METHOD FOR NETWORK TRAFFIC MIRRORING WITH DATA PRIVACY
    3.
    发明申请
    METHOD FOR NETWORK TRAFFIC MIRRORING WITH DATA PRIVACY 有权
    网络流量模式与数据隐私的方法

    公开(公告)号:US20100268933A1

    公开(公告)日:2010-10-21

    申请号:US12732356

    申请日:2010-03-26

    IPC分类号: G06F21/00 H04L9/00

    摘要: Systems and methods are provided for preserving the privacy of data contained in mirrored network traffic. The mirrored network traffic may comprise data that may be considered confidential, privileged, private, or otherwise sensitive data. For example, the data payload of a frame of mirrored network traffic may include private Voice over IP (VoIP) communications between users on one or more networks. The present invention provides various techniques for securing the privacy of data contained in the mirrored network traffic. Using the techniques of the present invention, network traffic comprising confidential, privileged, private, or otherwise sensitive data may be mirrored in such a manner as to provide for the privacy of such data over at least a portion if not all of the mirrored communications between the mirror source point and the minor destination point.

    摘要翻译: 提供了系统和方法,用于保护镜像网络流量中包含的数据的隐私。 镜像网络流量可以包括可被认为是机密,特权,私有或其他敏感数据的数据。 例如,镜像网络业务帧的数据有效载荷可以包括在一个或多个网络上的用户之间的专用IP语音(VoIP)通信。 本发明提供了用于保护包含在镜像网络业务中的数据的隐私的各种技术。 使用本发明的技术,包括机密,特权,私有或其他敏感数据的网络业务可以以这样的方式被镜像,以便通过至少一部分(如果不是全部)的所有镜像通信提供这样的数据的隐私, 镜像源点和次要目标点。

    Distributed intrusion response system
    4.
    发明授权
    Distributed intrusion response system 有权
    分布式入侵响应系统

    公开(公告)号:US07581249B2

    公开(公告)日:2009-08-25

    申请号:US10713560

    申请日:2003-11-14

    IPC分类号: G06F11/00 G06F21/00

    摘要: A system and method to respond to intrusions detected on a network system including attached functions and a network infrastructure. The system includes means for receiving from an intrusion detection function information about intrusions, a directory service function for gathering and reporting at least the physical and logical addresses of devices of the network infrastructure associated with the detected intrusions, and a plurality of distributed enforcement devices of the network infrastructure for enforcing policies responsive to the detected intrusions. A policy decision function evaluates the reported detected intrusions and makes a determination whether one or more policy changes are required on the enforcement devices in response to a detected intrusion. A policy manager function configures the distributed enforcement devices with the responsive changed policy or policies. Policy changes rules can vary from no change to complete port blocking on one or more identified enforcement devices associated with the detected intrusion, to redirecting the associated traffic including the intrusion and these policies may be modified or removed over time as warranted by network operation.

    摘要翻译: 一种用于响应在包括附加功能和网络基础设施的网络系统上检测到的入侵的系统和方法。 该系统包括用于从入侵检测功能接收关于入侵的信息的装置,用于收集和报告至少与检测到的入侵相关联的网络基础设施的物理和逻辑地址的目录服务功能的装置,以及多个分布式执行装置 用于执行响应于检测到的入侵的策略的网络基础设施。 策略决策功能评估报告的检测到的入侵,并且确定是否需要在执行设备上响应于检测到的入侵而需要进行一个或多个策略改变。 策略管理器功能使用响应更改的策略或策略配置分布式强制实施设备。 策略更改规则可以在与检测到的入侵相关联的一个或多个识别的强制设备上的完全端口阻塞之间变化到完全端口阻塞,重定向包括入侵的相关联的流量,并且这些策略可以随着网络操作的保证而被修改或删除。

    System, method and apparatus for traffic mirror setup, service and security in communication networks
    6.
    发明申请
    System, method and apparatus for traffic mirror setup, service and security in communication networks 有权
    通信网络中的流镜像设置,业务和安全性的系统,方法和装置

