Multilayer firewall system
Abstract
A system provides for establishing security in a network that include nodes having security functions operating in multiple protocol layers. Multiple network devices, such as remote access equipment, routers, switches, repeaters and network cards having security functions are configured to contribute to implementation of distributed firewall functions in the network. By distributing firewall functionality throughout many layers of the network in a variety of network devices, a pervasive firewall is implemented. The pervasive, multilayer firewall includes a policy definition component that accepts policy data that defines how the firewall should behave. The policy definition component can be a centralized component, or a component that is distributed over the network. The multilayer firewall also includes a collection of network devices that are used to enforce the defined policy. The security functions operating in this collection of network devices across multiple protocol layers are coordinated by the policy definition component so that particular devices enforce that part of the policy pertinent to their part of the network.

Term
Term ended
Projected expiry passed 28 May 2018, 8.3 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
59 claims: 59 independent, 0 dependent
- 1System for generating safety in a network (10) With nodes of a variety of types, with the node in a set of nodes in the network (10) Security features include that are performed in response to configuration data, the for are the appropriate node type suitable, with:a topology data store (30), The information about security features, in the set of nodes in the network (10) work, and over the connection of the node stores in the set of nodes;one Configuration interface (31) Coupled to the topology data store (30is) coupled, comprising an input, via which Security policy statements are received, within the the nodes in the network (10) To implement security policies specify;and a configuration driver (32), of the to the network (10), The configuration interface (31) And the topology data store (30) coupled is, includes the resources that are suitable, in response to the topology data, the security policy statements into configuration data for the Plurality of types of nodes in the network (10) to translate, and which are adapted to transfer the configuration data to the nodes. System zum Erzeugen von Sicherheit in einem Netzwerk (10) mit Knoten einer Vielzahl von Typen, wobei die Knoten in einem Satz der Knoten in dem Netzwerk (10) Sicherheitsfunktionen umfassen, die als Reaktion auf Konfigurationsdaten ausgeführt werden, die für den entsprechenden Knotentyp geeignet sind, mit: einem Topologie-Datenspeicher (30), der Informationen über Sicherheitsfunktionen, die in dem Satz von Knoten in dem Netzwerk (10) arbeiten, und über die Verbindung der Knoten in dem Satz von Knoten speichert;einer Konfigurationsschnittstelle (31), die mit dem Topologie-Datenspeicher (30) gekoppelt ist, die einen Eingang umfasst, über den Sicherheitsrichtlinienangaben empfangen werden, die die innerhalb der Knoten in dem Netzwerk (10) zu implementierenden Sicherheitsrichtlinien angeben;und einem Konfigurationstreiber (32), der mit dem Netzwerk (10), der Konfigurationsschnittstelle (31) und dem Topologie-Datenspeicher (30) gekoppelt ist, der Ressourcen umfasst, die geeignet sind, als Reaktion auf die Topologiedaten die Sicherheitsrichtlinienangaben in Konfigurationsdaten für die Vielzahl von Knotentypen in dem Netzwerk (10) zu übersetzen, und die geeignet sind, die Konfigurationsdaten zu den Knoten zu übertragen.
- 2System for generating safety in a network (10) With nodes of a variety of types, with the node in a set of nodes in the network (10) Security features include that are performed in response to configuration data, the for are the appropriate node type suitable, with:a topology data store (30), The information on security features in the set of nodes in the network (10) And the Connecting the node stores in the set of nodes, where the Topology data store (30includes) data structures information for provide specific nodes, including addresses at one or several protocol layers, whether the particular node is trusted, a security policy to enforce, or not, of the type the security policy that enforce the particular node is capable, and connections of the particular node to other Node;a configuration interface (31), the with the topology data store (30is) coupled, the comprises an input, via to the security policy statements are received, the between source records a or more Endarbeitstationen and target rates of one or more end stations in the network (10) To implement security policies specify that includes a script interpreter, of a scripting language interpreted to determine the security policy statements, and the scripting language syntax for describing a security policy statement including a source set identifier, a destination set identifier, a communication activity identifier and a RegelQuellsatzkennzei-label, a destination set identifier, a communication activity identifier and a rule for the identified communication activity between the identified Source set and the identified target rate includes;and a Configuration driver (32) Connected to the network (10) the configuration interface (31) And the topology data store is coupled, which includes resources that are suitable as the reaction the topology data, the security policy statements into configuration data for different definition node types in the network, and send the configuration data to the nodes. System zum Erzeugen von Sicherheit in einem Netzwerk (10) mit Knoten einer Vielzahl von Typen, wobei die Knoten in einem Satz von Knoten in dem Netzwerk (10) Sicherheitsfunktionen umfassen, die als Reaktion auf Konfigurationsdaten ausgeführt werden, die für den entsprechenden Knotentyp geeignet sind, mit: einem Topologie-Datenspeicher (30), der Informationen über Sicherheitsfunktionen in dem Satz von Knoten in dem Netzwerk (10) und über die Verbindung der Knoten in dem Satz von Knoten speichert, wobei der Topologie-Datenspeicher (30) Datenstrukturen umfasst, die Informationen für bestimmte Knoten bereitstellen, einschließlich Adressen an einer oder mehrerer Protokollschichten, ob der bestimmte Knoten vertrauenswürdig ist, um eine Sicherheitsrichtlinie durchzusetzen oder nicht, des Typs der Sicherheitsrichtlinie, die der bestimmte Knoten durchzusetzen in der Lage ist, und Verbindungen des bestimmten Knotens zu anderen Knoten;einer Konfigurationsschnittstelle (31), die mit dem Topologie-Datenspeicher (30) gekoppelt ist, die einen Eingang umfasst, über den die Sicherheitsrichtlinienangaben empfangen werden, die die zwischen Quellensätzen einer oder mehrerer Endarbeitstationen und Zielssätzen einer oder mehrerer Endarbeitsstationen in dem Netzwerk (10) zu implementierenden Sicherheitsrichtlinien angeben, die einen Skript-Interpreter umfasst, der eine Skriptsprache interpretiert, um die Sicherheitsrichtlinienangaben zu bestimmen, und wobei die Skriptsprache eine Syntax zum Beschreiben einer Sicherheitsrichtlinienangabe einschließlich eines Quellsatzkennzeichens, eines Zielsatzkennzeichens, eines Kommunikationsaktivitätskennzeichens und eines RegelQuellsatzkennzeichens, eines Zielsatzkennzeichens, eines Kommunikationsaktivitätskennzeichens und einer Regel für die identifizierte Kommunikationsaktivität zwischen dem identifizierten Quellsatz und dem identifizierten Zielsatz umfasst;und einem Konfigurationstreiber (32), der mit dem Netzwerk (10), der Konfigurationsschnittstelle (31) und dem Topologie-Datenspeicher gekoppelt ist, der Ressourcen umfasst, die geeignet sind, als Reaktion auf die Topologiedaten die Sicherheitsrichtlinienangaben in Konfigurationsdaten für verschiedene Knotentypen in dem Netzwerk zu übersetzen, und die die Konfigurationsdaten zu den Knoten senden.
- 3System according to claim 1 or 2, wherein the set of includes Node node, the MAC (medium access control) layer filtering according to filter parameters provide, and wherein the configuration data includes filter parameters for the MAC layer filtering. System nach Anspruch 1 oder 2, wobei der Satz von Knoten Knoten umfasst, die MAC-(medium access control)-Schicht-Filterung gemäß Filterparametern vorsehen, und wobei die Konfigurationsdaten Filterparameter für die MAC-Schicht-Filterung umfassen.
- 4System according to claim 1 or 2, wherein the set of includes nodes nodes that a network-layer (Network Layer) filtering according to filter parameters provide and the configuration data filter parameters for the network layer filtering include. System nach Anspruch 1 oder 2, wobei der Satz von Knoten Knoten umfasst, die eine Vermittlungsschicht-(Network Layer-)Filterung gemäß Filterparametern vorsehen, und wobei die Konfigurationsdaten Filterparameter für die Vermittlungsschicht-Filterung umfassen.
