Method and system for securely scanning network traffic
    91.
    发明授权
    Method and system for securely scanning network traffic 有权
    安全扫描网络流量的方法和系统

    公开(公告)号:US07188365B2

    公开(公告)日:2007-03-06

    申请号:US10115554

    申请日:2002-04-04

    IPC分类号: G06F9/00

    摘要: A method and system for implementing secure network communications between a first device and a second device, at least one of the devices communicating with the other device via a firewall device, are provided. The method and system may include obtaining an encryption parameter that is shared by the first device, second device and firewall device. A data packet sent by the first device may then be copied within the firewall device, so that decryption of the copy of the data packet within a portion of the firewall device may take place. In particular, the portion of the firewall device in which decryption takes place is defined such that contents of the portion are inaccessible to an operator of the firewall device. Thus, scanning of the decrypted copy of the data packet for compliance with a predetermined criterion may take place within the firewall device, without an operator of the firewall device having access to the contents of the data packet to be transmitted. Thereafter, the original data packet can be forwarded to its originally-intended recipient.

    摘要翻译: 提供了一种用于在第一设备和第二设备之间实现安全网络通信的方法和系统,至少一个设备经由防火墙设备与另一设备通信。 该方法和系统可以包括获得由第一设备,第二设备和防火墙设备共享的加密参数。 然后可以在防火墙设备内复制由第一设备发送的数据分组,从而可以在防火墙设备的一部分内对数据分组的副本进行解密。 特别地,定义防火墙设备中发生解密的部分,使得该部分的内容对于防火墙设备的操作者是不可访问的。 因此,在防火墙设备内可以进行符合预定标准的数据分组的解密副本的扫描,而防火墙设备的操作者可以访问要发送的数据分组的内容。 此后,原始数据包可以转发到其原始的接收方。

    Path analysis tool and method in a data transmission network including several internet autonomous systems
    92.
    发明申请
    Path analysis tool and method in a data transmission network including several internet autonomous systems 审中-公开
    包括几个互联网自主系统在内的数据传输网络中的路径分析工具和方法

    公开(公告)号:US20050283639A1

    公开(公告)日:2005-12-22

    申请号:US10638445

    申请日:2003-08-11

    IPC分类号: H04L12/24 G06F11/00

    CPC分类号: H04L41/00

    摘要: Method for performing the analysis of the characteristics of a data path from a first data processing device to a second data processing device through a network comprising at least an autonomous system consisting in defining a scenario file the scenario to be used, such a scenario including the actions to be used, building a parameter file defining the parameters to be used in the actions, running at least one analysis module based upon the actions of the scenario file and the parameters of the parameter file, the analysis module calling at least a predefined information requesting procedure, and storing in at least an output file the data resulting from the running of the analysis modules

    摘要翻译: 用于通过网络执行从第一数据处理设备到第二数据处理设备的数据路径的特性的分析的方法,所述网络包括至少包括将待使用的场景定义为场景文件的自治系统, 要使用的动作,构建定义要在动作中使用的参数的参数文件,基于脚本文件的动作和参数文件的参数运行至少一个分析模块,分析模块至少调用预定义的信息 请求过程,并且至少在输出文件中存储由分析模块运行产生的数据

    Method and system for retrieving an anti-virus signature from one or a plurality of virus-free certificate authorities
    93.
    发明授权
    Method and system for retrieving an anti-virus signature from one or a plurality of virus-free certificate authorities 有权
    从一个或多个无病毒证书机构检索防病毒签名的方法和系统

    公开(公告)号:US06976271B1

    公开(公告)日:2005-12-13

    申请号:US09665524

    申请日:2000-09-19

    摘要: A method and system as disclosed for use in a virus-free certificate proxy (107, 801), of retrieving from one or a plurality of virus-free certificate authorities (104, 804) a virus-free certificate (200) certifying that a file is virus-free. The method includes the steps of: receiving (1001) virus-free certificate request for a file; selecting a virus-free certificate authority (104, 804) having authority to generate a virus-free certificate (200) for the file; requesting (1003 . . . 1007) the virus-free certificate to the selected virus-free certificate authority (104, 804); receiving (1003 . . . 1007) from the selected virus-free certificate authority the generated virus-free certificate; sending back (1005) in response to the virus-free certificate request the received virus-free certificate.

    摘要翻译: 公开了用于无病毒证书代理(107,801)中的方法和系统,从一个或多个无病毒证书颁发机构(104,804)检索无病毒证书(200),证明该证书 文件是无病毒的。 该方法包括以下步骤:接收(1001)无病毒证书请求文件; 选择具有为文件生成无病毒证书(200)的权限的无病毒证书颁发机构(104,804); 向所选择的无病毒证书颁发机构(104,804)请求(1003 ... 1007)无病毒证书; 从选定的无病毒认证机构接收(1003 ... 1007)生成的无病毒证书; 发回(1005)回应无病毒证书请求收到的无病毒证书。

    Method for transmitting high-priority packets in an IP transmission network
    94.
    发明申请
    Method for transmitting high-priority packets in an IP transmission network 有权
    用于在IP传输网络中传输高优先级分组的方法

