发明名称 METHODS FOR EFFECTIVE NETWORK-SECURITY INSPECTION IN VIRTUALIZED ENVIRONMENTS
摘要 The present invention discloses methods for effective network-security inspection in virtualized environments, the methods including the steps of: providing a data packet, embodied in machine-readable signals, being sent from a sending virtual machine to a receiving virtual machine via a virtual switch; intercepting the data packet by a sending security agent associated with the sending virtual machine; injecting the data packet into an inspecting security agent associated with a security virtual machine via a direct transmission channel which bypasses the virtual switch; forwarding the data packet to the security virtual machine by employing a packet-forwarding mechanism; determining, by the security virtual machine, whether the data packet is allowed for transmission; upon determining the data packet is allowed, injecting the data packet back into the sending security agent via the direct transmission channel; and forwarding the data packet to the receiving virtual machine via the virtual switch.
申请公布号 US2010269171(A1) 申请公布日期 2010.10.21
申请号 US20090507830 申请日期 2009.07.23
申请人 CHECK POINT SOFTWARE TECHNOLOGIES, LTD. 发明人 RAZ OFER;PERLMUTTER AMNON;BERKNER EREZ
分类号 G06F17/00;G06F11/00;G06F15/16 主分类号 G06F17/00
代理机构 代理人
主权项
地址