- 5System according to claim 1 or 2, wherein the set of includes nodes nodes, the transport layer filtering according to filter parameters provide and the configuration data filter parameters for the transport layer filtering include. System nach Anspruch 1 oder 2, wobei der Satz von Knoten Knoten umfasst, die Transportschicht-Filterung gemäß Filterparametern vorsehen, und wobei die Konfigurationsdaten Filterparameter für die Transportschicht-Filterung umfassen.
- 6System according to claim 1 or 2, wherein the set of includes Node node, the application layer filtering according to filter parameters provide and the configuration data filter parameters for the application layer filtering include. System nach Anspruch 1 oder 2, wobei der Satz von Knoten Knoten umfasst, die Anwendungsschicht-Filterung gemäß Filterparameter vorsehen, und wobei die Konfigurationsdaten Filterparameter für die Anwendungsschicht-Filterung umfassen.
- 7System nach Anspruch 1, wobei die Sicherheitsfunktionen Authentifizierungsprotokolle umfassen. The system of claim 1, wherein the security feature Authentication protocols include.
- 8System nach Anspruch 1, wobei die Sicherheitsfunktionen Auditieren umfassen. The system of claim 1, wherein the security feature Auditing include.
- 9System nach Anspruch 1, wobei die Sicherheitsfunktionen Autorisierung umfassen. The system of claim 1, wherein the security feature Authorization include.
- 10System nach Anspruch 1, wobei der Satz von Knoten Knoten umfasst, die Repeater-Funktionen ausführen, und wobei die Sicherheitsfunktionen MAC-(medium access control)-Schicht-Filterung in den Repeater-Funktionen umfassen. The system of claim 1, wherein the set of nodes includes nodes running repeater functions and the safety functions MAC (medium access control) layer filtering in the repeater functions include.
- 11System nach Anspruch 1, wobei der Satz von Knoten Knoten umfasst, die Sicherungsschicht-(data link layer)-Switch-Funktionen ausführen, und wobei die Sicherheitsfunktionen MAC-(medium access control)-Schicht-Filterung in den Switch-Funktionen umfassen. The system of claim 1, wherein the set of nodes includes nodes Sicherungsschicht- (data link layer) switch functions run, and wherein the security features MAC (medium access control) layer filtering in the switch functions include.
- 12System nach Anspruch 1, wobei der Satz von Knoten Knoten umfasst, die Vermittlungsschicht-(network layer)-Routing-Funktionen ausführen, und wobei die Sicherheitsfunktionen Vermittlungsschicht-Filterung in den Routing-Funktionen umfassen. The system of claim 1, wherein the set of nodes includes nodes that network-layer (network layer) routing functions run, and wherein the security features network layer filtering in include the routing functions.
- 13System nach Anspruch 1, wobei der Satz von Knoten Knoten umfasst, die Mehrfachprotokollschicht-(multiple protocol layer)Routing-Funktionen ausführen, und wobei die Sicherheitsfunktionen Authentifizierungsmechanismen umfassen. The system of claim 1, wherein the set of nodes includes nodes Mehrfachprotokollschicht- (multiple protocol perform layer) routing functions, and wherein the security features authentication mechanisms include.
- 14System nach Anspruch 1, wobei der Satz von Knoten Knoten umfasst, die Vermittlungsschicht-Routing-Funktionen ausführen, und Knoten, die Sicherungsschicht-(data link layer)-Switch-Funktionen ausführen, und wobei die Sicherheitsfunktionen MAC-(medium access control)-Schicht-Filterung und Vermittlungsschicht-Filterung umfassen. The system of claim 1, wherein the set of nodes includes nodes running the network layer routing functions, and Nodes Sicherungsschicht- (data link layer) run -Switch functions and the safety functions MAC (medium access control) layer filtering and network layer filtering include.
- 15System nach Anspruch 14, wobei der Satz von Knoten Knoten umfasst, die Mehrfachprotokollschicht-(multiple protocol layer)Routing-Funktionen ausführen, und wobei die Sicherheitsfunktionen Authentifizierung umfassen. The system of claim 14, wherein the set of nodes includes nodes Mehrfachprotokollschicht- (multiple protocol perform layer) routing functions, and wherein the security functions include authentication.
- 16System nach Anspruch 1, wobei der Topologie-Datenspeicher (30) Daten umfasst, die Knoten angeben, die mit Netzwerkverbindungen zu Knoten gekoppelt sind, die außerhalb des Satzes von Knoten liegen. The system of claim 1, wherein the topology data store (30includes) data indicative of nodes with network connections are coupled to nodes external to the set of nodes lie.
- 17System nach Anspruch 1, wobei der Topologie-Datenspeicher (30) Daten umfasst, die Knoten angeben, die mit Netzwerkverbindungen zu Knoten außerhalb des Satzes von Knoten gekoppelt sind, aktive Knoten, die geeignet sind, eine Sicherheitsrichtlinie durchzusetzen, und passive Knoten, die nicht geeignet oder nicht vertrauenswürdig sind, eine Sicherheitsrichtlinie durchzusetzen;und wobei die Sicherheitsrichtlinienangaben Sicherheitsrichtlinien für aktive Knoten, passive Knoten und für Kommunikationen angeben, die Netzwerkverbindungen zu Knoten außerhalb des Satzes von Knoten durchqueren. The system of claim 1, wherein the topology data store (30includes) data indicative of nodes with network connections to nodes outside the set of nodes are coupled, active Knoth, the appropriate are to enforce a security policy and passive nodes, the unsuitable or not trustworthy, a security policy enforce;and wherein the security policy statements indicate security policies for active Node passive node and for specify communications, the network links to nodes external the set of nodes traverse.
- 18System nach Anspruch 1, wobei die Konfigurationsschnittstelle (31) einen Skript-Interpreter umfasst, der eine Skriptsprache interpretiert, um die Sicherheitsrichtlinienangaben zu bestimmen. The system of claim 1, wherein the configuration interface (31) A script interpreter includes that interprets a scripting language to the security policy statements to determine.
- 19System nach Anspruch 1, wobei der Topologie-Datenspeicher (30) Daten umfasst, die aktive Knoten angeben, die geeignet sind, eine Sicherheitsrichtlinie durchzusetzen, und passive Knoten, die nicht geeignet oder nicht vertrauenswürdig sind, eine Sicherheitsrichtlinie durchzusetzen. The system of claim 1, wherein the topology data store (30includes) data indicating active nodes capable are to enforce a security policy and passive nodes, the unsuitable or not trustworthy, a security policy enforce.
- 20System nach Anspruch 19, wobei die Sicherheitsrichtlinienangaben Sicherheitsrichtlinien für die Kommunikation zwischen einem Quellsatz einer oder mehrerer Endarbeitsstationen und einem Zielsatz einer oder mehrerer Endarbeitsstationen angeben. The system of claim 19, wherein the security policy statements Safety Guidelines communication between a source set of one or more end stations and specify a target set of one or more end stations.
- 21System nach Anspruch 19, wobei der Konfigurationstreiber (32) Ressourcen umfasst, um Sicherheitsrichtlinien für passive Knoten mittels Erzeugen von Konfigurationsraten für aktive Knoten durchzusetzen, die mit passiven Knoten verbunden sind. The system of claim 19, wherein the configuration driver (32includes) resources to security policies for passive Nodes by generating configuration rates for active enforce nodes that are connected to the passive node.
- 22System nach Anspruch 18, wobei die Skriptsprache eine Syntax zum Beschreiben einer Sicherheitsrichtlinienangabe einschließlich eines Quellsatzkennzeichens, eines Zielsatzkennzeichens, eines Kommunikationsaktivitätskennzeichens und eine Regel für die identifizierte Kommunikationsaktivität zwischen dem identifizierten Quellsatz und dem identifizierten Zielsatz umfasst. The system of claim 18, wherein the scripting language a syntax for describing a security policy statement including a Source set identifier, a destination set identifier, a communication activity identifier and a rule for the identified communication activity between the identified includes source set and the identified destination set.
