IP Library Granted Patent US 7,047,288
Granted Patent B2
US 7,047,288 · App. 09/878,098 · Granted May 16, 2006

Automated generation of an english language representation of a formal network security policy specification

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,047,288
App. No.
09/878,098
Granted
May 16, 2006
Kind
B2
Abstract

A system and method for generating a human readable, e.g. English language, description of a formal specification of network security policy that allows non-technical staff within a user's organization to comprehend the policy. The description is simple enough to be understood, yet captures salient details of the policy.

Claims (53)

1. A method for allowing comprehension of a network security policy specification for a network by generating a human language representation of said policy, said specification having a text representation, said method comprising:

loading said text representation of said policy specification into a parser;

said parser looping through all protocols, wherein said looped protocols are supported in said policy specification, said supported protocols having actions, and said supported protocols having associated rules:

for each supported protocol, sorting said rules in order of rank:

looping in ranked order through said sorted rules:

for each rule, generating a text description of said each rule using an algorithm; and

if said text description not first generated text description, then appending said text description to a collection of already generated descriptions, else, creating said collection of already generated descriptions with said text description;

wherein said algorithm comprising:

outputting a name of said each rule;

outputting a name of an agent, wherein said agent is a network, monitor on said network;

looping through all combinations of said protocol and said actions;

for each action, if said action is ignored, then applying said each rule to an entirety of said protocol, else applying said each rule to some or all of said actions;

evaluating an immediate outcome of said each rule;

outputting a first disposition corresponding to said immediate outcome;

outputting conditions on said first disposition, if any said conditions exist;

evaluating a final outcome of said each rule;

outputting a second disposition corresponding to said final outcome;

outputting conditions on said second disposition, if any said conditions exist;

if said each rule applies to a target and/or initiator, outputting name(s) of said target and/or initiator, else outputting a term representing any entity; and

outputting prerequisites, if any exist.

2. A system for allowing comprehension of a network security policy specification for a network by generating a language representation of said policy, said specification having a text representation, said system comprising:

means for loading said text representation of said policy specification into a parser;

means for said parser looping through all protocols, wherein said looped protocols are supported in said policy specification, said supported protocols having actions, and said supported protocols having associated rules:

for each supported protocol, means for sorting said rules in order of rank:

means for looping in ranked order through said sorted rules:

for each rule, means for generating a text description of said each rule using an algorithm; and

means for if said text description not first generated text description, then appending said text description to a collection of already generated descriptions, else, creating said collection of already generated descriptions with said text description;

wherein said algorithm comprising:

means for outputting a name of said each rule;

means for outputting a name of an agent wherein said agent is a network monitor on said network;

means for looping through all combinations of said protocol and said actions;

for each action, if said action is ignored, means for applying said each rule to an entirety of said protocol, else applying said each rule to some or all of said actions;

means for evaluating an immediate outcome of said each rule;

means for outputting a first disposition corresponding to said immediate outcome;

means for outputting conditions on said first disposition, if any said conditions exist;

means for evaluating a final outcome of said each rule;

means for outputting a second disposition corresponding to said final outcome;

means for outputting conditions on said second disposition, if any said conditions exist;

if said each rule applies to a target and/or initiator, means for outputting name(s) of said target and/or initiator, else outputting a term representing any entity; and

means for outputting prerequisites, if any exist.

3. A system for generating a text description of a policy rule of a network security policy specification for a network, said rule associated with a protocol and actions, said system comprising:

means for outputting a name of said rule;

means for outputting a name of an agent, wherein said agent is a network monitor on said network;

means for looping through all combinations of said protocol and said actions;

for each action, if said action is ignored, means for applying said rule to entirety of said protocol, else applying said rule to some or all of said actions;

means for evaluating an immediate outcome of said rule;

means for outputting a first disposition corresponding to said immediate outcome;

means for outputting conditions on said fist disposition, if any said conditions exist;

means for evaluating a final outcome of said rule;

means for outputting a second disposition corresponding to said final outcome;

means for outputting conditions on said second disposition, if any said conditions exist;

if said rule applies to a target and/or initiator, means for outputting name(s) of said target and/or initiator, else outputting a term representing any entity; and

means for outputting prerequisites, in any exist.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →