发明授权
US06219786B1 Method and system for monitoring and controlling network access 有权
用于监控和控制网络访问的方法和系统

  • 专利标题: Method and system for monitoring and controlling network access
  • 专利标题(中): 用于监控和控制网络访问的方法和系统
  • 申请号: US09150264
    申请日: 1998-09-09
  • 公开(公告)号: US06219786B1
    公开(公告)日: 2001-04-17
  • 发明人: Mark CunninghamAndrew Trevarrow
  • 申请人: Mark CunninghamAndrew Trevarrow
  • 主分类号: G06F1300
  • IPC分类号: G06F1300
Method and system for monitoring and controlling network access
摘要:
A method and system for monitoring and controlling network access includes non-intrusively monitoring network traffic and assembling data packets that are specific to individual node-to-node transmissions in order to manage network access both inside and outside of a network. A rules base is generated to apply at either or both of the connection time and the time subsequent to connection. With regard to a particular node-to-node transmission, the data packets are assembled to identify the source and destination nodes, as well as contextual information (i.e., ISO Layer 7 information). The access rules are applied in a sequential order to determine whether the transmission is a restricted transmission. The rules are maintained in a single rules base for the entire network and are distributed to each monitoring node. Any of the protocols in the suite of TCP/IP protocols can be managed. The result of an analysis against the rules base causes a connection attempt to be completed or denied, a previously established connection to be broken, logging to occur, or a combination of these and other actions. Data collected during connection attempts or during a connection's lifetime may be passed to a third-party hardware or software component in order for independent validation to take place. Traffic monitoring and access management can be executed at a node other than a choke point of the network.
信息查询
0/0