Network defense system utilizing endpoint health indicators and user identity
    1.
    发明授权
    Network defense system utilizing endpoint health indicators and user identity 有权
    网络防御系统利用端点健康指标和用户身份

    公开(公告)号:US08001610B1

    公开(公告)日:2011-08-16

    申请号:US11236987

    申请日:2005-09-28

    IPC分类号: G06F7/04

    摘要: An endpoint defense system uses endpoint health indicators and user identity information to provide fine-grain access control over network resources. For example, the endpoint defense system may include a controller, a set of protection devices, and a set of agents. The agents are software applications installed on a set of endpoints to gather the health information that represents security states of the endpoint devices. The agents send updated health information to the controller. In response to a login attempt, the controller processes the health indicators and identity information through a set of administrator-defined policies to generate a set of access rights. The controller transfers the set of access rights to the protection devices. The protection devices then control user access to network resources according to the set of access rights. The controller sends updated sets of access rights to the protection devices whenever the access rights change.

    摘要翻译: 端点防御系统使用端点健康指标和用户身份信息来提供对网络资源的细粒度访问控制。 例如,端点防御系统可以包括控制器,一组保护装置和一组代理。 这些代理是安装在一组端点上的软件应用程序,用于收集表示端点设备安全状态的运行状况信息。 代理将更新的健康信息发送给控制器。 响应于登录尝试,控制器通过一组管理员定义的策略处理健康指示符和身份信息,以生成一组访问权限。 控制器将一组访问权限传递给保护设备。 然后,保护设备根据一组访问权限控制用户对网络资源的访问。 只要访问权限发生变化,控制器就会向保护设备发送更新的访问权限集。

    Dynamic toolbar for markup language document
    2.
    发明授权
    Dynamic toolbar for markup language document 有权
    标记语言文档的动态工具栏

    公开(公告)号:US09183188B2

    公开(公告)日:2015-11-10

    申请号:US12955665

    申请日:2010-11-29

    CPC分类号: G06F17/2247 G06F3/04812

    摘要: A toolbar that is provided or inserted in a markup language document so as to facilitate features or functionality provided by a server is disclosed. The toolbar is able to determine whether the toolbar should be displayed as part of the markup language page being displayed. In one embodiment the server is an intermediary server.

    摘要翻译: 公开了提供或插入到标记语言文档中以便于由服务器提供的特征或功能的工具栏。 工具栏能够确定工具栏是否应显示为正在显示的标记语言页面的一部分。 在一个实施例中,服务器是中间服务器。

    Method and system for modifying requests for remote resources
    3.
    发明授权
    Method and system for modifying requests for remote resources 有权
    修改远程资源请求的方法和系统

    公开(公告)号:US07085817B1

    公开(公告)日:2006-08-01

    申请号:US09706182

    申请日:2000-11-03

    IPC分类号: G06F15/16

    摘要: Techniques for modifying requests or browser viewable documents (e.g., markup language documents) are described. By modifying requests or browser viewable documents, access to resources residing on remote servers through an intermediate server is facilitated. In one embodiment, Universal Resource Locators (URLs) associated with requests or markup language documents are modified. The techniques are suitable for both secure and unsecure requests. The techniques can also modify requests or browser viewable documents at the intermediate server, a client device, or both.

    摘要翻译: 描述了用于修改请求或浏览器可浏览文档(例如,标记语言文档)的技术。 通过修改请求或可浏览浏览的文档,便于通过中间服务器访问位于远程服务器上的资源。 在一个实施例中,与请求或标记语言文档相关联的通用资源定位符(URL)被修改。 这些技术适用于安全和不安全的请求。 这些技术还可以修改中间服务器,客户端设备或两者的请求或浏览器可查看的文档。

    Local caching of one-time user passwords
    4.
    发明授权
    Local caching of one-time user passwords 有权
    本地缓存一次性用户密码

    公开(公告)号:US08225102B1

    公开(公告)日:2012-07-17

    申请号:US12825077

    申请日:2010-06-28

    IPC分类号: G06F21/00

    摘要: An intermediate network device includes a local caching module that caches user information from a remote server before a local user requests the information. In particular, the local caching module securely obtains and caches one-time passwords for a local user. The local caching device maintains separate sets of one-time passwords for each user. The local caching module may access the locally cached one-time passwords to authenticate a local user to a resource protected by a one-time password.

    摘要翻译: 中间网络设备包括在本地用户请求信息之前缓存来自远程服务器的用户信息的本地缓存模块。 特别地,本地缓存模块安全地获取并缓存本地用户的一次性密码。 本地缓存设备为每个用户维护单独的一次性密码。 本地缓存模块可以访问本地缓存的一次性密码,以将本地用户认证为一次性密码保护的资源。

    Method and system for modifying requests for remote resources
    5.
    发明授权
    Method and system for modifying requests for remote resources 有权
    修改远程资源请求的方法和系统

    公开(公告)号:US07877459B2

    公开(公告)日:2011-01-25

    申请号:US11423087

    申请日:2006-06-08

    IPC分类号: G06F15/173

    摘要: Techniques for modifying requests or browser viewable documents (e.g., markup language documents) are described. By modifying requests or browser viewable documents, access to resources residing on remote servers through an intermediate server is facilitated. In one embodiment, Universal Resource Locators (URLs) associated with requests or markup language documents are modified. The techniques are suitable for both secure and unsecure requests. The techniques can also modify requests or browser viewable documents at the intermediate server, a client device, or both.