- 24System according to claim 2 or 22, wherein the configuration driver (32includes) resources to security policy statements identify which of the data in the topology data store (30) Not enforced can be. System nach Anspruch 2 oder 22, wobei der Konfigurationstreiber (32) Ressourcen umfasst, um Sicherheitsrichtlinienangaben zu identifizieren, die gemäß der Daten in dem Topologie-Datenspeicher (30) nicht durchgesetzt werden können.
- 25System according to claim 1 or 2, the configuration memory comprises with persistent storage capability in Communication with a particular node in the set of nodes , and wherein the configuration driver (32) Configuration data for the certain node to the configuration memory transfers. System nach Anspruch 1 oder 2, das einen Konfigurationsspeicher mit ausdauernder Speicherfähigkeit in Kommunikation mit einem bestimmten Knoten in dem Satz von Knoten umfasst, und wobei der Konfigurationstreiber (32) Konfigurationsdaten für den bestimmten Knoten zu dem Konfigurationsspeicher überträgt.
- 26System nach Anspruch 25, wobei der Konfigurationsspeicher mit dem bestimmten Knoten mittels einer Kommunikationsverbindung gekoppelt ist. The system of claim 25, wherein said configuration memory with the particular node via a communication link coupled.
- 27System nach Anspruch 1, wobei der Topologie-Datenspeicher (30) Datenstrukturen umfasst, die Informationen für bestimmte Knoten einschließlich Vermittlungsschicht-Adressen, MAC-(medium access control)-Schicht-Adressen, Benutzerkennzeichen, ob der bestimmte Knoten vertrauenswürdig ist, eine Sicherheitsrichtlinie durchzusetzen oder nicht, den Typ der Sicherheitsrichtlinie, den er durchzu setzen geeignet ist, und dessen Verbindungen zu anderen Knoten bereitstellen. The system of claim 1, wherein the topology data store (30includes) data structures that provide information for certain node including Network layer addresses, MAC (medium access control) layer addresses, User ID whether the particular node is trusted, enforce a security policy or not, the type of Security policy, which he put durchzu suitable, and its provide connections to other nodes.
- 28System nach Anspruch 1, wobei die Sicherheitsrichtlinienangaben Sicherheitsrichtlinien für die Kommunikation zwischen einem Quellsatz einschließlich einer oder mehrerer Endarbeitsstationen in dem Netzwerk (10) und einem Zielsatz einschließlich einer oder mehrerer Endarbeitsstationen in dem Netzwerk angeben, und wobei der Konfigurationstreiber (32) Ressourcen umfasst, um einen Artikulationssatz (cut vertex set) von Knoten zu identifizieren, die geeignet sind, die angegebenen Sicherheitsrichtlinien innerhalb des Satzes von Knoten in dem Netzwerk durchzusetzen, und um die Konfigurationsdaten in den Knoten in dem Artikulationssatz einzurichten. The system of claim 1, wherein the security policy statements Safety Guidelines communication between a source set including a or more end stations in the network (10) and a destination set including specify one or more end stations in the network, and wherein the configuration driver (32includes) resources a vertex set to identify nodes (cut vertex set) are suitable, the specified security policies within enforce the set of nodes in the network, and to the set configuration data to the nodes in the cut vertex set.
- 29System nach Anspruch 28, wobei der Artikulationssatz aus einem minimalen Artikulationssatz besteht. The system of claim 28, wherein the vertex set consists of a minimal cut vertex set.
- 30System nach Anspruch 2, wobei der Topologie-Datenspeicher (30) Daten umfasst, die aktive Knoten angeben, und die geeignet sind, eine Sicherheitsrichtlinie durchzusetzen, sowie passive Knoten, die nicht geeignet oder nicht vertrauenswürdig sind, eine Sicherheitsrichtlinie durchzusetzen. The system of claim 2, wherein the topology data store (30includes) data indicating the active node, and the are capable of enforcing a security policy and passive Nodes that do not are not suitable or trustworthy, enforce a security policy.
- 31System nach Anspruch 2, wobei der Topologie-Datenspeicher (30) Daten umfasst, die Knoten angeben, die mit Netzwerkverbindungen zu Knoten außerhalb des Satzes von Knoten gekoppelt sind. The system of claim 2, wherein the topology data store (30includes) data, the node isBen, the network connections to nodes outside coupled the set of nodes.
- 32System nach Anspruch 31, wobei die Sicherheitsrichtlinienangaben Sicherheitsrichtlinien für Kommunikationen angeben, die Netzwerkverbindungen zu Knoten außerhalb des Satzes von Knoten durchqueren. The system of claim 31, wherein the security policy statements Safety Guidelines specify communications, the network links to nodes external the set of nodes traverse.
- 33System nach Anspruch 2, wobei der Konfigurationstreiber Ressourcen umfasst. um einen Artikulationssatz von Knoten zu identifizieren, die geeignet sind, die angegebenen Sicherheitsrichtlinien durchzusetzen und die Konfigurationsdaten in den Knoten in dem Artikulationssatz zu errichten. The system of claim 2, wherein the configuration driver includes resources. to identify a cut vertex set of nodes, which are capable of enforcing security policies and indicated the configuration data in the nodes in the cut vertex set to build.
- 34System nach Anspruch 33, wobei der Artikulationssatz aus einem minimalen Arti kulationssatz besteht. The system of claim 33, wherein the vertex set consists of a minimum Arti kulationssatz.
- 35A method of constructing a firewall system in a network (10) Including a set of nodes a variety of types, the nodes in the set of nodes in the network (10include) security features in response to configuration data for the corresponding node are capable of running are, with the following steps:Providing topology data including information about Security features that are effective in the nodes in the set, and over Compounds of the nodes in the set;Deploying security policy statements, specify the security policies between Endsystemgeräten in the Set to be implemented;Translate the security policy statements in response to the topology data into configuration data for security functions, which are effective in nodes in the set;and Building up the configuration data in the security features of the nodes in the network (10). Verfahren zum Errichten eines Firewall-Systems in einem Netzwerk (10) einschließlich eines Satzes von Knoten einer Vielzahl von Typen, wobei die Knoten in dem Satz von Knoten in dem Netzwerk (10) Sicherheitsfunktionen umfassen, die als Reaktion auf Konfigurationsdaten, die für den entsprechenden Knoten geeignet sind, ausgeführt werden, mit den folgenden Schritten: Bereitstellen von Topologiedaten einschließlich Informationen über Sicherheitsfunktionen, die in den Knoten in dem Satz wirksam sind, und über Verbindungen der Knoten in dem Satz;Bereitstellen von Sicherheitsrichtlinienangaben, die Sicherheitsrichtlinien angeben, die zwischen Endsystemgeräten in dem Satz zu implementieren sind;Übersetzen der Sicherheitsrichtlinienangaben als Reaktion auf die Topologiedaten in Konfigurationsdaten für Sicherheitsfunktionen, die bei Knoten in dem Satz wirksam sind;und Aufbauen der Konfigurationsdaten in den Sicherheitsfunktionen an den Knoten in dem Netzwerk (10).
