摘要:
Information on a communication relation or communication path to be monitored is automatically generated to reduce load of a user. A path information generation part of a network monitoring device receives a destination IP address designated by a user as an object of monitoring. When the input of the destination IP address is received, the path information generation part uses configuration information tables, which store configuration information of a device on a network being monitoring, to identify IP addresses of networks to which a plurality of terminals belong, as branch IP addresses. Further, the path information generation part uses the configuration information tables and transfer destination information tables which store a routing table of a router on the network, in order to identify the connection order of routers between the designated destination IP address and the identified branch IP addresses, to generate path information.
摘要:
According to the invention, techniques for controlling the quality of each communication service in a network automatically according to measured information of network traffic are provided. In a representative embodiment, a network measurement controlling system is provided according to the present invention, which comprises a control server, a router, and a meter connected to a network. The meter receives packets from a network and measures the number of packets, and the like, according to preset measurement rules, and transfers measured data to a control server. The control server holds control rules including its control policy for assuring the quality of each communication service, analyzes measured data transferred from the meter, and transmits control commands. The router controls the QoS automatically in real time according to the status of the network by receiving control commands and controlling communication service quality.
摘要:
To provide an access control service and control server for protecting a computer from an Illegal access such as a password cracking, in a terminal service and other related services. An access server 3 includes an authentication manager 7 for authenticating a user to operate a terminal, and an ACE manager 9 for setting a network link that enables communication between a terminal 1 that the user operates and a specific computer unit 2, to a hub 4 in accordance with a result of the authentication. Information on each user and information on the specific computer unit 2 that the each user can use are associated with each other and registered in the ACE manager 9.
摘要:
With a plurality of computer apparatuses connected to a network, operation log information, including an operation type and an output destination of a file, and acquisition source information indicating an acquisition source of the file are recorded based on a user's input/output operation; the acquisition source information is managed by relating it with an access authority over the acquisition source of the file; when the operation log information for the user's output operation exists in the operation log information, a range of the access authority over the acquisition source of an output target file, which is a target of the user's output operation, and an addressee user who can access an output destination of the output target file are specified; whether or not the addressee user belongs to the range of the access authority over the acquisition source of the output target file is judged; and if a negative judgment result is obtained, risk information indicating that the user's output operation is an output outside the range of the access authority.
摘要:
A computer system for providing a remote access service includes a unit for acquiring information on a relation between a terminal and a user using the terminal, a unit for acquiring network information about the terminal, a unit for acquiring network information about a blade that the terminal will access, a unit for acquiring information on a relation between the blade and a storage area, and a management server for extracting information on the user and its usage information and providing these information in real time. The management server also has a unit for permitting an administrator of the management server, persons other than the user and a management program to use the blade.
摘要:
Information on a communication relation or communication path to be monitored is automatically generated to reduce load of a user. A path information generation part receives a destination IP address designated by a user, through an input receiving part. When the input of the destination IP address is received, the path information generation part uses configuration information tables, each of which stores configuration information of a device on a network, to identify IP addresses of networks each having a plurality of terminals, as branch IP addresses. The path information generation part uses the configuration information tables and transfer destination information tables each storing a routing table of a router, to identify the connection order of routers between the designated destination IP address and the identified branch IP addresses, to generate path information.
摘要:
An object of the present invention is to provide a network measurement configuration apparatus which selects an IP meter for measurement traffic of a network, and sets a measurement rule in the IP meter.In order to achieve the above object, there is provided a network measurement configuration apparatus connected to a network having a plurality of measurement devices arranged therein, which measures traffic data of the network based on a measurement rule, comprising, a receiving means which receives a user request including path information and a measurement type, a measurement device selecting means which selects a measurement device responsible for a measurement based on the user request, and a measurement rule setting means which sets a measurement rule in the measurement device thus selected.
摘要:
To effectively allocate a computer resource in an environment where the number of computer resources is smaller than the number of users. It is provided with a section for monitoring the utilization state of the computer resources and a section for registering the condition of the possibility of release depending on the user attributes and the computer resource attributes, where when a new allocation request comes up in the state where all the computer resources are allocated, the unused computer resource is identified, released and allocated depending on the utilization state and the condition of the possibility of release.
摘要:
An IP multicast communication system includes a layer-2 switch for accommodating a plurality of recipients dynamically joining or not joining a multicast group, a layer-3 switch adapted to a subnet for receiving IP multicast data sent from a sender via an IP network and distributing the received IP multicast data to authorized recipients joining the multicast group via the layer-2 switch under control, and a controller for collectively managing recipient management information for authentication of the recipients obtained according to an Internet Group Management Protocol IGMP. The layer-3 switch authenticates the recipients according to the recipient management information adapted to its subnetwork among the recipient management information collectively managed by the controller. The layer-2 switch stops transmission of the IP multicast data or thins the IP multicast data sent to recipients that are determined to have made unauthorized accesses by the layer-3 switch.
摘要:
Information on a communication relation or communication path to be monitored is automatically generated to reduce load of a user. A path information generation part receives a destination IP address designated by a user, through an input receiving part. When the input of the destination IP address is received, the path information generation part uses configuration information tables, each of which stores configuration information of a device on a network, to identify IP addresses of networks each having a plurality of terminals, as branch IP addresses. The path information generation part uses the configuration information tables and transfer destination information tables each storing a routing table of a router, to identify the connection order of routers between the designated destination IP address and the identified branch IP addresses, to generate path information.