CA2445751C

Dynamic packet filter utilizing session tracking

Abstract

A novel and useful dynamic packet filter that can be incorporated in an hardware based firewall suitable for use in portable computing devices such as cellular telephones and wireless connected PDAs that are adapted to connect to the Internet. The invention performs dynamic packet filtering on packets received over an input packet stream. The dynamic filter cheeks dynamic protocol behaviour using information extracted from the received packet. Sessions are created and stored in a session database to track the state of communications between the source and destination. Recognition of a session is accelerated by use of a hash table to quickly determine the corresponding session record in the session database. Session related data is read from the session database and the received packet is checked against a set of rules for determination of whether to allow or deny the packet.

CA2445751C, drawing sheet 1
Sheet 1 of 26

Term

Term ended

Expired 10 May 2022, 4.4 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

43 claims: 5 independent, 38 dependent

  1. 1
    CA 02445751 2009-11-16 CLAIMS:1. A method of filtering an input packet stream, said method comprising the steps of: establishing a session database adapted to store session related data for a plurality of sessions, each session corresponding to a socket, the session database comprising at least one linked list of sessions;opening a new session in said session database upon receipt of a socket not previously stored in said session database;recognizing a session associated with a received packet in accordance with its associated socket;processing the session data corresponding to said received packet in accordance with a plurality of predefined rules to generate processing results;and deciding whether to allow or deny said received packet in accordance with said processing results.
  2. 15
    A method of monitoring the state of a communications session, said method comprising the steps of:establishing a session database adapted to store session related data for a plurality of sessions, each session corresponding to a socket, the session database comprising at least one linked list of sessions;recognizing a session in accordance with a first hash calculation on the socket associated with a received packet;recognizing a hole session in accordance with a second hash calculation on a partial socket associated with said received packet;reading session data from said session database, said session data associated with either a recognized session or a recognized hole session;tracking a connection state of said session and checking said state against a plurality of rules to determine whether to allow or deny said received packet;and writing updated session data back into said session database.
  3. 27
    A dynamic filter for filtering an input packet stream, comprising:a session database adapted to store session related data for a plurality of sessions, each session corresponding to a socket, the session database comprising at least one linked list of sessions;a session recognition module adapted to search said session database for a session whose associated socket matches that of a received packet;a session management module adapted to maintain said session database including adding, deleting and modifying sessions in said session database;and a main filter module operative to track a connection state of the session corresponding to a receive packet and checking said connection state against a plurality of rules to determine whether to allow or deny said received packet.
  4. 42
    A digital computing apparatus, comprising:communication means adapted to connect said apparatus to a wide area network (WAN);memory means comprising volatile and non-volatile memory, said non-volatile memory adapted to store one or more application programs;a processor coupled to said memory means and said communication means for executing said one or more application programs;and a dynamic filter for filtering an input packet stream, comprising: a session database adapted to store session related data for a plurality of sessions, each session corresponding to a socket, the session database comprising at least one linked list of sessions;a session recognition module adapted to search said session database for a session whose associated socket matches that of a received packet;a session management module adapted to maintain said session database including adding, deleting and modifying sessions in said session database;and a main filter module operative to track a connection state of the session corresponding to a receive packet and checking said connection state against a plurality of rules to determine whether to allow or deny said received packet. CA 02445751 2009-11-16
  5. 43
    A computer readable storage medium having a computer program embodied thereon for causing a suitably programmed system to search for a plurality of strings by performing the following steps when such program is executed on said system:establishing a session database adapted to store session related data for a plurality of 5 sessions, each session corresponding to a socket, the session database comprising at least one linked list of sessions;opening a new session in said session database upon receipt of a socket not previously stored in said session database;recognizing a session associated with a received packet in accordance with its 10 associated socket;processing the session data corresponding to said received packet in accordance with a plurality of predefined rules to generate processing results;and deciding whether to allow or deny said received packet in accordance with said processing results. RIDOUT & MAYBEE LLP Toronto, Canada Patent Agents