CN100544289C - 将加密https网络数据包映射到其经过解密的副本的系统和方法 - Google Patents

将加密https网络数据包映射到其经过解密的副本的系统和方法 Download PDF

Info

Publication number
CN100544289C
CN100544289C CNB200680002778XA CN200680002778A CN100544289C CN 100544289 C CN100544289 C CN 100544289C CN B200680002778X A CNB200680002778X A CN B200680002778XA CN 200680002778 A CN200680002778 A CN 200680002778A CN 100544289 C CN100544289 C CN 100544289C
Authority
CN
China
Prior art keywords
network
port number
decrypted
module
web server
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Fee Related
Application number
CNB200680002778XA
Other languages
English (en)
Chinese (zh)
Other versions
CN101107812A (zh
Inventor
保罗·F.·克莱因
耶西·N.·佩雷斯
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
International Business Machines Corp
Original Assignee
International Business Machines Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Family has litigation
First worldwide family litigation filed litigation Critical https://patents.darts-ip.com/?family=36273444&utm_source=google_patent&utm_medium=platform_link&utm_campaign=public_patent_search&patent=CN100544289(C) "Global patent litigation dataset” by Darts-ip is licensed under a Creative Commons Attribution 4.0 International License.
Application filed by International Business Machines Corp filed Critical International Business Machines Corp
Publication of CN101107812A publication Critical patent/CN101107812A/zh
Application granted granted Critical
Publication of CN100544289C publication Critical patent/CN100544289C/zh
Anticipated expiration legal-status Critical
Expired - Fee Related legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/16Implementing security features at a particular protocol layer
    • H04L63/168Implementing security features at a particular protocol layer above the transport layer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/02Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425Traffic logging, e.g. anomaly detection

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Storage Device Security (AREA)
  • Computer And Data Communications (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Peptides Or Proteins (AREA)
  • Information Transfer Between Computers (AREA)
CNB200680002778XA 2005-02-28 2006-02-20 将加密https网络数据包映射到其经过解密的副本的系统和方法 Expired - Fee Related CN100544289C (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US11/067,990 2005-02-28
US11/067,990 US7657737B2 (en) 2005-02-28 2005-02-28 Method for mapping an encrypted https network packet to a specific url name and other data without decryption outside of a secure web server

Publications (2)

Publication Number Publication Date
CN101107812A CN101107812A (zh) 2008-01-16
CN100544289C true CN100544289C (zh) 2009-09-23

Family

ID=36273444

Family Applications (1)

Application Number Title Priority Date Filing Date
CNB200680002778XA Expired - Fee Related CN100544289C (zh) 2005-02-28 2006-02-20 将加密https网络数据包映射到其经过解密的副本的系统和方法

Country Status (10)

Country Link
US (1) US7657737B2 (https=)
EP (1) EP1854243B1 (https=)
JP (1) JP4596554B2 (https=)
CN (1) CN100544289C (https=)
AT (1) ATE441264T1 (https=)
BR (1) BRPI0608276B1 (https=)
CA (1) CA2598227C (https=)
DE (1) DE602006008749D1 (https=)
TW (1) TWI362871B (https=)
WO (1) WO2006089879A1 (https=)

