发明名称 System and method for a group-based network access control for a computer
摘要 Systems and methods for group-based network access control systems are provided. The group-based network access control system includes a software process operating on a computer. The software process is configured to communicate a packet through a group-based network protocol stack to a network interface card that includes an interface attribute. A table of network attributes, associated with a session filter module and a network filter module, compares the network endpoint attribute with the interface attribute in the table of network attributes to determine whether the software process can access the network interface card. Each network endpoint attribute comprises a primary group identifier and a supplemental group identifier list, and each interface attribute comprises a network group list. The method includes the steps of operating a software process that includes a network endpoint attribute. Next, packets are communicated through a network protocol stack to a network interface card, where the network interface card includes an interface attribute. Association between the network endpoint attribute and the interface attribute is established, and both the network endpoint attribute and the interface attribute are placed in a table. The network endpoint attribute is then compared with the interface attribute to determine whether the software process can access the network interface card. Each network endpoint attribute comprises a primary group identifier and a supplemental group identifier list, and each interface attribute comprises a network group list.
申请公布号 US2002078383(A1) 申请公布日期 2002.06.20
申请号 US20010897262 申请日期 2001.07.02
申请人 LEERSSEN SCOTT ALAN;CLARK BRETT MILLER 发明人 LEERSSEN SCOTT ALAN;CLARK BRETT MILLER
分类号 H04L29/06;(IPC1-7):G06F11/30 主分类号 H04L29/06
代理机构 代理人
主权项
地址