KR20170047533A - 비인가 우회접속 차단 방법 - Google Patents
비인가 우회접속 차단 방법 Download PDFInfo
- Publication number
- KR20170047533A KR20170047533A KR1020150147759A KR20150147759A KR20170047533A KR 20170047533 A KR20170047533 A KR 20170047533A KR 1020150147759 A KR1020150147759 A KR 1020150147759A KR 20150147759 A KR20150147759 A KR 20150147759A KR 20170047533 A KR20170047533 A KR 20170047533A
- Authority
- KR
- South Korea
- Prior art keywords
- connection
- session
- service providing
- bypass
- providing server
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
- 238000000034 method Methods 0.000 title claims abstract description 45
- 230000000903 blocking effect Effects 0.000 title claims abstract description 25
- 238000007726 management method Methods 0.000 description 28
- 230000000737 periodic effect Effects 0.000 description 4
- 230000005540 biological transmission Effects 0.000 description 3
- 238000012217 deletion Methods 0.000 description 3
- 230000037430 deletion Effects 0.000 description 3
- 238000012550 audit Methods 0.000 description 2
- 238000004891 communication Methods 0.000 description 2
- 238000005516 engineering process Methods 0.000 description 2
- 238000012546 transfer Methods 0.000 description 2
- 230000000694 effects Effects 0.000 description 1
- 230000014509 gene expression Effects 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/30—Network architectures or network communication protocols for network security for supporting lawful interception, monitoring or retaining of communications or communication related information
- H04L63/306—Network architectures or network communication protocols for network security for supporting lawful interception, monitoring or retaining of communications or communication related information intercepting packet switched data communications, e.g. Web, Internet or IMS communications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/30—Network architectures or network communication protocols for network security for supporting lawful interception, monitoring or retaining of communications or communication related information
- H04L63/308—Network architectures or network communication protocols for network security for supporting lawful interception, monitoring or retaining of communications or communication related information retaining data, e.g. retaining successful, unsuccessful communication attempts, internet access, or e-mail, internet telephony, intercept related information or call content
Landscapes
- Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Technology Law (AREA)
- Computer And Data Communications (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
도 2는 접근 제어부의 동작을 설명하기 위한 흐름도.
도 3은 접속 세션 관리부의 동작을 설명하기 위한 흐름도.
도 4는 우회접속 차단 동작을 설명하기 위한 흐름도.
20: 접근제어 장치
30: 서비스 제공 서버 그룹
40: 우회접속 관리 장치
Claims (3)
- 사용자 단말기와, 접근 제어 장치와, 우회접속 관리 장치와, 복수 개의 서비스 제공 서버를 포함하는 환경에서 상기 우회접속 관리 장치가 수행하는 비인가 우회접속 차단 방법에 있어서,
특정 서비스 제공 서버에 접근이 허용된 사용자가 사용자 단말기를 통해 접속하면 상기 특정 서비스 제공 서버 접속의 세션 정보를 상기 우회접속 관리 장치가 저장하는 제1 단계와,
상기 우회접속 관리 장치는 주기적 또는 비주기적으로 상기 복수 개의 서비스 제공 서버로부터 접속되어 있는 네트워크 커넥션 정보를 수집하는 제2 단계와,
상기 우회접속 관리 장치는 상기 제2 단계에서 수집한 네트워크 커넥션 정보 중 상기 제1 단계에서 저장된 세션 정보에 존재하지 않는 접속이 있는지 판단하는 제3 단계와,
상기 제3 단계에서 존재하지 않는 접속이 있으면 해당 접속을 차단하는 제4 단계를 포함하는,
비인가 우회접속 차단 방법.
- 청구항 1에 있어서,
상기 네트워크 커넥션 정보는 소스 아이피(Source IP), 소스 포트(Source Port) 및 프로세스 아이디(PID; Process ID) 중 적어도 어느 하나인,
비인가 우회접속 차단 방법.
