首页> 外国专利> System and methodology for managing internet access on a per application basis for client computers connected to the internet

System and methodology for managing internet access on a per application basis for client computers connected to the internet

机译:用于基于每个应用程序管理连接到Internet的客户端计算机的Internet访问的系统和方法

摘要

A computing environment with methods for monitoring access to an open network, such as a WAN or the Internet, is described. The system includes one or more clients, each operating applications or processes (e. g., Netscape Navigator™ or Microsoft Internet Explorer™ browser software) requiring Internet (or other open network) access (e.g., an Internet connection to one or more Web servers). Client-based monitoring and filtering of access is provided in conjunction with a centralized enforcement supervisor. The supervisor maintains access rules for the client-based filtering and verifies the existence and proper operation of the client-based filter application. Access rules which can be defined can specify criteria such as total time a user can be connected to the Internet (e.g., per day, week, month, or the like), time a user can interactively use the Internet (e.g., per day, week, month, or the like), a list of applications or application versions that a user can or cannot use in order to access the Internet, a list of URLs (or WAN addresses) that a user application can (or cannot) access, a list of protocols or protocol components (such as Java Script™) that a user application can or cannot use, and rules to determine what events should be logged (including how long are logs to be kept). By intercepting process loading and unloading and keeping a list of currently-active processes, each client process can be checked for various characteristics, including checking executable names, version numbers, executable file checksums, version header details, configuration settings, and the like. With this information, the system can determine if a particular process in question should have access to the Internet and what kind of access (i. e., protocols, Internet addresses, time limitations, and the like) is permissible for the given specific user.
机译:描述了一种具有用于监视对诸如WAN或因特网之类的开放网络的访问的方法的计算环境。该系统包括一个或多个客户端,每个操作应用程序或过程(例如,Netscape Navigator™或Microsoft Internet Explorer™浏览器软件)需要互联网(或其他开放网络)访问(例如,到一个或多个Web服务器的互联网连接)。与集中的执法监督人员一起提供基于客户端的访问监视和筛选。主管维护基于客户端的筛选器的访问规则,并验证基于客户端的筛选器应用程序的存在和正确运行。可以定义的访问规则可以指定标准,例如用户可以连接到Internet的总时间(例如每天,每周,每月等),用户可以交互使用Internet的时间(例如每天,周,月等),用户可以或不能使用以访问Internet的应用程序或应用程序版本列表,用户应用程序可以(或不能)访问的URL(或WAN地址)列表,用户应用程序可以使用或不能使用的协议或协议组件(例如Java Script™)的列表,以及确定应记录哪些事件(包括将日志保留多长时间)的规则。通过拦截进程的加载和卸载并保留当前活动进程的列表,可以检查每个客户端进程的各种特征,包括检查可执行文件名称,版本号,可执行文件校验和,版本标头详细信息,配置设置等。利用该信息,系统可以确定所讨论的特定过程是否应当可以访问因特网,以及对于给定的特定用户,允许什么样的访问(即,协议,因特网地址,时间限制等)。

著录项

  • 公开/公告号US5987611A

    专利类型

  • 公开/公告日1999-11-16

    原文格式PDF

  • 申请/专利权人 ZONE LABS INC.;

    申请/专利号US19970851777

  • 发明设计人 GREGOR FREUND;

    申请日1997-05-06

  • 分类号G06F13/00;

  • 国家 US

  • 入库时间 2022-08-22 01:39:11

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号