    公开(公告)号:US20050175013A1

    公开(公告)日:2005-08-11

    申请号:US10638898

    申请日:2003-08-11

    摘要: Method for transmitting high-priority packets in an IP transmission network based upon the Internet Protocol (IP) wherein low-priority packets or fragments of packets are transmitted between a sender and a receiver and at least a high-priority packet can be transmitted from the sender to the receiver by pre-emption of a low-priority packet or a fragment of packet. The method comprises in the sender, the steps of determining whether a low-priority packet or fragment of packet is being transmitted from the sender to the receiver when a high-priority packet has to be transmitted, setting to 1 a reserved bit within the IP header of the high-priority packet used as a pre-emption indicator if a low-priority packet or fragment of packet is currently transmitted, transmitting the high-priority packet with the pre-emption indicator set to 1 from the sender to the receiver, and resuming the transmission of the low-priority packet or fragment of packet at the end of transmission of the high-priority packet.

    摘要翻译: 基于互联网协议(IP)在IP传输网络中发送高优先级分组的方法,其中低优先级分组或分组在发送方和接收方之间传送,并且至少高优先级分组可以从 发送方通过优先级低优先级的数据包或数据包的片段来发送给接收方。 该方法包括在发送方中,当必须发送高优先级的分组时,确定低优先级分组或分组是否正在从发送方发送到接收方,设置为1内的保留位 如果当前正在发送低优先级分组或分组片段,则用作优先级指示符的高优先级分组的报头,将优先级分组以从发送方设置为1的优先级分组发送到接收方, 并且在高优先级分组的传输结束时恢复低优先级分组或分组分段的传输。

    Method and system for managing the exchange of files attached to electronic mails
    95.
    发明申请
    Method and system for managing the exchange of files attached to electronic mails 审中-公开
    管理电子邮件附件文件交换的方法和系统

    公开(公告)号:US20050076082A1

    公开(公告)日:2005-04-07

    申请号:US10638861

    申请日:2003-08-11

    摘要: Method of managing the exchange of a file from a sender (13) to a receiver (12, 15) in a data transmission network (10, 11) wherein any user amongst a plurality of users can send an electronic mail with at least an attached file to at least another user. The method comprises the following steps: the original file corresponding to the file to be sent as an attachment to the electronic mail is forwarded by the sender to a file server (14), a substitute file including at least data identifying the original file is sent by the file server back to the sender upon receiving the original file, the substitute file is attached to the electronic mail before sending this one by the sender to the receiver, and the receiver gets, at anytime, the original file from the file server by providing the file server with the parameters of the substitute file.

    摘要翻译: 管理从数据传输网络(10,11)中的发送器(13)到接收器(12,15)的文件的交换的方法,其中多个用户中的任何用户可以发送至少附着的电子邮件 文件至少另一个用户。 该方法包括以下步骤:将作为电子邮件的附件发送的文件的原始文件由发送方转发到文件服务器(14),至少包含标识原始文件的数据的替代文件被发送 由文件服务器在接收到原始文件时返回发送方,将发送者发送给接收者之前的替代文件附加到电子邮件,并且接收者随时从文件服务器获取原始文件 为文件服务器提供替代文件的参数。

    AAL-5 SSCS for AAL-1 and AAL-2 in ATM networks
    96.
    发明授权
    AAL-5 SSCS for AAL-1 and AAL-2 in ATM networks 失效
    ATM网络中AAL-1和AAL-2的AAL-5 SSCS

    公开(公告)号:US6108336A

    公开(公告)日:2000-08-22

    申请号:US934231

    申请日:1997-09-19

    摘要: The present invention uses the SAR and CPCS functions of the AAL-5 to define an AAL-5 SSCS for performing the AAL-1 and AAL2 functions. The defined AAL-5 format comprises a SSCS trailer of N (preferred value is 8) bytes an CPCS-PDU of N+8 (preferred value is 16) cells (16.times.48 bytes=768 bytes). In the preferred embodiment, the AAL-5 CPCS-PDU is transported inside 16 ATM cells. The CPCS and SSCS trailers provide the the same efficiency as AAL-1 and the global structure based on 16 cells is completely similar and transparent in term of delay and overhead. The payload size is 48 bytes for the 15 first cells, and 32 bytes for the last cell. The CPCS-PDU payload size is always a multiple of 8 bytes.

    摘要翻译: 本发明使用AAL-5的SAR和CPCS功能来定义用于执行AAL-1和AAL2功能的AAL-5 SSCS。 所定义的AAL-5格式包括N(优先值为8)字节的SSCS预告片,N + 8的CPCS-PDU(优选值为16)的单元(16×48字节= 768字节)。 在优选实施例中,AAL-5 CPCS-PDU在16个ATM信元内传送。 CPCS和SSCS预告片提供与AAL-1相同的效率,并且基于16个单元的全局结构在延迟和开销方面完全相似和透明。 15个第一个单元格的有效载荷大小为48个字节,最后一个单元格为32个字节。 CPCS-PDU有效载荷大小总是8字节的倍数。