Multi-layer based method for implementing network firewalls
Abstract
Provides a method, a method for a firewall of the fire wall structure. The fire structure comprises multiple network layer and a first machine. The two-stage transmitting the data packet and information packet information to the first a host, and data packet context and transmitting and then each, and processing data packets. The first a single time with one or more filtering and information packet information the images, and is connected to the operation to these layer, wherein pointed of how handle to the information packet.
Term
Term ended
Expired 3 June 2024, 2.3 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
15 claims: 6 independent, 9 dependent
- 1The is a request stage operating a strategy's method, wherein the support stage is a framework one of multiple stages; the framework fire - comprising with multiple mounting filters' a engine, the is composed characterised, comprising:Connected with the support table, which are multiple stages the preceding stage receiving information, packets Connected with the support table, wherein the preceding stage receiving information packet context data structure, wherein the data packet high and low invention comprises with the data packet with the preceding table;data Connected with the support table, externally connected with the data packet the related parameter acquisition;Output end of the classifying to transfer, and classifying to transfer comprising a packet information associated wherein the parameter acquisition;Wherein the information packet parameter acquisition to compare with multiple filter of filtering and comprises a matching to the information packet parameter acquisition at least filter and is connected with a policy at least filter;assigns The response a classifying to exchange according, with a a policy arranged on the operation. 一种用于在请求阶段执行防火墙策略的方法,所述请求阶段是防火墙构架中的多个阶段之一,所述防火墙构架进一步包括具有多个被安装的滤波器的防火墙引擎,其特征在于,包括:通过所述请求阶段,从所述多个阶段中的前一个阶段接收信息包;通过所述请求阶段,从所述前一个阶段接收信息包上下文数据结构,所述信息包上下文包括与所述信息包关联的前一个阶段的数据;通过所述请求阶段,识别与所述信息包关联的参数集;发出分类调用,所述分类调用包括与所述信息包关联的所述参数集;将所述信息包参数集与多个滤波器的滤波条件进行比较并识别匹配所述信息包参数集的至少一个滤波器和由所述至少一个滤波器指定的关联的防火墙策略;响应于所述分类调用,根据所述关联的防火墙策略来接收动作。
- 10A tailing is a comprising a group of mounting filters' is a method for a firewall policy method, the mounting filter each comprises a group of filter state and an associated movement, the side of characterised, comprising:A group of information packet parameters, wherein the data packet parameter comprises an as follows data structure with a request layer association's first data packet information and a signal and second information generation, information Identification matching filter collection, wherein the matching filter centralized each filter corresponding to the information packet parameter the filter;stateAnd, which is at least filter is a matching filter is sleeved to with the operation. 10. —种用于在包括一组被安装的滤波器的防火墙引擎中执行防火墙策略的方法,所 述被安装的滤波器每个都包括一组滤波器条件和一个关联的动作,其特征在于,包括:接收一组信息包参数,所述信息包参数包括与请求层关联的第一信息包信息以及与信 息包上下文数据结构关联的第二信息包信息;识别匹配滤波器集,所述匹配滤波器集中的每个滤波器具有对应于所述信息包参数的 滤波器条件;以及,从所述匹配滤波器中的至少一个滤波器中识别所述关联的动作。
- 11A method of claim io for is composed characterised, wherein the matching filter centralized each filter with priority, associated movement and utility terminal operation from rotating and filter, and method - comprising:Which is in matching filter centralized one or more low and filter is sleeved to with the movement, till achieving terminal operation. 11. 如权利要求io所述的方法,其特征在于,所述匹配滤波器集中的每个滤波器具有优先级,并且,来自最高优先级滤波器的关联的动作是非终止动作,所述方法进一步包括:从所述匹配滤波器集中的一个或多个较低优先级滤波器中识别所述关联的动作,直到达到终止动作为止。
- 12A method of claim the IO of the characterised is made from, the matching filter collecting filter identification to shout the module, and method - comprising:Wherein the information packet parameter and came from the matching filter collecting mark of filter substrate-processing of the exhales module. 12. 如权利要求IO所述的方法,其特征在于,来自所述匹配滤波器集的滤波器识别呼出模块,所述方法进一步包括:将所述信息包参数和来自所述匹配滤波器集的滤波器的标识发送到所述呼出模块。
- 14A method of claim the IO for is composed characterised, wherein the fire the end of the operating system and method. 14. 如权利要求IO所述的方法,其特征在于,所述防火墙引擎在操作系统的用户模式中执行。
- 15A method of claim the IO for is composed characterised, wherein the fire the end of the operating system and method. 15. 如权利要求IO所述的方法,其特征在于,所述防火墙引擎在操作系统的核心模式中执行。
Independent claims6
368 paragraphs, as filed
For carrying out a network a subject based on method (0001) is related blue i (0002) and application of multi-layer comprises a claim patented for A Firewall Structure of the application submits on the same antenna (proxy and a: 221038), A for Unifying Multiple Network Strategies Method And the Framework (proxy serial number: 221041) And For Managing Base and Filter Network Strategy Method of proxy (serial number: 221037) Subject, and patented one of claims explain of the special comprises, used as a.
technical field
[0003] The invention claims a computer system and network security generally. Is special, the invention relates to a method for method for fire wall of the network device.
background technology
[0004] The design of network protocol for facilitating via common data exchange, and the communication between each network device.
The common data exchange of strengthened the network device to achieve the task using; meanwhile, which is provided questions part, which is no design for network security wherein a network protocol; therefore which is providing network security generally. Is coupled to public network and private network (. e.g, local area network and Wide area network, and intranet) and is easy for directly or indirectly connected with the network connecting the malicious attacks of the network device. The attack of the device for evaluating malicious comprising burglary data, a service of cooled (D0S) attack and computer virus dispersing and similar attack. The computer coupled to network, wherein a arranged relative items (e.g., a rotor is provided needing or unsuitable web access stand).
[0005] The fire is used to user protecting personal generally, network device and network avoiding the utility experience malicious attack a tool; meanwhile, then introducing a network and capability of data exchange by the strategy. Through the inspection network information generation, and a acting according to the inspection device for confirming the licence or hinders the information packets to further pass through the network on the top, the fire and a out a policy.
[0006] The mixed according performs filled with two is one or more filters via the fire. The filter a filter parameter and associated operation. The filter parameters are used to distinguish are restrained the fire mixed network information generation, and comprising such as hardware (address. e.g, a Media Access Control rod (MAC) address), network address (e.g., an Internet protocol (') protocol address), protocol type (e.g., a transmission control protocol groove (TCP)), a port and disclosure and information. How the operation definition handle is provided with a parameter information generation of the filter matched parameter. A special invention is: The filter comprises a uniform resource locating groove (a) URL address (e.g., a http: 〃 A w. foo. com'), wherein a parameter. The filter structure for u-disc to movement (. i.e, the output information packet) and URL address associated. In long and fire inspection information generation, and is of an and URL address of http: 〃 Www. foo. the com for identifying is inserted in the information generation, the server by the information generation, wherein a preventing to pass through the network.
[0007] Use by a hierarchical network architecture's network stack transmitting and receiving information generation, network device and exchange the data. With different network structure mode, further majority at least comprises an application layer and transmission layer, a network layer and link layer. The network data packet sequential based on each layer; and each layer is connected with, packet information processing experience. And the output information generation, the application layer has application protocol (e.g., wherein one part of: Of hypertext transmission protocol groove (HTTP), a file transmission protocol groove (FTP) and simple mail transmission protocol groove (SMTP)) processes the data. An layer (e.g.; the network layer and transmission layer) is inserted into the data in TCP head and IP head, calling function end is set (packetize) is a. The relieve layer packet through (e.g). the head and a data disc (packetize) equal, came is an information packet operating exchange processing.
The stack structure and processing function in a dynamic information package structure of laminations of the executions, thereby, wherein the information packet passes through the network protocol stack, wherein - comprising a information packet contents of the information packet parameter.
[0008] A inspection device is equal information packet located at the network lamination stack. At the same time, the fixing part of the application layer of. For example, wherein a served and a tiered service supplier (') LSP. The application layer of information packet comprising a key data, the key data is transmitted to the network device or is received from the network device is.
Searching through the data packet of the application layer, and a licence the fire identifying application layer parameter (e.g., the URL address) and realizes with the filter parameters and application layer parameters the images. The, an information packet parameters (e.g., IP address, port number and address and disclosure) is available, which is configured or their is not connected to the electric output information generation, or left the information an packet is respectively.
[0009] On the other side, the network stack (and clamped with the link layer is driver the network layer is the low level and method for a firewall device socket. The network stack the low level of information packet including a biggest quantity parameter (e.g., the number and address, IP address and protocol type, port and payload data). Although the information packets comprising such a parameter, wherein, which is express to think: A are the easily parameter. The fire receiving the information generation, wherein a need to intervals and explain of the related information packet parameter, a compares with the filter parameter. , Wherein the network the base and fire and a pluggable unnecessary information packet analysis and emitter function.
invention content
[0010] The invention executing method for fire wall in a framework in aggregate of a. The fire frame comprises multiple stages; each layer of for handling packet information according to layer protocol; each layer of the further can request is applied with a policy in the information packets. The framework fire - comprising a host, wherein a host includes multiple for filtering.
[0011] Request layer the preceding/receiving information network packets from multiple levels. The request layer comprises a group of parameter from the information generation, and a classify the through-connection to distribution with a machine of the parameter acquisition. And the response, wherein a machine is connected to the operation to the support layer. And the movement of the containing information packet is further connected with multiple layers the instructions; and support layer automatically according to the protocol whence and data packet, and transmitting the information packet to multiple layer is. On the top; and movement of by the information packet the instruction; and no process the information generation, and without the sending information packet is then the.
[0012] The mounting filter centralized each filter comprising a group of filter state and a movement. The request layer out from the classified transfer, wherein a host: determiningA any filters in multiple filter is matched with the parameter acquisition. Adhesive; and a machine automatically according to the information in the matching filter is connected to the operation.
[0013] The invention further claims a vertical to the data packet from credible starting outfit to pass through the fire (usually is configured to for u-disc request an information packet) and to respond method for device. The starting outfit first switch is a to discuss the estimation of protocol. Once completes the estimation successfully; the response computer and a base filter, the filter circuit IC2 from the starting computer information packet is bolted with target processing of the response of computer.
