NETWORK SPLITTING DEVICE, SYSTEM AND METHOD USING VIRTUAL ENVIRONMENTS
First Claim
1. A network separation apparatus which allows a user terminal, connected to an internal network, to connect an external network, the apparatus comprising:
- a packet transmission/reception unit configured to receive a packet generated in a virtual environment on the user terminal and transmit the packet either to the external network or the internal network;
a packet analysis unit configured to analyze the packet received from the packet transmission/reception unit; and
a packet processing unit configured to allow the packet to be transmitted to the external network or the internal network, separately, based on an analysis result of the packet from the packet analysis unit and a preset packet processing policy.
1 Assignment
0 Petitions
Accused Products
Abstract
A network separation apparatus allows a user terminal, connected to an internal network, to connect an external network. The network separation apparatus includes a packet transmission/reception unit to receive a packet generated in a virtual environment on the user terminal and transmit the packet either to the external network or the internal network. The apparatus also includes a packet analysis unit to analyze the packet received from the packet transmission/reception unit and a packet processing unit to allow the packet to be transmitted to the external network or the internal network, separately, based on an analysis result of the packet from the packet analysis unit and a preset packet processing policy.
-
Citations
14 Claims
-
1. A network separation apparatus which allows a user terminal, connected to an internal network, to connect an external network, the apparatus comprising:
-
a packet transmission/reception unit configured to receive a packet generated in a virtual environment on the user terminal and transmit the packet either to the external network or the internal network; a packet analysis unit configured to analyze the packet received from the packet transmission/reception unit; and a packet processing unit configured to allow the packet to be transmitted to the external network or the internal network, separately, based on an analysis result of the packet from the packet analysis unit and a preset packet processing policy. - View Dependent Claims (2, 3, 4, 5)
-
-
6. A network separation system, the system comprising:
-
a user terminal, connected to an internal network, configured to transmit a packet generated in a virtual environment via the internal network; and a network separation apparatus configured to analyze the packet received from the user terminal, and selectively transmitting the packet either to an external network or the internal network, separately, based on an analysis result and a preset packet processing policy. - View Dependent Claims (7, 8, 9, 10)
-
-
11. A method for network separation, the method comprising:
-
generating a virtual environment when there is a need for a connection between a user terminal, connected to an internal network, and an external network; receiving a packet generated in the virtual environment; analyzing the received packet; and selectively transmitting the packet to either the external network or the internal network, separately, based on an analysis result of the packet and a preset packet processing policy. - View Dependent Claims (12, 13, 14)
-
Specification