发明名称 System and method for building intelligent and distributed L2-L7 unified threat management infrastructure for IPv4 and IPv6 environments
摘要 A security gateway appliance is configured to evaluate network traffic according to security rules that classify traffic flows according to specifically identified application programs responsible for producing and/or consuming the network traffic and to enforce policies in accordance with network traffic classifications. The appliance includes an on-box anti-virus/anti-malware engine, on-box data loss prevention engine and on-box authentication engine. One or more of these engines is informed by an on-box dynamic real tie rating system that allows for determined levels of scrutiny to be paid to the network traffic. Security gateways of this type can be clustered together to provide a set of resources for one or more networks, and in some instances as the backbone of a cloud-based service.
申请公布号 US8839404(B2) 申请公布日期 2014.09.16
申请号 US201113116760 申请日期 2011.05.26
申请人 Blue Coat Systems, Inc. 发明人 Li Qing;Frederick Ronald Andrew;Clare Thomas A.
分类号 H04L29/06;H04L29/08 主分类号 H04L29/06
代理机构 Ascenda Law Group, PC 代理人 Ascenda Law Group, PC
主权项 1. A security gateway appliance, comprising: a memory and a processor communicatively coupled to the memory, the processor and the memory are included in the security gateway appliance, wherein the memory stores computer-executable instructions which, when executed by the processor, cause the processor to: (a) evaluate network traffic received at the security gateway appliance according to security rules that classify traffic flows according to specifically identified application programs responsible for producing and/or consuming the network traffic, (b) enforce policies in accordance with network traffic classifications, wherein the policies are associated with one or more connection management actions associated with one or more of: load balancing, traffic shaping, and quality of service actions, (c) provide real-time ratings and protection against undesired web content for a network, (d) evaluate the network traffic for potential data loss from the network, (e) provide application filtering and controls while enforcing quality of service, and (f) scan inbound network traffic for viruses and malware engines, and scan outbound traffic from the network for data leaks, without diverting the traffic off of the security gateway appliance.
地址 Sunnyvale CA US