首页> 外国专利> Webserver alternative for increased security

Webserver alternative for increased security

机译:Web服务器替代品可提高安全性

摘要

A system and method for preventing unauthorized access to a website's sensitive information in which a website web server is located on a public network with a public IP address and known port number, but only performs a listening function. The responding function is located on a separate device on a private network with a private and dynamic IP address and having a randomly assigned port number. The responder has no listening sockets (open ports expecting to receive from client application) and therefore does not listen to the public network, and therefore is not accessible to unauthorized access, much in the way that a private user's PC is not accessible to unauthorized access. The web server having the listening function does not initiate connection with the device having the responding function because its private IP address is unreachable from the public network and unknown, even to the web server, and by virtue of the fact that there are no listening sockets to accept any requests. Instead, the communication link between the device having the responder function and the web server having the listening function is initiated by the device having the responder function.
机译:一种用于防止未经授权访问网站敏感信息的系统和方法,其中网站Web服务器位于具有公共IP地址和已知端口号的公共网络上,但仅执行侦听功能。响应功能位于具有专用和动态IP地址且具有随机分配的端口号的专用网络上的单独设备上。响应者没有侦听套接字(期望从客户端应用程序接收的开放端口),因此不侦听公共网络,因此无法进行未经授权的访问,这很像私有用户的PC无法未经授权的访问。具有监听功能的Web服务器不会启动与具有响应功能的设备的连接,这是因为其专用IP地址无法从公用网络访问,并且甚至对于Web服务器都是未知的,并且由于没有监听套接字而这一事实接受任何请求。相反,具有响应者功能的设备与具有监听功能的Web服务器之间的通信链接由具有响应者功能的设备启动。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号