[0014] Connected to declarative embodiment detailed description of the following have a digital time, the extra and power of this invention is a transparent.
Brief description for drawings
[0015] The auxiliary claim 1-3 of the characteristic of this invention is detail, further through the detail of one attached with shape, and best degrees understand the invention and volume and power. In the auxiliary certain:
[0016] Digital 1) is diagram, generally with demonstrated above the invention computer display system,
[0017] Digital 2) is diagram, a generally demonstrated from the can use the invention the display network, environment
[0018] Digital 3) is diagram, a generally demonstrated can use the invention claims a method for fire wall structure;
[0019] Digital 4) is diagram, comprising demonstrated the display filter is the invention,
[0020] Digital 5) is diagram, demonstrated and is used for the invention the displaying data structure of information generation, context(0021) Digital 6), diagram with demonstrated application program interface the display device is the invention,
[0022] Digital 7) is diagram, comprising demonstrated the display application program interface is the invention,
[0023] Digital 8) is diagram, and demonstrated automatically according to the invention, and functions of the network layer executing;
[0024] Digital 9) is diagram, and demonstrated for the invention the exhales (callout) display device,
[0025] Digital 10 is a current image, and demonstrated automatically according to the invention, by end of the display method of; a
[0026] Digital 11 is a current image, and demonstrated by end of the display method of a a network layer,
[0027] Digital 12 is a current image, and demonstrated by end of the display method for fire wall of the fire wall; the
[0028] Digital 13 is a current image, and demonstrated method, device and is used to allow is filled with a firewall of the credible network device is started for the communication of request.
detailed description of illustrated embodiments
[0029] Claims a method for acting according to the fire structure of network device and a method for a firewall. The method for in network information generation subordination protocol stack multiple layers of filtering. In one embodiment of this invention, multiple operation system processing (are called and a core schema proccessing " and user schema proccessing') are out a method and a structure. Method for selecting; a single operating processing system, or executing the method and structure one or more program module or a applications external the operation system and device.
[0030] The core schema proccessing and one or more exhales a protocol stack core and a machine. The protocol stack a application layer and transmission layer, network layer and link layer. On - demand flowing capacity or deletes the extra layer from the system. The section of the support layer; the support layer formerly a layer of flexible is arranged on the data packet context data of the network information generation and communication. Adhesive; the support layer via an API, wherein the classify request to the distribution core a machine. The classified request comprises a first support layer and data packets, the information packet context and the support layer with a group of layer parameters of. The core is a processing the support, and is connected to the operation. The invention, the operation fault how the support layer head the information packet (e.g., is or hinders). And the movement is; and support layer has layer protocol whence and data packet, use the information packet context comprising the parameters, and transmitting the information and packet data packet context lower. And the movement hinders; and support layer by the information generation, and without the sending information and packet. And the u-disc the operation the inspection, the support layer covers possibly sent to the extra function (e.g. demolishes, the TCP) is.
[0031] The core a host and exhales API comprising the API and a group of for filtering. The mounting filter centralized each filter comprising a group of filter state and an associated operation. The core a machine by distinguishing one or more matching filter, formed thereby request layer is transmitted classifying request. The matching filter provided with a filtering state of the parameter information and packet context matching. A once the matching filter, pressing filter and order to apply them. And the is by using the movement of the filtering or, hinders
Loop to the inside to the support layer. And the movement, exhales with a matching filter mark is transmitted to the exhale the module exhale the classified request of the support layer from top to the module. The exhale the module end of the further programmed function, and is connected to the operation to the core a machine. A frame is information packet identification matching filter, to the support layer informing: Once which is discover the matching filter; Adhesive; the support layer as to how handle the data packet.
[0032] Displaying user schema proccessing a user mode a engine and one or more suppliers strategy. The mixed suppliers from a source (e.g. volatile, or nonvolatile memory) obtain the strategy. The mixed is provided with a a information source of novel filter, comprising a filter device of state and associated operation. The user a machine via filter WITH engine, engages the novel filter is a filter collecting the core a machine.
[0033] The user mode - comprising a core a engine's example, wherein the is a user mode layer. , And the user mode layer is a user mode of the core a host is sleeved with a filter is a group of parameter matching, the group of parameters to apply a filtering in the user mode.
[0034] The embodiment of this invention, a group exhales the module exhales the interface in the licence the unlimited has of the fire performance from the core a machine. The invention, the HTTP context exhales by URL address of distinguishing acceptable and it housing, a parents the. Internet with the safety (IPSec) exhales: determiningThe data packet with experienced IPSec processing thereof. The micro-control exhales the standard information generation of writer and is united arranged, wherein after the upgrade, the inspection information packet. The intrusion detection exhales to known algorithm to distinguish the suspicious information packet.
[0035] The invention further claims a method, for allowing end of the credible network device for the communication of request, at hinders from the network device for suspending the communication of request.
[0036] Is the gasket (certain the same, a teeth are similar element), the invention is demonstrated for performed end is in a computational environment. Although is not made of the other;, a computer of personal computer operating of the executive wire (e.g., program module) is a universal context where the invention. Usually, program module comprises a bearing special distribution or the special abstract data type device, program, object part, and data structure. Is further practice the invention in distributed computing environment, wherein said distributed computing environment, and a remote processing device for of the task through the communication network. In distributed computing environment, a program module can be arranged on the local memory storage device and a remote memory storage device.
[0037] Digital 1) demonstrated and a pluggable a computing system condition 100 examples of this invention is. The computing system condition 100 is only the invention of a computational environment, wherein there is intend to or filler the input to the invention uses the hand-free to limit. Any dependency or the requirements of the is not involve to the displaying work environment 100 to demonstrate the computer environment 100 explanations any part or a part of combination.
[0038] The invention can be used in the numerous universal or special computing system condition or a one. Possibly suitable for the invention well-known the invention of computing system, environment and/or a configuration (, it does not limit) to personal computer and computer server, a handheld or the portable device and multiprocessor and system for microprocessor-based system, set-pot box, a programmable gate consuming device and A network, the minicomputer, a large computer, comprising a any one or system of distributed computing environment, and disclosure.
[0039] Capable of the computer of computer operating provided with an executive wire (e.g., program module) is a universal context where the invention. Usually, program module comprises a bearing special distribution or the special abstract data type device, program, object part, and data structure. Is further practice the invention in distributed computing environment, wherein said distributed computing environment, and a remote processing device for of the task through the communication network. In distributed computing environment, a program module can be arranged at a memory storage device local computer and storage medium and telecomputer storage medium.
[0040] Reference image l, for carrying out the invention representing system comprises adopting computer and 110 universal calculating device. Computer 110 parts of a (, it does not to limit) processing unit 120, system storages 130 and system bus 121, the system bus 121 in each comprises a system unit couplings of the storage system to the processing unit 120. The bus 121 can be multiple types bus (structure and uses the buses to construct a memory bus or storage control unit is any main bus structure of the bus) to bus structure. The invention (without for limiting), wherein a structure comprises an industrial standard structure of the (ISA bus), a micro channel structure of the (MCA bus), a reinforced ISA of the (EISA bus), a video electronic with standard of the (VESA) local bus and is also and called of the middle deck building (Mezzanine) is composed of the connecting part of the (PCI) bus.
[0041] The 110 typically comprises a computer is connected to the computer-readable medium. The function adding the medium be arranged in any available medium the computer 110 is deposited and withdrawn, comprising volatile and non-volatile medium, removable and intransportable medium. The invention (without for limiting), a function adding the medium is connected to a computer and storage medium and communication method. Computer and storage medium comprising volatile and non-volatile removable and intransportable medium, and media connected with the information (e.g., function adding the instructions, framework of data, program module or data) to method or the process of memory is filled with. Computer and storage medium comprising (, it does not to limit) RAM, ROM, EEPROM and quick memory storage or storage technology, CD-ROM and digital universal CD (DVD) or CD memory, head, magnetic disc and magnetic-disc memory or magnetic storage device, or can be used to save the need for information and 110 end of the deposits a computer any other media. The communication medium usually to display the computer is connected to an indication, the data structure, the program module or a modulating data signal (e.g., the holding or transmission mechanism) other data, comprising any information transmission method. Terminology a modulating data signal a method of signal; the signal one or more characteristic is arranged on the exchange according to such groove, in order to for coding information in the signal. The invention (without for limiting), the medium comprising a medium (e.g. wireline, network or linear connection) and wireless medium (e.g., the sounds, RF, an and wireless media). The combination of any one content and is further comprises; the function adding the medium in a range.
[0042] The system for storing 130) is fixed volatile and/or a non-volatility memory (e.g. non-erasable, storage ROM (131) and random access memory 132)Computer and storage medium. Basic input-output system (133 BIOS) is usually saved in ROM 131, wherein the basic input-output system comprises is compressed parameter computer 110 in each element the pass-along message (e.g.; during starting) and basic routines. RAM 132 in usually is can immediately a processing unit (120) deposited, and/or 120) connecting the operation a processing unit the data and/or a program module. The invention (without for limiting), digital 1 demonstrated with an operation system 134, 135 application program, which 136 and program 137 data.
[0043] The computer 110 of further comprises an to intransportable/volatile/computer non-volatile storage medium. Without is an example, digital 1 demonstrated with the intransportable non-volatile magnetic computer-readable medium or 141 to read-in wherein the HDD, a mobile non-volatile floppy disk reading 152 or 151 to read-in wherein the CD driver, and a removable non-volatile CD 156 ). e.g, the CD ROM or media optical reading) or 155 to read-in wherein the driver of. Can be used for displaying the operating environment the removable/intransportable volatile/computer non-volatile storage medium comprising (, it does not to limit the clamping head band unit, a flash memory card, a digital universal CD, a digital recorder belt and solid RAM and solid ROM same and storage medium thereof. The HDD 141) through the intransportable memory interface (e.g. interface, 140) are usually connected with the system bus 121, CD driver 151 and optical driver 155 in usually removable memory interface (e.g., interface 150) With the system bus 121.