Families Citing this family (19)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7865511B2 (en) 2004-06-25 2011-01-04 Apple Inc. News feed browser
US8612844B1 (en) * 2005-09-09 2013-12-17 Apple Inc. Sniffing hypertext content to determine type
US7882091B2 (en) * 2008-01-09 2011-02-01 Stephen Schneider Record tagging, storage and filtering system and method
US20100132007A1 (en) * 2008-11-25 2010-05-27 Cisco Technology, Inc. Accelerating channel change time with external picture property markings
US8850013B2 (en) * 2010-05-10 2014-09-30 Jaron Waldman Server load balancing using geodata
KR20120132013A (ko) * 2011-05-27 2012-12-05 주식회사 팬택 휴대용 단말, 휴대용 단말의 하드웨어 모듈간에 전송되는 데이터의 보안 방법
CN102811426A (zh) * 2011-05-30 2012-12-05 网秦无限(北京)科技有限公司 移动设备的消息的加密发送和接收的方法和系统
TWI581124B (zh) * 2012-01-13 2017-05-01 精品科技股份有限公司 網際網路之資料封包防護系統與方法
US9176838B2 (en) 2012-10-19 2015-11-03 Intel Corporation Encrypted data inspection in a network environment
US9043593B2 (en) * 2013-03-11 2015-05-26 International Business Machines Corporation Session attribute propagation through secure database server tiers
GB2516050A (en) * 2013-07-09 2015-01-14 Ibm A Network Security System
CN103701819B (zh) * 2013-12-30 2017-04-05 北京网康科技有限公司 超文本传输协议解密的处理方法及装置
CN105812345B (zh) * 2014-12-31 2019-08-23 广州市动景计算机科技有限公司 一种实现网页到客户端通信的方法及装置
US9774572B2 (en) * 2015-05-11 2017-09-26 Salesforce.Com, Inc. Obfuscation of references to network resources
JP6700894B2 (ja) * 2016-03-25 2020-05-27 キヤノン株式会社 画像処理装置、制御方法、プログラム
CN109165511B (zh) * 2018-08-08 2022-07-15 深圳前海微众银行股份有限公司 Web安全漏洞处理方法、系统及计算机可读存储介质
EP4611313A3 (en) 2020-05-04 2025-09-10 Juniper Networks, Inc. Efficient encryption and decryption of duplicate packets communicated via a virtual private network
US11575653B2 (en) * 2020-05-04 2023-02-07 Juniper Networks, Inc. Efficient encryption and decryption of duplicate packets communicated via a virtual private network
EP4009602B1 (en) * 2020-12-07 2022-11-09 Siemens Healthcare GmbH Providing a first digital certificate and a dns response

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1276073A (zh) * 1996-11-21 2000-12-06 摩托罗拉有限公司 用于数据加密/解密的结构和包括该数据加密/解密结构的数据载体
US6363477B1 (en) * 1998-08-28 2002-03-26 3Com Corporation Method for analyzing network application flows in an encrypted environment

Family Cites Families (28)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP3263878B2 (ja) * 1993-10-06 2002-03-11 日本電信電話株式会社 暗号通信システム
WO1998011702A1 (en) 1996-09-10 1998-03-19 Accrue Software, Inc. Apparatus and methods for capturing, analyzing and viewing live network information
US6065046A (en) * 1997-07-29 2000-05-16 Catharon Productions, Inc. Computerized system and associated method of optimally controlled storage and transfer of computer programs on a computer network
US6092196A (en) * 1997-11-25 2000-07-18 Nortel Networks Limited HTTP distributed remote user authentication system
US6148336A (en) * 1998-03-13 2000-11-14 Deterministic Networks, Inc. Ordering of multiple plugin applications using extensible layered service provider with network traffic filtering
US6324648B1 (en) * 1999-12-14 2001-11-27 Gte Service Corporation Secure gateway having user identification and password authentication
US6510464B1 (en) * 1999-12-14 2003-01-21 Verizon Corporate Services Group Inc. Secure gateway having routing feature
US7325127B2 (en) * 2000-04-25 2008-01-29 Secure Data In Motion, Inc. Security server system
US7673329B2 (en) * 2000-05-26 2010-03-02 Symantec Corporation Method and apparatus for encrypted communications to a secure server
US20020035559A1 (en) * 2000-06-26 2002-03-21 Crowe William L. System and method for a decision engine and architecture for providing high-performance data querying operations
US20020035681A1 (en) * 2000-07-31 2002-03-21 Guillermo Maturana Strategy for handling long SSL messages
US8364798B2 (en) * 2001-01-23 2013-01-29 Verizon Business Global Llc Method and system for providing software integration for a telecommunications services on-line procurement system
US9219708B2 (en) * 2001-03-22 2015-12-22 DialwareInc. Method and system for remotely authenticating identification devices
US7409714B2 (en) 2001-06-13 2008-08-05 Mcafee, Inc. Virtual intrusion detection system and method of using same
US7149892B2 (en) * 2001-07-06 2006-12-12 Juniper Networks, Inc. Secure sockets layer proxy architecture
GB0119488D0 (en) * 2001-08-10 2001-10-03 Cellectivity Ltd E-commerce method for mobile telephones
US20030065941A1 (en) * 2001-09-05 2003-04-03 Ballard Clinton L. Message handling with format translation and key management
US6970918B2 (en) * 2001-09-24 2005-11-29 International Business Machines Corporation System and method for transcoding support of web content over secure connections
US7010608B2 (en) * 2001-09-28 2006-03-07 Intel Corporation System and method for remotely accessing a home server while preserving end-to-end security
US7181141B1 (en) * 2001-11-02 2007-02-20 Ciena Corporation Method and system for collecting network topology in an optical communications network
US7093121B2 (en) * 2002-01-10 2006-08-15 Mcafee, Inc. Transferring data via a secure network connection
JP2003209570A (ja) * 2002-01-11 2003-07-25 Fujitsu Ltd 中継方法そのクライアント、サーバ、中継装置
US20030163608A1 (en) * 2002-02-21 2003-08-28 Ashutosh Tiwary Instrumentation and workload recording for a system for performance testing of N-tiered computer systems using recording and playback of workloads
US7260623B2 (en) * 2002-06-27 2007-08-21 Sun Microsystems, Inc. Remote services system communication module
JP3794491B2 (ja) * 2002-08-20 2006-07-05 日本電気株式会社 攻撃防御システムおよび攻撃防御方法
US7386723B2 (en) * 2002-11-22 2008-06-10 Intel Corporation Method, apparatus and system for compressing IPSec-protected IP packets
US7412539B2 (en) * 2002-12-18 2008-08-12 Sonicwall, Inc. Method and apparatus for resource locator identifier rewrite
US7627669B2 (en) * 2003-05-21 2009-12-01 Ixia Automated capturing and characterization of network traffic using feedback

