Network service zone locking
    1.
    发明授权
    Network service zone locking 有权
    网络服务区域锁定

    公开(公告)号:US07895326B2

    公开(公告)日:2011-02-22

    申请号:US12628892

    申请日:2009-12-01

    IPC分类号: G06F15/173

    摘要: A zone locking system detects unauthorized network usage internal to a firewall. The system determines unauthorized network usage by classifying internal hosts inside a firewall into zones. Certain specified zones are unauthorized to initiate client communications with other selected zones. However, zone override services can be designated for each associated internal zone, and thus, authorizing selected network services. An alarm or other appropriate action is taken upon the detection of unauthorized network usage.

    摘要翻译: 区域锁定系统检测防火墙内部的未经授权的网络使用情况。 系统通过将防火墙内的内部主机分类为区域来确定未授权的网络使用情况。 某些指定的区域是未经授权的,以启动与其他选定区域的客户端通信。 但是,可以为每个相关联的内部区域指定区域覆盖服务,从而授权所选择的网络服务。 在检测到未经授权的网络使用时,会采取警报或其他适当措施。

    Flow-based detection of network intrusions
    2.
    发明授权
    Flow-based detection of network intrusions 有权
    基于流的网络入侵检测

    公开(公告)号:US07185368B2

    公开(公告)日:2007-02-27

    申请号:US10000396

    申请日:2001-11-30

    IPC分类号: G06F11/30

    摘要: A flow-based intrusion detection system for detecting intrusions in computer communication networks. Data packets representing communications between hosts in a computer-to-computer communication network are processed and assigned to various client/server flows. Statistics are collected for each flow. Then, the flow statistics are analyzed to determine if the flow appears to be legitimate traffic or possible suspicious activity. A concern index value is assigned to each flow that appears suspicious. By assigning a value to each flow that appears suspicious and adding that value to the total concern index of the responsible host, it is possible to identify hosts that are engaged in intrusion activity. When the concern index value of a host exceeds a preset alarm value, an alert is issued and appropriate action can be taken.

    摘要翻译: 一种用于检测计算机通信网络入侵的基于流的入侵检测系统。 表示计算机到计算机通信网络中的主机之间的通信的数据分组被处理并分配给各种客户端/服务器流。 收集每个流量的统计数据。 然后,分析流量统计信息,以确定流量是否似乎是合法流量或可能的可疑活动。 关注索引值被分配给显示为可疑的每个流。 通过为显示为可疑的每个流分配一个值,并将该值添加到负责主机的总体关注索引,可以识别从事入侵活动的主机。 当主机的关注索引值超过预设的报警值时,发出警报并采取适当的措施。

    Modem with improved handshaking capability
    3.
    发明授权
    Modem with improved handshaking capability 失效
    调制解调器具有改进的握手能力

    公开(公告)号:US4782498A

    公开(公告)日:1988-11-01

    申请号:US901134

    申请日:1986-08-28

    CPC分类号: H04M11/06

    摘要: The preferred embodiment (11) of the modem comprises a control unit (13), a memory (27), a switch (14), and a modem engine (17). The modem engine (17) establishes communications with a modem (30) using conventional handshake methods. The control unit (13) then initiates a special handshake sequence composed of nonprintable, opposing characters to the modem (30) via the switch (14) and the modem engine (17). If the modem (30) completes the special handshake sequence then the control unit (13) and the modem (30) exchange the desired information. If the modem (30) does not complete the special handshake sequence then the preferred embodiment (11) functions as a conventional modem. The use of nonprinting, opposing characters for the special handshake sequence prevents the special handshake sequence from adversely affecting the external devices (10) (34).

    摘要翻译: 调制解调器的优选实施例(11)包括控制单元(13),存储器(27),开关(14)和调制解调器引擎(17)。 调制解调器引擎(17)使用传统的握手方法建立与调制解调器(30)的通信。 然后,控制单元(13)经由开关(14)和调制解调器引擎(17)向调制解调器(30)发起由不可打印的相反字符组成的特殊握手顺序。 如果调制解调器(30)完成特殊握手序列,则控制单元(13)和调制解调器(30)交换所需的信息。 如果调制解调器(30)没有完成特殊握手序列,则优选实施例(11)用作常规调制解调器。 对于特殊的握手顺序使用非打印,相反的字符可防止特殊握手顺序对外部设备(10)(34)产生不利影响。

    Multilayered optical integrated circuit
    4.
    发明授权
    Multilayered optical integrated circuit 失效
    多层光集成电路

    公开(公告)号:US4438447A

    公开(公告)日:1984-03-20

    申请号:US339849

    申请日:1982-01-18

    CPC分类号: H04B10/801 G02B6/42 H01L31/12

    摘要: An electro-optic integrated circuit is disclosed wherein the long electrical connections normally present on a large scale integrated circuit are replaced by an optical waveguide layer. A plurality of epitaxial layers are grown on a single substrate and at least three of the plurality of epitaxial layers are grown with bandgaps that are suitable for optical sources, detectors and waveguiding. These primary layers are separated from each other by a barrier layer having a bandgap greater than either of the adjacent primary layers. Two of the layers adjacent to the substrate are grown to accommodate electrical devices that can be used to couple electrical signals to the optical source layers and to amplify electrical signals provided by the optical detection layer.