[0044] The discussed the driver and associated with a storage medium and digital 1 demonstrated 110 providing computer is connected to the reading of memory instructions other; the framework of data, a program module and data for computer. The digital 1, for example, the HDD 141) are demonstrated is an operation storage system 144, 145 application program, which 146 and program 147 data. The warning; the part of the equate or different in the operation system 134, 135 application program, which 136 and program 137 data. Here is an operation system 144, 145 application program, which 146 and program data 147 providing different number, a demonstrate: Solution at least are different transcriptions. The user is connected with the input device (e.g., keyboard 162) and embedding device (161) is usually called and middle rod and tracking ball rod or a touch plate'), wherein a information and input 110 computer. An input devices (is not shown) is connected to a microphone, wherein the handle, a cushion and satellite disc, scanner or similar input device. And and input device via 160 are connected unusually to the system bus's user interface by connecting a processing unit 120, further - by an interface and bus structure (e.g., parallel port, a port or serial bus (u) method for) connected. Monitor 191 or the length display device is via interface (e.g., video interface 190)Which is connected with the bus 121. Is the monitoring device, a computer is further comprises the periphery of the output unit (e.g. loudspeaker, 197 and printer 196), and output units capable 195) is connected with the output interface of.
[0045] The computer 110 of the use with one or multiple telecomputers (e.g. telecomputer, 180) in the environment of logic ring and operation. The telecomputer 180 can be in personal computer server, router, and network PC, a node device or common network nodes, wherein usually comprising a to personal computer 110 plurality of description or the switch element, although digital 1) is installed demonstrated memory storage device 181. The logic a shape of claims 1 and a local area network171 and Wide area network173, further - comprising an network. The combining network environment enterprise-wide's computer network, intranet and Internet is very common the component and a.
[0046] Which is used for AND/OR the network environment, personal computer IIO 170) is connected with AND/OR a network interface or a adapter 171. By a WAN network environment, the 110 typically comprises a demodulator 172 or is provided with a WAN 173 ). e.g, and) are arranged on the other communication device. Modem (172 possibly built-, further possibly is a 160 or other mechanism is connected with the bus via the user input interface of the set-top 121). The network environment, or 110 wherein each program module of description can be storing the personal computer the remote memory storage device. The invention (without for limiting), digital 1 remote application 185 to demonstrations wherein the storage device (181). A understand: The network connection for fixing the function of display, can use in the computer is the other device of information link.
[0047] Is as follows, only some instructions, wherein of the symbolic representation operation of the operation and one or multiple computer and connected to the invention in addition. To, wherein understand: The device for operation and operation (are sometimes called and a a computer executions') comprises a display operation of with structured data form electric signal processing unit of the executing. The operation converting the data or wherein on the computer each of the storage system, and redeploy or change the operation of the computer according to the way of the skilled the technical field of familiar is a. A wire with the framework of data of data of memory physical position, the stored in the data a specific attribute of forming parts. The, wherein the context where the invention; the no intend to the function of limiting, the shape of a skilled the technical field a understand which is in each of the movements and operations in hardware and follows described.
[0048] Now, wherein of the digital 2 to the using the invention for carrying out firewall's method the network environment. The network role played for example, wherein a arranged in a to any network device of network configuration of the connection method of this invention. The network environment a private network 200 and public network 202. A private network 200 and public network 202 belong to any a fuse (. e.g, local area network and Wide area network, intranets Internet, or any combinations).
[0049] The network environment comprises multiple network device 204, 206, 208, 210 and 212. Network device 204 and 206 are coupled to the private network 200. Network device 210 and 212 are coupled to public network 202. The network device 208 and coupled to the private network 200 and public network 202, tariff in the two networks interface. The network device by connecting a to any a process (. e.g, Ethernet, 1394 or 802. l1 (b) and public network and private network. The network device are performed further end part, and one a calculating device (e.g., personal computer, server, handheld, printer, converter, router, bridge forwarder, or similar) device.
[0050] The network device 208 and a firewall 214 and one or more 216 filters. The fire 214 to a firewall structure (the; and according to program module or a group of program module for method of this invention) is method and device. A 214 inspections is coupled to private network 200 network device 204, 206 and 208 and is coupled to public network 202 network device 210, 212 exchanged network packets information. The embodiment of this invention, the fire - 214 inspect a private network 200 in network device is transmitted and gone of the network device of the local assigned network data packet.
[0051] The fire 214 208 carried out a network device, a protection and controlling the private network 200 and public network 202 exchanged network flow, which is called and a firewall of the. Method for selecting, a firewall 214 executing the single network device according to the network device demonstrated 210) and protecting the single network device, comprising a called and host of a. The fire and further, the regulating collecting of host and/or a edge according to synchronous mode method end of, a called and a distributed with a. Of selecting with the operating a good 214 the or a device of the network device, so for a firewall of 216 inspect, a on network traffic according the network device is a protection and methods.
[0052] The filter 216) is a 214 one part is filled with. Method for selecting, a filter 216) is independent data structure for a firewall device 214 and a to receive end of. The fire 214 and 216 filter unit for a firewall strategy, wherein a policy is designed the network protection device 204, 206 and 208 to prevent the utility experience originating from a coupled to the network device 210 and 212 attacks malicious of the public network. The fire 214) and an increase filler (e.g., present invention parents controller, intrusion and detecting for network information generation and an based on gain filter filler is).
[0053] The filter 216 comprises a group of filter state and one or more secondary movements. The filter that comprises a parameter and information; the parameter information and from the network data packet (e.g. interface, a software-hardware address, network address and protocol type, port and a data application-aware) are respectively or obtain from the network data packet. How the operation parts of the one or more secondary executing the network device for a firewall is engaged with the data packet of the filter matched environment. The typical movement a allowing (. i.e, permits the information packet to casing and traversal) and (hinders. i.e, a transmitting packet information, further hinders network traversal).
[0054] When the fire 214 inspections the network equipment (208) are received penetrates through the network the network information, packet, A time with the filter that the information packet parameters the images, a firewall 214) comprises one or more matching filter. When the tubular filter matched with the information packet parameters, generating matching filter. Is the same as the filter state; the information packet parameter comprises are respectively from the data packet the information according or relating. The identification a matching filter; and one or more movements of executions and filter associations state.
[0055] And the terminology according here for made of information of packet is a data. The information generation possibly performs the formatted according to network protocol network information generation, possibly is a data stream for layer, program or the module are processed.
[0056] Digital 3) is displayed and a out the invention claims a method of an example of a structure to implement the invention. The method provided with a bending the data packet the lower-stage in network the base seat filters' abilities. The method provides adjusting performance, and adjusting performance of increase and delete the filter; and worried and according treats the filter conflict of identifying for. The fire wall structure is extensible; the manifests in that: The filter flowing layer is increased and deleted on - demand, and a LF2407, includes licence and u-disc of the operation the special filler. Although is a firewall and a filter specifically describes the invention, using the method promotes managing and filtering and strategies. And the special invention, the invention is suitable for present invention and tube is provided with a service quality groove (QOS), an Internet protocol safety the other (IPSec suite) and encryption protocol, authentication protocol and a managing protocol filter.
[0057] The fire structure processing 250 comprising a user mode and core processing mode 252. The user processing mode and 250 core processing mode 252 to move network and a part of operating system to receive end of. The section of the skilled the technical field a understand: The operating and system for processing 250 and core processing mode 252 comprises an extra part, a simplicity, comprising an shown the extra element. Method for selecting; the whole of single operation system for processing method for a firewall structure and one or more program module or an application the operation system or contacts.
[0058] The core processing mode 252) comprises a network stack 254 core, a engine 256 and optional 258 exhales. Generally talk-back, core processing mode is 252 to process information generation and other end movements to the data packet according to the matching filter assigns for network information packet identification matching filter and has known protocol, same is a policy.
[0059] The network stack more than comprises 254 layers, and a a data current layer (268), transmission layer, 270 and 272 layers and link layer 274. The fire wall structure is extensible; the flowing is dynamic increase on - demand is within a extra layer. A layer of for increasing comprising a file access layer 276, wherein the file access layer has a server main block of the (SMB) protocol method end of. The can with an program module (e.g., a hypertext transmission protocol groove (HTTP) program analysis module 278) with operation.
[0060] Network stack 254 the processing an network information generation and output network data packet. The output network information packet is a connecting with the network device is of the fire wall structure is transmitted to a network in the data packet. A an information packet is communicating with the data packet with the network device for a firewall structure and is received. An arrow shape of 3 cooling strengthening part, an information packet passes through the network stack from top to bottom 254, the output information packet passes through the network stack from top to bottom 254.
[0061] The network data packet sequential passes through the network layer, and sequential is processed by the network layer. To a known technology, network stack 254 each layer of a front layer or module/receiving information generation, hood according to the standard or a protocol whence and data packet, and energy data packet transmitting with the flexible to the lower layer or a module. To the invention, network stack 254 each layer is on the data packet context, transmission and information the packet context, wherein the classify request to the distribution core a to 256, and method to the action to the information packet according to the fire strategy.
[0062] The information packet context follows the information packet to the base layer from a layer of data structure. Each layer is) is one group of parameters of the level flowing to perform process (. e.g; the level of) from information in information packet switch, respectively disposed or) is arm the context data structure, and context. A position where 5) is provided with the information packet context the displaying data structure.
[0063] The operations in operations for network bars are 254 to the inventions and a: aIs used for the classifying request according to a core 256 machine. The classified request is a transfer for network base (254) is arranged in: requestThe identification with any filter with the information packet distribution, and returning to any with a policy (e.g., a policy). Output end of the classified request layer is called and a request here stage shape or a request layer of. Each layer is taken the action of the data packet of a core is 256 loop. The user mode layer can also form the support layer.
[0064] The core a host 256 comprises an API 280 and a group of for filtering and 282 exhales API284. The core a machine shaft 256 according to the invention claims a method end of each functions, comprising: (l) of the two a policy and filter collecting 282, the (2) Is network bars are 254 and classifying, requests(3) Request according to the classifying is separately one or more matching filter; And (4) going is applied to the request feedback layer is any policy of the information packet.
[0065] The mounting filter centralized each filter comprising a group of filter state and one or more secondary movements. And is digital description 2, the filter state identification experience with the network packets information of operation filter. The movements is installed filter collecting 282 stipulated a permitting and hindering. Via optional 258 exhales increase the extra filler. Reference image 4 where the display part of the filter.
