会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 45. 发明授权
    • Automatic address range detection for IP networks
    • IP网络的自动地址范围检测
    • US09112945B2
    • 2015-08-18
    • US13390037
    • 2010-08-03
    • Bernhard JansenAndreas KindMarc P. Stoecklin
    • Bernhard JansenAndreas KindMarc P. Stoecklin
    • H04L12/28H04L29/12H04L29/08
    • H04L61/6068H04L29/1232H04L29/12933H04L61/2092H04L67/34
    • Mechanisms are provided for automatic address range detection for an IP network. Flow data is obtained comprising one of the source and destination IP addresses for the flow and one of (a) the other of the source and destination IP addresses and (b) direction data indicative of the flow direction across the network boundary. A tree data structure is generated representing the IP addresses in the flow data. IP addresses with initial portions in common are represented in the tree with at least one node in common. Weights are assigned to nodes in the tree in dependence on occurrences of the represented IP addresses in at least a subset of the flow data. The IP address range of the network is then detected by identifying, in dependence on the assigned weights, the node associated with the last initial address portion common to all IP addresses in the network. A device is automatically configured with the IP address range to permit distinction between IP addresses inside and outside the network in operation of the device, e.g. for filtering or traffic classification.
    • 为IP网络的自动地址范围检测提供了机制。 获得流数据,其包括用于流的源和目的地IP地址之一,(a)源和目的地IP地址中的另一个以及(b)指示跨越网络边界的流向的方向数据。 生成表示流数据中的IP地址的树数据结构。 具有公共初始部分的IP地址在树中被表示为具有至少一个共同的节点。 根据在流数据的至少一个子集中所表示的IP地址的出现,权重被分配给树中的节点。 然后,通过根据所分配的权重,通过与网络中所有IP地址共同的最后一个初始地址部分相关联的节点来识别网络的IP地址范围。 自动配置设备的IP地址范围,以允许在设备操作中区分网络内部和外部的IP地址。 用于过滤或流量分类。
    • 46. 发明授权
    • Firewall for controlling connections between a client machine and a network
    • 防火墙,用于控制客户机和网络之间的连接
    • US08875272B2
    • 2014-10-28
    • US12121689
    • 2008-05-15
    • Bernhard JansenAxel Tanner
    • Bernhard JansenAxel Tanner
    • G06F21/00G06F21/30G06F13/24H04L29/06
    • H04L63/0281G06F13/24G06F21/305H04L63/1441
    • A firewall system adapted for location outside the client machine, preferably in the same data processing device as the client machine but outside a virtual machine containing the client machine. Control logic of the firewall system receives incoming and outgoing connections from the network and client machine respectively. In response to a connection request initiating a connection between respective endpoints in the network and client machine, the control logic performs a security assessment comprising obtaining from at least one of the network and client machine information indicative of the security state of the endpoint therein, and allows or inhibits the connection in dependence on the result of the security assessment. The security assessment may be performed in accordance with a security policy of the system, and different security assessments may be performed for different connection requests in accordance with the security policy.
    • 防火墙系统适于位于客户机外部,优选地在与客户机相同的数据处理设备中,但在包含客户端机器的虚拟机之外。 防火墙系统的控制逻辑分别从网络和客户机接收传入和传出的连接。 响应于发起网络中的相应端点和客户机之间的连接的连接请求,控制逻辑执行安全性评估,包括从网络和客户机中的至少一个获取指示其中的端点的安全状态的信息,以及 根据安全评估的结果允许或禁止连接。 可以根据系统的安全策略执行安全评估,并且可以根据安全策略对不同的连接请求执行不同的安全评估。
    • 49. 发明授权
    • Determination of network topology using flow-based traffic information
    • 使用基于流的流量信息确定网络拓扑
    • US07864707B2
    • 2011-01-04
    • US12391556
    • 2009-02-24
    • Xenofontas DimitropoulosAndreas KindBernhard JansenJeroen Massar
    • Xenofontas DimitropoulosAndreas KindBernhard JansenJeroen Massar
    • H04L12/28
    • H04L41/12
    • A method for determination of a network topology includes generating a list of device sets for a destination; removing any duplicate device sets from the list; creating a tree for the destination by introducing a root node into the tree; sorting the list of device sets for the destination by length; removing the shortest device set from the list; introducing a new node representing the shortest device set into the tree; determining whether a node in the tree represents a maximum length subset of the shortest device set, and in the event that a node is determined, connecting the new node to the determined node, or else connecting the new node to the root node; setting the identifier of the introduced node to a list of members of the shortest device set that are not included in the maximum length subset of the determined node.
    • 一种用于确定网络拓扑的方法包括生成目的地的设备集列表; 从列表中删除任何重复的设备集合; 通过将根节点引入到树中为目的地创建树; 按长度对目的地的设备集列表进行排序; 从列表中删除最短的设备集; 将表示最短设备集的新节点引入到树中; 确定树中的节点是否表示最短设备集合的最大长度子集,并且在确定节点的情况下,将新节点连接到确定的节点,或者将新节点连接到根节点; 将引入的节点的标识符设置为不包括在所确定的节点的最大长度子集中的最短设备集的成员的列表。