Security monitoring apparatus, security monitoring method, and security monitoring program based on a security policy
    1.
    发明授权
    Security monitoring apparatus, security monitoring method, and security monitoring program based on a security policy 失效
    安全监控设备,安全监控方法和基于安全策略的安全监控程序

    公开(公告)号:US08539546B2

    公开(公告)日:2013-09-17

    申请号:US13058122

    申请日:2010-11-19

    IPC分类号: G06F17/00 H04L29/06

    CPC分类号: G06Q10/0635

    摘要: A management server monitors even the occurrence of items, which are not targets of security policies, evaluates a change of the monitoring result, and implements specific output when necessary. Particularly, also regarding items which are considered to be non-targets of the security policies in management based on the security policies, the occurrence of such items is also monitored and the monitoring result is appropriately reported to an administrator so that the administrator can recognize a threat and takes necessary countermeasure at appropriate timing.

    摘要翻译: 管理服务器甚至监视不是安全策略目标的项目的发生,评估监视结果的变化,并在必要时实现特定的输出。 特别地,对于被认为是基于安全策略的管理安全策略的非目标的项目,也监视这些项目的发生,并将监视结果适当地报告给管理员,以便管理员能够识别 威胁并在适当的时机采取必要的对策。

    Remote access providing computer system and method for managing same
    2.
    发明申请
    Remote access providing computer system and method for managing same 有权
    远程访问提供计算机系统和管理方法

    公开(公告)号:US20080275962A1

    公开(公告)日:2008-11-06

    申请号:US11607317

    申请日:2006-11-30

    IPC分类号: G06F15/16

    摘要: A computer system for providing a remote access service includes a unit for acquiring information on a relation between a terminal and a user using the terminal, a unit for acquiring network information about the terminal, a unit for acquiring network information about a blade that the terminal will access, a unit for acquiring information on a relation between the blade and a storage area, and a management server for extracting information on the user and its usage information and providing these information in real time. The management server also has a unit for permitting an administrator of the management server, persons other than the user and a management program to use the blade.

    摘要翻译: 用于提供远程访问服务的计算机系统包括用于获取关于终端和使用终端的用户之间的关系的信息的单元,用于获取关于终端的网络信息的单元,用于获取关于该终端的网络信息的单元 将访问用于获取关于刀片与存储区域之间的关系的信息的单元,以及用于提取关于用户的信息及其使用信息并且实时提供这些信息的管理服务器。 管理服务器还具有允许管理服务器的管理员,用户以外的人员和管理程序来使用刀片的单元。

    Network traffic measurement system
    4.
    发明申请
    Network traffic measurement system 审中-公开
    网络流量测量系统

    公开(公告)号:US20050044213A1

    公开(公告)日:2005-02-24

    申请号:US10853158

    申请日:2004-05-26

    CPC分类号: H04L43/10 H04L43/00

    摘要: A measurement system is provided. In that measurement system, an active measurement device and passive measurement devices can cooperate to perform flexible measurement. The measurement system comprises passive measurement devices, each of which receives packets flowing through a network and performs measurement according to a measurement rule; an active measurement device that sends a request for a measurement to a content providing server according to a measurement rule, and acquires information relating to contents as measurement objects based on a response to said request for a measurement; and an analysis device that derives characteristics relating to provision of the contents, by performing calculation according to an analysis rule, with said calculation using measurement results corresponding to the information acquired by said active measurement device among measurement results of said passive measurement devices.

    摘要翻译: 提供测量系统。 在该测量系统中,主动测量装置和被动测量装置可配合进行灵活的测量。 测量系统包括被动测量装置,每个装置接收流经网络的分组,并根据测量规则进行测量; 基于测量规则向内容提供服务器发送测量请求的主动测量设备,并且基于对所述测量请求的响应来获取与内容相关的信息作为测量对象; 以及分析装置,通过使用与所述有源测量装置获取的信息对应的测量结果,使用与所述被动测量装置的测量结果对应的测量结果,根据分析规则进行计算,从而获得与提供内容有关的特性。

    SECURITY MONITORING APPARATUS, SECURITY MONITORING METHOD, AND SECURITY MONITORING PROGRAM BASED ON A SECURITY POLICY
    5.
    发明申请
    SECURITY MONITORING APPARATUS, SECURITY MONITORING METHOD, AND SECURITY MONITORING PROGRAM BASED ON A SECURITY POLICY 失效
    安全监察装置,安全监察方法和基于安全政策的安全监察方案

    公开(公告)号:US20120102542A1

    公开(公告)日:2012-04-26

    申请号:US13058122

    申请日:2010-11-19

    IPC分类号: G06F21/00

    CPC分类号: G06Q10/0635

    摘要: A management server monitors even the occurrence of items, which are not targets of security policies, evaluates a change of the monitoring result, and implements specific output when necessary. Particularly, also regarding items which are considered to be non-targets of the security policies in management based on the security policies, the occurrence of such items is also monitored and the monitoring result is appropriately reported to an administrator so that the administrator can recognize a threat and takes necessary countermeasure at appropriate timing.