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1276073A (zh) * 1996-11-21 2000-12-06 摩托罗拉有限公司 用于数据加密/解密的结构和包括该数据加密/解密结构的数据载体
US6363477B1 (en) * 1998-08-28 2002-03-26 3Com Corporation Method for analyzing network application flows in an encrypted environment

Also Published As

Publication number Publication date
EP1854243A1 (en) 2007-11-14
EP1854243B1 (en) 2009-08-26
BRPI0608276A2 (pt) 2009-12-15
JP4596554B2 (ja) 2010-12-08
ATE441264T1 (de) 2009-09-15
CA2598227C (en) 2014-10-07
JP2008532398A (ja) 2008-08-14
US7657737B2 (en) 2010-02-02
TW200640217A (en) 2006-11-16
BRPI0608276B1 (pt) 2019-02-05
CA2598227A1 (en) 2006-08-31
US20060195687A1 (en) 2006-08-31
TWI362871B (en) 2012-04-21
CN101107812A (zh) 2008-01-16
WO2006089879A1 (en) 2006-08-31
DE602006008749D1 (de) 2009-10-08

Similar Documents

Publication Publication Date Title
CN100544289C (zh) 将加密https网络数据包映射到其经过解密的副本的系统和方法
US6442687B1 (en) System and method for secure and anonymous communications
US8145898B2 (en) Encryption/decryption pay per use web service
US7441116B2 (en) Secure resource distribution through encrypted pointers
EP2850770B1 (en) Transport layer security traffic control using service name identification
US6836795B2 (en) Mapping connections and protocol-specific resource identifiers
US8335916B2 (en) Secure request handling using a kernel level cache
US20040015725A1 (en) Client-side inspection and processing of secure content
JP2004513453A (ja) 信頼性のある分散型ピアツーピアネットワークを確立する方法及びシステム
KR20060100920A (ko) 웹 서비스를 위한 신뢰되는 제3자 인증
CN101299753A (zh) 基于代理服务器的Web服务安全控制机制
CN107959660A (zh) 一种基于Nginx的静态文件访问方法和装置
US20020184489A1 (en) High volume secure internet server
CN106031097A (zh) 业务处理方法及装置
US7765310B2 (en) Opaque cryptographic web application data protection
US7421576B1 (en) Interception and modification of network authentication packets with the purpose of allowing alternative authentication modes
KR100423191B1 (ko) 보안 프로토콜을 이용하여 전송될 벌크 데이터의 대칭 암호화 효율을 향상시키기 위한 방법, 시스템 및 기록 매체
US20130024543A1 (en) Methods for generating multiple responses to a single request message and devices thereof
US7424739B2 (en) On-machine communication verification
CN110995730A (zh) 数据传输方法、装置、代理服务器和代理服务器集群
CN113645193B (zh) 网络安全防护方法、业务管理系统及计算机可读存储介质
CN111541710B (zh) 一种网络中数据内容的鉴授权方法和计算机可读存储介质
CN106355101A (zh) 一种面向简易存储服务的透明文件加解密系统及其方法
CN119484053A (zh) 一种国密改造方法、装置、设备及介质
Zaman et al. A Study of the Effects of Heartbleed Vulnerability in Bangladesh

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CF01 Termination of patent right due to non-payment of annual fee
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20090923

Termination date: 20190220