Patent
1994-11-21
1997-04-22
Beausoliel, Jr., Robert W.
39518801, G06F 1100
Patent
active
056236018
ABSTRACT:
An apparatus and method for providing a secure firewall between a private network and a public network are disclosed. The apparatus is a gateway station having an operating system that is modified to disable communications packet forwarding, and further modified to process any communications packet having a network encapsulation address which matches the device address of the gateway station. The method includes enabling the gateway station to transparently initiate a first communications session with a client on a first network requesting a network service from a host on a second network, and a second independent communications session with the network host to which the client request was addressed. The data portion of communications packets from the first session are passed to the second session, and vice versa, by application level proxies which are passed the communications packets by the modified operating system. Data sensitivity screening is preferably performed on the data to ensure security. Only communications enabled by a security administrator are permitted. The advantage is a transparent firewall with application level security and data screening capability.
REFERENCES:
patent: 5023907 (1991-06-01), Johnson et al.
patent: 5416842 (1995-05-01), Aziz et al.
patent: 5548646 (1996-08-01), Aziz et al.
Stempel, "Ipaccess-an Internet Service Access System for Firewall Installations", Network and Distributed System Security, IEEE, pp. 31-41. Feb. 1995.
Nueman, "Proxy-Based Authproization and Accounting for Dsitributed Systems", Distributed Computing systems, IEEE Conf. pp. 283-291. Jan. 1993.
Bellovin et al., "Network Firewalls", IEEE Communications Magazine. pp. 50-57 Sep. 1994.
Tirenin et al., "Enhanced Multinet Gateway: Survivable Multi-Level Secure Data Communications", Milcom IEEE, pp. 740-744 1991.
A Network Firewall, Marcus J. Ranum, Digital Equipment Corporation, Washington Open Systems Resource Center, Greenbelt, MD, Jun. 12, 1992.
White Paper-InterLock.sup..SM. 2.1, Ans Co+Re Systems, Inc., Aug. 18, 1993.
Checkpoint Firewall-1.sup..TM. -Technical White Paper, CheckPoint Software Technologies Ltd., 1994.
Thinking about Firewalls, Marcus J. Ranum, Trusted Information Systems, Inc. Glenwood, Md, 1993.
Socks, David Koblas and Michelle Koblas, 1993.
Internet Firewalls - An Overview, Marcus J. Ranum, A slide presentation, 1993, Trusted Information Systems, Inc.
Screen External Access Link (SEAL) Introductory Guide, Digital, publication date unknown.
Increasing Security on IP Networks, Cisco Systems, Inc., advertising brochure, publication date unknown.
Beausoliel, Jr. Robert W.
Dougherty Ralph H.
Milkway Networks Corporation
Palys Joseph E.
LandOfFree
Apparatus and method for providing a secure gateway for communic does not yet have a rating. At this time, there are no reviews or comments for this patent.
If you have personal experience with Apparatus and method for providing a secure gateway for communic, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Apparatus and method for providing a secure gateway for communic will most certainly appreciate the feedback.
Profile ID: LFUS-PAI-O-348280