发明名称 INTROSPECTION METHOD AND APPARATUS FOR NETWORK ACCESS FILTERING
摘要 Some embodiments of the invention provide a method for performing network access filtering and/or categorization through guest introspection (GI) on a device. In some embodiments, this GI method intercepts directly on a device a data message that device is preparing to send, and uses a service appliance to determine whether the data message can be sent. The device in some embodiments is a guest virtual machine (VM) that executes on a multi-VM host computing device along with a service VM (SVM) that is the service appliance that determines whether the data message can be sent based on a set of filtering rules. In some embodiments, the method uses one or more introspectors (e.g., network introspector and/or file introspector) to capture introspection data from the guest VM (GVM) about the data message that the GVM is preparing to send. To perform the network access filtering, the GI method in some embodiments captures contextual information, such as user and application information (e.g., application associated with a particular URL request). Hence, in some embodiments, this method seamlessly processes granular user-aware URL filtering rules (e.g., members of the sales organization can access social networking sites but not other members). This approach requires no additional configuration on networking infrastructure.
申请公布号 US2016191521(A1) 申请公布日期 2016.06.30
申请号 US201514814413 申请日期 2015.07.30
申请人 Nicira, Inc. 发明人 Feroz Azeem;Kumar Vasantha;Wiese James Christopher;Patil Amit Vasant
分类号 H04L29/06;G06F9/455 主分类号 H04L29/06
代理机构 代理人
主权项 1. A system for filtering network access on host devices on which data compute nodes executes, the system comprising: a plurality of guest introspectors installed on a plurality of data compute nodes for capturing data regarding network access attempts on the data compute nodes; at least one service compute node (SCN) executing on each host devices; each host device's SCN for (i) receiving captured data regarding network access attempts from a set of guest introspectors on the host device, (ii) rejecting a network access attempt when a network access policy stored on the host device requires the rejection of the network access; and (iii) allowing a network access when no network access policy stored on the host device requires the rejection of the network access.
地址 Palo Alto CA US