Multiplex communications – Wide area network – Packet switching
Patent
1995-05-18
1998-09-01
Robertson, David L.
Multiplex communications
Wide area network
Packet switching
39520059, 39520073, 370355, 340827, G06F 1300, G06F 15163
Patent
active
058023208
ABSTRACT:
A system for screening data packets transmitted between a network to be protected, such as a private network, and another network, such as a public network. The system includes a dedicated computer with multiple (specifically, three) types of network ports: one connected to each of the private and public networks, and one connected to a proxy network that contains a predetermined number of the hosts and services, some of which may mirror a subset of those found on the private network. The proxy network is isolated from the private network, so it cannot be used as a jumping off point for intruders. Packets received at the screen (either into or out of a host in the private network) are filtered based upon their contents, state information and other criteria, including their source and destination, and actions are taken by the screen depending upon the determination of the filtering phase. The packets may be allowed through, with or without alteration of their data, IP (internet protocol) address, etc., or they may be dropped, with or without an error message generated to the sender of the packet. Packets may be sent with or without alteration to a host on the proxy network that performs some or all of the functions of the intended destination host as specified by a given packet. The passing through of packets without the addition of any network address pertaining to the screening system allows the screening system to function without being identifiable by such an address, and therefore it is more difficult to target as an IP entity, e.g. by intruders.
REFERENCES:
Ip-Masq. c from Linux Kernel (v 2.0.27) Pauline Middelink, 1994.
Ip-Fw. c from Linux Kernel (v 2.0.27) Middelink, 1994.
Cheswick and Bellain, Firewalls and Internet Security:repelling the wily hacker, Addison-Wesley, Apr. 1994, pp. 94-96.
Baehr Geoffrey G.
Danielson William
Lyon Thomas L.
Mulligan Geoffrey
Patterson Martin
Robertson David L.
Sun Microsystems Inc.
LandOfFree
System for packet filtering of data packets at a computer networ does not yet have a rating. At this time, there are no reviews or comments for this patent.
If you have personal experience with System for packet filtering of data packets at a computer networ, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and System for packet filtering of data packets at a computer networ will most certainly appreciate the feedback.
Profile ID: LFUS-PAI-O-280764