[0066] An API 280 network and base 254) and a core is 256 providing interface. Through an API 280, wherein the support layer sending the classified request the core a host 256. The data packet context of the classified request receiving information packet according to the support layer claims a comprises a request from layer, and parameter. The parameter is composed the request processing layer (e.g., cylindrical or the) information packet parameter. And the special invention, the source Internet protocol address and volume Internet protocol address is and out a protocol CONVERTING layer of parameter for network layer (272) is transmitted. The level parameter of further comprises a siamesed the information packet or from the information generation of the information packet parameters of information of resolution. Special for example, the parameters a local address type. The local address type is determined by the IP layer according and method for transmitting and a part of the classified request. The local address type transmitting (anycast) and similar type comprising a simple point transmission, playing, multi-point transmission and bitrary point. Reference image 6 described layer WITH special 280 implementations.
[0067] With a talk-back, using exhales 258 end of the licence and u-disc of the filter movement the filler of capacity. Core and a machine 256 of the information packet (and association's operation, comprising exhale to the when exhalation) are identification matching filter, the operating exhales. The classified request of the core is a to the support layer claims a remote device (i.e. alarm information and packet layer parameter information and packet context) together via exhaling API 284 transmitting with a mark of the matching filter to the exhale component. The fire structure comprises exhaling fundamental 258 device. Is the same as a layer, flowing capacity extra exhalation on - demand, wherein a scalable structure. A position where 6 exhales WITH the special 284 implementations.
[0068] The user processing mode 250 comprises a user a to 260, and is externally is an PP1 “and PP2 " and PP3 of one or more policy 262 suppliers. The mixed supplier (262. i.e filter is 282) arm a policy processing of the fire wall structure. Made of any processing to achieve the task. The invention is inheritance (legacy) IPSec policy service. The inheritance IPSec policy service is corresponding to the is IPSec protocol (e.g., a sealing safety protocol groove (ESP) and estimation and protocol groove (AH) is a network access realizes the definition the filter. And the special invention, the inheritance IPSec policy service is a a policy, wherein a policy pointed: aFlowing to the ESP protocol, receive are all for a an information generation of encrypted request. The mixed further stipulated: The u-disc for determining orders any for request an information packet (information of packet. i.e is not encrypted). Policy supplier from 262 to a source (e.g. volatile, or the data in nonvolatile memory, or is network administrator or system user DC input policy the graphical user interface (') inlet) and acquiring strategy. The user a host 260 into the policy And Signal the filter, S, 卩 defining the mixed according to the filter state, and engages the novel filter is filter collecting 282.
[0069] The user a host 260 is in a filter to sentence computer and conflict releasing function. In a mixed supplier 262 and 260 the new strategy for user mode a host, the user a host: determiningIs resistant to the novel policy the new filter whether a conflict with filter is 282 to filter. And there is conflict; and user a host 260 solve the conflict. The title is An for Managing Network Strategy Filter-based Method of the patented claim (agent label of: 221037) Describes a that is suitable the framework of the invention, a distinguishing and conflict resolution the invention method thereof.
[0070] The structure further filter comprising an API 266, wherein the filter an API 266) is user mode a engine 260 and a core is between 256 interface. Filter an API 266 provided with a user a host device 260, wherein arm for collecting filter is a new filter 282, and is used to inspect the mounting filter 282, in order to be detecting for filtering conflict. An API 290 to 262 and a filter an API 266 functionalities to the policy supplier.
[0071] User mode a host 260 further comprises a filter module 294. The filter module (294) and user mode 250 core a host 256 examples. The user mode a host 260 filter module 294 the opening examples the user a host 260 to serve is one or more user mode and 282 duplication a core and 256 are items. With gain the user mode layer and a substrate core mode layer are 282 method. Wherein the filter module 294 of the chip a host 256 the user mode examples, therefore, wherein understand: Here of the core for a firewall to any of filler description can also applied in the filter module 294. For example, increases the extra user mode layer or deletes the extra user mode layer from the system structure, and a found exhales, wherein providing filler for the user mode gain stages.
[0072] Password module WITH 288 to 260 and 296 the interface and password module in the user policy machine . The password module provides a mechanism, for determining methods to one safety settings the data packet for. A password module WITH 288) and signal to inform the password: moduleNeed to the SWITCH.
[0073] The reference diagram 4, now to the mounting filter collecting 282. The filter more than 310 in the fields; the fields a filter Id 312, 314 weighting and one or more movement 316, mixed context 317 and a group of filter 318 environment. Filter Id 312 is a mark of the filter. For example, filter Id 312 served and is a core a host 256 the matching filter information in connected to the user a host 260 and 258 exhales a tool. The embodiment of this invention, the filter is 310 to assigned network stack 254 one layer of each. One filtering filter Id 312 256 are used for tracking and methods of a core machine to one layer.
[0074] The weighted field 314) is sleeved with a filtering 310 priorities the values. Weighted field 314 the value of, the filter and is higher. The filter and device for confirming core a host 256 the matching filter a applied is connected with the information packet.
[0075] The embodiment of this invention, the first applied with the highest and (i.e. the biggest weighted value) filtering; and application and located at the lower filter, equal, till is provided with a terminal operation matching filter. The following are more of detail where the operation terminal. Once applied with a matching filter of the operation terminal, a core a host 256 apply the matching filter on the fixing. , Wherein the applying the terminal operation, is not adopted to the information generation of the movement of low and matching filter 316 stipulated. Method for selecting, a machine 256 identification single cover, filter circuit and a group of movements from the single matching filter. No matter the weighted value 314 how, a machine 256 of the apply the matching filter.
[0076] Wherein the filter state collecting 318 and information packets 310) matching with a filtering. The filter state 318) (320, 322 data and then Id: field Id 324. Variable length and number of the data of type 320 definition housing comprises 322. A known type of the back claim pre-definition (e.g., the bytes( and short” and long sides and “8” bytes and a series of character” and an ipv6 (4) IPv4 address” and an ipv6 (6) IPv6 address and a via a IPv4 address switch is a cover and for IPv6 address overlapped on the cover and address distance'). The data field 322 comprises a data of the type distribution. For example, and type of the IPv4 address shape, and data field 322 acceptable values is 00. 00. 00. 00 to 255. 255. 255. 32 of the voltage range is 255 to the denary notation at least one unit. All examples, type 320 specified data field 322 multiple values. A address distance' and via a IPv4 address switch is a cover and for IPv6 address switch upper cover of the types permits by two IP address values, wherein the two IP address the beginning end; the input. And the maximum flexible; the structure further moulded by user definition type. Method for selecting, extra type manual with the arm 13 system
structure.
[0077] Are made of Id: Field Id 332 are the connection layer and parameter from the connection layer are. The connection layer and definition parameter information packet parameter from the connection layer, namely 322 compares the data layer parameter information and packet context. The connection portion and network base layer. The parameter identification and source of the related parameter from the connection layer. The filter state 326 demonstrated with the special of. The type of IPv4, wherein pointed: aThe data 322) is 32 AND addresses. The Id is an IP shape, indicated: The digital 32 and IP (i.e network.) is parameter. The field Id is an Src IP Addr, wherein represents the IP layer parameter in the invention (especially supply IP address). The source IP address in the data of providing is an 123. 3. 2. l shape, pointed: aWith any information generation of the IP address of the filter state, wherein matched with the filter.
[0078] A stipulate multiple filter 318 environment. The stipulates plurality of claims 318:00; and when satisfies four filters state 318:00, the data packet filtering and 310 matching.
[0079] A filter 310 movements assigned 326 are moulded u-disc, or exhale. And the filter 310 movements 324 is or hinders; and information generation and filter matched 310, then; the licence or u-disc the operation 256 to with a core is a to the support layer. And the first 316 exhale; and core is a distribution 256 wherein producing classified request the exhalation module according assigns 258, wherein the classified request comprising the alarm information and packet mark layer of parameter, context and matching filter. The exhales module 258 pairs of the information packets end of the further programmed function (e.g., intrusion detecting). The exhale is in acting (is or hindering) connected to the core a host, wherein the conveyed the closing to the support layer. The exhale of the interface of the core a machine continuously is applied to the data packet, wherein it is provided to licence or u-disc the operation. The exhale hood and maintain information packet context; the information packet context 256 returned to via the core a machine similar to the support layer.
[0080] The movement of assigned is a terminal or the is. The default condition of; a grant " and hindering shape of assigned for operation terminal. The first terminal is made of a first colour; the once are externally in matching information generation, which can be used to said application matching filter the process of teeth and a.
[0081] Use policy context 317 (the except a policy the policy (e.g., safety or mixed Q0S) strategy. The mixed context is any a data structure. For example, the policy context is a digital 64) related processing of the policy context has been invention. The mixed context and/or the operation further possibly and space values.
[0082] Digital 5) demonstrated is provided with the data packet context the data structure 330 examples; the information packet context 254) is exhaled 258 module is a network base of each, and is transmitted the two-stage. The inputting or an output network information packet based on said and a labelled is 336-340 is one or more projects, the data packet context 330 associate with the network data packet. And each layer comprises: IdField Id 332 and value of communication 334.
[0083] Layer Id: The field Id 332 meanings equate the Id layer is a filter 310 and 318 state part and performs to provide: Field Id 324 meanings digital (4). The other testing layer, Id: Field Id322 is a field 334 the data identification the connection layer and parameter layer from the connection layer. The value field 334 comprises a special layer parameter.
[0084] And the special of, and 336 comprises a Id: Field Id 332 'NDIS: Src. MACAddr shape. . A NDIS unit of the link layer 274 ( network interface and a specification of digital (1) . The SrcMAC addr. Unit of the source address. Adhesive layer: Field Id 332 pointed: aA field 334 the data are once of the source address of the NDIS (a) layer is processed. The value field 334 comprises the leads source address, wherein the invention, the source address is according to any hexadecimal notation unit of). 08. 74. 4F. 22. The E5.
[0085] And the second example, 338 and has a NDIS: IF Two layers: Idfield Id 332. The once more identification is NDIS, wherein the box, configuration the interface of the parameter identification of the special NDIS parameter of IF The. The value field 334 comprises the leads value interface, the interface of the shell is 2 .
[0086] And the third example, 340 and has a: ANDst IP Addr conductive layers: Idfield Id 332. The shape of IP using same AND protocol configuration the network layer; the conductive Dst IP Addr unit of the volume IP address of the IP layer parameter. The value field 334 comprises an 123. 3. 2. shape of the leads target IP address.
[0087] Fabricating the same and a structure, system and function interface for displaying method for now pays warning is here to the pedestal a structure according to method and device . The function interface is an application program interface to receive end of. The APIs and digital 7) is an API for fixing illustration 280, exhale to API 284, the filter WITH a digital to 6 and 266 password module WITH 288.
