Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

7 results about "Application firewall" patented technology

An application firewall is a form of firewall that controls input, output, and/or access from, to, or by an application or service. It operates by monitoring and potentially blocking the input, output, or system service calls that do not meet the configured policy of the firewall. The application firewall is typically built to control all network traffic on any OSI layer up to the application layer. It is able to control applications or services specifically, unlike a stateful network firewall, which is - without additional software - unable to control network traffic regarding a specific application. There are two primary categories of application firewalls, network-based application firewalls and host-based application firewalls.

METHOD FOR DISTRIBUTING ELEMENTARY CALCULATIONS

One aspect of the invention relates to a method 100 for distributing elementary calculations, the method 100 comprising the steps of: 101 breaking down a complex calculation into a plurality of elementary calculations via an application; 102 transmitting said elementary calculations to an application firewall; 104 distributing said elementary calculations to a plurality of web browsers via said application firewall; 105 executing one received elementary calculation via each web browser; 106 aggregating the results of elementary calculations obtained from said web browsers via said application firewall; 107 transmitting said aggregated results of elementary calculations to said application. Figure to be published with the abstract: Figure 1
Owner:AMADEUS SAS

Epsilon machine-based unknown traffic clustering identification method and system, and storage medium

The invention discloses an unknown traffic clustering identification method based on an epsilon machine, and the method comprises the steps: S1, carrying out the adaptive sampling of network traffic, and obtaining a traffic data sample; s2, extracting a feature sequence from the traffic data sample; s3, converting the feature sequence into a symbol sequence; s4, constructing an epsilon machine of the symbol sequence by executing a causal state segmentation reconstruction algorithm on the symbol sequence, and obtaining a causal state set corresponding to the epsilon machine; s5, on the basis of the causal state set, calculating and outputting a feature vector representing a flow mode; s6, calculating the distance between different feature vectors, and recording the distance as a similarity distance; and S7, comparing the similarity distance with a preset threshold value, and judging the type of a flow mode according to a comparison result to complete clustering identification of unknown flow. According to the invention, efficient and accurate identification of unknown traffic can be realized, and the invention also provides an application firewall system and a computer readable storage medium, which also have the above beneficial effects.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

A detection method, system, and device for defending against network attacks based on the Netfilter framework.

This application provides a detection method, system, and apparatus for defending against network attacks based on the Netfilter framework. The detection method is applied to a defense system between a client and a server to be accessed by the client. The method includes: sending access traffic from the client to an authentication tunnel module via a first detection point for authentication; after successful authentication, the defense system initiates a process to establish a secure communication tunnel with the client; sending data packets destined for the application layer to an application firewall module via a second detection point for web attack detection; the second and first detection points are respectively set on the PREROUTING chain of the Netfilter framework; and sending data packets detected by the application firewall module to a packet filtering module via a third detection point for network layer detection; the third detection point is set on the FORWARD chain of the Netfilter framework.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

Firewall configuration method and apparatus, computer device and storage medium

The application relates to an application firewall configuration method and device, computer equipment and a storage medium. Service traffic obtained by mirroring processing of received traffic from a switch is received, the service traffic is analyzed, network information and load information of a site are obtained, site information for protecting the site is obtained according to the network information, corresponding site protection rules are generated according to the site information for protecting the site, corresponding site resource configuration rules are generated according to the load information, and the application firewall is configured according to the site protection rules and the site resource configuration rules, so that the application firewall does not need to be connected in series to networking, thus the original network result is not changed, and the configuration strategy can be automatically deployed according to the network information and the load condition, so that the flexibility and the configuration efficiency of the application firewall configuration are improved.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Dynamically Scalable Application Firewall Deployment for Cloud-Native Applications

The configuration of a cloud application exposed through a public IP address is replicated with modifications to include a private IP address to expose the application internally. The original configuration is updated so that external network traffic sent to the application is redirected to and distributed among agents running on nodes of a cloud cluster where a web application firewall (WAF) is implemented. The set of agents that each WAF should inspect the redirected network traffic is selected based on cluster metrics, such as network and resource utilization metrics. The redirected network traffic targets ports allocated to the application-specific agents, where ports are allocated per application, and thus each agent can support WAF protection for multiple applications. Network traffic allowed through by the WAF is directed from the agent to the application via its private IP address.
Owner:PALO ALTO NETWORKS INC

Content management systems, methods, and media using an application level firewall

Content management systems, methods, and media using an application level firewall are provided. In accordance with some embodiments of the disclosed subject matter, the system for managing advertisement adjacencies comprises: a firewall component in an application layer comprising a processor and a memory, wherein the firewall component is configured to operate in an advertisement call stack of the application layer and wherein the processor is programmed to: receive an advertisement call for publishing an advertisement in an advertisement server on a web page, wherein a verification tag is inserted in the advertisement call that redirects the advertisement call to the firewall component prior to transmission to the advertisement server; determine whether the web page associated with the advertisement call contains objectionable content; and, in response to determining that the web page does not contain objectionable content, transmit the advertisement call to the advertisement server for publishing the advertisement on the web page.
Owner:INTEGRAL AD SCIENCE INC

Operation data report generation method and device, electronic equipment and storage medium

The embodiment of the invention discloses an operation data report generation method and device, electronic equipment and a storage medium, historical operation data of a cloud application firewall is obtained by responding to a request for generating an operation data report for the cloud application firewall, the historical operation data is written into a pre-created webpage file, and the operation data report is generated. Executing the webpage file through the headless browser, calling the data analysis module to analyze based on the historical operation data according to the calling path, drawing a result obtained based on the analysis of the historical operation data in the headless browser to obtain a target webpage, converting the target webpage through the headless browser, generating an operation data report, and displaying the operation data report. The running data report is generated in the mode that the headless browser is introduced to process the target webpage, automatic generation of the running data report can be achieved, the generation efficiency of the running data report is effectively improved, and the method and device are widely applied to scenes such as the cloud technology.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD