发明名称 |
Compliance validator for restricted network access control |
摘要 |
A method, system, and computer program product for detecting and enforcing compliance with access requirements for a computer system in a restricted computer network. A compliance validation configuration file is created for the computer system. A maintenance service utility is configured to launch a compliance validation executable file at a specified time during operation of the computer system. A digital hash is generated for the compliance validation executable file and for the compliance validation configuration file. A determination is made if the computer system or a computer system user is a member of a configured restricted group. If the computer system or the computer system user is a member of a configured restricted group, a determination is made if a directory site code for a subnet of the restricted computer network to which the computer system is connected corresponds to a configured and allowed site. If the directory site code does not correspond to a configured and allowed site, compliance with access requirements are enforced. Enforcement actions can include a forced logoff of the computer system user, and/or a forced shutdown of the computer system. |
申请公布号 |
US9270677(B1) |
申请公布日期 |
2016.02.23 |
申请号 |
US201414175372 |
申请日期 |
2014.02.07 |
申请人 |
Open Invention Network, LLC |
发明人 |
Feeser Colin Lee;Ondrus Anthony William;Canup Mark Jackson |
分类号 |
H04L29/06;G06F11/00;G06F12/14;G06F12/16;G08B23/00 |
主分类号 |
H04L29/06 |
代理机构 |
Haynes and Boone, LLP |
代理人 |
Haynes and Boone, LLP |
主权项 |
1. A method, comprising:
determining if there are any updates at a location for either a compliance validation executable file or a compliance configuration file, based on a digital hash of the compliance validation executable file and the compliance validation configuration file; automatically updating the compliance validation executable file and the compliance validation configuration file, if any updates are available; determining if a compliance validation executable update file has been removed from the location; and removing the compliance validation executable file and the compliance validation configuration file from a computer system if:
the update file has been removed; andeither the computer system is not a member of a configured restricted group or a computer system user is not a member of the configured restricted group. |
地址 |
Durham NC US |