    摘要翻译: 管理服务器甚至监视不是安全策略目标的项目的发生,评估监视结果的变化,并在必要时实现特定的输出。 特别地,对于被认为是基于安全策略的管理安全策略的非目标的项目,也监视这些项目的发生,并将监视结果适当地报告给管理员,以便管理员能够识别 威胁并在适当的时机采取必要的对策。

    COMPUTER SYSTEM, RESOURCE MANAGEMENT SERVER FOR COMPUTER SYSTEM, AND RESOURCE MANAGEMENT METHOD FOR COMPUTER SYSTEM
    6.
    发明申请
    COMPUTER SYSTEM, RESOURCE MANAGEMENT SERVER FOR COMPUTER SYSTEM, AND RESOURCE MANAGEMENT METHOD FOR COMPUTER SYSTEM 审中-公开
    计算机系统,计算机系统资源管理服务器,计算机系统资源管理方法

    公开(公告)号:US20110196968A1

    公开(公告)日:2011-08-11

    申请号:US12526946

    申请日:2009-03-25

    IPC分类号: G06F15/173

    摘要: A computer system that achieves effective utilization of physical servers' resources in a virtual client system is provided.In the virtual client system, the present invention obtains operation information about virtual machines, obtains access information indicating whether a user has logged on to the virtual machines or not, judges from connection information whether the user is using the virtual machines or not, calculates the capacity of the virtual machine(s) which are active, but is not accessed by the user, based on the capacity of resources used by the virtual machine(s), and then identifies the virtual machine(s) used by users from those not used by the users.

    摘要翻译: 提供了一种在虚拟客户端系统中实现物理服务器资源的有效利用的计算机系统。 在虚拟客户端系统中,本发明获得关于虚拟机的操作信息,获取表示用户是否登录到虚拟机的访问信息,从连接信息判断用户是否正在使用虚拟机, 基于虚拟机使用的资源的容量,然后识别用户使用的虚拟机的虚拟机的活动的容量,但是不被用户访问的虚拟机的容量 由用户使用

    NETWORK MONITORING DEVICE, NETWORK MONITORING METHOD, AND NETWORK MONITORING PROGRAM
    7.
    发明申请
    NETWORK MONITORING DEVICE, NETWORK MONITORING METHOD, AND NETWORK MONITORING PROGRAM 有权
    网络监控设备,网络监控方法和网络监控程序

    公开(公告)号:US20100061257A1

    公开(公告)日:2010-03-11

    申请号:US12486419

    申请日:2009-06-17

    IPC分类号: H04L12/26

    摘要: Information on a communication relation or communication path to be monitored is automatically generated to reduce load of a user. A path information generation part of a network monitoring device receives a destination IP address designated by a user as an object of monitoring. When the input of the destination IP address is received, the path information generation part uses configuration information tables, which store configuration information of a device on a network being monitoring, to identify IP addresses of networks to which a plurality of terminals belong, as branch IP addresses. Further, the path information generation part uses the configuration information tables and transfer destination information tables which store a routing table of a router on the network, in order to identify the connection order of routers between the designated destination IP address and the identified branch IP addresses, to generate path information.

    摘要翻译: 将自动生成要监视的通信关系或通信路径的信息,以减少用户的负载。 网络监视装置的路径信息生成部接收由用户指定的作为监视对象的目的地IP地址。 当接收到目的地IP地址的输入时,路径信息生成部使用存储被监视的网络上的设备的配置信息的配置信息表来识别多个终端所属的网络的IP地址作为分支 IP地址。 此外,路径信息生成部使用在网络上存储路由器的路由表的配置信息表和传送目的地信息表,以便识别指定的目的地IP地址和所识别的分支IP地址之间的路由器的连接顺序 ,以生成路径信息。

    Storage network management server, storage network managing method, storage network managing program, and storage network management system
    8.
    发明授权
    Storage network management server, storage network managing method, storage network managing program, and storage network management system 失效
    存储网络管理服务器,存储网络管理方法,存储网络管理程序和存储网络管理系统