- 36A method of constructing a firewall system in a network (10) Including a set of nodes a variety of types, the nodes in the set of nodes in the network (10include) security features in response to configuration data for the corresponding node are capable of running are, with the following steps:Providing topology data including information about Security features that are effective in nodes in the set, and compounds of nodes in the set;Deploying security policy statements, specify the security policy between a source sentence of end stations and a target set of end stations are to be implemented in the set;Identifying an articulation rate of nodes that consist of nodes that are capable of the security policy statements enforce, in response to the topology data and the security policy statements and, when they leave the network (10would be removed), the would isolate the source set of the target set;as reaction to the identified vertex set and the security policy statements Translate in configuration information Security features that take effect on nodes in the cut vertex set are;and Installation of the configuration data in the safety functions at the nodes in the cut vertex set. Verfahren zum Errichten eines Firewall-Systems in einem Netzwerk (10) einschließlich eines Satzes von Knoten einer Vielzahl von Typen, wobei die Knoten in dem Satz von Knoten in dem Netzwerk (10) Sicherheitsfunktionen umfassen, die als Reaktion auf Konfigurationsdaten, die für den entsprechenden Knoten geeignet sind, ausgeführt werden, mit folgenden Schritten: Bereitstellen von Topologiedaten einschließlich Informationen über Sicherheitsfunktionen, die in Knoten in dem Satz wirksam sind, und über Verbindungen von Knoten in dem Satz;Bereitstellen von Sicherheitsrichtlinienangaben, die Sicherheitsrichtlinien angeben, die zwischen einem Quellsatz von Endarbeitsstationen und einem Zielsatz von Endarbeitsstationen in dem Satz zu implementieren sind;Identifizieren eines Artikulationssatzes von Knoten, die aus Knoten bestehen, die geeignet sind, die Sicherheitsrichtlinienangaben durchzusetzen, als Reaktion auf die Topologiedaten und die Sicherheitsrichtlinienangaben, und die, wenn sie aus dem Netzwerk (10) entfernt würden, den Quellsatz von dem Zielsatz isolieren würden;als Reaktion auf den identifizierten Artikulationssatz und die Sicherheitsrichtlinienangaben Übersetzen in Konfigurationsdaten für Sicherheitsfunktionen, die an Knoten in dem Artikulationssatz wirksam sind;und Aufbauen der Konfigurationsdaten in den Sicherheitsfunktionen an den Knoten in dem Artikulationssatz.
- 37The method of claim 35, wherein the topology data Data structures include providing information for particular nodes, including Addresses in one or more protocol layers, whether the particular Node trustworthy is to enforce security policies, type of security policy, which can enforce the specific nodes and links of the particular node to other nodes. Verfahren nach Anspruch 35, wobei die Topologiedaten Datenstrukturen umfassen, die Informationen für bestimmte Knoten bereitstellen, einschließlich Adressen in einer oder mehrerer Protokollschichten, ob der bestimmte Knoten vertrauenswürdig ist, Sicherheitsrichtlinien durchzusetzen, Typ der Sicherheitsrichtlinie, die der bestimmte Knoten durchsetzen kann, und Verbindungen des bestimmten Knotens zu anderen Knoten.
- 38A method according to claim 35 or 36, wherein said step the Bereiststellens the security policy statements interpreting includes a scripting language to the security policy statements to determine the scripting language syntax for describing a security policy statement including a source identifier, a destination identifier, a communication activity identifier and a rule for the identified communication activity between the identified comprising source and the identified target. Verfahren nach Anspruch 35 oder 36, wobei der Schritt des Bereiststellens der Sicherheitsrichtlinienangaben das Interpretieren einer Skriptsprache umfasst, um die Sicherheitsrichtlinienangaben zu bestimmen, wobei die Skriptsprache eine Syntax zum Beschreiben einer Sicherheitsrichtlinienangabe einschließlich eines Quellkennzeichens, eines Zielkennzeichens, eines Kommunikationsaktivitätskennzeichens und eine Regel für die identifizierte Kommunikationsaktivität zwischen der identifizierten Quelle und dem identifizierten Ziel umfasst.
- 39The method of claim 38, wherein the syntax of the Furthermore, an identifier of the location includes at which enforce the rule is. Verfahren nach Anspruch 38, wobei die Syntax des Weiteren ein Kennzeichen des Ortes umfasst, an dem die Regel durchzusetzen ist.
- 40The method of claim 35, wherein the step of Constructing transferring the configuration data via the network comprises a permanent memory which is in communication is connected to the node. Verfahren nach Anspruch 35, wobei der Schritt des Aufbauens das Übertragen der Konfigurationsdaten über das Netzwerk zu einem dauerhaften Speicher umfasst, der in Kommunikation mit dem Knoten steht.
- 41The method of claim 36 or 40, wherein for at least a node of the permanent memory in communication with the node for the Node is local, and where for at least one other node of the permanent memory in communication Located at the node of the node is located. Verfahren nach Anspruch 36 oder 40, wobei für mindestens einen Knoten der dauerhafte Speicher in Kommunikation mit dem Knoten für den Knoten lokal ist, und wobei für mindestens einen anderen Knoten der dauerhafte Speicher in Kommunikation mit dem Knoten von dem Knoten entfernt liegt.
- 42A method according to claim 40, wherein for at least a node of the permanent memory in communication with the node away from the node, and wherein the step of establishing the configuration data at the node after transmitting the configuration data to the persistent store, the signaling of the safety function includes at the node that the configuration data has changed. Verfahren nach Anspruch 40, wobei für mindestens einen Knoten der dauerhafte Speicher in Kommunikation mit dem Knoten entfernt von dem Knoten liegt, und wobei der Schritt des Aufbauens der Konfigurationsdaten an dem Knoten nach dem Übertragen der Konfigurationsdaten zu dem dauerhaften Speicher das Signalisieren der Sicherheitsfunktion an dem Knoten umfasst, dass die Konfigurationsdaten geändert wurden.
- 43The method of claim 35, wherein the topology data include data indicating active nodes capable of a enforce security policy and passive nodes which unsuitable or not trusted are to enforce a security policy. Verfahren nach Anspruch 35, wobei die Topologiedaten Daten umfassen, die aktive Knoten angeben, die geeignet sind, eine Sicherheitsrichtlinie durchzusetzen, sowie passive Knoten, die ungeeignet oder nicht vertrauenswürdig sind, eine Sicherheitsrichtlinie durchzusetzen.
- 44The method of claim 43, wherein the topology data include data indicative of nodes with network connections to nodes outside coupled the set of nodes. Verfahren nach Anspruch 43, wobei die Topologiedaten Daten umfassen, die Knoten angeben, die mit Netzwerkverbindungen zu Knoten außerhalb des Satzes von Knoten gekoppelt sind.
- 45The method of claim 44, wherein the security policy statements Safety Guidelines specify communications, the network links to nodes external the set of nodes traverse. Verfahren nach Anspruch 44, wobei die Sicherheitsrichtlinienangaben Sicherheitsrichtlinien für Kommunikationen angeben, die Netzwerkverbindungen zu Knoten außerhalb des Satzes von Knoten durchqueren.
- 46The method of claim 45, wherein the step of translating generating configuration data for active nodes comprises the are connected to the passive node to security policies for passive nodes enforce. Verfahren nach Anspruch 45, wobei der Schritt des Übersetzens das Erzeugen von Konfigurationsdaten für aktive Knoten umfasst, die mit passiven Knoten verbunden sind, um Sicherheitsrichtlinien für passive Knoten durchzusetzen.
- 47The method of claim 35, wherein the step of translating identifying security policy statements includes that according to the data in the topology data store can not be enforced. Verfahren nach Anspruch 35, wobei der Schritt des Übersetzens das Identifizieren von Sicherheitsrichtlinienangaben umfasst, die gemäß der Daten in dem Topologie- Datenspeicher nicht durchgesetzt werden können.
- 48The method of claim 35, wherein the set of nodes includes nodes, provide the MAC layer filtering according to filter parameters, and wherein the configuration data filter parameters for the MAC layer filtering include. Verfahren nach Anspruch 35, wobei der Satz von Knoten Knoten umfasst, die MAC-Schicht-Filterung gemäß Filterparametern vorsehen, und wobei die Konfigurationsdaten Filterparameter für die MAC-Schicht-Filterung umfassen.
- 49The method of claim 35, wherein the set of nodes includes nodes, the network layer filtering according to filter parameters provide and the configuration data filtering parameters for network layer filtering include. Verfahren nach Anspruch 35, wobei der Satz von Knoten Knoten umfasst, die Vermittlungsschicht-Filterung gemäß Filterparameter vorsehen, und wobei die Konfigurationsdaten Filterparameter für Vermittlungsschicht-Filterung umfassen.
- 50The method of claim 35, wherein the set of nodes includes nodes, the transport layer filtering according to filter parameters provide and the configuration data filtering parameters for transport layer filtering include. Verfahren nach anspruch 35, wobei der Satz von Knoten Knoten umfasst, die Transportschicht-Filterung gemäß Filterparametern vorsehen, und wobei die Konfigurationsdaten Filterparameter für Transportschicht-Filterung umfassen.
