会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 5. 发明申请
    • SYSTEM AND METHOD FOR HOST-INITIATED FIREWALL DISCOVERY IN A NETWORK ENVIRONMENT
    • 网络环境中主动防火发现的系统和方法
    • US20130097692A1
    • 2013-04-18
    • US13275196
    • 2011-10-17
    • Geoffrey CooperMichael W. GreenJohn Richard Guzik
    • Geoffrey CooperMichael W. GreenJohn Richard Guzik
    • G06F21/00
    • G06F21/00G06F21/30H04L61/2514H04L63/0254H04L63/029H04L63/10H04L67/16
    • A method is provided in one example embodiment that includes intercepting a network flow to a destination node having a network address and sending a discovery query based on a discovery action associated with the network address in a firewall cache. A discovery result may be received and metadata associated with the flow may be sent to a firewall before releasing the network flow. In other embodiments, a discovery query may be received from a source node and a discovery result sent to the source node, wherein the discovery result identifies a firewall for managing a route to a destination node. Metadata may be received from the source node over a metadata channel. A network flow from the source node to the destination node may be intercepted, and the metadata may be correlated with the network flow to apply a network policy to the network flow.
    • 在一个示例实施例中提供了一种方法,其包括拦截具有网络地址的目的地节点的网络流,并且基于与防火墙高速缓存中的网络地址相关联的发现动作来发送发现查询。 可以接收到发现结果,并且在释放网络流之前可以将与流相关联的元数据发送到防火墙。 在其他实施例中,可以从源节点接收发现查询和发送到源节点的发现结果,其中发现结果标识用于管理到目的地节点的路由的防火墙。 可以通过元数据信道从源节点接收元数据。 可以拦截从源节点到目的地节点的网络流,并且元数据可以与网络流相关联,以将网络策略应用于网络流。
    • 9. 发明授权
    • Secure network proxy for connecting entities
    • 用于连接实体的安全网络代理
    • US6003084A
    • 1999-12-14
    • US713424
    • 1996-09-13
    • Michael W. GreenRicky Ronald Kruse
    • Michael W. GreenRicky Ronald Kruse
    • H04L29/06H04L29/08G06F13/00
    • H04L63/0281H04L29/06H04L67/14H04L69/24H04L69/32H04L69/326H04L69/327H04L69/328
    • A proxy which is part of a firewall program controls exchanges of information between two application entities. The proxy interrogates attempts to establish a communication session by requesting entities with a server entity in lower layers in accordance with defined authentication procedures. The proxy interfaces with networking software to direct a communication stack to monitor connection requests to any address on specific ports. The requestor's address, and the server's address are checked against an access control list. If either address is invalid, the proxy closes the connection. If both are valid, a new connection is setup such that both the requestor and server are transparently connected to the proxy with variable higher levels being connected in a relay mode. Protocol data units are interrogated for conformance to a protocol session, and optionally further decoded to add additional application specific filtering. In one embodiment, an OSI architecture comprises the levels.
    • 作为防火墙程序一部分的代理控制两个应用实体之间的信息交换。 代理询问通过根据定义的认证过程请求具有较低层中的服务器实体的实体来建立通信会话的尝试。 代理与网络软件接口,以指示通信栈来监视特定端口上任何地址的连接请求。 根据访问控制列表检查请求者的地址和服务器的地址。 如果任一地址无效,代理将关闭连接。 如果两者都有效,则建立新的连接,使得请求者和服务器透明地连接到代理,其中可变的较高级别以中继模式连接。 询问协议数据单元以符合协议会话,并且可选地进一步解码以添加附加的特定应用过滤。 在一个实施例中,OSI架构包括这些级别。