首页> 外国专利> Identities correlation infrastructure for passive network monitoring

Identities correlation infrastructure for passive network monitoring

机译:身份关联基础架构,用于被动网络监控

摘要

User names and user groups serve as the basis of a formal policy in a network. A passive monitor examines network traffic in near real time and indicates: which network traffic is flowing on the network as before; which users or user groups were logged into workstations initiating this network traffic; and which of this traffic conforms to the formal policy definition. In one embodiment of the invention, users and user groups are determined by querying Microsoft® Active Directory and Microsoft® Windows servers, to determine who is logged onto the Microsoft® network. Other sources of identity information are also possible. The identity information is then correlated with the network traffic, so that even traffic that does not bear on the Microsoft® networking scheme is still tagged with identity
机译:用户名和用户组是网络中正式策略的基础。被动监视器几乎实时地检查网络流量,并指示:像以前一样网络上正在流动哪些网络流量;哪些用户或用户组已登录到启动此网络流量的工作站;以及哪些流量符合正式的政策定义。在本发明的一个实施例中,通过查询Microsoft Active Directory和Windows服务器来确定用户和用户组,以确定谁登录了Microsoft网络。身份信息的其他来源也是可能的。然后将身份信息与网络流量相关联,以便即使不承载Microsoft®网络方案的流量也仍被标记为身份

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号