IDENTIFICATION OF UNAUTHORIZED APPLICATION DATA IN A CORPORATE NETWORK
An appliance works in conjunction with an agent on a remote device to control application access to a corporate network. In conjunction with an SSL tunnel and policy operating at the appliance, granular application control may be implemented. In particular, a device user may determine what applications from a set of applications may access the corporate network and which applications do not access the network. The policies applied to application traffic may be generated by an administrator. Policies may also be applied from a remote server to data stored on the user device.
1 . A method for establishing a connection, comprising:
establishing a connection between a user client device and a server, the user client device having a plurality of applications;
receiving by a server a list of applications on a user device requesting access to a corporate network;
granting corporate network access by the server to applications within the list of applications on the user device that satisfy a rule set.
2 . The method of claim 1 , wherein the connection is a virtual private network tunnel.
3 . The method of claim 1 , wherein the server is located on the edge of the corporate network and receives all corporate network access requests.
4 . The method of claim 1 , wherein granting corporate network access by the server to applications within the list of applications on the user device that satisfy the rule set includes denying corporate network access by the server to applications within the list of applications on the user device that do not satisfy the rule set.
5 . The method of claim 1 , wherein the rule set includes at least one rule that specifies access by an application of the list of applications to a selected set of corporate resources for a selected set of one or more users.
6 . The method of claim 1 , wherein the rule set allows a single rule to control both device level corporate network access and application level corporate network access.
7 . The method of claim 1 , further comprising providing the rule set to the client device from the server, the rule set applied to application data traffic initiated from the client and intended for the corporate network.
8 . The method of claim 1 , further comprising controlling application data accessed at the user client device by the corporate network based on the rule set.
9 . The method of claim 1 , wherein the policy controls data access by an application at the user client device.
10 . The method of claim 1 , wherein the rule set controls whether application data is transmitted to the corporate network.
11 . The method of claim 1 , wherein the policy is enforced at the server.
12 . The method of claim 11 , further comprising:
modifying the rule set; and
applying the modified rule set to application data at the user client device.
13 . A non-transitory computer readable storage medium having embodied thereon a program, the program being executable by a processor to perform a method for establishing a connection, the method comprising:
establishing a connection between a user client device and a server, the user client device having a plurality of applications;
applying a policy created at a server to data at the user client device; and
controlling data access at the user client device based on the policy. establishing a connection between a user client device and a server, the user client device having a plurality of applications;
receiving by a server a list of applications on a user device requesting access to a corporate network;
granting corporate network access by the server to applications within the list of applications on the user device that satisfy a rule set.
14 . The non-transitory computer readable storage medium of claim 13 , wherein the connection is a virtual private network tunnel.
15 . The non-transitory computer readable storage medium of claim 13 , wherein the server is located on the edge of the corporate network and receives all corporate network access requests.
16 . The non-transitory computer readable storage medium of claim 13 , wherein granting corporate network access by the server to applications within the list of applications on the user device that satisfy the rule set includes denying corporate network access by the server to applications within the list of applications on the user device that do not satisfy the rule set.
17 . The non-transitory computer readable storage medium of claim 13 , wherein the rule set includes at least one rule that specifies access by an application of the list of applications to a selected set of corporate resources for a selected set of one or more users.
18 . The non-transitory computer readable storage medium of claim 13 , wherein the rule set controls device level corporate network access and application level corporate network access.
19 . The non-transitory computer readable storage medium of claim 13 , further comprising providing the rule set to the client device from the server, the rule set applied to application data traffic initiated from the client and intended for the corporate network.
20 . The non-transitory computer readable storage medium of claim 13 , the method of claim 1 , further comprising controlling application data accessed at the user client device by the corporate network based on the rule set.
21 . The non-transitory computer readable storage medium of claim 13 , wherein the policy controls data access by an application at the user client device.
22 . The non-transitory computer readable storage medium of claim 13 , wherein the rule set controls whether application data is transmitted to the corporate network.
23 . The non-transitory computer readable storage medium of claim 13 , wherein the policy is created at the server.
24 . The non-transitory computer readable storage medium of claim 23 , further comprising:
modifying the rule set; and
applying the modified rule set to application data at the user client device.
25 . A system for establishing a connection, the system including:
a server in communication with a user client device, the server including a processor, memory, and one or more applications stored in memory at the server and executable to establish a connection between a user client device and a server, the user client device having a plurality of applications, receive by a server a list of applications on a user device requesting access to a corporate network, and grant corporate network access by the server to applications within the list of applications on the user device that satisfy a rule set.
26 . The system of claim 25 , wherein the connection is a virtual private network tunnel.
27 . The system of claim 25 , wherein the server is located on the edge of the corporate network and receives all corporate network access requests.
28 . The system of claim 25 , wherein granting corporate network access by the server to applications within the list of applications on the user device that satisfy the rule set includes denying corporate network access by the server to applications within the list of applications on the user device that do not satisfy the rule set.
29 . The system of claim 25 , wherein the rule set includes at least one rule that specifies access by an application of the list of applications to a selected set of corporate resources for a selected set of one or more users.
30 . The system of claim 25 , wherein the rule set controls device level corporate network access and application level corporate network access.
31 . The system of claim 25 , further comprising providing the rule set to the client device from the server, the rule set applied to application data traffic initiated from the client and intended for the corporate network.
32 . The system of claim 25 , the method of claim 1 , further comprising controlling application data accessed at the user client device by the corporate network based on the rule set.
33 . The system of claim 25 , wherein the policy controls data access by an application at the user client device.
34 . The system of claim 25 , wherein the rule set controls whether application data is transmitted to the corporate network.
35 . The system of claim 25 , wherein the policy is created at the server.
36 . The system of claim 35 , further comprising:
modifying the rule set; and
applying the modified rule set to application data at the user client device.