×

Method and system for security policy management

  • US 20030014644A1
  • Filed: 05/02/2002
  • Published: 01/16/2003
  • Est. Priority Date: 05/02/2001
  • Status: Abandoned Application
First Claim
Patent Images

1. A method for determining whether a network comprising a plurality of network elements is conformant to a policy statement, wherein the policy statement indicates whether a set of clients is denied or granted access to a network-service supported by a set of servers, the method comprising the steps of:

  • building a topology and model of the network, wherein said model comprises a plurality of service models corresponding to the network elements, and wherein said service models indicate how the network elements will treat network packets, identifying a first network element from the set of clients and a second network element from the set of servers, building a packet in accordance with the network-service and the identified first and second network elements, attempting to move the packet from the first network element to the second network element by applying the packet to the network element service models, and based on whether the packet reaches the server, indicating whether the network is conformant to the policy statement.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×