首页> 外国专利> method and system for enforcing a kommunikationsicherheitsverfahrens

method and system for enforcing a kommunikationsicherheitsverfahrens

机译:加强公信力的方法和系统

摘要

A method for enforcing a security policy for selectively preventing the downloading and execution of undesired Executable Objects in an individual workstation, comprising the steps of, (1) providing a security agent suitable to be installed in an individual workstation, said security agent being provided with means for introducing at least one marker in one or more data packet transmitted by a workstation to a server through a gateway, said at least one marker indicating that a security agent is installed in the transmitting workstation; (2) providing means in or coupled to the gateway for analyzing the first one or more data packet(s) received from a transmitting workstation initiating communication to a remote server, to determine whether said first ore or more data packet(s) comprise at least one marker indicating that a suitable security agent is installed in the transmitting workstation; (3) If at least one marker indicating that a suitable security agent is installed in the transmitting workstation is detected in said first one or more data packet(s), deleting said marker(s) from said first one or more data packet(s), and allowing said data packet(s) to be transmitted to their destination; and (4) If no marker indicating that a suitable security agent is installed in the transmitting workstation is detected in said first one or more data packet(s), preventing any data packet(s) received from the server to which the workstation is connected from being transmitted to the workstation.
机译:一种用于实施安全策略以选择性地防止在单个工作站中下载和执行不希望的可执行对象的方法,该方法包括以下步骤:(1)提供适合于安装在单个工作站中的安全代理,所述安全代理具有用于在工作站通过网关向服务器发送的一个或多个数据包中引入至少一个标记的装置,所述至少一个标记指示在发送工作站中安装了安全代理; (2)提供在网关中或耦合到网关的装置,用于分析从发送工作站接收的,开始与远程服务器的通信的第一或多个数据包,以确定所述第一矿石或多个数据包是否包括:至少一个标记,指示在传输工作站中安装了合适的安全代理; (3)如果在所述第一个或多个数据包中检测到至少一个指示合适的安全代理已安装在传输工作站中的标记,则从所述第一个或多个数据包中删除所述标记。 ),并允许将所述数据包传输到其目的地; (4)如果在所述第一个或多个数据包中未检测到指示在传输工作站中安装了合适的安全代理的标记,则阻止从与工作站连接的服务器接收到的任何数据包从传输到工作站。

著录项

  • 公开/公告号DE69824444D1

    专利类型

  • 公开/公告日2004-07-15

    原文格式PDF

  • 申请/专利权人 COMPUTER ASSOCIATES THINK INC.;

    申请/专利号DE1998624444T

  • 发明设计人 ELGRESSY DORON;JOSPE ASHER;

    申请日1998-02-23

  • 分类号H04L29/06;

  • 国家 DE

  • 入库时间 2022-08-21 22:40:17

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号