    公开(公告)号:US07619965B2

    公开(公告)日:2009-11-17

    申请号:US10988590

    申请日:2004-11-16

    IPC分类号: G01R31/08

    CPC分类号: H04L67/1097

    摘要: In a system which manages path information and status of network with respect to a path being used for access to a storage apparatus and has a redundant path, when a fault occurs in the network, whether or not the path can be recovered by rerouting in network apparatuses is discriminated, thereby performing proper path switching. Construction information and the path information of the network are managed as information of the path which is being used for a storage access by a management server. Further, when the access path is made redundant, the management server obtains fault information in the network and information showing whether or not the path is being reconstructed from the network apparatuses, thereby discriminating the necessity of the path switching. If the path switching is necessary, the management server notifies a host computer and the storage apparatus of it and each apparatus executes a switching process.

    摘要翻译: 在管理相对于用于访问存储装置的路径的路径信息和网络状态并具有冗余路径的系统中,当网络中发生故障时,是否可以通过在网络中重新路由来恢复路径 鉴别装置,从而执行适当的路径切换。 构建信息和网络的路径信息作为用于由管理服务器进行存储访问的路径的信息进行管理。 此外,当访问路径变得冗余时,管理服务器获得网络中的故障信息,并且从网络装置获取表示是否正在重建路径的信息,从而区分路径切换的必要性。 如果路径切换是必要的,则管理服务器通知主计算机及其存储装置,并且每个装置执行切换处理。

    Communication band controller
    9.
    发明申请
    Communication band controller 审中-公开
    通信频带控制器

    公开(公告)号:US20060072608A1

    公开(公告)日:2006-04-06

    申请号:US11012132

    申请日:2004-12-16

    IPC分类号: H04J3/16

    摘要: The band controller 500 included in the computer system 1000 regularly acquires map information and IF information, etc. from the work server 100, the storage device 200, and the routers 300 and 400, and based on these pieces of information, detects iSCSI sessions for which the communication band is insufficient. When an iSCSI session with insufficient band is detected, the band controller 500 selects another iSCSI session to perform band allocation based on the iSCSI session importance level or the circuit use-rate. The band controller 500 allocates at least part of the communication band of the network route used by the iSCSI session selected in this way to the iSCSI session with insufficient band. The computer system 1000 performs efficient data transfer in storage area networks on which many variations of communication band exist.

    摘要翻译: 包括在计算机系统1000中的频带控制器500从工作服务器100,存储设备200和路由器300和400定期地获取地图信息和IF信息等,并且基于这些信息,检测iSCSI会话 通信频段不足。 当检测到带宽不足的iSCSI会话时,频带控制器500基于iSCSI会话重要性级别或电路使用率,选择另一个iSCSI会话来执行频带分配。 频带控制器500将以这种方式选择的iSCSI会话使用的网络路由的至少部分通信频带分配给具有不足频带的iSCSI会话。 计算机系统1000在存在多个通信频带变化的存储区域网络中执行有效的数据传输。

    Storage connection changing method for storage management system
    10.
    发明申请
    Storage connection changing method for storage management system 审中-公开
    存储管理系统的存储连接更换方法

    公开(公告)号:US20060036818A1

    公开(公告)日:2006-02-16

    申请号:US10959971

    申请日:2004-10-08

    IPC分类号: G06F12/14

    摘要: To provide a storage connection changing method for a storage management system of setting and releasing an external connection between a primary storage system and an external storage system in a storage system, the storage management system includes a computer, the primary storage system, the external storage system, a network device, and a management device which manages the computer, the primary storage system, the external storage system, and the network device. The management device obtains a communication group information for limiting a communicable range between the computer and the storage systems from the network device, upon receiving of a request for changing an external connection state, And the management device generates a communication group information after the changing of the external connection state based on the request for changing the external connection state and the obtained communication group information.

    摘要翻译: 为了提供存储管理系统的存储连接改变方法,用于在存储系统中的主存储系统和外部存储系统之间设置和释放外部连接,存储管理系统包括计算机,主存储系统,外部存储 系统,网络设备和管理计算机,主存储系统,外部存储系统和网络设备的管理设备。 管理装置在接收到改变外部连接状态的请求时,从网络装置获取用于限制计算机和存储系统之间的可通信范围的通信组信息,并且管理装置在改变之后生成通信组信息 基于改变外部连接状态的请求的外部连接状态和获得的通信组信息。