System And Method For Intrusion Prevention In A Communications Network
Abstract
A method and system for monitoring UDP communications and for preventing unauthorized UDP communications within a computer network. A method for managing access to a resource comprises assigning a unique user identifier to each authorized user, upon initiation of a UDP communication initialed by a specific authorized user for access to a specific resource, appending the unique user identifier of the specific authorized user to each UDP packet of the UDP communication, intercepting the plurality of UDP packets within the computer network, extracting the unique user identifier from each UDP packet to identify the specific authorized user associated with the respective UDP packet, and allowing each respective UDP packet to reach the specific resource as a function of the unique user identifier extracted from the respective UDP packet.
Claims
exact text as granted — not AI-modified1 . A method for managing access to a resource within a computer network, comprising the steps of:
assigning a unique user identifier to each authorized user of the computer network; upon initiation of a UDP communication initiated by a specific authorized user for access to a specific resource within the computer network, appending the unique user identifier of the specific authorized user to each UDP packet of the UDP communication; intercepting the plurality of UDP packets within the computer network; extracting the unique user identifier from each UDP packet to identify the specific authorized user associated with the respective UDP packet; and allowing each respective UDP packet to reach the specific resource as a function of the unique user identifier extracted from the respective UDP packet.
2 . The method of claim 1 wherein the unique user identifier comprises a user name of the specific authorized user.
3 . The method of claim 1 , further comprising the step of encrypting the unique user identifier prior to appending the unique user identifier to each of the UDP packets.
4 . The method of claim 3 , further comprising the step of decrypting the unique user identifier after extracting the unique user identifier from each UDP packet.
5 . The method of claim 1 , further comprising the step of notifying a network administrator if one or more of the UDP packets of the UDP communication attempt is not allowed to reach the specific resource.
6 . The method of claim 1 , further comprising the step of logging the respective UDP packet if the UDP packet is not allowed to continue to the specific resource.
7 . The method of claim 1 , wherein the specific resource is a database.
8 . The method of claim 1 , wherein the specific resource is an application.
9 . The method of claim 1 , wherein the specific resource is an authorized computer within the computer network.
10 . A method for preventing unauthorized access to one or more resources within a computer network, wherein the computer network includes a plurality of authorized users and wherein a unique user identifier is assigned to each of the plurality of authorized users, comprising the steps of:
maintaining the plurality of unique user identifiers in a database; intercepting a UDP packet from an undetermined user, wherein the UDP packet represents a communication attempt with a specific resource within the computer network; obtaining data from the UDP packet; comparing the data obtained from the UDP packet with the unique user identifiers maintained in the database; and preventing the UDP packet from reaching the specific resource if the data obtained from the UDP packet does not match one of the plurality of unique user identifiers maintained in the database.
11 . The method of claim 10 , wherein each unique user identifier comprises a user name of the specific authorized user.
12 . The method of claim 10 , further comprising the step of decrypting the data obtained from the UDP packet if the data has been previously encrypted.
13 . The method of claim 10 , further comprising the step of storing the UDP packet in a database.
14 . The method of claim 10 , further comprising the step of notifying a network administrator if any UDP packet is blocked.
15 . The method of claim 10 , further comprising the step of storing the data obtained from the UDP packet in a database.
16 . A method for monitoring access to a specific resource within a computer network, comprising the steps of:
assigning a unique user identifier (UID) to each authorized user of the computer network; assigning a unique, non-dynamic system identifier (SID) to each authorized computer within the computer network; defining policy profiles for authorized computers and for authorized users of the computer network, wherein each policy profile defines rights of access to resources within the computer network for the authorized users and the authorized computers; upon initiation of a UDP communication for access to the specific resource, wherein the UDP communication is initiated by a specific authorized user logged into a specific authorized computer, appending the unique user identifier of the specific authorized user and the unique system identifier of the specific authorized computer to each UDP packet of the UCP communication; intercepting the UDP packets within the computer network; extracting the unique user identifier and unique system identifier from one or more of the UDP packets of the UDP communication to identify the specific authorized user and the specific authorized computer associated with the UDP communication; and allowing the UDP communication to continue with the specific resource as a function of the policy profile of the specific authorized user and the policy profile of the specific authorized computer associated with the UDP communication.
17 . The method of claim 16 , further comprising the step of blocking the UDP communication if one or more UDP packets does not contain a unique user identifier or unique system identifier that matches at least one of the unique user identifiers and at least one of the unique system identifiers within the computer network.
18 . The method of claim 16 , further comprising the step of blocking any UDP packet that does not contain a unique user identifier or unique system identifier that matches at least one of the unique user identifiers and at least one of the unique system identifiers within the computer network.
19 . A method for monitoring UDP communications with a resource within a computer network, the computer network including a plurality of authorized users and wherein a unique user identifier is allocated to each of the plurality of authorized users, comprising the steps of:
receiving a UDP packet at the resource within the computer network, the UDP packet having associated therewith the unique user identifier of a specific authorized user sending the UDP packet; obtaining the unique user identifier from the UDP packet; and logging in a database the UDP communication by the specific authorized user with the resource based on the unique user identifier obtained from the UDP packet.
20 . The method of claim 19 , wherein the unique user identifier comprises a user name of the specific authorized user.
21 . The method of claim 19 , further comprising the step of decrypting the unique user identifier after obtaining the unique user identifier from the UDP packet if the unique user identifier has been previously encrypted.Join the waitlist — get patent alerts
Track US2008276297A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.