    摘要翻译: 公开了一种电光集成电路,其中通常存在于大规模集成电路上的长电连接被光波导层代替。 在单个衬底上生长多个外延层,并且使用适合于光源,检测器和波导的带隙生长多个外延层中的至少三个外延层。 这些主层通过阻挡层彼此分离,该阻挡层的带隙大于相邻原始层中的任一个。 生长与衬底相邻的两个层以容纳可用于将电信号耦合到光源层的电器件,并放大由光学检测层提供的电信号。

    Network port profiling
    5.
    发明授权
    Network port profiling 有权
    网络端口分析

    公开(公告)号:US07290283B2

    公开(公告)日:2007-10-30

    申请号:US10062621

    申请日:2002-01-31

    IPC分类号: G06F11/30

    摘要: A port profiling system detects unauthorized network usage. The port profiling system analyzes network communications to determine the service ports being used. The system collects flow data from packet headers between two hosts or Internet Protocol (IP) addresses. The collected flow data is analyzed to determine the associated network service provided. A host data structure is maintained containing a profile of the network services normally associated with the host. If the observed network service is not one of the normal network services performed as defined by the port profile for that host, an alarm signal is generated and action can be taken based upon the detection of an Out of Profile network service. An Out of Profile operation can indicate the operation of a Trojan Horse program on the host, or the existence of a non-approved network application that has been installed.

    摘要翻译: 端口分析系统检测未经授权的网络使用情况。 端口分析系统分析网络通信以确定正在使用的服务端口。 系统从两个主机或互联网协议(IP)地址之间的包头收集流数据。 分析收集的流数据以确定提供的相关网络服务。 维护主机数据结构,其中包含通常与主机关联的网络服务的配置文件。 如果观察到的网络服务不是由该主机的端口配置文件定义的正常网络服务之一,则生成报警信号,并且可以基于Out of Profile网络服务的检测来采取行动。 Out of Profile操作可以指示主机上的特洛伊木马程序的操作,或者是否已经安装了未经批准的网络应用程序。

    High sensitivity photon feedback photodetectors
    6.
    发明授权
    High sensitivity photon feedback photodetectors 失效
    高灵敏度光子反馈光电探测器

    公开(公告)号:US4399448A

    公开(公告)日:1983-08-16

    申请号:US230873

    申请日:1981-02-02

    摘要: Large current gains and high degrees of sensitivity to impinging primary photons are realized in photon feedback photodetectors embodying the invention. A photocurrent generated by an internal photodiode (10, 11) in response to the primary photons (6) causes secondary photons to be emitted by internal serially connected luminescence diodes (12, 13; 14, 15). Secondary photons traveling away from the photodiode are redirected by a reflector (16) to impinge on the photodiode and thereby sustain the photocurrent. Gains of the order of 100 are realized by these photodetectors.

    摘要翻译: 在体现本发明的光子反馈光电探测器中实现大电流增益和对入射光子的高度敏感度。 由内部光电二极管(10,11)响应于主光子(6)产生的光电流使得内部串联的发光二极管(12,13; 14,15)发射次级光子。 远离光电二极管的次级光子通过反射器(16)重新定向以照射在光电二极管上,从而维持光电流。 这些光电探测器实现了100级的增益。

    Flow-based detection of network intrusions
    7.
    发明授权
    Flow-based detection of network intrusions 有权
    基于流的网络入侵检测

    公开(公告)号:US07475426B2

    公开(公告)日:2009-01-06

    申请号:US11624441

    申请日:2007-01-18

    IPC分类号: G06F11/30

    CPC分类号: H04L63/1441 H04L63/1416

    摘要: A flow-based intrusion detection system for detecting intrusions in computer communication networks. Data packets representing communications between hosts in a computer-to-computer communication network are processed and assigned to various client/server flows. Statistics are collected for each flow. Then, the flow statistics are analyzed to determine if the flow appears to be legitimate traffic or possible suspicious activity. A concern index value is assigned to each flow that appears suspicious. By assigning a value to each flow that appears suspicious and adding that value to the total concern index of the responsible host, it is possible to identify hosts that are engaged in intrusion activity. When the concern index value of a host exceeds a preset alarm value, an alert is issued and appropriate action can be taken.