- 51The method of claim 35, wherein the set of nodes includes nodes, the application layer filtering according to filter parameters deploy, and wherein the configuration data filter parameters Application layer filtering include. Verfahren nach anspruch 35, wobei der Satz von Knoten Knoten umfasst, die Anwendungsschicht-Filterung gemäß Filterparametern bereitstellen, und wobei die Konfigurationsdaten Filterparameter für Anwendungsschicht-Filterung umfassen.
- 52The method of claim 35, wherein the security feature Authorization include. Verfahren nach Anspruch 35, wobei die Sicherheitsfunktionen Autorisierung umfassen.
- 53The method of claim 35, wherein the security feature Authentication include. Verfahren nach Anspruch 35, wobei die Sicherheitsfunktionen Authentifizierung umfassen.
- 54The method of claim 35, wherein the security feature Auditing include. Verfahren nach Anspruch 35, wobei die Sicherheitsfunktionen Auditieren umfassen.
- 55A method according to claim 35 or 36, wherein the set includes node node, the network layer filtering according to IP (Internet Protocol) provide filter parameters, and wherein the configuration data IP filter parameters include. Verfahren nach Anspruch 35 oder 36, wobei der Satz von Knoten Knoten umfasst, die Vermittlungsschicht-Filterung gemäß IP-(Internet Protocol)Filterparametern vorsehen, und wobei die Konfigurationsdaten IP-Filterparameter umfassen.
- 56A method according to claim 35 or 36, wherein the set includes node node, the filtering according to TCP / IP (Transport Control Protocol / Internet Protocol) filter parameters provide and wherein the configuration data TCP / IP filter parameters include. Verfahren nach Anspruch 35 oder 36, wobei der Satz von Knoten Knoten umfasst, die eine Filterung gemäß TCP/IP-(Transport Control Protocol/Internet Protocol) Filterparametern vorsehen, und wobei die Konfigurationsdaten TCP/IP- Filterparameter umfassen.
- 57The method of claim 36, wherein the topology data Data structures include providing information for particular nodes, including Addresses whether the particular node is trusted, a security policy enforce, type the security policy that the specific Node can enforce, and connections of the particular node to other nodes. Verfahren nach Anspruch 36, wobei die Topologiedaten Datenstrukturen umfassen, die Informationen für bestimmte Knoten bereitstellen, einschließlich Adressen, ob der bestimmte Knoten vertrauenswürdig ist, eine Sicherheitsrichtlinie durchzusetzen, Typ der Sicherheitsrichtlinie, die der bestimmte Knoten durchsetzen kann, und Verbindungen des bestimmten Knotens zu anderen Knoten.
- 58The method of claim 36, wherein the step of Constructing transferring the configuration data via includes the network to persistent storage in communication with the nodes in the Artikulationssatz stands. Verfahren nach Anspruch 36, wobei der Schritt des Aufbauens das Übertragen der Konfigurationsdaten über das Netzwerk zu einem dauerhaften Speicher umfasst, der in Verbindung mit den Knoten in dem Artikulationssatz steht.
- 59The method of claim 36, wherein said cut vertex set consists of a minimal cut vertex set. Verfahren nach Anspruch 36, wobei der Artikulationssatz aus einem minimalen Artikulationssatz besteht.
Independent claims59
172 paragraphs in 4 sections, as filed
BACKGROUND THE INVENTION
territorially invention
The This invention relates to the generation and enforcing Security functions in a network; and more particularly to systems for generating security features in a variety of protocol layers, a multilayer firewall to build a network.
description of the prior art
safety is an increasingly important matter for Network users, both within companies, the so-called operating intranets, and for worldwide global data networks. An extensive technology has been developed for the purpose of securing networks. The Security features which have been developed include at least the following product categories: (1) filtration, (2) access control, (3) protected Compounds (4) security support and (5) security policy management.
filtering dropping or converting packets or frames comprises (Frames) based on values within their head sets or within their data. Access control includes determining whether a user or a user-initiated Connection to get access to a specific computing resource. Protected Compounds affecting the procedures to ensure that control information or data by unauthorized persons were neither modified nor read. Security support product types offer a network device support for securing other Components of the system. refers Security Policy Management to manage the data security policies define in the network.
These Types of security features are in existing systems enforced in certain network devices. Network devices, where safety in addition conventional terminals and end systems implemented include facilities such. As the following: (1) network interface cards (NICs) and modems, (2) repeaters, (3) switches, (4) routers, (5) remote access equipment, which Line server package server include and Access Server and (6) network management systems. Although Products exist that for generating security in certain product families provide, require systems that are products in all the different categories make use of devices that can be found in networks, exploit, a substantial administrative burden. In a network having a size Variety of network intermediate devices and terminals includes, it is necessary that an administrator setting up a Security policy in all different protocol levels and managed in all the different systems.
Z. As it is possible in a system of the prior art, a build configuration that is local as a virtual network (VLAN), respectively. By configuring the VLAN, membership in the group controlled. For example, Port number, MAC address, protocol type of the third layer, the address third layer, and custom criteria that match patterns match in packets of the third layer, are used to define VLAN membership in such devices. A similar Pattern matching (Pattern matching) can log data for. Example in layers 3 comprise up. 7 Other systems support a per call filtering in remote access systems. This allows customers to different Types of transport users for to allow users or deny. A wide variety of other security systems is available in the market.
The Variety of security features and the various devices and protocol layers for which they work, but provide a significant administration problem for the user of the security features . Because of the complexity it is difficult for a coordinated security policy across all layers and device types of the network to build away, and it is particularly difficult, such a system to wait, even if it is implemented successfully could be.
Also remain, when developing networks, older Devices, which is often referred to as legacy systems, may not be suitable for attend a particular safety function. A security feature the added to a network is, could therefore may not be able to penetrate the entire network successfully. Alternatively complicates the existence of Altsyste<?page 3?>men in the network the Coordination and implementation of a security system in addition.
Traditional Way to implement firewalls as limiting devices such. B. Router and Application Proxy Gateways that a private network protect against external attacks. However, it is likely that between 50% and 85% of the losses of companies are the result of insider attacks, z. B. from disgruntled or opportunistic employees. Consequently, a main safety requirement to corporate intranets of protection against internal attacks.
In addition, requires the economic situation of modern large enterprises increasingly that Companies outsource work or in partnership with other companies Collaborate. As the information technology the daily business in the modern enterprise penetrates, requires such outsourcing and the partnership without exception that companies share information with each other by electronic means. It is rare that this information is available in devices from those isolated are that the rest of the data files the company include. Thus making the outsourcing and the partnership requires that a company other company gives access to parts of its intranet. Of Further comprises usually different each swap, or partnership agreement Subgroups or departments of the company. This means that the percentage of data sets a company that for at least one outside accessible of the company is, is quite large.
The conventional Border firewall is largely unsuitable to the safety requirements satisfy, arising from these two concerns out, d. h, consisting of threats from the inside and from the widespread external shared data arise. Border firewalls are completely unsuitable for threats to address by insiders. They serve external invaders deter them from attacking the corporate intranet, but have no ability on to prevent insiders do this.
Around external access to enable corporate data, have "holes" to be drilled in border firewalls, so that the necessary information can flow. In extreme cases, departments can simple corporate firewall, fully converted hen and direct connections for swap and deploy Partnership Company or its employees.
On To meet these requirements, it is approach, the company's own Intranet into several pieces break and to arrange between these border firewalls.
This Approach has some value, but it leads to shortages in the corporate intranet.
D. h. that internal firewalls adversely the performance within the influence company. Once the partitioning is fine-grained, learns access to resources outside the firewall partition in increasingly degraded performance.
On Another approach to this problem it is, firewall functionality down into lower layers to distribute the protocol hierarchy. Thus, for. Example, when network interface cards, Repeaters and switches some firewall packet filtering activities run, are routers that perform packet filtering conventional manner, of relieves a significant processing and therefore can perform better provide at a given cost. In addition, the distribution Firewall better scaling possibilities. Ie. When the Network grows, grow naturally the resources available are to carry out a filtering. This prevents the formation of choke or loss points such. As the, which may occur in internal border firewalls. US Patent 5,606,668 describes a packet filtering system.