[0088] An API 280 upgrading network stack 254 in each layer and core in a machine 256 between each of data. A pores, an API 280 comprises an classifying the law 350, an increase layer of law 352 and a deletion layer ( 354) method.
[0089] The request layer is a classifying the law 350, transmitting the data packet and information packet context for layer, parameter to the support layer claims a to the core a host 256. The core a host 256 (1) converts the support layer the parameters and (2) information packet context projects each filter 310 of claims 318 and with of assigned to the support layer, said to distinguish matching filter. The following of the conductive classifying of displaying the embodiment of method. A understand: A those methods are described receiving or a return data value. To a known programmable technology, the method may use directional data of the indication, which is not the leads data value.
[0090] NTSTATUS
[0091] WFPClassify
[0092] (
[0093] IN ULONG, Layerld
[0094] IN WFP_INCOMING_VALUES*, plnFixedValues
[0095] IN WFP_INCOMING_CONTEXT_VALUE*, plnContext
[0096] PVOID, pPacket
[0097] OUT WFP-ACTION-TYPE*, pActionType
[0098] OUT UINT6 is pOutContext
[0099] );
[0100] , The following content of the parameter of with the enumerated.
[0101] The Layerld identification output end of the classified request the network layer, wherein the support layer. A diagram 3, wherein the Id for identifying data current layer (268), transmission layer (270), network layer 272 (274 layer. A are joined the system, while the other (a user mode layer) efficiency. For example, a engages the SMB is 276; and SMB layer with wherein thereof is mark. A fire wall structure of the invention is further network base (254 implementations protocol of layer of. For example, wherein the base is provided with two transmission layer 270-- the first transmission layer is the protocol TCP, the second transmission layer is the UDP protocol.
[0102] plnFixedValues comprises a first support layer processing parameter the subsets. Compares together with the information packet context projects with the filter that the plnFixedValues, determining of the information packet a matched with the filter. The following form A portion of the level default parameter of the plnFixedValues of each layer comprises. A understand: The default layer is a examples, it does not work the role of limiting, any parameter of wherein the can be can use in the plnFixedValues comprising a.
[0103] form A
[0104]
[0105]
[0106]
[0107]
[0108]
[0109]
[0110]The Singapore link layer transmission layer network application layer 黒 bail i of THE woven the source address and volume address; The source of IP address and volume IP address; Protocol; theAddress local power supply ports number and destination port; theDeciphered application layer protocol application-aware
[0111] pInContext a contextual data structure according to the support layer claims a 330 digital (5). The core a host 256 is the information packet context and communication the parameters to distinguish the matching information packet.
[0112] pPacket comprises a data packet according to the support layer claims a. The pPacket 256) are used to distinguish of a core and matching filter. And teeth on, a core a host 256 adopts the pInFixedValues and pInContext comprises a matching filter. The pPacket is in the shape of classifying, France, a set of a core is 256 and may send a to is externally 316 for moving the matching filter one or more exhales 258 module.
[0113] pActionType a returned to the level request operation 316. The movement of the loop is 316 to hinders, a grant in the matching filter a or it is provided, or a exhalation module of the matching filter operating.
[0114] pOutContext comprising a policy context data. And the teeth; and policy context to impel with IPSec and QOS and any other non-firewall filter-based the policy and associated network strategy.
[0115]The constant layer ( 352) and deletion layer ( 354) is method to enhancing layer and from the fire wall structure is within layer.
The following is a cylindrical layer ( 352) for displaying of.
[0116] NTSTATUS
[0117] AddExtensionLayer (PUL0NG OUT pLayerld);
[0118] , The following content of the parameter of with the enumerated.
[0119] of layer is pLayerld returned increase to the i.e. executing the conductive layer is composed of layer of law) is the mark layer value.
[0120] The following is a deletion layer ( 406) for displaying of.
[0121] NTSTATUS
[0122] RemoveExtensionLayer hunger ONG Layerld);
[0123] , The following content of the parameter of with the enumerated.
[0124] Layerld identification solution for layer, namely executing the conductive layer deletion with a layer of method.
[0125] Exhales API 284 upgrading core a engine 256 and 258 exhaling between the data exchanging. 280 Is the same as an API, a exhalation an API 284) has a classifying the method. The exhalation API " 284 " classifying the law 356 is similar to a layer of API280 classifying of the law 350, comprises matching filter is provided with a clamping the socket. The invention is used end of the exhale classifying of the law 356 to display.
[0126] typede pre-TSTATUS (*WFP_CALLOUT_CLASSIFY_FN)
[0127] (
[0128] IN const WFP_INC0MING_VALUES*, fixedValues
[0129] IN WFP_INC0MING_C0NTEXT_VALUE*, wfpContext
[0130] IN VOID*, packet
[0131] IN WFP-FILTER*, matchedFilter
[0132] OUT WFP-ACTION-TYPE* action;
[0133] OUT UINT64* outContext
[0134] );
[0135] , The following content of the parameter of with the enumerated.
[0136] fixedValues from the request/layer is the parameter. The fixedValues are the same data of the support layer of claims pInFixedValues providing data, the pInFixedValues data and an API " 280 " classifying 350 method for method and substrate-processing.
[0137] wfpContext a context data structure 330 digital (5). The data part of the data according to the support layer from the plnContext transmitting; the plnContext and an API " 280 " classifying 350 method for method and substrate-processing.
[0138] packet comprises a data packet according to the support layer claims a. The data part of the data according to the support layer from the pPackett transmitting; the pPacket and an API " 280 " classifying 350 method for method and substrate-processing.
[0139] the matchedFilter identification request the filtering of exhalation. Usually; the matching filter classifying of the law 356 matching filter 310 and 312 Id method for identifying of which is exhaled 284 API.
[0140] pActionType comprises a exhaling 258 returned to the core a chassis (256 movements. And the pActionType is or hinders, loop to the support layer, and a pActionType of the conductive layer is API280 to. The exhale is further connected to a casing shaft, the casing the operation to interface for a firewall core is 256 casing the matching filter is applied to the information packet.
[0141] pOutContext comprising a policy context data (e.g., a or mixed QOS) data.
[0142] Exhales API 408 further comprises an informing " 358 method. When the filter 310) are joined for collecting filter (282 to exhale 258 module for identifying wherein movement of 316), and a informing a method of claims 358 to inform to exhale. For informing the exhale to provide for opportunistic with any claim the operation (e.g., wherein a core the 256 end of the movement, wherein methods or hardware distribution of exhaling of an eight-line buffer 258) for. The following is an informing a method displaying 358 to.
[0143] typede pre-TSTATUS (*WFP_CALL0UT_N0TIFY_FN)
[0144] (
[0145] IN WFP_N0TIFY_ENUM, notify
[0146] IN WFP-FILTER* filter
[0147]);
[0148] , The following content of the parameter of with the enumerated.
[0149] notify comprising a conductor; the conductor pointed out of the sound or a deleting the filter. For example, 1 pointed value of the is increasing the filter, 2 pointed values of according deleting of the filter.
[0150] the identification filter is a single-pole or the filter of deletion. A providing as filter 310 the part comprises filter Id 312, capable of the socket.
[0151] The exhale API further comprises an exhales registration a method and 360 ' exhales to relieve a register 362 method, increase which is within exhaling module. The exhales registering method of displaying 360 to form is as follows:
[0152] NTSTATUS WfpRegisterCallout
[0153] (17)
[0154] IN const GUID*, calloutld
[0155] IN const WFP_CALL0UT*, callout
[0156] IN const SECURITY-DESCRIPTOR* sd
[0157] );
[0158] , The following content of the parameter of with the enumerated.
[0159] callout Id providing and register exhales without mark assembly.
[0160] callout providing any exhales a specific information (e.g. driver, service server and device, server and aim at said to exhale classified and informing function indication).
[0161] sd providing and exhalation safety descrptor. Which the safety descrptor a to process of reading and delete the exhale.
[0162]The exhales to relieve registration with method displaying 362 to form is as follows:
[0163] NTSTATUS WfpDeregisterCallout
[0164] (
[0165] IN const GUID* calloutld
[0166] );
[0167] , The following content of the parameter of with the enumerated.
[0168] callout Id (is within a exhalation without Id.
[0169] Filter an API 266 upgrade mode and a engine 260 core and a mode is between 256 and an. A cooling filter, an API 266 comprises a filter is a method, 364 'to delete filter ( 366 method and enumerates layer ( 368) method. And teeth on, a filter an API 266 the method may be comprises a managing API 290, in order to 262 claims a filler is a policy supplier.
[0170] Is a cylindrical filter are " 364 " and deletes filter ( 366 method, wherein receive the new filter to arm is filter collecting 282, 282 and a delete the extant filter is a filter collecting. The following is a filter is a method displaying 364 to.
[0171] NTSTATUS
[0172] AddFilterToLayer
[0173] (
[0174] UL0NG Layer I, d
[0175] WFP-FILTER* pFilter
[0176] );
[0177] , The following content of the parameter of with the enumerated.
[0178] A Layerld of assigned to the level of the filter.
[0179] pFilter of the mounting the filter collecting 282 filters 310.
[0180] The following is an deletes filter ( 366 method of display.
[0181] NTSTATUS
[0182] DeleteFilterFromLayer
[0183] (
[0184] UL0NG Layer I, d
[0185] UL0NG Filterld
[0186] );
[0187] , The following content of the parameter of with the enumerated.
[0188] The Layerld identification assigns of layer of the filter is a.
[0189] pFilter is from the mounting filter is deleted filter.
[0190]The enumerates layer of law 368 to provide with a user a host 260 a mechanism, which is sleeved with four filters for sleeve matched standard. Thus, capable of the filter WITH an identification with a filtering of conflict, sentences computer and conflict solution is a filter. The following is an enumerates layer ( 368) method of display.
[0191] IndexStartE disc and
[0192] (
[0193] PWFP_ENUM_TEMPLATE pE disc, mTemplate
[0194] OUT PUL0NG, pMatchCount
[0195] OUT PWFP_ENUM_HANDLE pE disc mHandle
[0196] )
[0197] , The following content of the parameter of with the enumerated.
[0198] pE disc mTemplate comprising the filters' a framework of data of the parts of substrates are connected to. For example, comprising a parameter, the filter flowing that is a filter is of substrates to circuit, and matched with the parameter.
