首页> 外国专利> Methods for effective network-security inspection in virtualized environments

Methods for effective network-security inspection in virtualized environments

机译:在虚拟环境中进行有效网络安全检查的方法

摘要

The present invention discloses methods for effective network-security inspection in virtualized environments, the methods including the steps of: providing a data packet, embodied in machine-readable signals, being sent from a sending virtual machine to a receiving virtual machine via a virtual switch; intercepting the data packet by a sending security agent associated with the sending virtual machine; injecting the data packet into an inspecting security agent associated with a security virtual machine via a direct transmission channel which bypasses the virtual switch; forwarding the data packet to the security virtual machine by employing a packet-forwarding mechanism; determining, by the security virtual machine, whether the data packet is allowed for transmission; upon determining the data packet is allowed, injecting the data packet back into the sending security agent via the direct transmission channel; and forwarding the data packet to the receiving virtual machine via the virtual switch.
机译:本发明公开了用于在虚拟环境中进行有效的网络安全检查的方法,该方法包括以下步骤:提供体现为机器可读信号的数据包,该数据包经由虚拟交换机从发送虚拟机发送到接收虚拟机。 ;与发送虚拟机关联的发送安全代理拦截数据包;通过绕过虚拟交换机的直接传输通道,将数据包注入与安全虚拟机关联的检查安全代理中;通过报文转发机制将数据报文转发至安全虚拟机;安全虚拟机确定是否允许数据包传输;在确定允许该数据包后,将该数据包通过直接传输通道注入回发送安全代理中;通过所述虚拟交换机将所述数据包转发至所述接收虚拟机。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号