摘要:
A method of setting up a backup path for a primary path on a network includes the steps of grouping nodes constituting the primary path into segments each including a plurality of nodes, and setting a backup path connecting between a head node and end node of each of the segments separately for each segment by notifying of information about segment position by a primary-path-provision requesting message.
摘要:
A method of setting up a backup path for a primary path on a network includes the steps of grouping nodes constituting the primary path into segments each including a plurality of nodes, and setting a backup path connecting between a head node and end node of each of the segments separately for each segment by notifying of information about segment position by a primary-path-provision requesting message.
摘要:
A connection-oriented network node capable of becoming an originating node of a protection path serving as a bypath of a protection segment included in a working path in a network system in which data is transferred via a path previously set up between nodes, comprises a usage bandwidth determining unit determining, when setting up the protection path, a usage bandwidth of the setup target protection path on the basis of a working path including the protection segment to be protected by the setup target protection path, and a generation unit generating, if a value obtained by adding the determined usage bandwidth to a current protection path usage bandwidth of an interface transmitting data that is forwarded on the setup target protection path, does not exceed a usable bandwidth for the protection path that is preset with respect to the interface, a signaling message for setting up the setup target protection path to send this message.
摘要:
A secure data communications system with an enhanced function of preventing information leakage. The system includes a user terminal and a router. The router has a security condition definition unit and a storage unit to receive and store a set of security conditions. A packet parser identifies and parses a packet produced by a file transfer application protocol and extracts from that packet a destination address and a security condition ID that the sending user has specified for a file in the packet. The packet parser discards the packet to prevent information leakage if the extracted destination address does not satisfy the security condition corresponding to the user-specified security condition ID. The user terminal has a security condition user interface that requests the router to provide information about security conditions and gives a security condition ID to each file to indicate which security condition the sending user has specified.
摘要:
A filter-information transmitting/receiving unit transmits path information with the filter information when the filter information is set by a filter setting unit, and receives the path information when the filter information is set in other network device. A filter-combining determining unit determines whether redundant filter information with the other network device is to be combined or deleted, based on the filter information and the path information. A filter control unit issues a filter-setting request or a filter release request based on a result of determination by the filter-combining determining unit.
摘要:
A terminal infected by an e-mail with a new virus is identified by storing information of e-mails as mail archive information, storing a distribution request history in which each distribution request of an email is associated with a terminal identification information which serves as a terminal information for identifying the terminal that has issued the distribution request, checking the mail archive and identifying an e-mail with a new virus, when definitions of new viruses have been added in a virus definition file, obtaining account information of the identified e-mail with the new virus, and extracting the terminal identification information of the terminal that issued the distribution request of the e-mail with the new virus, based upon both the obtained account information and the distribution request history.
摘要:
A connection-oriented network node capable of becoming an originating node of a protection path serving as a bypath of a protection segment included in a working path in a network system in which data is transferred via a path previously set up between nodes, comprises a usage bandwidth determining unit determining, when setting up the protection path, a usage bandwidth of the setup target protection path on the basis of a working path including the protection segment to be protected by the setup target protection path, and a generation unit generating, if a value obtained by adding the determined usage bandwidth to a current protection path usage bandwidth of an interface transmitting data that is forwarded on the setup target protection path, does not exceed a usable bandwidth for the protection path that is preset with respect to the interface, a signaling message for setting up the setup target protection path to send this message.
摘要:
A proxy server includes a harmful site information memory portion storing source site identification information for identifying a Web site that provides harmful data, an access log memory portion storing a data obtaining log indicating which terminal device has obtained which data, an access control portion making the terminal device obtain the data that the terminal device tried to obtain if the data is not the harmful data provided by the Web site related to the source site identification information, and that refuses the terminal device to obtain the data if the data is the harmful data, a harmful site access terminal identifying portion identifying a terminal device that has obtained the harmful data provided by the source site related to new source site identification information, based on the data obtaining log, and a message transmitting portion requesting the router to perform a quarantine process for the identified terminal device.
摘要:
A secure data communications system with an enhanced function of preventing information leakage. The system includes a user terminal and a router. The router has a security condition definition unit and a storage unit to receive and store a set of security conditions. A packet parser identifies and parses a packet produced by a file transfer application protocol and extracts from that packet a destination address and a security condition ID that the sending user has specified for a file in the packet. The packet parser discards the packet to prevent information leakage if the extracted destination address does not satisfy the security condition corresponding to the user-specified security condition ID. The user terminal has a security condition user interface that requests the router to provide information about security conditions and gives a security condition ID to each file to indicate which security condition the sending user has specified.