U.S. patents available from 1976 to present.
U.S. patent applications available from 2005 to present.

System for packet filtering of data packets at a computer network interface

Patent 5878231 Issued on March 2, 1999. Estimated Expiration Date: Icon_subject February 4, 2017. Estimated Expiration Date is calculated based on simple USPTO term provisions. It does not account for terminal disclaimers, term adjustments, failure to pay maintenance fees, or other factors which might affect the term of a patent.

Patent References

Routing mechanism with encapsulated FCS for a multi-ring local area network
Patent #: 4577313
Issued on: 03/18/1986
Inventor: Sy

Security system for preventing unauthorized communications between networks by translating communications received in ip protocol to non-ip protocol to remove address and routing services information
Patent #: 5550984
Issued on: 08/27/1996
Inventor: Gelb

Method and apparatus for secure data packet bus communication
Patent #: 5559883
Issued on: 09/24/1996
Inventor: Williams

Network station with multiple network addresses
Patent #: 5590285
Issued on: 12/31/1996
Inventor: Krause, et al.

System for securing inbound and outbound data packet flow in a computer network
Patent #: 5606668
Issued on: 02/25/1997
Inventor: Shwed

Apparatus and method for providing a secure gateway for communication and data exchanges between networks Patent #: 5623601
Issued on: 04/22/1997
Inventor: Vu

Inventors

Application

No. 795374 filed on 02/04/1997

US Classes:

709/245, COMPUTER-TO-COMPUTER DATA ADDRESSING709/243Decentralized controlling

Examiners

Primary: Robertson, David L.

Attorney, Agent or Firm

International Classes

G06F 013/38
G06F 015/17

Abstract

A system for screening data packets transmitted between a network to be protected, such as a private network, and another network, such as a public network. The system includes a dedicated computer with multiple (specifically, three) types of network ports: one connected to each of the private and public networks, and one connected to a proxy network that contains a predetermined number of the hosts and services, some of which may mirror a subset of those found on the private network. The proxy network is isolated from the private network, so it cannot be used as a jumping off point for intruders. Packets received at the screen (either into or out of a host in the private network) are filtered based upon their contents, state information and other criteria, including their source and destination, and actions are taken by the screen depending upon the determination of the filtering phase. The packets may be allowed through, with or without alteration of their data, IP (internet protocol) address, etc., or they may be dropped, with or without an error message generated to the sender of the packet. Packets may be sent with or without alteration to a host on the proxy network that performs some or all of the functions of the intended destination host as specified by a given packet. The passing through of packets without the addition of any network address pertaining to the screening system allows the screening system to function without being identifiable by such an address, and therefore it is more difficult to target as an IP entity, e.g. by intruders.

Other References

  • "Firewalls and Internet Security," by Cheswick & Bellovin, Addison Wesley, 1994
  • "Firewall Routers and Packet Filtering," by Gary Kessler, Feb. 1995
  • Ip-masq.c from Linux kernel (v.2.0.27), 1994
  • Ip-fw.c from Linux kernel (v 2.0.27), 199
PatentsPlus Images
Enhanced PDF formats
loading...
PatentsPlus: add to cart
PatentsPlus: add to cartSearch-enhanced full patent PDF image
$9.95more info
PatentsPlus: add to cart
PatentsPlus: add to cartIntelligent turbocharged patent PDFs with marked up images
$16.95more info
 
Sign InRegister
Username  
Password   
forgot password?