Security system for network address translation systems

Multiplex communications – Pathfinding or routing – Switching a message which includes an address header

Reexamination Certificate

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

C370S392000, C370S395520, C370S401000, C709S219000, C709S245000

Reexamination Certificate

active

07113508

ABSTRACT:
A system and method are provided for translating local IP addresses to globally unique IP addresses. This allows local hosts in an enterprise network to share global IP addresses from a limited pool of such addresses available to the enterprise. The translation is accomplished by replacing the source address in headers on packets destined for the Internet and by replacing destination address in headers on packets entering the local enterprise network from the Internet. Packets arriving from the Internet are screened by an adaptive security algorithm. According to this algorithm, packets are dropped and logged unless they are deemed nonthreatening. DNS packets and certain types of ICMP packets are allowed to enter local network. In addition, FTP data packets are allowed to enter the local network, but only after it has been established that their destination on the local network initiated an FTP session.

REFERENCES:
patent: 4962532 (1990-10-01), Kasiraj et al.
patent: 5159592 (1992-10-01), Perkins
patent: 5185860 (1993-02-01), Wu
patent: 5287103 (1994-02-01), Kasprzyk et al.
patent: 5371852 (1994-12-01), Attanasio et al.
patent: 5377182 (1994-12-01), Monacos
patent: 5406557 (1995-04-01), Baudoin
patent: 5426637 (1995-06-01), Derby et al.
patent: 5430715 (1995-07-01), Corbalis et al.
patent: 5477531 (1995-12-01), McKee et al.
patent: 5513337 (1996-04-01), Gillespie et al.
patent: 5550984 (1996-08-01), Gelb
patent: 5560013 (1996-09-01), Scalzi et al.
patent: 5581552 (1996-12-01), Civanlar et al.
patent: 5621727 (1997-04-01), Vaudreuil
patent: 5623601 (1997-04-01), Vu
patent: 5664185 (1997-09-01), Landfield et al.
patent: 5757924 (1998-05-01), Friedman et al.
patent: 5790548 (1998-08-01), Sistanizadeh et al.
patent: 5793763 (1998-08-01), Mayes et al.
patent: 5856974 (1999-01-01), Gervais et al.
patent: 5870386 (1999-02-01), Perlman et al.
patent: 6061797 (2000-05-01), Jade et al.
patent: 6128664 (2000-10-01), Yanagidate et al.
patent: 6154839 (2000-11-01), Arrow et al.
patent: 6178450 (2001-01-01), Ogishi et al.
patent: 6188671 (2001-02-01), Chase et al.
patent: 6188684 (2001-02-01), Setoyama et al.
patent: 6233234 (2001-05-01), Curry et al.
patent: 6353614 (2002-03-01), Borella et al.
patent: 6434627 (2002-08-01), Millet et al.
patent: 6510154 (2003-01-01), Mayes et al.
Internet posting for Test Sites to Beta Test and IP Address Translation product; posted on firewalls mailing list: posting made on or after Oct. 28, 1994.
Y. Reckhter. B. Moskowitz, D. Karrenberg, and G. de Groot. “Address Allocation for Private Internets.” RFC 1597. T.J. Watson Research Center, IBM Corp., Chrysler Corp., RIPE NCC. Mar. 1994.
K. Egevang and P. Francis. “The IP Network Address Translator (NAT).” RFC 1631. Cray Communications. NTT. May 1994.

LandOfFree

Say what you really think

Search LandOfFree.com for the USA inventors and patents. Rate them and share your experience with other people.

Rating

Security system for network address translation systems does not yet have a rating. At this time, there are no reviews or comments for this patent.

If you have personal experience with Security system for network address translation systems, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Security system for network address translation systems will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFUS-PAI-O-3577200

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.