Dynamic distribution of unified policies in a cloud-based policy enforcement system

The technology discloses a method applied by a policy manager to a cloud-based security system that unifies functions of access control and traffic inspection, threat detection and activity contextualization on inspectable and non-inspectable traffic, with a data manager coupled to the policy manage...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Ly, Kand, Datar, Amit Ganesh, Subbanna, Kartik
Format: Patent
Sprache:eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:The technology discloses a method applied by a policy manager to a cloud-based security system that unifies functions of access control and traffic inspection, threat detection and activity contextualization on inspectable and non-inspectable traffic, with a data manager coupled to the policy manager storing a superset of fields used to specify security policies across the cloud-based unified functions, including common fields shared by two or more of the functions. The method includes the manager validating, saving and distributing policy specifications applicable to respective functions among the functions, and receiving requests for policy specifications stored in common fields from each of the functions, converting the common fields into values used by a respective requesting function, and returning the values of the field used by the respective requesting function to any requesting function among the functions of access control and traffic inspection, threat detection and activity contextualization on inspectable and non-inspectable traffic.