[0199] pMatchCount comprising the stipulation-based pEn Template matching filter device.
[0200] pE disc mHanlde comprises a between the references for filtering and.
[0201] Password module WITH 288 to 282 and 260 the interface and user a machine of the user mode password module layer. Password module WITH 288) of the SWITCH IPSec gain a method, 370 'ineffective informing a method, 372 'the IPSec SWITCH gain to achieve the law 374, the password module registration the law 376, the password module relieve registration with method, 378 'IPSec connected to obtain the SPI 380 method, an increase connected with the SWITCH 382 method, an increase output SWITCH of law 384, the SWITCH connected to a failures 386 method and password switch module ( 388) method.
[0202] Using the password module WITH present invention the safety protocol (e.g., is defined by IPSec, wherein a computer and a response is) using. IPSec comprising such as estimation head (AH) and packaging safety protocol (ESP) and protocol. The ESP (protocol is RFC (2406) performs to show in the IETF request illustration') is a estimation and encryption protocol; the protocol is password mechanism for providing integrity, the connection estimation and data confidentiality. The AH protocol is mainly composed IETF RFC 2402) is shown) of the appraises protocol; the protocol for the information generation and a hash to a to confirm the information data packet integrity and sender's reliability.
[0203] The IKE protocol (2409) is performs to show in IETF RFC) claims a starting of the computer and responds method for computer, a discuss and ESP protocol is the AH a safety setting of protocol. The anti-theft settings according discussed is a called and a secondary safety of the (SA) data structure. The SWITCH of two or ESP AH is used to protect the IP data packet the contents parameters (e.g. appraises, the service life of algorithm, encryption algorithm, keys and key. SWITCH is configured ESP and AH circuit is arranged; therefore, the front edge and response computer using the ESP or a AH protocol, executing the IKE discussion. A called and SWITCH is a safety index parameter of the (SPI) and a to methods.
[0204] Each a computer the starting computer and response computer comprises a IPSec driver; the IPSec driver according to any IPSec strategy for determining the starting computer is a data and response computer is a requirement encryption or the other estimation. The IPSec policy is one group of filtering how, a defining the network device by IPSec, comprising a filter detailed list and estimation method for information. The embodiment of this invention, the two IPSec policy a filter with the mounting centralism filter is a.
[0205] The user a chassis (260) via client representative transfer) of the SWITCH IPSec obtaining the law 370, receive the driver gain or the external edge request transmitting the password module. The password module is layer to the transfer, and asynchronous executing the discussion. The once password module and completed the discussion; the password module layer of the IPSec SWITCH gain completes a method of transfer 374, inform to the user a: machineThe discussion completes. The following is made of the IPSec SWITCH gain of the displaying method and.
(0206: (0207: (0208: (0209:
(0210: (02':
(0212: (0213: (0214: (0215: (0216: (0217:
ipsecContext, acquire, inbo disc dSAspitypedef WIN32-ERR (*PROCESS_IPSEC_SA_ACQUIREO) IN FWP_IPSEC_ACQUIRE_CONTEXTO IN const FWP_IPSEC_SA_ACQUIREO* IN FWP-IPSEC-SPI);
, The following content of the parameter of with the enumerated. ipsecContext the gain with a handle electric connecting SWITCH. acquire a acting according to a known protocol (e.g. IKE,) discussed the SWITCH required information. a inboundSAspi is provided with an SPI SWITCH.
A transfer ineffective informing the law 372, so that the number of the ineffective informing transmitting increase the SWITCH connected with password module. The following of the conductive ineffective informing of the displaying method and.
[0218] typedef VOID
[0219] (*PROCESS_IPSEC_SA_EXPIREO)
[0220] (
[0221] IN const FWP_IPSEC_SA_EXPIRE_NOTIFYO*expireNotify
[0222] );
[0223] , The following content of the parameter of with the enumerated.
[0224] square Sodium ireNotify comprises are the expired SWITCH information. For example, the output SWITCH condition, providing the SPI .
[0225] The password module is a IPSec the SWITCH gain to achieve " 374 method, so the back could which is finished discussed and increasing the switch SA, or by which a bumped into two, closing contextual of the user a machine. After connecting with the method, the password module layer is not used side of the ipsecContext of any other API method. The following is made of the IPSec SWITCH gain completes of the displaying method and.
[0226] WIN32_ERRFwpIPSecSAAcquireCompleteO
[0227]
[0228]
[0229]
[0230]
[0231]
[0232]
[0233]
[0234]
[0235]IN FWPM_ENGINE_HANDLEIN FWP_IPSEC_ACQUIRE_CONTEXTOIN const FWP IPSEC NEGOTIATION STATUSO*engineHandle, ipsecContext, state);
, The following content of the parameter of with the enumerated. engineHandle 260 providing a handle for user a machine.
ipsecContext is a contextual using the via a IPSec gain via a method and a host is transmitted.
[0236] identity providing the SWITCH discussion the other and details. And the external terminal with the gain via FwpKeyingModulelnitiateO; and user a host 260 connected to the state.
[0237] Are transferred the password module registration of the password module and a method 376, wherein a to a user a machine registrations 260, wherein a power function. The following of the password a registration module via a display method and.
[0238] WIN32_ERRFwpKeyingModuleRegisterO
[0239]
[0240]
[0241]
[0242]
[0243]
[0244]
[0245]
[0246]
[0247]
[0248]IN FWPM_ENGINE_HANDLE IN const GUID received const FWP KEYING MODULE INFOO*engineHandle, keyingModuleID, Keymodlnfo, the following content of the parameter of with the enumerated. engineHandle 260 providing the handle for user a machine. keyingModuleID and password module is OF.
a keymodlnfo and password module and registering message (e.g., the IPSec SWITCH gain” and IPSec SWITCH for processing expires the functional power).
[0249] Calling is a password module relieve registration of the password module the law 378, wherein a to 260 hardware from the user a register and password module. The following of the conductive password module hardware registration of the displaying method and.
[0250] WIN32_ERRFwpKeyingModuleDeregisterO
[0251]
[0252]
[0253]
[0254]
[0255]
[0256]
[0257]
[0258]
[0259] The SPIIN FWPM_ENGINE_HANDLE IN const GUID receiving engineHandle, keyingModuleID, wherein the content of the parameter of with the enumerated. engineHandle to a user machine 260 the head. keyingModuleID of the password module layer is OF.
Is bottom of IPSec connected to obtain SPI of the password module and a method, 380 to obtain the novel an SWITCH; and when the password module and executing the network device of response, usually made of IPSec an SPI obtaining " 380 method. The following of the conductive IPSec an SPI obtaining of the displaying method and.
[0260] WIN32-ERRFwpIPSecSAInboundGetSpiO
[0261]
[0262]
[0263]
[0264]
[0265]
[0266]
[0267]
[0268]IN FWPM_ENGINE_HANDLE IN const FWP_IPSEC_TRAFFIC (IN (const FWP_IPSEC_UDP_ENCAPO* OUT FWP IPSEC SPI*engineHandle, ipsecTrafficDescription, udpEnc is Two, inbo disc dSpi, wherein the content of the parameter of with the enumerated.
[0269] engineHandle to a user machine 260 the head.
[0270] ipsecTrafficDescription is used to found connected with immature 5 tuple explanations of SWITCH. The 5 tuples comprising a supply IP address and volume IP address, supply ports and volume port, and transmission layer protocol type.
[0271] udpEnc is Accommodator is used to found the immature of the SWITCH UDP data package. The UDP sealing acting according to secure protocol the UDP information packet a known method for performs information generation of a formatting not to encrypt.
[0272] inboudSpi of the SWITCH connected with the SPI .
[0273] Is bottom of the password module is a cylindrical connected with the SWITCH 382 method, increase an SWITCH (. i.e, updating immature of the SWITCH. The user a host 260) and SPI the SWITCH to receive the transfer to map wherein internal behaviour, and SWITCH is ioctl to the IPSec driver. The following of the groove is an SWITCH via a display method and.
[0274] WIN32-ERR
[0275] FwpIPSecSAInbo disc dAddO
[0276] (
[0277] IN FWPM_ENGINE_HANDLE, engineHandle
[0278] IN const FWP_IPSEC_SA_STRUCTO* inboundSA
[0279] );
[0280] , The following content of the parameter of with the enumerated.
[0281] engineHandle to the handle of the user a machine.
[0282] inboundSA comprising the inputting SWITCH.
[0283] Is bottom of the password module is an output SWITCH ( 384), method for increasing output SWITCH. The user a host is an SPI parameter method of map the transfer wherein internal behaviour, and SWITCH is ioctl to the IPSec driver.
The following is an increasing output SWITCH via a display method and.
[0284] WIN32-ERR
[0285] FwpIPSecSAOutboundAddO
[0286] (
[0287] IN FWPM-ENGINE-HANDLE, engineHandle
[0288] IN FWP_IPSEC_SPI, inboundSpi
[0289] IN const FWP_IPSEC_SA_STRUCTO*outboundSA
[0290] );
[0291] , The following content of the parameter of with the enumerated.
[0292] engineHandle to a user machine 260 the head.
[0293] onboundSpi of the SWITCH connected with the SPI, wherein an SWITCH and outputting the SWITCH.
[0294] outboundSA comprising the output SWITCH.
[0295] Are transferred a SWITCH connected to a failures in method the password module 386, switching of the inputting SWITCH according formerly capacity. The following is fixedly connected with the SWITCH expires the law 386 to display.
[0296] WIN32_ERR
[0297] FwpIPSecSAInbo disc dExpireO
[0298] (
[0299] IN FWPM_ENGINE_HANDLE, engineHandle
[0300] IN const FWP_IPSEC_SA_EXPIRE0* failures
[0301] );
[0302] , The following content of the parameter of with the enumerated.
[0303] engineHandle to a user machine 260 the head.
[0304] square Sodium ire with the SWITCH according data of substrates to failures.
[0305] (For example RAS and Winsock API and disclosure) are called the password module is a method of known external application 388, set according to the application of the substrate-processing wherein network flow switch, the password module layer and a SWITCH. The user a host 260 for asynchronous the RPC to transfer, which are, obtaining the SPI from IPSec driver/, and transmitting the gain and a password module. The once password module layer is FwpIPSecSAAcquireCompleteO; the user a machine completes with the asynchronous RPC of the discussion and. The following of the password the switch module via a display method and.
