首页> 外国专利> SECURITY POLICY ENFORCEMENT AND VISIBILITY FOR NETWORK ARCHITECTURES THAT MASK EXTERNAL SOURCE ADDRESSES

SECURITY POLICY ENFORCEMENT AND VISIBILITY FOR NETWORK ARCHITECTURES THAT MASK EXTERNAL SOURCE ADDRESSES

机译:屏蔽外部源地址的网络体系结构的安全策略实施和可见性

摘要

Some network architectures include perimeter or edge devices which perform network address translation or otherwise modify data in a network traffic packet header, such as the source address. The modification of the source address prevents downstream devices from knowing the true or original source address from which the traffic originated. To address this issue, perimeter devices can insert the original source address in an X-Forwarded-For field of the packet header. Firewalls and related security services can be programmed to record the original source address in the XFF field in addition to the other packet information and to consider the original source address during security analysis. Using the original source address in the XFF field, services can determine additional characteristics about the traffic, such as geographic origin or associated user accounts, and use these characteristics to identify applicable rules or policies.
机译:某些网络体系结构包括外围设备或边缘设备,这些外围设备或边缘设备执行网络地址转换或修改网络流量数据包头中的数据,例如源地址。源地址的修改可防止下​​游设备知道流量源自的真实或原始源地址。要解决此问题,外围设备可以将原始源地址插入数据包头的X-Forwarded-For字段中。可以对防火墙和相关安全服务进行编程,以在其他包信息之外,在XFF字段中记录原始源地址,并在安全分析期间考虑原始源地址。使用XFF字段中的原始源地址,服务可以确定有关流量的其他特征,例如地理来源或关联的用户帐户,并使用这些特征来识别适用的规则或策略。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号