U.S. patents available from 1976 to present.
U.S. patent applications available from 2005 to present.

System for securing the flow of and selectively modifying packets in a computer network

Patent 5835726 Issued on November 10, 1998. Estimated Expiration Date: Icon_subject June 17, 2016. Estimated Expiration Date is calculated based on simple USPTO term provisions. It does not account for terminal disclaimers, term adjustments, failure to pay maintenance fees, or other factors which might affect the term of a patent.

Patent References

Graphical automatic programming
Patent #: 4315315
Issued on: 02/09/1982
Inventor: Kossiakoff

Computer language structure for process control applications, and translator therefor
Patent #: 4736320
Issued on: 04/05/1988
Inventor: Bristol

Cryptographic protocol for secure communications
Patent #: 5241599
Issued on: 08/31/1993
Inventor: Bellovin, et al.

Computer language structure for process control applications and method of translating same into program code to operate the computer
Patent #: 5247693
Issued on: 09/21/1993
Inventor: Bristol

Apparatus for providing cryptographic support in a network
Patent #: 5329623
Issued on: 07/12/1994
Inventor: Smith, et al.

Computer network encryption/decryption device
Patent #: 5442708
Issued on: 08/15/1995
Inventor: Adams, Jr., et al.

Computer network encryption/decryption device
Patent #: 5444782
Issued on: 08/22/1995
Inventor: Adams, Jr., et al.

Packet filtering for data networks
Patent #: 5473607
Issued on: 12/05/1995
Inventor: Hausman, et al.

Network having secure fast packet switching and guaranteed quality of service
Patent #: 5485455
Issued on: 01/16/1996
Inventor: Dobbins, et al.

Communication apparatus and methods
Patent #: 5515376
Issued on: 05/07/1996
Inventor: Murthy, et al.

More ...

Inventors

Assignee

Application

No. 664839 filed on 06/17/1996

US Classes:

709/229, Network resources access controlling709/247Compressing/decompressing

Examiners

Primary: Asta, Frank J.
Assistant: Patru, Daniel

Attorney, Agent or Firm

International Classes

G06F 013/36
G06F 015/401

Foreign Application Priority Data

1995-06-15 IL

Abstract

The present invention discloses a novel system for controlling the inbound and outbound data packet flow in a computer network. By controlling the packet flow in a computer network, private networks can be secured from outside attacks in addition to controlling the flow of packets from within the private network to the outside world. A user generates a rule base which is then converted into a set of filter language instruction. Each rule in the rule base includes a source, destination, service, whether to accept or reject the packet and whether to log the event. The set of filter language instructions are installed and execute on inspection engines which are placed on computers acting as firewalls. The firewalls are positioned in the computer network such that all traffic to and from the network to be protected is forced to pass through the firewall. Thus, packets are filtered as they flow into and out of the network in accordance with the rules comprising the rule base. The inspection engine acts as a virtual packet filtering machine which determines on a packet by packet basis whether to reject or accept a packet. If a packet is rejected, it is dropped. If it is accepted, the packet may then be modified. Modification may include encryption, decryption, signature generation, signature verification or address translation. All modifications are performed in accordance with the contents of the rule base. The present invention provides additional security to a computer network by encrypting communications between two firewalls between a client and a firewall. This permits the use of insecure public networks in constructing a WAN that includes both private and public network segments, thus forming a virtual private network.

Other References

  • Ranum M.J. "A Network Firewall" Digital Equipment Corp
  • Chapman, D.D. "Network (in) Security . . . " Proceedings of the 3 UNSENIX UNIX Security Symposium; Baltimore, MD, Sep. 1992
  • Safford, D.R. et al. "The TAMU Security Package . . . " Unix Security Symposium IV, Oct. 4-6, 1993
  • Cheswick, B. "The Design of a Secure Internet . . . " AT&T Bell Laboratory, Jun. 1990
  • Schauer, H. "An Internet Gate Keeper", Herve Schauer Consultant
PatentsPlus Images
Enhanced PDF formats
loading...
PatentsPlus: add to cart
PatentsPlus: add to cartSearch-enhanced full patent PDF image
$9.95more info
PatentsPlus: add to cart
PatentsPlus: add to cartIntelligent turbocharged patent PDFs with marked up images
$18.95more info
 
Sign InRegister
Username  
Password   
forgot password?