Apparatus for high speed communication on asymmetric line
    1.
    发明授权
    Apparatus for high speed communication on asymmetric line 有权
    非对称线高速通信装置

    公开(公告)号:US06587435B1

    公开(公告)日:2003-07-01

    申请号:US09263792

    申请日:1999-03-05

    IPC分类号: H04L1256

    摘要: The apparatus 10 is set on the line between the first and second computers 1,2 which respectively communicates by a protocol, such as TCP, having a flow control. The delay between the first computer 1 and a position, at which the apparatus 10 is set, is less than the delay between the position and the second computer 2. The apparatus 10 sends and receives a packet to/from the computers 1,2. The apparatus 10 transfers to the second computer 2, a data packet sent from the first computer 1 and being larger than a maximum data amount notified by the second computer 2. The apparatus 10 transfers, to the first computer 1, a data packet sent from the second computer 2, but does not transfer, to the first computer 1, an ACK packet sent from the second computer 2. The apparatus 10 generates, instead of the second computer 2, an ACK packet for a data packet sent from the first computer 1 and then sends the ACK packet to the first computer 1. Therefore, in a case that a large delay section having exists in the line between the computers 1 and 2, it is possible to perform a high speed communication on one way by only setting one apparatus 10.

    摘要翻译: 设备10设置在分别通过具有流量控制的诸如TCP的协议通信的第一和第二计算机1,2之间的线上。 第一计算机1与设备10所设置的位置之间的延迟小于位置与第二计算机2之间的延迟。装置10向/从计算机1,2发送和接收分组。 装置10向第二计算机2传送从第一计算机1发送的数据分组,并且大于由第二计算机2通知的最大数据量。装置10向第一计算机1传送从第一计算机1发送的数据分组 第二计算机2,但不向第一计算机1传送从第二计算机2发送的ACK分组。装置10代替第二计算机2生成用于从第一计算机发送的数据分组的ACK分组 1,然后将ACK分组发送到第一计算机1.因此,在计算机1和2之间的线路中存在大的延迟部分的情况下,可以通过仅设置来单向执行高速通信 一个装置10。

    Method, apparatus and program for detecting spoofed network traffic
    2.
    发明授权
    Method, apparatus and program for detecting spoofed network traffic 有权
    用于检测欺骗性网络流量的方法,装置和程序

    公开(公告)号:US08925079B2

    公开(公告)日:2014-12-30

    申请号:US13295553

    申请日:2011-11-14

    CPC分类号: G06F21/00 H04L63/1466

    摘要: A method, an apparatus and a program for detecting spoofed Internet Protocol (IP) traffic directed to a network having a plurality of autonomous systems (AS) is provided. The method comprises receiving an incoming packet through an AS, the incoming packet containing a source IP address and a destination IP address, acquiring a corresponding source and destination IP address prefixes, converting the corresponding source and destination IP address prefixes into a source AS number and a destination AS number, determining if the incoming packet arrived from an unexpected source based upon the corresponding destination IP address prefix and the converted source and destination AS number using an unexpected pair tuple table generated from network routing information and generating an alert indicating that the incoming packet is not allowed to enter the network.

    摘要翻译: 提供了一种用于检测针对具有多个自治系统(AS)的网络的欺骗性因特网协议(IP)流量的方法,装置和程序。 该方法包括:通过AS接收输入的分组,该分组包含源IP地址和目的IP地址,获取相应的源和目的IP地址前缀,将相应的源和目的IP地址前缀转换为源AS号, 目的AS号码,根据网络路由信息生成表示基于相应的目的地IP地址前缀和转换后的源和目的地AS号码,确定传入分组是否从意外的源到达,并产生一个警报, 数据包不允许进入网络。

    Method and apparatus for detecting spoofed network traffic
    3.
    发明授权
    Method and apparatus for detecting spoofed network traffic 有权
    用于检测欺骗性网络流量的方法和装置

    公开(公告)号:US08281397B2

    公开(公告)日:2012-10-02

    申请号:US12769696

    申请日:2010-04-29

    IPC分类号: H04L29/06

    CPC分类号: H04L63/1416

    摘要: A method and apparatus for detecting spoofed IP network traffic is presented. A mapping table is created to indicate correlations between IP address prefixes and AS numbers, based on routing information collected from a plurality of data sources. At each interface of a target network, IP address prefixes from a training traffic flow are acquired and further converted into AS numbers based on the mapping table. An EAS (Expected Autonomous System) table is populated by the AS numbers collected for each interface. The EAS table is used to determine if an operation traffic flow is allowed to enter the network.