Typically is the prior art, firewall functionality as the Packet filtering in individual nodes or groups of similar Nodes with the same firewall rules arranged. These nodes are usually used at the boundaries of the networks to the network against attacks from the outside to protect. However, this approach does not scale very well if a network expands. also he cares for a very rough grain the control for network security. A variety of different approaches that possible in the implementation of are obscure, interact as separate systems in the network. Also cause these individual systems, if they are furnished to unauthorized activity to protect within a network, typically significant performance problems (see, eg. as "Building Internet Firewalls "by Chapman et al., O'Reilly & Associates, September 1995; "In<?page 4?>ternet Firewalls and Security " 3Com Technical Report, 1996 by Semeria.) Accordingly, it is desirable to provide a system for implement the coordinated security policy implementation over several layers allows network systems.
SUMMARY THE INVENTION
The present invention provides a system for generating security ready in a network that includes nodes in multiple protocol layers work and have the security features. Several network devices, such. as routers, remote access devices, switches, repeaters and Network cards and terminals procedures have the security features that are configured such that it for implementation of distributed firewall functions in the contributing network. By distributing the firewall functionality of the network in a variety of network devices and end is a ubiquitous Firewall implemented. The everywhere existing multilayer firewall includes a policy definition component, the policy data receives that define how the firewall will behave. The policy definition component can be a centralized component or may be a component of the above the network is distributed. The multilayer firewall includes also a collection of network devices that are used to enforce the defined policy. The safety functions, in this collection of network devices across multiple work log tiers, are the policy definition component coordinated so that certain institutions that part of the Directive prevail, which is one of its part of the network.
Z. B. is a router in the network by the terms of the Directive, of one of the systems and network devices whose Traffic the router may crosses. A switch enforces the terms of the Directive, the one of the systems and network devices whose traffic the Switch crosses. A repeater is by the part of the directive, one of the systems and network devices whose traffic the repeater crosses. A network interface card is the part of the Directive, which is part of the system or the device, with the or it is connected.
Furthermore are other components of the network of the multilayer firewall includes such. as terminal operating systems and applications, network management systems of remote access devices to Controlling network traffic and for observing the network traffic, and other auxiliary systems such. as name services and file services are included in the collection of network devices, in which the ubiquitous Multilayer Firewall is implemented the present invention.
The This invention provides a coordinated access control, cooperative protected Connection features and an overall security policy management in numerous network devices and end. A security administrator there is provided a suitable and clear control system that the allows management of the security features of the network. Furthermore allows The invention reductions in unnecessary redundancy in security services, enough significant customer requirements in the area of legacy support features, Cost and ensures a reduction of complexity.
In order to the present invention according to one aspect as a system be characterized that provides security on a network, includes the node. Node in a set of nodes in the network include security features in one or more protocol layers work and such security functions in response to configuration data run, have the formats for the corresponding node types are suitable. The system includes a topology data store, the information about security features, who work in the set of nodes in the network, and connections the nodes in the network stores. A configuration interface is coupled to the topology data store. the interface comprises an input to which the security policy statements are received, to be implemented under the nodes in the network specify security policies. A configuration driver is on the network, the configuration interface and the topology data store coupled. The configuration driver includes resources that the security policy statements translate into configuration data in the formats for the node needed in the network be, and under the configuration data to the nodes using the communication channels Send that for the corresponding nodes available are.
According to different lead aspects of the invention the nodes of several protocol layers, including a MAC (Medium Access Control) layer, and the set of nodes includes Nodes that provide a MAC layer filtering according to filter parameters. The configuration data includes filter Para<?page 5?>parameters for the MAC layer filtering. In a another aspect include the multiple protocol layers a network layer (Network layer), such. As an IP (Internet Protocol) layer. The set of nodes in accordance with this Aspect includes nodes according to a network layer filtering filter parameters provide. The configuration data includes filter parameters for the Network layer filtering in such a node. According to a another aspect include the multiple protocol layers a Transport layer function, such as, for. Example, the TCP (Transport Control Protocol), via the the IP (Internet Protocol) operates. According to this aspect comprises the Configuration driver resources, the security policy information in configuration information the transport layer functions, such as filtering, application layer functions for, such as. for example, filtering and / or for Functions in higher translating layers of the protocol stack. Such higher layer functions include, for. example, authentication protocols, authorization protocols Audit logs and other security features. A variety of equipment, filtering, access control, secure connections and security support features run, are distributed in the network infrastructure and in a coordinated Manner in accordance with the present Invention administered.
According to other Aspects of the invention comprises the configuration of an interface Script interpreter, interprets a script language to the security policy statements to determine. The Scripisprache can via a keyboard or a graphical user interface be entered. For support the script language includes the topology data store data, the active node in the network, which are capable of a security policy enforce, and specify passive nodes which are not suitable or untrustworthy are to enforce a security policy. additionally includes the topology data store data indicative of nodes with network connections to nodes outside the set of nodes coupled within the safety frame work are. The security policy statements give security policies for at terminals. Active Node, passive nodes and nodes with network connections to nodes outside the secure network are coupled, are configured, execute the Directive. According to a another aspect of the invention, the script language syntax for determining a security policy statement, the source indicator a for one Source node or a source category, a destination indicator for a Destination node or a target audience, a communication activity indicator and a rule for the identified communication activity between the identified comprising source and the identified target. In one aspect of the invention, the syntax further includes an identifier of the location (d, h. Source node, destination node, both source and destination nodes, or an intermediate node) to which the rule is enforced.
In yet another aspect of the invention provide the security policy statements Safety Guidelines communication between a source set of one or more Endarbeitsstatianen in the network and a destination set including a or more end stations in the network. The configuration driver includes resources to a vertex set (Cut Vertex Set) identifying of nodes that are capable of the indicated Security policies within the set of nodes in the network enforce, and the configuration data in nodes in the cut vertex set establish, with the vertex set consists of active nodes, which, if they were removed from the network, the source set by the Target rate would isolate. In an optimized embodiment, is the vertex set of a minimum vertex set.
According to still further Aspects of the invention, the configuration driver resources, to security policies passive nodes by generating configuration data for active enforce nodes that are connected to the passive node. Also identify the resources in the configuration driver Security policy statements, which according to the data in the Topology memory can not be enforced.
Of the Topology data store in one preferred aspect includes data structures, the information about provide certain nodes in the set of nodes within the security frame work fall. The data structures include Information such. As network layer addresses, MAC-layer addresses, User IDs higher Layers, transport layer port and socket designed number, whether a particular Node trustworthy is to enforce a security policy or not, the type the security policy, the node can enforce that To implement the policy structure that is used, the format of the configuration data, the constructions for Sicherheitskon are required and the connections of the node to other Nodes in the network.
In yet further aspect of the invention, a configuration driver generates Configuration data for Security features, which are distributed in the network. The configuration data are stored in a configuration memory of a permanent storage capacity and said communication in <?page 6?>the particular node in the Set of nodes is, to which the configuration data relate. The configuration memory is in some institutions in the included in the network device itself with such. B. Form of programmable nonvolatile memory. In alternative Systems, the configuration memory of a node in the Network provided, which is a node other than that to the policy is enforced, and with the specific Node at which the policy is to enforce, through a communication link coupled. According to this transmitted aspect of the invention configuring drivers updated configuration data to the Configuration memory and follows it with a message the node at which the safety function is to be executed, that the configuration was updated in the memory. The knot then reads the updated configuration data and begins with the updated execute policy.
