发明名称 Method and system for monitoring and controlling network access
摘要 <p>A method and system for monitoring and controlling network access includes non-intrusively monitoring network traffic and assembling data packets that are specific to individual node-to-node transmissions in order to manage network access both inside and outside of a network. A rules base (78) is generated to apply at either or both of the connection time and the time subsequent to connection. With regard to a particular node-to-node transmission, the data packets are assembled to identify the source and destination nodes, as well as contextual information (i.e., ISO Layer 7 information). The access rules are applied in a sequential order to determine whether the transmission is a restricted transmission. The rules are maintained in a single rules base (78) for the entire network and are distributed to each monitoring node. Any of the protocols in the suite of TCP/IP protocols can be managed. The result of an analysis against the rules base (78) causes a connection attempt to be completed or denied, a previously established connection to be broken, logging to occur, or a combination of these and other actions. Data collected during connection attempts or during a connection's lifetime may be passed to a third-party hardware or software component in order for independent validation to take place. Traffic monitoring and access management can be executed at a node other then a choke point of the network. &lt;IMAGE&gt;</p>
申请公布号 EP0986229(A2) 申请公布日期 2000.03.15
申请号 EP19990116787 申请日期 1999.08.31
申请人 SURFCONTROL PLC 发明人 CUNNINGHAM, MARK;TREVARROW, ANDREW
分类号 H04L12/26;H04L29/06;(IPC1-7):H04L29/06 主分类号 H04L12/26
代理机构 代理人
主权项
地址