud and the other security supervisors, the negotiation being based on information relating to the security event and on the respective security policies of the other security supervisors, and sending by one of the other security supervisors of the second security order to at least a third resource, the third resource being included in a cloud of the plurality of interconnected clouds, different from the first cloud. 2. The supervision method as claimed in claim 1 , comprising: detection of an inconsistency between a knowledge database of the security supervisor, said knowledge database comprising all the security events sent by the security controllers of the first cloud and a rules database of the first cloud, said rules database comprising the rules of operation inside the first cloud. 3. The supervision method as claimed in claim 1 , wherein, the first resource included in the first security domain being associated with a first execution level, the method furthermore comprises: selecting and sending a second security order by the first security controller of the first security domain to a fourth resource of the first security domain, the fourth resource being associated with a second execution level. 4. A system for supervising security of a computer architecture, the system comprising, for a first cloud belonging to a plurality of interconnected clouds of the architecture and for the other clouds of the plurality: a processing unit; and a non-transitory memory comprising code instructions stored thereon, which when executed by the processing unit configure the processing unit to: receive a security event by a first security controller of the first cloud of the plurality of clouds, wherein each cloud comprises a plurality of resources and a security supervisor, the plurality of resources forming a plurality of resource groups in the cloud that are respectively associated with a security domain, each security domain comprises a security controller supervising the resources of the security domain, a plurality of physical machines comprising resources of the plurality of clouds, wherein the respective security supervisors of the clouds comprise a set of security rules forming a security policy, and wherein said security event originates from a first of the resources associated with a first of the security domains, sending by the first security controller of the first cloud said security event to the security supervisor of the first cloud, sending by the security supervisor of the first cloud a security order to at least a second security controller of the first cloud in reaction to the security event, and sending by the second security controller the security order to a second resource supervised by the second security controller, sending by the security supervisor of the first cloud, information relating to the security event to the security supervisors of the other clouds of the plurality of interconnected clouds, negotiating a second security order between the security supervisor of the first cloud and the security supervisors of the other clouds, the negotiation being based on information relating to the security event and on the respective security policies of the security supervisors, and sending by one of the security supervisors of the other clouds the second security order to at least a third resource, the third resource being included in a cloud of the plurality of interconnected clouds, different from the first cloud.

Assignees

Inventors

Classifications

  • involving negotiation or determination of the one or more network security mechanisms to be used, e.g. by negotiation between the client and the server or between peers or by selection according to the capabilities of the entities involved (negotiation of communication capabilities H04L69/24) · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • for detecting or protecting against malicious traffic · CPC title

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9380075B2 cover?
A method is provided for supervising security of an architecture having a plurality of interconnected clouds. A cloud includes a plurality of resources and a security supervisor. The plurality of resources forms in the cloud a plurality of groups of resources associated respectively with a security domain. A security controller supervises the resources of the domain, and a plurality of physical…
Who is the assignee on this patent?
Orange
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 28 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).