- 청구항 1 또는 청구항 2에 있어서,
제4 단계는 해당 접속의 프로세스 아이디에 대해서 Kill 명령어로 프로세스를 제거하는 단계인,
비인가 우회접속 차단 방법.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR1020150147759A KR20170047533A (ko) | 2015-10-23 | 2015-10-23 | 비인가 우회접속 차단 방법 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR1020150147759A KR20170047533A (ko) | 2015-10-23 | 2015-10-23 | 비인가 우회접속 차단 방법 |
Publications (1)
Publication Number | Publication Date |
---|---|
KR20170047533A true KR20170047533A (ko) | 2017-05-08 |
Family
ID=60164355
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
KR1020150147759A Ceased KR20170047533A (ko) | 2015-10-23 | 2015-10-23 | 비인가 우회접속 차단 방법 |
Country Status (1)
Country | Link |
---|---|
KR (1) | KR20170047533A (ko) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR102014807B1 (ko) * | 2019-02-25 | 2019-08-27 | 주식회사 넷앤드 | 우회 접속 탐지 및 차단 기능을 구비한 접근통제 시스템 |
-
2015
- 2015-10-23 KR KR1020150147759A patent/KR20170047533A/ko not_active Ceased
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR102014807B1 (ko) * | 2019-02-25 | 2019-08-27 | 주식회사 넷앤드 | 우회 접속 탐지 및 차단 기능을 구비한 접근통제 시스템 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US20240340340A1 (en) | Systems and methods for distributing partial data to subnetworks | |
US10623232B2 (en) | System and method for determining and forming a list of update agents | |
EP2837131B1 (en) | System and method for determining and using local reputations of users and hosts to protect information in a network environment | |
US9654445B2 (en) | Network traffic filtering and routing for threat analysis | |
US20190297055A1 (en) | Automated learning of externally defined network assets by a network security device | |
US11563750B2 (en) | System, method and computer readable medium for determining users of an internet service | |
GB2551792A (en) | Elastic outbound gateway | |
US9413778B1 (en) | Security policy creation in a computing environment | |
US11695650B2 (en) | Secure count in cloud computing networks | |
EP3169039A1 (en) | Method and system for managing security certificates in a networked application environment | |
US12335315B2 (en) | Method and system for smart recommendation and dynamic grouping of devices for a better device management | |
US10949193B2 (en) | System and method of updating active and passive agents in a network | |
US11874845B2 (en) | Centralized state database storing state information | |
KR101522139B1 (ko) | DNS 서버 선별 차단 및 Proxy를 이용한 DNS 주소 변경 방법 | |
US20230300141A1 (en) | Network security management method and computer device | |
KR20170047533A (ko) | 비인가 우회접속 차단 방법 | |
Hafeez et al. | Securing edge networks with securebox | |
AU2023203129B2 (en) | Systems and methods for distributing partial data to subnetworks | |
US20230051016A1 (en) | Systems and methods for network monitoring, reporting, and risk mitigation | |
Agbariah | Policy exchange and management for Policy Compliance and Change Detection System in managed service in data networks | |
CN114363023A (zh) | 一种Web安全防护系统实施及策略调优方法、系统 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
A201 | Request for examination | ||
PA0109 | Patent application |
Patent event code: PA01091R01D Comment text: Patent Application Patent event date: 20151023 |
|
PA0201 | Request for examination | ||
E902 | Notification of reason for refusal | ||
PE0902 | Notice of grounds for rejection |
Comment text: Notification of reason for refusal Patent event date: 20170412 Patent event code: PE09021S01D |
|
PG1501 | Laying open of application | ||
E601 | Decision to refuse application | ||
PE0601 | Decision on rejection of patent |
Patent event date: 20171113 Comment text: Decision to Refuse Application Patent event code: PE06012S01D Patent event date: 20170412 Comment text: Notification of reason for refusal Patent event code: PE06011S01I |