SECURITY CONTROL APPARATUS AND METHOD FOR CLOUD-BASED VIRTUAL DESKTOP
    12.
    发明申请
    SECURITY CONTROL APPARATUS AND METHOD FOR CLOUD-BASED VIRTUAL DESKTOP 有权
    用于基于云的虚拟桌面的安全控制装置和方法

    公开(公告)号:US20150326611A1

    公开(公告)日:2015-11-12

    申请号:US14474242

    申请日:2014-09-01

    CPC classification number: H04L63/0218 H04L12/22 H04L41/046 H04L63/20

    Abstract: The security control apparatus includes a network control unit for receiving a security protocol-based packet that includes a protocol control header and data and that is transmitted between a cloud-based virtual desktop interaction remote agent unit and a virtual machine of a cloud-based virtual desktop interaction device, and blocking network traffic between cloud-based virtual desktop interaction remote agent unit and the virtual machine, depending on received results of checking. A policy checking unit checks whether information extracted from the security protocol-based packet is compliant with control policies, and transmits results of checking to the network control unit. If the information is not compliant with the control policies, a security solution interaction unit transmits the extracted information to an external security solution, and transmits results of checking by a corresponding security solution to the network control unit.

    Abstract translation: 安全控制装置包括网络控制单元,用于接收基于安全协议的分组,该分组包括协议控制头部和数据,并且在基于云的虚拟桌面交互远程代理单元与基于云的虚拟的虚拟机 桌面交互设备,以及根据接收到的检查结果阻止基于云的虚拟桌面交互远程代理单元与虚拟机之间的网络流量。 策略检查单元检查从基于安全协议的分组提取的信息是否符合控制策略,并将检查结果发送到网络控制单元。 如果信息不符合控制策略,则安全解决方案交互单元将提取的信息发送到外部安全解决方案,并将相应的安全解决方案的检查结果发送到网络控制单元。

    APPARATUS AND METHOD FOR DETECTING HTTP BOTNET BASED ON DENSITIES OF WEB TRANSACTIONS
    13.
    发明申请
    APPARATUS AND METHOD FOR DETECTING HTTP BOTNET BASED ON DENSITIES OF WEB TRANSACTIONS 审中-公开
    基于WEB交易密码检测HTTP BOTNET的装置和方法

    公开(公告)号:US20140047543A1

    公开(公告)日:2014-02-13

    申请号:US13958552

    申请日:2013-08-03

    CPC classification number: H04L63/1441 H04L2463/144

    Abstract: An apparatus and method for detecting a Hyper Text Transfer Protocol (HTTP) botnet based on the densities of transactions. The apparatus includes a collection management unit, a web transaction classification unit, and a filtering unit. The collection management unit extracts metadata from HTTP request packets collected by a traffic collection sensor. The web transaction classification unit extracts web transactions by analyzing the metadata, and generates a gray list by arranging the extracted web transactions according to the frequency of access. The filtering unit detects an HTTP botnet by filtering the gray list based on a white list and a black list.

    Abstract translation: 一种基于事务密度检测超文本传输​​协议(HTTP)僵尸网络的装置和方法。 该装置包括收集管理单元,网络交易分类单元和过滤单元。 收集管理单元从由流量采集传感器收集的HTTP请求数据包中提取元数据。 Web事务分类单元通过分析元数据来提取Web事务,并且通过根据访问频率排列提取的Web事务来生成灰色列表。 过滤单元通过基于白名单和黑名单过滤灰名单来检测HTTP僵尸网络。

    APPARATUS AND METHOD FOR PERFORMING REAL-TIME NETWORK ANTIVIRUS FUNCTION
    19.
    发明申请
    APPARATUS AND METHOD FOR PERFORMING REAL-TIME NETWORK ANTIVIRUS FUNCTION 有权
    用于实现实时网络抗病毒功能的装置和方法

    公开(公告)号:US20160065595A1

    公开(公告)日:2016-03-03

    申请号:US14791929

    申请日:2015-07-06

    CPC classification number: H04L63/1416 H04L29/06877 H04L29/06884 H04L63/101

    Abstract: An apparatus and method for performing a real-time network antivirus function, which can perform, at high speed, real-time antivirus scanning on a transmission file in a network to be protected and blocking of a malicious file. The apparatus includes a packet processing unit for parsing input packets and outputting a transmission data stream, a packet-based checksum calculation unit for calculating a checksum of the transmission data stream for each packet, and outputting a signature included in the transmission data stream when a last packet of the transmission data stream is input, a virus scanning unit for performing virus scanning based on the signature, a detection and blocking unit for blocking each input packet or transmitting it to a destination, based on result of the virus scanning unit, and a caching unit for updating a blacklist, based on result of the detection and blocking unit.

    Abstract translation: 一种用于执行实时网络防病毒功能的装置和方法,其可以高速地执行要保护的网络中的传输文件的实时防病毒扫描和阻止恶意文件。 该装置包括用于解析输入分组并输出传输数据流的分组处理单元,用于计算每个分组的传输数据流的校验和的基于分组的校验和计算单元,以及当发送数据流中包含的签名时 输入传输数据流的最后一个分组,用于基于该签名执行病毒扫描的病毒扫描单元,用于阻止每个输入分组或将其发送到目的地的检测和阻断单元,基于病毒扫描单元的结果,以及 基于检测和阻塞单元的结果来更新黑名单的高速缓存单元。

Patent Agency Ranking