    摘要翻译: 提出了一种用于检测欺骗性IP网络流量的方法和装置。 基于从多个数据源收集的路由信息​​,创建映射表以指示IP地址前缀和AS号之间的相关性。 在目标网络的每个接口处,获取来自训练业务流的IP地址前缀,并根据映射表进一步转换成AS号。 EAS(预期自治系统)表由每个接口收集的AS号码填充。 EAS表用于确定操作流量是否允许进入网络。

    METHOD AND APPARATUS FOR DETECTING SPOOFED NETWORK TRAFFIC
    4.
    发明申请
    METHOD AND APPARATUS FOR DETECTING SPOOFED NETWORK TRAFFIC 有权
    检测网络交通流量的方法和装置

    公开(公告)号:US20110271340A1

    公开(公告)日:2011-11-03

    申请号:US12769696

    申请日:2010-04-29

    IPC分类号: G06F21/00

    CPC分类号: H04L63/1416

    摘要: A method and apparatus for detecting spoofed IP network traffic is presented. A mapping table is created to indicate correlations between IP address prefixes and AS numbers, based on routing information collected from a plurality of data sources. At each interface of a target network, IP address prefixes from a training traffic flow are acquired and further converted into AS numbers based on the mapping table. An EAS (Expected Autonomous System) table is populated by the AS numbers collected for each interface. The EAS table is used to determine if an operation traffic flow is allowed to enter the network.

    摘要翻译: 提出了一种用于检测欺骗性IP网络流量的方法和装置。 基于从多个数据源收集的路由信息​​,创建映射表以指示IP地址前缀和AS号之间的相关性。 在目标网络的每个接口处,获取来自训练业务流的IP地址前缀,并根据映射表进一步转换成AS号。 EAS(预期自治系统)表由每个接口收集的AS号码填充。 EAS表用于确定操作流量是否允许进入网络。

    Method, Apparatus and Program for Detecting Spoofed Network Traffic
    6.
    发明申请
    Method, Apparatus and Program for Detecting Spoofed Network Traffic 有权
    用于检测欺骗性网络流量的方法,装置和程序

    公开(公告)号:US20130125235A1

    公开(公告)日:2013-05-16

    申请号:US13295553

    申请日:2011-11-14

    IPC分类号: G06F21/20

    CPC分类号: G06F21/00 H04L63/1466

    摘要: A method, an apparatus and a program for detecting spoofed Internet Protocol (IP) traffic directed to a network having a plurality of autonomous systems (AS) is provided. The method comprises receiving an incoming packet through an AS, the incoming packet containing a source IP address and a destination IP address, acquiring a corresponding source and destination IP address prefixes, converting the corresponding source and destination IP address prefixes into a source AS number and a destination AS number, determining if the incoming packet arrived from an unexpected source based upon the corresponding destination IP address prefix and the converted source and destination AS number using an unexpected pair tuple table generated from network routing information and generating an alert indicating that the incoming packet is not allowed to enter the network.

    摘要翻译: 提供了一种用于检测针对具有多个自治系统(AS)的网络的欺骗性因特网协议(IP)流量的方法,装置和程序。 该方法包括:通过AS接收输入的分组,该分组包含源IP地址和目的IP地址,获取相应的源和目的IP地址前缀,将相应的源和目的IP地址前缀转换为源AS号, 目的AS号码,根据网络路由信息生成表示基于相应的目的地IP地址前缀和转换后的源和目的地AS号码,确定传入分组是否从意外的源到达,并产生一个警报, 数据包不允许进入网络。

    Cross-domain access control
    7.
    发明授权
    Cross-domain access control 有权
    跨域访问控制

    公开(公告)号:US07062654B2

    公开(公告)日:2006-06-13

    申请号:US10148940

    申请日:2001-11-09

    IPC分类号: H04L9/00

    摘要: The present invention provides systems and methods of cross-domain access control in which a client node (250) sends a request (250) for a resource to a resource server (260). In response, a local proxy server (270) automatically obtains a ticket having a revocation status (275) and forwards the ticket (275) to an authorization server (280) that communicates with the resource server (260) regarding access.

    摘要翻译: 本发明提供了跨域访问控制的系统和方法,其中客户端节点(250)向资源服务器(260)发送用于资源的请求(250)。 作为响应,本地代理服务器(270)自动获得具有撤销状态(275)的故障单,并将故障单(275)转发到与资源服务器(260)进行通信的授权服务器(280)。

    Communication system and security assurance device
    8.
    发明申请
    Communication system and security assurance device 失效
    通信系统和安全保障设备

    公开(公告)号:US20060048228A1

    公开(公告)日:2006-03-02

    申请号:US11212442

    申请日:2005-08-26

    摘要: A communication system and a security assurance device are proposed, which are capable of assuring that a target party for communication is implementing security countermeasures. A server 3 transmits information 104 necessary for AC issuance to a security assurance authority 2. The security assurance authority 2 verifies the security of the server 3 during communication based upon this information necessary for AC issuance 104. And, when the security of the server 3 during communication is confirmed, the security assurance authority 2 issues an AC 105 which proves the security of the server 3 during communication, and transmits it to the server 3. Upon receipt of this AC 105, the server 3 transmits the AC 105 to a client 4, according to a connection request from the client 4. And, upon receipt of this AC 105, the client 4 verifies the security during communication of the server 3, based upon the AC 105.