    公开(公告)号:US20060059163A1

    公开(公告)日:2006-03-16

    申请号:US11208372

    申请日:2005-08-19

    IPC分类号: G06F17/30

    摘要: The present invention provides method and systems for dynamically mirroring network traffic. The mirroring of network traffic may comprise data that may be considered of particular interest. The network traffic may be mirrored by a mirror service portal from a mirror sender, referred to as a mirror source, to a mirror receiver, referred to as a mirror destination, locally or remotely over various network segments, such as private and public networks and the Internet. The network traffic may be mirrored to locations not involved in the network communications being mirrored. The present invention provides various techniques for dynamically mirroring data contained in the network traffic from a mirror source to a mirror destination.

    摘要翻译: 本发明提供了用于动态镜像网络业务的方法和系统。 网络流量的镜像可以包括可被认为特别感兴趣的数据。 网络流量可以由镜像服务门户从称为镜像源的镜像服务器镜像到本地或远程通过各种网段(如私有和公共网络)的镜像接收器(称为镜像目的地),以及 互联网。 可以将网络流量镜像到不涉及正在镜像的网络通信中的位置。 本发明提供了用于动态镜像从镜像源到镜像目的地的网络流量中包含的数据的各种技术。

    Method for network traffic mirroring with data privacy
    7.
    发明授权
    Method for network traffic mirroring with data privacy 有权
    网络流量镜像与数据隐私的方法

    公开(公告)号:US08239960B2

    公开(公告)日:2012-08-07

    申请号:US12732356

    申请日:2010-03-26

    摘要: Systems and methods are provided for preserving the privacy of data contained in mirrored network traffic. The mirrored network traffic may comprise data that may be considered confidential, privileged, private, or otherwise sensitive data. For example, the data payload of a frame of mirrored network traffic may include private Voice over IP (VoIP) communications between users on one or more networks. The present invention provides various techniques for securing the privacy of data contained in the mirrored network traffic. Using the techniques of the present invention, network traffic comprising confidential, privileged, private, or otherwise sensitive data may be mirrored in such a manner as to provide for the privacy of such data over at least a portion if not all of the mirrored communications between the mirror source point and the mirror destination point.

    摘要翻译: 提供了系统和方法,用于保护镜像网络流量中包含的数据的隐私。 镜像网络流量可以包括可被认为是机密,特权,私有或其他敏感数据的数据。 例如,镜像网络业务帧的数据有效载荷可以包括在一个或多个网络上的用户之间的专用IP语音(VoIP)通信。 本发明提供了用于保护包含在镜像网络业务中的数据的隐私的各种技术。 使用本发明的技术,包括机密,特权,私有或其他敏感数据的网络业务可以以这样的方式被镜像,以便通过至少一部分(如果不是全部)的所有镜像通信提供这样的数据的隐私, 镜像源点和镜像目标点。

    Creating, modifying and storing service abstractions and role abstractions representing one or more packet rules
    8.
    发明授权
    Creating, modifying and storing service abstractions and role abstractions representing one or more packet rules 有权
    创建,修改和存储表示一个或多个数据包规则的服务抽象和角色抽象

    公开(公告)号:US07855972B2

    公开(公告)日:2010-12-21

    申请号:US10071228

    申请日:2002-02-08

    IPC分类号: G06F11/00 H04L12/28 H04L12/56

    摘要: The present invention provides a method and system for controlling usage of network resources on a communications network. The method comprising acts of: (a) creating one or more packet rules for analyzing packets received at one or more devices of the communications network, each rule including a condition and action to be taken if a packet received at a device satisfies the condition; and (b) creating one or more service abstractions associated with a user of the communication network, each service abstraction representing a named set of one or more of the packet rules. In some embodiments one or more role abstractions may be created, each role abstraction representing a role of a user with respect to the communications network, and each role abstraction including a set of one or more packet rules, and possibly one or more service abstractions.