The present invention may also more generally as a method of characterized erecting a firewall system in a network will. The method includes providing topology data including information about security features, operating in nodes in the network, and through the connection of nodes in the network. Next the method includes providing security policy statements, include the security policies that are in between or under the secured devices Network are to be implemented, using formats and Communication channels are matched to the type or types of nodes involved. Furthermore, the method comprises translating the security policy statements in response to the topology data into configuration data for security functions, operating in the network. Finally, the method comprises Structure of configuration data in the safety functions on the active node in the network using formats and communication channels, Voted the different on the type or types of nodes are. The plurality of protocol layers, in which the security features work in an alternative comprise at least two per protocol layers, z. B. at least two of the security layer (Data Link Layer), network layer, Transport layer and applications, or equivalents.
Accordingly makes the present invention exploit security features in network interface cards in switches, routers and in be placed remotely systems, and provides a system administrator the possibility ready firewall functionalities to to postpone variety of devices in the network to provide ubiquitous Multilayer Firewall to produce. Security features may in several layers are spread across multiple facilities and using a coherent Security policy management interface to manage, the security administrator a useful and clear control of the Safety properties of the network provides. distributed functionality and the useful enable and clear control Scaling benefits Firewalls, which currently only applies Systems, such as z. B. dRMON (Distributed remote monitoring), or other sophisticated network systems exist, the functions on are directed to a single purpose.
There the number of network devices increases, the security policy data such filter rules and infrastructure information sets encrypted connections included, providing a coherent and coordinated management will these data are increasingly important. The present invention provides a coherent approach as regards the management and distribution of security policy enforcement data ready in a diverse multi-layer network.
Other Aspects and advantages of the present invention when viewing the following figures, detailed description and claims significantly.
SHORT DESCRIPTION THE FIGURES
<figref idrefs="S55">1</figref> offers a simplified block diagram of a network including a Multilayer firewall system according to the present Invention.
<figref idrefs="S56">2</figref> is a representative Representation of a plurality of network components, of the Multilayer firewall system of the present invention are included.
<figref idrefs="S57">3</figref> is a flow diagram showing the process of building a multilayer firewall according to the present Invention.
<figref idrefs="S58">4</figref> is a flow diagram of a an alternative technique for establishing Multilayer firewall functionality according to the present Invention.
<?page 7?>
<figref idrefs="S59">5</figref> is a flow diagram illustrating steps performed by the structure to Configuration data in nodes in the network according to the multilayer firewall system of the present invention belong.
<figref idrefs="S60">6</figref> and <figref idrefs="S61">7</figref> are variants of <figref idrefs="S56">2</figref>Highlighted to represent of exemplary security frameworks according to the present invention.
DETAILED DESCRIPTION
A detailed Description of the present invention will be described with reference to the <figref idrefs="S55">1</figref> to <figref idrefs="S59">5</figref> provided, <figref idrefs="S55">1</figref> an overview offers.
In <figref idrefs="S55">1</figref> includes a network <figref>10</figref> a plurality of nodes. At least one Node in the network has a network management workstation <figref>11</figref> or another security policy server. Other nodes in the network comprise a switch <figref>12</figref>, A remote access device <figref>13</figref>. a router <figref>14</figref> and an end station with a network interface card and their supportive driver software <figref>15</figref> and a repeater <figref>16</figref>, In order to is a variety of network devices in the network <figref>10</figref> includes. The Switch <figref>12</figref>, The remote access device <figref>13</figref>. the router <figref>14</figref>That Endarbeitsstations network interface card <figref>15</figref> and the repeater <figref>16</figref> include all security policy management agent <figref>22</figref>. <figref>23</figref>. <figref>24</figref>. <figref>25</figref> or. <figref>26</figref>, The security policy management agent <figref>22</figref> to <figref>26</figref> perform safety functions at a variety of protocol layers. Dependent on the protocol layers in the specific network device are traversed, in which the agent is implemented and in dependence by others, the structure in question features vary the constructions, used by the security features of the device type to Device Type.
In the embodiment in the <figref idrefs="S55">1</figref> is shown, comprising the Netzwerkmanagementar beitsstation <figref>11</figref> a Topology data store <figref>30</figref>, A configuration interface front end <figref>31</figref> and a security policy management back end <figref>32</figref>That a Configuration driver provides. The topology data store<figref>30</figref> stores information about Security features of the security policy management agent <figref>22-26</figref> be executed working in multiple protocol layers of nodes in the network. The topology database also gives the compounds of the nodes in the network.
the Configuration interface front end <figref>31</figref> is connected to the topology data base <figref>30</figref> coupled. It includes entries, through which it security policy statements receives, such. as by providing a script in a security policy language the by an interpreter <figref>34</figref> is interpreted to security policy statements provide. The security policy management back end<figref>32</figref> is to the configuration interface front end <figref>31</figref> and the Topology database <figref>30</figref> coupled, and includes resources, the security policy statements into configuration data for nodes translating in the network. The security policy management back end <figref>32</figref> provides a Configuration driver which the configuration data for the security policy management agents <figref>22</figref> to <figref>26</figref> at Nodes in the network determines where the security policy statements must be enforced.
the Configuration interface front end <figref>31</figref> includes a embodiment a text input device with which a security policy language script is entered into the system. In alternative approaches includes the configuration system interface front end <figref>31</figref> a graphical User interface, with which the user determines the security policy statements. In all the tests there is provided a security policy script that syntax a which the translation the the security policy statements into configuration data for the corresponding Protocol level and the type of device the node in the network permits, on which the directive is to enforce.
Security Policy Language and security policy language front end
The Security policy language is used (edge) conditions in type to determine within a network. comprises Such activity the activity, the., both of network devices such as repeaters, switches, Routers, remote access devices, etc. as well as devices in the network accomplished will. The multilayer firewall can implemen with any security policy language Animal T be responsible for an investment is suitable, but will hereafter an example language explained.
Each terminal and each active network device has one or more network addresses on that part of its security policy management agent, and is one or more Netzwerkein<?page 8?>devices connected. These Information is from the security policy language front end through interactions with a system administrator as well as the Topology database determined. Interactions with a system administrator can a User interface, or the reading of files or other storage resources such. B. Domain Name System (DNS), Network Information Service (NIS) or other databases done. Terminals differ from network devices that it always leaves in the graph are derived from the topology database is formed. The general term "node" refers to either terminal or Network devices. terminals (Also called hosts) are the nodes in policy statements Marked are. A special case occurs z. B. if a network device for administrative purposes is accessed. In this case, the network device acts in the role as a terminal.
Terminals in the network can belong to groups. Groups are named and their membership is by entering by a system administrator in the security policy language front end or set at another way, or in an alternative in implements the topology database. Again, this input either by user interaction or by the security policy language front end, the files or other databases reads. Groups of terminals can be determined so that they individual terminals or other groups of terminals contain. After all be nodes on Communication links associated with other nodes outside of the network are, in which the security is applied in the topology database records. In an example implementation provides the syntax a special "virtual" nodes that which is designated by "external" the terminal represents the outside the management domain the multilayer firewall lie. Thus indicates the topology of whether a particular node in the topology with the particular node is coupled to "external". In alternatives are there is the possibility more than to designate a node as externally. This makes it possible the multilayer firewall, a policy for communications with more to be defined as another external multilayer firewall.
the Security policy language front end manages preferably also or as a front end to other information, such. as user ID, Groups of user ID, time rules for a period of time, while is allowed to access a source to a target, rules of time intervals, while granted increased access to a target is to determine so.
The Security policy language itself is used to a set writing of security policy statements which allowed the activity between terminals determine in the network. An illustrative rule base and .NET syntax looks like this: <?page 9?><img img-content="tb" img-format="tif" he="111" wi="166" file="00140001.tif" />
Topology data database
The Topology information database contains information about the Nodes and how they are connected. The specified to a node Information in one example its network address or addresses, its MAC address or addresses, its licensed associated user ID, its port or socket number, whether he is trustworthy, enforce a security policy or not, what kind by enforcing rules he is enforce able formats security constructs in the node and its connection within the nodes in the network.
The Information about how nodes are connected to each other, comprises a flag for each Node or node network interface and graphical information, indicating which node directly with which other nodes through which Node interfaces are connected. This information includes Also nodes that "external" to the node or other Firewall systems or other data structures are connected to the specify external connections. In an addition to the information marks individual processes within the physical nodes.
