首页> 外国专利> METHOD AND SYSTEM FOR ANALYSING AND FILTERING HTTPS TRAFFIC IN CORPORATE NETWORKS

METHOD AND SYSTEM FOR ANALYSING AND FILTERING HTTPS TRAFFIC IN CORPORATE NETWORKS

机译:企业网络中HTTPS流量的分析和过滤方法及系统

摘要

The proxy system according to the present invention, consists of forwarding the content of the HTTPS requests in an unusual way, by automatically generating a new certificate for the requested destination server. This new certificate is faked. It is signed by a corporate internal Certificate Authority (CA). The new certificate is included in the response sent by the proxy to the client during the SSL session establishment (according to the SSL protocol, the destination server, which in this case will be the proxy server, identifies itself using a certificate). The request is then transparently forwarded to the destination server as a normal or standard HTTP Proxy server does. To prevent clients from detecting this 'man-in-the middle attack', the internal corporate Certificate Authority (CA) used to sign the 'fake' certificates, must be included in the list of Certificates Authorities recognized by the clients in the corporate network.
机译:根据本发明的代理系统包括通过自动地为所请求的目的地服务器生成新证书,以不寻常的方式转发HTTPS请求的内容。此新证书是伪造的。它由公司内部证书颁发机构(CA)签名。在SSL会话建立期间,新证书包含在代理发送给客户端的响应中(根据SSL协议,目标服务器(在本例中将为代理服务器)使用证书进行自身标识)。然后,该请求将像普通或标准的HTTP代理服务器一样透明地转发到目标服务器。为了防止客户端检测到这种“中间人攻击”,必须在公司网络中客户端认可的证书颁发机构列表中包括用于签署“伪造”证书的内部公司证书颁发机构(CA)。 。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号