[0306] WIN32_ERR
[0307] FwpKeyingModulelnitiateO
[0308] (
[0309] IN FWPM_ENGINE_HANDLE, engineHandle
[0310] IN const FWP_IPSEC_SA_ACQUIREO*, acquire
[0311] IN HA chaotic STRUCTURE, waitEvent
[0312] OUT FWP IPSEC_NEG0TIATI0N_STATUS0* negotiationStatus
[0313] );
[0314] , The following content of the parameter of with the enumerated.
[0315] engineHandle to a user machine 260 the head.
[0316] acquire comprising discussing SWITCH key data.
[0317] waitEvent, which is discussion is composed trigger's event handle. And the client (. i.e, calls external application) is provided with a interest to wait for of the discussion completes, and it can the parameter is provided NULL. The housing, which is representative transmitting at least the event RPC, the once asynchronous RPC transfer completes, request of which are the event.
[0318] negotiationStatus comprising the discussion result. A waitEvent chaotic is L-SHAPED, and negotiationStatus is L-SHAPED chaotic. Otherwise, negotiationStatus of motor, L1 is the waitEvent of mobile phone.
[0319] Digital 8) demonstrated automatically according to the invention, and each method for network stack 254) which are used. Method for digital 8 demonstrated and is 282 to 294 and a user is 260 efforts connected with a filtering module is one or more user mode layer.
[0320] Each layer of terminal with multiple functions, comprising: Processing network information, packetA classify the request to distribution a core is 256; And managing, the data packet context. The embodiment of this invention, executing the functions of shim 400, 402, 404 and 406 in each layer of each of the network bars are 254. Method for selecting; the filler is placed in the independent layer by, it has no need the shims.
[0321] The network base (254) comprises a data current layer (268), transmission layer, 270 and 272 layers and link layer 274. Stemming demonstrating from the volume of the invention, the link layer is 274 to carry part and NDIS drive, network layer (272) is filled end and IP layer, a transmission layer (270) is filled with and TCP layer, a data current layer (268) is filled with as HTTP layer. A understand: And a insulating layer according to any protocol. For example, the transmission layer is matched with the User Datagram Protocol (') UDP. The application layer and a file transmission protocol groove (FTP), a remote process of call (RPC), a simple mail transmission protocol groove (SMTP), a server main board (') SMB equal. And teeth on, a arm extra layer the structure, and a delete layer. For example, a reference image 6 ' layer is method according to the conductive method and a deletion layer of method, and is a deletion.
[0322] Which is labelled is 408 (a) and (d) network information wrapped in order to pass through the base 254 and each of these are processed, comprising demonstrated the network data packet. And the data packet 408 (a) and (d) is an information generation, and passes through the network stack from top to bottom. And the data packet 408 (a) and (d) is the output information generation, and passes through the network stack from top to bottom. The same processing well-known, and columns (demonstrated of the invention the volume, and brief description to a.
[0323] A in the network equipment (. e.g, the application of web browser) and a switch and is positioned at the network device webpage the support on content of; and application sending the request the data current 268 layer. The invention, the data stream 264 shaft according to the HTTP protocol to receive to the request filled with a formatting, and transmitting the request to information packet (408) is in transmission layer. Transmission layer (270) receiving information packet (408) and a. The transmission layer (270) in of the protocol TCP) is provided with the data one or more data packets, providing TCP part of each information packet. The TCP head comprising such as the supply ports and volume port and protocol type (i.e. TCP, a number, symbol and inspection and) and information. Adhesive; the transmission layer is a labelled is 408 (b) and data packet transmitting to the network layer.
[0324] The network layer executing the IP protocol, and mounted in the data AND the head, AND the head of the source IP address and volume IP address, symbol and inspection and known information. The IP head is pointed of the partitions of the information packet. The IP information packet's and super-junction and is used to transmit the data packet an internet of maximum transmission unit via a (MTU); size of the information packet partitions. for example, Ethernet technology stipulated: The MTU 1500) of bytes. And the IP data packet length super-junction the MTU, is divided into comprising two or more IP data packets of each IP data packet having wherein for IP head, ranges from the MTU, solution is equal to or a short terminal.
[0325] The embodiment of this invention, the network layer is divided into first and second. The first (of called and a fragment is') to process IP data packet fragment. For example, wherein the front end outputting IP data packet groove, and is a an IP data packet to assemble the single IP data packet, the second (of called and a full assembling layer') for processing alarm information AND packet. The network layer processing and split, the data packet 408 (c) is transmitted to the link 274 layer. The link layer (274) is MAC of providing the source address and other target MAC addresses and information method, wherein the substrate is set (packetizes) to the data. , Then transmits the information packet to network interface, a, the information comprises a physical is transmitted to a network in.
[0326] Processing an information packet with a switching path. Information packet 408 (d) is received from the NIC, and is transmitted to the link 274 layer. A assorted, except the RECEIVED head, and 408 (c) for transmitting the data packet to the network layer, a assembling, and IP data packet fragments; Respectively, AND the head. Adhesive; the network layer 408 (b) transmitting packet information to the transmission layer, a, except the TCP; and, And is transmitted the data stream multiple TCP information packets, and at the data stream. Finally, 408 (a) for transferring data stream to the data current layer (268), a, the data of the (in the case of the HTTP protocol) and decryption by protocol.
[0327] Of each outputting data packet; each layer of the network base and data packet context 410 (a) and (c). Of each information packet; each layer of the network base and data packet context 412 (a) and (c). When the information packet passes through the network strata times; the information packet context follows a. The data packet context is transmitted to exhale 258, and a shout to use of the digital (3).
[0328] Each layer of the processing data packets, updating information the packet context. Each layer switch wherein the parameter information packet context, wherein the providing information is then each or processing. A pores; the link layer 274 add the source address and volume of MAC address and the inputting information packet interface to context 412 (a) demonstrated. Of context 272) is received from a network layer, a network layer (272) add the source IP address and volume of IP address to context 412 (b) demonstrated. The transmission layer (266) and context, and linkage port sheets according to context 412 (a) demonstrated.
[0329] A for outputting data packet association's context 410 (a) and (c), wherein a processing same. The data current layer (268) such arm and URL address for and information to context 410 (a) from the data packet payload demonstrated of the transmission layer is 270 to the power supply of port and a destination port to context 410 (b) demonstrated of the network layer with supply IP address and volume of IP address to context 410 (c) demonstrated.
[0330] A understand: Each layer of arm (any context information of layer. Usually, comprising a layer is designed to perform to process (. i.e, increases information packet or the information packet or from information packet disposed) to information.
[0331] Each layer of a contextual of the information generation and corresponding, a distinguishing the parameters and transmitting is labelled is 414 classifications request of the operable as the support layer. The classifying request (414) comprises a parameter layer 416, which is formerly the data packet context of layer and 418 and alarm information 420 packet. By the number of the classified request the display method of edges of the level API280 method to the shape of classifying 350 method digital (7).
[0332] The response request in each classifying of the core for a firewall 256 to 416 and information packet context 418) are assigned layer parameter to the support layer and of the filter 318 digital (4) and comparison. The fire core is 256 to is labelled is responses 422 )with a a rotating weighted 314 matching filter 310 movements 424) to transmit the support layer. The core a host 256) is connected to the policy 426 context. Core and a host 256 is not respectively matching filter; and core a machine informs the request layers: Zero-halogen type matching filter. The fire core is 256 to casing are the matching filter, distributed inside end (i.e. to licence or u-disc) till the matching filter, or is examining of assigned to four filters of the support layer (one filter, no matter a first) and a. Method for selecting, a core a host 256) are all distribution, and returning to the movements the single response to the support layer.
[0333] A generally demonstrates, a recognition of parameter layer and a network stack 254) executions a part of the key processing tool. An extra requirement packet information analyzing, wherein the effect on the performance of a to is one-fifth. Additionally, wherein the layers of improving the process of information packet context a pluggable cooperation, therefore, the fire machine 256) is in usually of uses the information packet parameters of each information packet parameter end of the filter state the images. For example, network layer (268) from the source address and link layer (274) is a volume of MAC address and an information packet context. Wherein the network layer (272) sends out with the network parameter layer (e.g., supply IP address and volume IP address and information packet context) is classifying request, therefore, the several the RECEIVED addresses in usually available, a core a host 256 can also and filtering with the network and IP 272 addresses and MAC addresses.
[0334] The reference diagram 9, wherein now coated with a structure of this invention is a display device of exhalation 258 module. The exhales 258 module comprises a HTTP context to exhale 430, intrusion at exhale to 436, IPSec to 438 exhale and recording 440 exhales.
[0335] The HTTP context exhales maintaining 430 or acceptable (and URL address cache for selecting) and it 432. The HTTP context 430 exhales regular accesses with the server of the public network connection 434, wherein the public network and URL address and classifies of them acceptable shape or “it are”. When the fire the 256 end of the HTTP context exhales, wherein exhale search to the information generation, and decryption to the URL address (a) assorted, and: determiningTo the cache information 432, wherein there is acceptable. Wires; and URL address is acceptable; and HTTP exhales a return to licence, and operation 316, theAnd the URL 256 address it well and core mode a host, which is a u-disc,The 280 to act 316) connected via an API to the support layer. The HTTP context exhales the connecting of the process of parents control function of the work role.
[0336] The intrusion detection exhales 436) is available algorithms and technologies search the information, packet to distinguish viruses or suspicious information indicating packet. A detecting to suspicious information generation, which is u-disc to the operation 316. Suspicious information of packet's is made of a information generation, a marks are in IP head and TCP which are arranged as value 1. The data packet is suspicious, which is configured to which is never motor, and a point of the signature attack. Method for selecting, intrusion the detection exhales 436 the information packet context, so that the number of the sign information packet the suspicious medium, wherein a postponed and hinders the network stack then each layer the decisions of the data packet.
[0337] IPSec 438 exhales is designed to determine whether once type the pneumoelectric safety protocol in the information packet. IPSec 438 exhales end of the communication with IPSec processing, and according to any IPSec policy determining whether the information packet once is expected experiences IPSec processing. , And then IPSec exhales 438 to confirm according to the data packet: contextWherein the information packet in fact experiences the IPSec to process. And the information packet are once expected method to process according to IPSec, which is not set (e.g., an information of determining orders), which is u-disc to the operation. And the information packet with experienced IPSec processing; and IPSec exhales the: determiningBy the pneumoelectric SWITCH.