    摘要翻译: 描述了用于修改请求或浏览器可浏览文档(例如,标记语言文档)的技术。 通过修改请求或可浏览浏览的文档,便于通过中间服务器访问位于远程服务器上的资源。 在一个实施例中,与请求或标记语言文档相关联的通用资源定位符(URL)被修改。 这些技术适用于安全和不安全的请求。 这些技术还可以修改中间服务器,客户端设备或两者的请求或浏览器可查看的文档。

    DUAL AUTHENTICATION OF A REQUESTOR USING A MAIL SERVER AND AN AUTHENTICATION SERVER
    6.
    发明申请
    DUAL AUTHENTICATION OF A REQUESTOR USING A MAIL SERVER AND AN AUTHENTICATION SERVER 有权
    使用邮件服务器和认证服务器的请求者的双重认证

    公开(公告)号:US20060242241A1

    公开(公告)日:2006-10-26

    申请号:US10060525

    申请日:2002-01-29

    IPC分类号: G06F15/16

    CPC分类号: H04L63/083 H04L51/00

    摘要: Improved approaches for providing secure remote access to email resources maintained on private networks are disclosed. The secure access can be provided through a public network using a standard network browser. Multiple remote users are able to gain restricted and controlled access to email on a mail server within a private network through a common access point. The solution provided by the improved approaches allow not only native access to email resources but also robust authentication approaches.

    摘要翻译: 公开了用于提供对专用网络上维护的电子邮件资源的安全远程访问的改进方法。 可以通过使用标准网络浏览器的公共网络提供安全访问。 多个远程用户能够通过公共接入点在私有网络内的邮件服务器上获得对电子邮件的受限和受控访问。 改进方法提供的解决方案不仅允许本机访问电子邮件资源,还可以实现强大的身份验证方法。

    Dual authentication of a requestor using a mail server and an authentication server
    8.
    发明授权
    Dual authentication of a requestor using a mail server and an authentication server 有权
    使用邮件服务器和认证服务器对请求者进行双重身份验证

    公开(公告)号:US07146403B2

    公开(公告)日:2006-12-05

    申请号:US10060525

    申请日:2002-01-29

    IPC分类号: G06F13/00

    CPC分类号: H04L63/083 H04L51/00

    摘要: Improved approaches for providing secure remote access to email resources maintained on private networks are disclosed. The secure access can be provided through a public network using a standard network browser. Multiple remote users are able to gain restricted and controlled access to email on a mail server within a private network through a common access point. The solution provided by the improved approaches allow not only native access to email resources but also robust authentication approaches.

    摘要翻译: 公开了用于提供对专用网络上维护的电子邮件资源的安全远程访问的改进方法。 可以通过使用标准网络浏览器的公共网络提供安全访问。 多个远程用户能够通过公共接入点在私有网络内的邮件服务器上获得对电子邮件的受限和受控访问。 改进方法提供的解决方案不仅允许本机访问电子邮件资源,还可以实现强大的身份验证方法。

    Method and system for providing secure access to private networks
    9.
    发明授权
    Method and system for providing secure access to private networks 有权
    提供对私有网络的安全访问的方法和系统

    公开(公告)号:US08326981B2

    公开(公告)日:2012-12-04

    申请号:US12821928

    申请日:2010-06-23

    IPC分类号: G06F15/16

    摘要: Improved approaches for providing secure access to resources maintained on private networks are disclosed. The secure access can be provided through a public network using a standard network browser. Multiple remote users are able to gain restricted and controlled access to at least portions of a private network through a common access point. The solution provided by the invention is not only easily set up and managed, but also able to support many remote users in a cost-effective manner.

    摘要翻译: 公开了用于提供对私有网络上维护的资源的安全访问的改进的方法。 可以通过使用标准网络浏览器的公共网络提供安全访问。 多个远程用户能够通过公共接入点获得对私有网络的至少部分的受限和受控访问。 本发明提供的解决方案不仅容易建立和管理,而且能够以成本有效的方式支持许多远程用户。

    Web resource request processing
    10.
    发明授权
    Web resource request processing 有权
    Web资源请求处理

    公开(公告)号:US07877440B2

    公开(公告)日:2011-01-25

    申请号:US11555480

    申请日:2006-11-01

    IPC分类号: G06F13/00

    CPC分类号: H04L63/083 H04L51/00

    摘要: Improved approaches for providing secure remote access to email resources maintained on private networks are disclosed. The secure access can be provided through a public network using a standard network browser. Multiple remote users are able to gain restricted and controlled access to email on a mail server within a private network through a common access point. The solution provided by the improved approaches allow not only native access to email resources but also robust authentication approaches.

    摘要翻译: 公开了用于提供对专用网络上维护的电子邮件资源的安全远程访问的改进方法。 可以通过使用标准网络浏览器的公共网络提供安全访问。 多个远程用户能够通过公共接入点在私有网络内的邮件服务器上获得对电子邮件的受限和受控访问。 改进方法提供的解决方案不仅允许本机访问电子邮件资源,还可以实现强大的身份验证方法。