Invention Grant
- Patent Title: Apparatus, system and method for security management based on event correlation in a distributed multi-layered cloud environment
-
Application No.: US16764871Application Date: 2017-11-20
-
Publication No.: US11368489B2Publication Date: 2022-06-21
- Inventor: Iris Adam , Jing Ping , Stephane Mahieu
- Applicant: Nokia Technologies Oy
- Applicant Address: FI Espoo
- Assignee: Nokia Technologies Oy
- Current Assignee: Nokia Technologies Oy
- Current Assignee Address: FI Espoo
- Agency: Nokia Technologies Oy
- International Application: PCT/CN2017/111883 WO 20171120
- International Announcement: WO2019/095374 WO 20190523
- Main IPC: G06F21/57
- IPC: G06F21/57 ; H04L9/40 ; G06F21/62 ; H04L67/10

Abstract:
An apparatus for security management based on event correlation in a distributed multi-layered cloud environment is disclosed, wherein the distributed multi-layered cloud environment comprises at least one first layer cloud service provider, and at least one second layer cloud service provider as a tenant of the first layer cloud service provider, and the apparatus is installed at least on one cloud service provider of the first layer cloud service provider and the second layer cloud service provider, the apparatus comprising: a central processing module configured to: provide correlation as a Service (CORRaaS) to a plurality of tenants as virtualized security appliances or virtualized security functions for the plurality of tenants's lices, generate a second interface for allowing the plurality of tenants to configure the correlation as a Service (CORRaaS), and correlate and process security events from security functions in the plurality of tenants' slices to form processed security event data, and to detect or predict attacks or anomalies or incompliance with security requirements; and a third interface for transferring the processed security event data and/or log data and/or raw data to the plurality of tenants' security management systems and/or to a plurality of cloud service providers' security management systems; and a fourth interface towards a cloud manager of the cloud service provider for causing the cloud manager to mitigate the detected or predicted attacks or anomalies or incompliance with security requirements. A corresponding system and method for security management based on event correlation in a distributed multi-layered cloud environment, as well as a computer readable medium, are also provided.
Public/Granted literature
Information query