会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 3. 发明授权
    • System for packet filtering of data packets at a computer network
interface
    • 用于在计算机网络接口处对数据分组进行分组过滤的系统
    • US5878231A
    • 1999-03-02
    • US795374
    • 1997-02-04
    • Geoffrey G. BaehrWilliam DanielsonThomas L. LyonGeoffrey MulliganMartin PattersonGlenn C. ScottCarolyn Turbyfill
    • Geoffrey G. BaehrWilliam DanielsonThomas L. LyonGeoffrey MulliganMartin PattersonGlenn C. ScottCarolyn Turbyfill
    • G06F13/00H04L29/06G06F13/38G06F15/17
    • H04L63/0236
    • A system for screening data packets transmitted between a network to be protected, such as a private network, and another network, such as a public network. The system includes a dedicated computer with multiple (specifically, three) types of network ports: one connected to each of the private and public networks, and one connected to a proxy network that contains a predetermined number of the hosts and services, some of which may mirror a subset of those found on the private network. The proxy network is isolated from the private network, so it cannot be used as a jumping off point for intruders. Packets received at the screen (either into or out of a host in the private network) are filtered based upon their contents, state information and other criteria, including their source and destination, and actions are taken by the screen depending upon the determination of the filtering phase. The packets may be allowed through, with or without alteration of their data, IP (internet protocol) address, etc., or they may be dropped, with or without an error message generated to the sender of the packet. Packets may be sent with or without alteration to a host on the proxy network that performs some or all of the functions of the intended destination host as specified by a given packet. The passing through of packets without the addition of any network address pertaining to the screening system allows the screening system to function without being identifiable by such an address, and therefore it is more difficult to target as an IP entity, e.g. by intruders.
    • 一种用于筛选在诸如专用网络的被保护网络之间传送的数据分组和诸如公共网络的另一网络之间的数据分组的系统。 该系统包括具有多个(具体为三个)类型的网络端口的专用计算机:一个连接到每个私有和公共网络,以及一个连接到代理网络,其包含预定数量的主机和服务,其中一些 可能会反映在专用网络中发现的一个子集。 代理网络与专用网络隔离,因此不能作为入侵者的跳点使用。 根据其内容,状态信息和其他标准(包括其源和目的地),屏幕上接收到的数据包(进入或离开专用网络中的主机)被过滤,并且屏幕采取行动,这取决于 过滤阶段。 可以允许数据包通过或不改变其数据,IP(因特网协议)地址等,或者可以丢弃具有或不发送到分组的发送者的错误消息。 可以向代理网络上的主机发送或不进行分组,该主机执行由给定分组指定的预期目的地主机的一些或全部功能。 通过分组而不添加与筛选系统相关的任何网络地址,允许筛选系统在不被该地址识别的情况下起作用,因此更难以将其定位为IP实体。 由入侵者
    • 5. 发明授权
    • System for packet filtering of data packet at a computer network
interface
    • 在计算机网络接口上对数据包进行数据包过滤的系统
    • US5884025A
    • 1999-03-16
    • US795373
    • 1997-02-04
    • Geoffrey G. BaehrWilliam DanielsonThomas L. LyonGeoffrey MulliganMartin PattersonGlenn C. ScottCarolyn Turbyfill
    • Geoffrey G. BaehrWilliam DanielsonThomas L. LyonGeoffrey MulliganMartin PattersonGlenn C. ScottCarolyn Turbyfill
    • G06F13/00H04L29/06H04L9/00G06F15/163
    • H04L63/0236
    • A system for screening data packets transmitted between a network to be protected, such as a private network, and another network, such as a public network. The system includes a dedicated computer with multiple (specifically, three) types of network ports: one connected to each of the private and public networks, and one connected to a proxy network that contains a predetermined number of the hosts and services, some of which may mirror a subset of those found on the private network. The proxy network is isolated from the private network, so it cannot be used as a jumping off point for intruders. Packets received at the screen (either into or out of a host in the private network) are filtered based upon their contents, state information and other criteria, including their source and destination, and actions are taken by the screen depending upon the determination of the filtering phase. The packets may be allowed through, with or without alteration of their data, IP (internet protocol) address, etc., or they may be dropped, with or without an error message generated to the sender of the packet. Packets may be sent with or without alteration to a host on the proxy network that performs some or all of the functions of the intended destination host as specified by a given packet. The passing through of packets without the addition of any network address pertaining to the screening system allows the screening system to function without being identifiable by such an address, and therefore it is more difficult to target as an IP entity, e.g. by intruders.
    • 一种用于筛选在诸如专用网络的被保护网络之间传送的数据分组和诸如公共网络的另一网络之间的数据分组的系统。 该系统包括具有多个(具体为三个)类型的网络端口的专用计算机:一个连接到每个私有和公共网络,以及一个连接到代理网络,其包含预定数量的主机和服务,其中一些 可能会反映在专用网络中发现的一个子集。 代理网络与专用网络隔离,因此不能作为入侵者的跳点使用。 根据其内容,状态信息和其他标准(包括其源和目的地),屏幕上接收到的数据包(进入或离开专用网络中的主机)被过滤,并且屏幕采取行动,这取决于 过滤阶段。 可以允许数据包通过或不改变其数据,IP(因特网协议)地址等,或者可以丢弃具有或不发送到分组的发送者的错误消息。 可以向代理网络上的主机发送或不进行分组,该主机执行由给定分组指定的预期目的地主机的一些或全部功能。 通过分组而不添加与筛选系统相关的任何网络地址,允许筛选系统在不被该地址识别的情况下起作用,因此更难以将其定位为IP实体。 由入侵者