    摘要翻译: 提出了一种通信系统和安全保障装置,能够确保通信对象方正在实施安全对策。 服务器3向安全保证机构2发送AC发行所需的信息104。 安全保证机构2基于AC发行104所需的该信息,在通信期间验证服务器3的安全性。 并且,当确认通信期间的服务器3的安全性时,安全保证机构2发出在通信期间证明服务器3的安全性的AC105,并将其发送到服务器3。 在接收到该AC 105时,服务器3根据来自客户端4的连接请求将AC105发送给客户机4.并且,在接收到该AC 105之后,客户端4在服务器3的通信期间验证安全性 ,基于AC 105。

    Water pump attachment structure of water-cooled internal combustion engine
    9.
    发明授权
    Water pump attachment structure of water-cooled internal combustion engine 有权
    水冷式内燃机水泵附件结构

    公开(公告)号:US08276553B2

    公开(公告)日:2012-10-02

    申请号:US12635398

    申请日:2009-12-10

    IPC分类号: F01P5/10

    摘要: A water pump attachment structure of a water-cooled internal combustion engine is provided to facilitate the maintenance of a valve train. A water pump attachment structure of a water-cooled internal combustion engine includes a semicircular cut-away surface of a water pump holder opposed to a semicircular surface of a cylinder head to form a water pump support circular hole. Screw members are passed through respective screw through-holes of the cylinder head and threadedly engaged with internal thread holes of the water pump holder. Thus, the water pump holder is fastened to the cylinder head. A water pump is fitted into and secured to the water pump support circular hole. A cylinder head cover is attached to the cylinder head by allowing their mating surfaces to conform with each other with the water pump holder liquid-tightly sandwiched therebetween.

    摘要翻译: 提供了一种水冷式内燃机的水泵安装结构,以便于维持气门机构。 水冷式内燃机的水泵安装结构包括与气缸盖的半圆形表面相对的水泵保持架的半圆形切除面,形成水泵支承圆孔。 螺杆构件通过气缸盖的相应螺钉通孔,并与水泵保持架的内螺纹孔螺纹接合。 因此,水泵保持器紧固到气缸盖。 水泵安装在水泵支撑圆孔上并固定在水泵支撑圆孔上。 气缸盖罩通过允许它们的配合表面彼此顺应,水泵保持器液密地夹在气缸盖之间而附接到气缸盖。

    WATER PUMP ATTACHMENT STRUCTURE OF WATER-COOLED INTERNAL COMBUSTION ENGINE
    10.
    发明申请
    WATER PUMP ATTACHMENT STRUCTURE OF WATER-COOLED INTERNAL COMBUSTION ENGINE 有权
    水冷式内燃机水泵附件结构

    公开(公告)号:US20100162974A1

    公开(公告)日:2010-07-01

    申请号:US12635398

    申请日:2009-12-10

    IPC分类号: F01P5/10 F02B77/00

    摘要: A water pump attachment structure of a water-cooled internal combustion engine is provided to facilitate the maintenance of a valve train. A water pump attachment structure of a water-cooled internal combustion engine includes a semicircular cut-away surface of a water pump holder opposed to a semicircular surface of a cylinder head to form a water pump support circular hole. Screw members are passed through respective screw through-holes of the cylinder head and threadedly engaged with internal thread holes of the water pump holder. Thus, the water pump holder is fastened to the cylinder head. A water pump is fitted into and secured to the water pump support circular hole. A cylinder head cover is attached to the cylinder head by allowing their mating surfaces to conform with each other with the water pump holder liquid-tightly sandwiched therebetween.

    摘要翻译: 提供了一种水冷式内燃机的水泵安装结构,以便于维持气门机构。 水冷式内燃机的水泵安装结构包括与气缸盖的半圆形表面相对的水泵保持架的半圆形切除面,形成水泵支承圆孔。 螺杆构件通过气缸盖的相应螺钉通孔,并与水泵保持架的内螺纹孔螺纹接合。 因此,水泵保持器紧固到气缸盖。 水泵安装在水泵支撑圆孔上并固定在水泵支撑圆孔上。 气缸盖罩通过允许它们的配合表面彼此顺应,水泵保持器液密地夹在气缸盖之间而附接到气缸盖。