Methods and apparatus for a computer network firewall with proxy

Electrical computers and digital processing systems: support – Multiple computer communication using cryptography – Protection at a particular protocol layer

Patent

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

H04L 900

Patent

active

060981725

ABSTRACT:
Computer network firewalls which include one or more features for increased processing efficiency are provided. A firewall in accordance with the invention can support multiple security policies, multiple users or both, by applying any one of several distinct sets of access rules. The firewall can also be configured to utilize "stateful" packet filtering which involves caching rule processing results for one or more packets, and then utilizing the cached results to bypass rule processing for subsequent similar packets. To facilitate passage to a user, by a firewall, of a separate later transmission which is properly in response to an original transmission, a dependency mask can be set based on session data items such as source host address, destination host address, and type of service. The mask can be used to query a cache of active sessions being processed by the firewall, such that a rule can be selected based on the number of sessions that satisfy the query. Dynamic rules may be used in addition to pre-loaded access rules in order to simplify rule processing. To unburden the firewall of application proxies, the firewall can be enabled to redirect a network session to a separate server for processing.

REFERENCES:
patent: 5623601 (1997-04-01), Vu
patent: 5673322 (1997-09-01), Pepe et al.
patent: 5689566 (1997-11-01), Nguyen
patent: 5781550 (1998-07-01), Templin et al.
patent: 5793763 (1998-08-01), Mayes et al.
patent: 5828833 (1998-10-01), Belville et al.
patent: 5835726 (1998-11-01), Shwed et al.
patent: 5845068 (1997-11-01), Winiger
patent: 5848233 (1998-12-01), Radia et al.
patent: 5884025 (1997-11-01), Baehr et al.
patent: 5898830 (1999-04-01), Wesinger, Jr. et al.
patent: 6003084 (1997-11-01), Green et al.
Chapman et al., "Building Internet Firewalls", ISBN: 1-56592-124-0, Chpt. 4, Firewall Design, pp 57-89, 147, and 226, Nov. 1995.
Siyan et al., "Internet Firewalls and Network Security", ISBN: 1-56205-437-6, pp 306-326, Jan. 1995.
Press Release, "EliaShim Ltd. Announces CVP-Complaint Anti-Virus Plug-In for Check Point FireWall-1," pp. 1-2, Feb. 17, 1997.

LandOfFree

Say what you really think

Search LandOfFree.com for the USA inventors and patents. Rate them and share your experience with other people.

Rating

Methods and apparatus for a computer network firewall with proxy does not yet have a rating. At this time, there are no reviews or comments for this patent.

If you have personal experience with Methods and apparatus for a computer network firewall with proxy, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Methods and apparatus for a computer network firewall with proxy will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFUS-PAI-O-674366

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.