    摘要翻译: 本发明提供一种用于控制通信网络上的网络资源的使用的方法和系统。 该方法包括以下动作:(a)创建用于分析在通信网络的一个或多个设备处接收到的分组的一个或多个分组规则,每个规则包括如果在设备处接收到的分组满足该条件的条件和动作; 和(b)创建与通信网络的用户相关联的一个或多个服务抽象,每个服务抽象表示一个或多个分组规则的命名集合。 在一些实施例中,可以创建一个或多个角色抽象,每个角色抽象表示用户相对于通信网络的角色,并且每个角色抽象包括一组一个或多个分组规则,以及可能的一个或多个服务抽象。

    Method for network traffic mirroring with data privacy
    9.
    发明授权
    Method for network traffic mirroring with data privacy 有权
    网络流量镜像与数据隐私的方法

    公开(公告)号:US07690040B2

    公开(公告)日:2010-03-30

    申请号:US11075936

    申请日:2005-03-08

    摘要: Systems and methods are provided for preserving the privacy of data contained in mirrored network traffic. The mirrored network traffic may comprise data that may be considered confidential, privileged, private, or otherwise sensitive data. For example, the data payload of a frame of mirrored network traffic may include private Voice over IP (VoIP) communications between users on one or more networks. The present invention provides various techniques for securing the privacy of data contained in the mirrored network traffic. Using the techniques of the present invention, network traffic comprising confidential, privileged, private, or otherwise sensitive data may be mirrored in such a manner as to provide for the privacy of such data over at least a portion if not all of the mirrored communications between the mirror source point and the mirror destination point.

    摘要翻译: 提供了系统和方法,用于保护镜像网络流量中包含的数据的隐私。 镜像网络流量可以包括可被认为是机密,特权,私有或其他敏感数据的数据。 例如,镜像网络业务帧的数据有效载荷可以包括在一个或多个网络上的用户之间的专用IP语音(VoIP)通信。 本发明提供了用于保护包含在镜像网络业务中的数据的隐私的各种技术。 使用本发明的技术,包括机密,特权,私有或其他敏感数据的网络业务可以以这样的方式被镜像,以便通过至少一部分(如果不是全部)的所有镜像通信提供这样的数据的隐私, 镜像源点和镜像目标点。

    Method for network traffic mirroring with data privacy
    10.
    发明申请
    Method for network traffic mirroring with data privacy 有权
    网络流量镜像与数据隐私的方法

    公开(公告)号:US20050278565A1

    公开(公告)日:2005-12-15

    申请号:US11075936

    申请日:2005-03-08

    摘要: Systems and methods are provided for preserving the privacy of data contained in mirrored network traffic. The mirrored network traffic may comprise data that may be considered confidential, privileged, private, or otherwise sensitive data. For example, the data payload of a frame of mirrored network traffic may include private Voice over IP (VoIP) communications between users on one or more networks. The present invention provides various techniques for securing the privacy of data contained in the mirrored network traffic. Using the techniques of the present invention, network traffic comprising confidential, privileged, private, or otherwise sensitive data may be mirrored in such a manner as to provide for the privacy of such data over at least a portion if not all of the mirrored communications between the mirror source point and the mirror destination point.

    摘要翻译: 提供了系统和方法,用于保护镜像网络流量中包含的数据的隐私。 镜像网络流量可以包括可被认为是机密,特权,私有或其他敏感数据的数据。 例如,镜像网络业务帧的数据有效载荷可以包括在一个或多个网络上的用户之间的专用IP语音(VoIP)通信。 本发明提供了用于保护包含在镜像网络业务中的数据的隐私的各种技术。 使用本发明的技术,包括机密,特权,私有或其他敏感数据的网络业务可以以这样的方式被镜像,以便通过至少一部分(如果不是全部)的所有镜像通信提供这种数据的隐私, 镜像源点和镜像目标点。