发明名称 Security System with Methodology Providing Verified Secured Individual End Points
摘要 A security system with methodology providing verified secured individual end points is described. In one embodiment, for example, a method of the present invention is described for controlling access to a particular application, the method comprises steps of: defining firewall rules specifying filtering conditions for incoming network traffic, the firewall rules including an application attribute that allows individual rules to be associated with specific applications, the firewall rules also including extended attributes that allow specification of additional conditions that a given end point is required to meet; intercepting incoming network traffic destined for a particular application for which a particular application-specific firewall rule has been created; examining the extended attributes for the particular application-specific firewall rule, for determining what additional conditions the given end point must comply with in order to communicate with the particular application; if the given end point complies with the additional conditions, allowing the end point to communicate with the particular application; and otherwise blocking the end point to prevent communication with the particular application.
申请公布号 US2005273850(A1) 申请公布日期 2005.12.08
申请号 US20050907331 申请日期 2005.03.29
申请人 CHECK POINT SOFTWARE TECHNOLOGIES, INC. 发明人 FREUND GREGOR P.
分类号 G06F11/30;G06F12/14;H04L9/00;H04L9/32;H04L29/06;(IPC1-7):H04L9/00 主分类号 G06F11/30
代理机构 代理人
主权项
地址