    摘要翻译: 一种用于检测计算机通信网络入侵的基于流的入侵检测系统。 表示计算机到计算机通信网络中的主机之间的通信的数据分组被处理并分配给各种客户端/服务器流。 收集每个流量的统计数据。 然后,分析流量统计信息,以确定流量是否似乎是合法流量或可能的可疑活动。 关注索引值被分配给显示为可疑的每个流。 通过为显示为可疑的每个流分配一个值,并将该值添加到负责主机的总体关注索引,可以识别从事入侵活动的主机。 当主机的关注索引值超过预设的报警值时,发出警报并采取适当的措施。

    Trap doped laser combined with photodetector
    8.
    发明授权
    Trap doped laser combined with photodetector 失效
    陷波掺杂激光器结合光电探测器

    公开(公告)号:US4300107A

    公开(公告)日:1981-11-10

    申请号:US58470

    申请日:1979-07-18

    摘要: A semiconductor laser is disclosed wherein the active region has been doped with deep-level electron traps either by proton bombarding the active region or by doping with an impurity, such as oxygen, iron, or chromium. The density of traps is such that an optical absorption parameter of greater than 30 cm.sup.-1 is achieved. This laser, when combined with an ordinary photodiode, exhibits overall optical gain thereby permitting an array of optical logic circuits.

    摘要翻译: 公开了一种半导体激光器,其中有源区已经通过质子轰击有源区域或通过掺杂诸如氧,铁或铬的杂质掺杂深层电子阱。 阱的密度使光吸收参数达到大于30cm-1。 当与普通光电二极管组合时,该激光器显示出总体光学增益,从而允许光逻辑电路阵列。

    Semiconductor overload protection structure
    9.
    发明授权
    Semiconductor overload protection structure 失效
    半导体过载保护结构

    公开(公告)号:US4189739A

    公开(公告)日:1980-02-19

    申请号:US884414

    申请日:1978-03-08

    IPC分类号: H01L27/02

    CPC分类号: H01L27/0255

    摘要: An input voltage overload protection semiconductor structure useful with MOS circuitry consists of a p-region in an n-substrate with p+ type regions formed on both sides of the p-region and an n+ type region centrally located in the p-region. Input signals are applied to the first p+ region. The gate of an MOS structure to be protected from voltage overload is connected to the second p+ type region. A power supply used with the MOS structure is connected to the n+ region. This structure provides significantly greater load protection than the standard resistor-diode-resistor circuit.

    摘要翻译: 与MOS电路有用的输入电压过载保护半导体结构由n型衬底中的p区域构成,其中p +型区域形成在p区域的两侧和位于p区域中心的n +型区域。 输入信号被施加到第一p +区域。 要保护电压过载的MOS结构的栅极连接到第二p +型区域。 与MOS结构一起使用的电源连接到n +区域。 这种结构比标准电阻二极管电阻电路提供了更大的负载保护。

    Unidirectional optical device and regenerator
    10.
    发明授权
    Unidirectional optical device and regenerator 失效
    单向光学装置和再生器

    公开(公告)号:US4152713A

    公开(公告)日:1979-05-01

    申请号:US857369

    申请日:1977-12-05

    摘要: A light-activated light-emitting device has at least one p-n junction provided with electrodes for confining light-emission to an area of the junction. It has been determined that light-emission can be activated by light impinging on the junction outside this confined area, so two optical fibers are provided, one being an input fiber for bringing activating light to the nonemitting sensitive part of the junction and the other fiber being an output fiber coupled to the light-emitting area. When the device is a p-n-p-n light-activated light-emitting switch provided with an RCL reset control circuit, a very inexpensive unidirectional optical pulse regenerator is obtained. The device in its various forms is advantageously suited for use in each of many stations along optical fiber data busses or in optical logic arrays because the unidirectional feature prevents light feedback between adjacent devices and consequently avoids spurious switching of a preceding device.

    摘要翻译: 光激发的发光器件具有至少一个p-n结,其设置有用于将发光限制在接合区域的电极。 已经确定,通过光照射在该限制区域外部的接合处可以激发发光,因此提供了两个光纤,一个是用于将激活光引导到接头的非测试敏感部分的输入光纤,另一个光纤 作为耦合到发光区域的输出光纤。 当该装置是具有RCL复位控制电路的p-n-p-n激光发光开关时,获得非常便宜的单向光脉冲再生器。 其各种形式的装置有利地适用于沿着光纤数据总线或光逻辑阵列的许多站中的每一个,因为单向特征防止相邻设备之间的光反馈并因此避免了先前设备的伪切换。