[0338] The injection is made exhales 440 to perform balanced and information packet (e.g., and alarm information generation of later) is information. For example, wherein a later using (the network traffic beyond expectation is not possibly via a network are all network traffic, wherein it is receiving to u-disc or) is provided with a tracking system and diagnosing and program of malicious attack.
[0339] Digital 10) demonstrated by end of this invention processing of the integral a function 450. The pedal 452, wherein the support layer output end of the classifying information of packet request, identifying devices of the request the data packet parameter. The pedal 454, in the classified request the information packet parameters with a filtering for matching. , And according to the matching filter according to the steps as 456, wherein fixing the output the information packet. A decision the is composed of the information packet shape; and output information generation, the processing ended, wherein it is the device further information processing packet. A decision the is an without the output information packet shape; and support layer has the protocol whence of the support layer quarter operating and data packet, such of the several steps as 458 revises the information packet context data structure. A plurality of extra layer; and processing ended similar. Otherwise; and steps as 462, wherein handling packet information and information packet context transmitted to a a. The processing continuously, till connected with the information generation, or passes through the till the information packet.
[0340] Digital 11) demonstrated is labelled is 500 to method, device and is used for handling packet information, which is emitted out of the support layer classifying to request and maintain the data packet context. The method according here claims 400, 402, 404 and 406 carried out from the front network layers shim module. Method for selecting, method for 500 from said from the network storehouse's the wholes in the process end part, and no need an independent shim. Method of 500) are composed of one or more user mode layer.
[0341] The pedal 502, wherein the support layer formerly a receiving alarm information packet 408 and information packet context of communication 412. The information output packet's condition; the preceding is higher than the support layer of the base network. A an information packet's condition; the preceding is lower than the support layer of the base network.
[0342] The pedal 504, wherein the support layer comprises the parameter. The parameters through intervals the parameters from a an information generation of the support layer or arm for outputting data packet to receive to the processing parameter. The parameters of a TCP/IP from the information in the data packet disposed (e.g., the local address type). Is formed A where the default parameters layer, an API " 280 " classifying and method for 350 pInFixValues comprising the level default parameter.
[0343] The pedal 506, wherein the support layer sending the classified request the core a host 256. Reference layer WITH " 280 " classifying 350 method described that is to send of the classified request the display method.
[0344] The response request in the classifying loop according to the operation to the support layer. The request layer automatically according to the operation returned by by the data packet 508. And the core a host is a u-disc, and movement, then; the support layer by the information packet. Core and a host 256 connected to the operation, wherein the is not discovered the matching filter, then; the support layer is a voltage the information packet. The support layer contains with an discovered in matching filter condition wave information generation of the socket capable and system-wide substrate or a base and.
[0345] A returned movement permits, and further time information processing packet. The pedal 510, wherein the support layer revises the information packet context comprising a layer information, usually once fixed on the classified request the parameters comprising same type information. , Wherein not only form A (a) between a parameter, moreover is externally engages the information packet context of each layer default information. The information packet context is working the data structure (e.g., is 5 shape of data structure of description).
[0346] The pedal 512, wherein the support base layer and protocol for whence of layer and data packet. The same processing well-known, here no need for detailed description. Protocol for displaying of a HTTP, FTP, SMTP, and application layer RPC, and transmission layer TCP and UDP and the network and IP layer, and the link layer NDIS.
[0347] The pedal 514, wherein the support layer (automatically according to the protocol to perform process) and data packet context to transmit the information packet together with the use lower. And the information packet is an information generation, which is a high layer of the base network. And the information generation of the output information generation, which is a low level of the base network. Processing 500 in each layer of the base network to of the operating, and continuously, passes through the network stack till the information packet, or till one of the information diaper the network bars by the.
[0348] The reference diagram 12, now specifically to a display method 520, wherein the display method 520 256 are used to distinguish a firewall core and matching filter and returning the closing to the support layer. And teeth, and capable of 294 of the chip is a 256 functionalities the filter module in the user a an executing.
[0349] The pedal 522, wherein a core is 256 mm (e.g). a classifying the law 350) via API280 layer, and information generation and then parameter information and packet context from the support layer.
[0350] The pedal 524, wherein a core is respectively one or more matching filter. The embodiment of this invention, distributed filter is a specific request layer. A assigns the filter to the support layer; the information packet parameters 318) matched with the filter tubular, which a core is 256 attempt the filter identification is matched with the shape (5). And teeth, wherein the information packet parameter comprises a parameter and information packet context from the support layer. The distinguishing the matching filter, the core a machine automatically according to the field weighted each matching filter 314 at the filter.
[0351] The pedal 526, the core a host 256 applications further provided with a rotating weighted 314 filters for of application. Electrical talk-back core, a machine 256 are the movement of the filter 316 stipulated. And the first methods 316 to exhale component and 258; and core a host 256 532 are via to the invention exhales WITH 284 to the power to exhale. The reference the exhale the WITH a classifying the law 356 digital (6) are described that is filled with the display method of exhalation. The exhale is in acting is connected to the core a host 256.
[0352] And the movement without exhale, or by the operating and exhale, wherein a core is a converts the matching filter or to the exhale with movement of portion is connected to the support layer according to the invention 536 cooling. Method for selecting, a core a host 256 wait is connected to the operation, till with the wire matching filter.
[0353] The pedal 534, the core a host 256 determining whether with any extra matching filter. A not exist; and processing terminates. And there is extra matching filter; and processing loop comprises the steps 526, there, application and A Ju the second filter. The processing continuously, till applying the matching filter. And selecting, once of the information packet identification terminal operation, the processing terminates. A not of the information packet identification matching filter; and core a machine informs the request layers: Once which is discover the matching filter. Adhesive; the support layer by how handle to the information packet (. i.e, comprising is or hinders the information packet).
[0354] Digital 13) demonstrated automatically according to the invention claims a method using 560, for preventing from request the malicious attack of an information generation, relative to opening end of the communication with the credible user, wherein the starting communication of unknown network address.
[0355] The pedal 562, executing the invention the response computer and a firewall for the support an information packet. The invention claims 564, 560 processing to determine whether the inputting information generation appraises the support. For example, a estimation request according possibly is fixed to the IKE protocol. And the inputting information packet is a estimation request, the starting computer according and response computer attempt estimation to the invention 568 cooling. Used to appraise to the starting a method of computer according to approve the digital certificates. The digital certificates of the upper-stage authentication (CA) release, comprising such as user server, a series, the closing tracking and public key (are used for information and digital signature encryption transcription) and CA digital signature and information, so for is originating capable of confirm: The certificate of realistic.
[0356] Adhesive; the step 568, wherein the processing determining whether the estimation processing succeeds. And the estimation without (succeed. i.e, the response computer is to appraise of the computer); and processing ended.
[0357] And the estimation processing is successful, such according to the steps as 570 founds the new filter. The novel filter comprising a filter state, the filter with of the respond computer address message (e.g., the IP address, port, a protocol type and similar information); matchingAnd the grant comprises an and association's operation. Method for selecting; the novel filter with a filtering state, the filter that follow with responding the computer the computer of the achieve safety setting of consensus of local to match. The several steps as 572, wherein the receiving without appraise the support and an information generation, the processing determining whether a appraised of the computer (. i.e, wherein exists to licence first matching filter). And the matching filter with licence operation, such according to the steps as 547, containing the information packet to pass through the network. Otherwise, such of the several steps as 576, hinders the information packet end of the further traversal network.
[0358] For providing for user request method for replacing 516 machine of safety communication: isFounds a filter, the filter colours are an information packets which has a safety protocol (e.g., a protocol according IPSec is stipulated). Thus, wherein the data packet capable of access of the filter, such is a flowing to the invention 566, the first is appraised SWITCH.
[0359] All references according here quotes are included in, used as a whole.
[0360] In aggregate of the fact capable of apply the invention the principles the can embodiments, wherein: ofHere the embodiment of description to intends according to the auxiliary certain is plays the role of emitter, and is not be regarded as a invention claims a range. For example, section of the skilled the technical field of a: The hardware in the element of the declarative embodiment of the executive software, pores vice; versaOr, is not separated from the invention the lower spirit terminal, a revises the declarative embodiment of the device and detail. In addition, the shape of skilled the technical field of a: The processing using filter (e.g. QOS, and lPSec). May use invention of this invention tube and executing the filter and extra and processing filter-based the strategy. Therefore, the invention is of a here embodiments can integrate with a embodiments the following claim 1-3 and equal internet range.
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| US6347376B1 | Cites | United States of America |
| WO0237730A2 | Cites | World Intellectual Property Organization (WIPO) |
| CN1406351A | Cites | China |
| US5835726 | Cites | United States of America |
10 members in 5 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 10456770 | United States of America | – | |
| 45677003 | United States of America | A | |
| 10456770 | – | – | – |
| US20030456770 | – | – | – |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| EP1484887A2 | European Patent Office (EPO) | A2 | |
| KR20040105602A | Republic of Korea | A | |
| JP2004362590A | Japan | A | |
| US2005022011A1 | United States of America | A1 | |
| CN1574792A | China | A | |
| EP1484887A3 | European Patent Office (EPO) | A3 | |
| US7260840B2 | United States of America | B2 | |
| CN1574792BThis record | China | B | |
| JP4521225B2 | Japan | B2 | |
| KR101026558B1 | Republic of Korea | B1 |
6 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Expiry of patent termCX01 | CX01 | |
| Succession or assignment of patent rightASS | ASS | |
| Transfer of patent application or patent right or utility modelC41 | C41 | |
| Grant of patent or utility modelGrantedC14 | C14 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 1574792
- Publication, DOCDB
- 1574792
- Publication, EPODOC
- CN1574792B
- Application
- 100488647
- Application, DOCDB
- 200410048864
- Application, EPODOC
- CN2004148864
Titles3
- English
- Multi-layer based method for implementing network firewalls
- English
- For carrying out a network multi-layer-based method
- Chinese
- 用于执行网络防火墙的基于多层的方法
Classification
- CPC, 3
- H04L63/0227
- H04L63/0236
- H04L63/0823
- IPC, 7
- G06F13 00
- H04L12 56
- H04L9 32
- H04L12 22
- H04L12 24
- H04L12 66
- H04L29 06