摘要:
A scanning tool executing on a host computer may be used to scan a server only if the server (or a proxy) first exposes to the host a certificate that, upon processing by the host, indicates that the server may be scanned. The certificate preferably encrypts a scan permission and is made available from a given port on the server (or the proxy). Whenever the host desires to perform a scan of the server, the host searches the port for the certificate. The certificate is then decrypted to determine whether the scan permission exists. If so, the scan then proceeds, in accordance with any conditions set forth in the decrypted scan permission.
摘要:
A method of validating a request to access a target server in a computer network having an open, trusted database. The method begins when a request to access the target server is received at a host from which the scheme is supported. In response, a query is initiated to the trusted database to identify a technical, administrative or other contact person that may authorize the access request. In the Internet, the trusted database may be the WHOIS database that includes second level domain name information. A second query (e.g., an e-mail) is then launched to the identified contact. The e-mail preferably includes a URL and a key. The URL identifies a response Web page interface that is accessible upon entry of the key. If the identified contact accesses the Web page interface, he or she may then authorize the access request, deny the access request, or indicate under what conditions the request may occur. The invention takes advantage of existing Internet infrastructure and methods to provide a robust lightweight authentication mechanism.