The Topology database is maintained in a sample by a single database management system or it is alternatively constructed from multiple databases, the by database frontend systems at individual nodes or Collections are managed by node. Example data in several Databases include RMON and dRMON data from clients and Network devices managed security information and connection information, of over the network distributed network management systems have been identified.
Security policy management back end
the Security policy management back end uses the information from the security policies frontend configuration interface and the topology data base in order by the security policy statements to produce security policy described to store, to Update to distribute, and enforce. The backend is of elements in independent Management systems, from persistent storage systems and from nodes. The security policy management back end translates into the security policy statements rules described in a context of the information in the topology database and generates node-specific security policy configuration data, which distributes it to the network node towards which it has chosen. The security policy management back-end decides <?page 10?>as the Security Policy Nanga ben in rates of certain nodes enforceable Configuration data are to partition, and convert the rules the security policy statements in node-specific configuration data to which among the selected Nodes are enforceable.
The include node-specific security policy configuration data static data, such. as filter rules in the filter systems the node driving, or include dynamic data programs such. B. Java, source or bytecode, and programs in script languages, such. as TCL, Pearl, C-shell scripts are expressed. The format of the configuration data, the enforced to a specific node security policy statement express, is a function of the particular node and its security policy enforcement agent.
In an alternative analyzes the security policy management back end the security policy statements and topology database information, to device-specific security policy configuration data according to the following driving method, assuming that the security policy statements according to the above explained Syntax shown. <ul><li>1 nodes in two categories: 1) passive nodes that a directive can not prevail, either because they are unsuitable to or because they can not be trusted, carry this out, and 2) active nodes that can enforce the policy.</li><li>2. For each active node generating a list of all the passive node, which are connected either directly to him or for a Path from the passive node to the active node through other passive node exists. Each passive node on this list is called an active node associated node.</li><li>3. For each security policy rule Determine the set of source nodes (Ie by recursively expanding all groups of nodes in the Source sentence until the list only individual node contains) and the set of destination nodes (using the same decomposition algorithm except that nodes in the target block and not in nodes use the source sentence.</li><li>4. Make for every Security policy rule, the following calculation. determine for each passive node in the source node set, if there is any way of him are at any passive node in the destination node set, the no active node happened. If so, send a signal, that the rule can not be enforced.</li><li>5. If the rule determines that she prevailed at the source shall be:</li><li>• Determine the set of active nodes with associated nodes in the source node set.</li><li>• For each this active node translate, the security policy statement, which is described in the rule, in security policy configuration data by setting the node can, that rules in its own security policy language.</li><li>• Put these rules in the node determined using node-specific Communication channels.</li><li>6. If the rule determines that she prevailed at the destination node set shall be:</li><li>• Make the same as described by 5 with the exception that the associated node be used in the target node set.</li><li>7. If the rule determines that they both in the source and should also be enforced in the target node set:</li><li>• Make both 5 and 6 by.</li></ul>
The Implementation of the Security Policy in accordance with the rules set forth above can better with reference to the <figref idrefs="S56">2</figref> and <figref idrefs="S57">3</figref> Roger that , whereby the <figref idrefs="S56">2</figref> a more detailed example of the components a network providing, in which a security policy according to the present Invention is enforced in several layers. <figref idrefs="S57">3</figref> illustrated an overall flowchart for the implementation of the distributed multilayer firewall.
As in <figref idrefs="S56">2</figref> visible, comprises a representative A large network Variety of network devices and end. That's why shows <figref idrefs="S56">2</figref> a network with a set of nodes, the nodes in the set security functions in multiple protocol layers provide. The network comprises a general wide area network (WAN) <figref>100</figref>, The wide area network<figref>100</figref> is a first private network <figref>101</figref> and a second private network <figref>102</figref> coupled. Constituents in the first private network <figref>101</figref> are shown in the figure, while the private network <figref>102</figref> is represented by a cloud. The wide area network <figref>100</figref> is also independently routed to a terminal <figref>103</figref>. a management server <figref>104</figref>Which in turn mediated by a Telecommunication network (PSTN) <figref>105</figref> is coupled, and with an access server <figref>106</figref> coupled, which is also to the PSTN <figref>105</figref> coupled. As in<figref idrefs="S56">2</figref> shown, is the WAN <figref>100</figref> to the private network <figref>101</figref> over a Site router (Site Router) <figref>107</figref>, A package server <?page 11?><figref>108</figref> and another site router <figref>109</figref> coupled.
the PSTN <figref>105</figref> is over a modem <figref>110</figref> with a stand-alone dial-up terminal <figref>111</figref> connected. the PSTN <figref>105</figref> is also a Ferzugriffs router (Remote Access Router) <figref>112</figref> coupled. The Remote Access Router<figref>112</figref> is with the terminals <figref>113</figref> and <figref>114</figref> connected. Also, the remote access router <figref>112</figref> is a Terminal Server <figref>115</figref> connected, in turn connected to terminals <figref>116</figref> and <figref>117</figref> connected is.
In the first private network <figref>101</figref> the package server <figref>108</figref> With a stroke <figref>120</figref> connected, in this example repeater provides or switch functions. The hub in turn is connected to the Site router <figref>107</figref> and the site router <figref>109</figref> connected. Each of the site router <figref>107</figref>. <figref>109</figref> is also the wide area network <figref>100</figref> connected. The site router<figref>107</figref> is with an access server <figref>121</figref> connected to said PSTN <figref>105</figref> connected is. The site router<figref>107</figref> is also equipped with a set of switches including the switch <figref>122</figref> and the switch <figref>123</figref> connected. The site router <figref>109</figref> is a switch <figref>124</figref> connected. Of the Switch <figref>124</figref> is represented with a set of repeaters by the repeater <figref>125</figref>, connected. The repeater<figref>125</figref> is with an end station <figref>126</figref> connected, the corresponding security policy management resources the node <figref>11</figref> in <figref idrefs="S55">1</figref> includes.
the private network <figref>101</figref> also includes a number of other Devices which are represented by elements connected to the switches <figref>122</figref> and <figref>123</figref> are connected. The Switch <figref>122</figref> is shown in a configuration that connects to the repeater <figref>130</figref> includes, and a network interface card NIC in the terminal <figref>131</figref>, The repeater <figref>130</figref> is also connected to a set of terminals, which the terminal <figref>132</figref> include, containing a network interface card.
Of the Switch <figref>123</figref> is a repeater <figref>133</figref> connected, in turn, with a number of terminals including terminal <figref>134</figref> connected is. The Switch<figref>123</figref> is a switch network <figref>140</figref> connected, which is generally illustrated in the figure by a cloud. The switch network <figref>140</figref> is connected to a switch <figref>141</figref> coupled. The Switch <figref>141</figref> is to a repeater <figref>142</figref> coupled, in turn, with a terminal <figref>143</figref> connected is comprising a network interface card NIC.
In <figref idrefs="S56">2</figref> are Nodes at which a security policy enforcement agent is encoded by horizontal bars. Thus have when starts from the top left corner of the figure, the modem <figref>110</figref>. of the remote access router <figref>112</figref>, The terminal server <figref>115</figref>. access server <figref>106</figref>, The management server <figref>104</figref>. the package server <figref>108</figref>, The site router <figref>107</figref>. the site router <figref>109</figref>, The switch <figref>122</figref>, The switch <figref>123</figref>. the repeater <figref>133</figref> and the network interface cards the terminals <figref>131</figref> and <figref>132</figref> all Agents for enforcing security policies. The policy management workstation<figref>126</figref> includes the resources for the Providing a configuration interface, a topology database and a Configuration driver backend as described above.
An overview these devices in a typical network in which security policies according to the present Invention can be enforced, is given below. Next, the overall process of the present invention with reference to the <figref idrefs="S57">3</figref> to <figref idrefs="S60">6</figref> described.
Network interface cards and modems
The simplest products in the set of nodes are network interface cards (NICs) and modems. A NIC is an input / output device, at one terminal via its internal I / O bus is provided, and for the access of the terminal to a local network makes such. as Ethernet, Fast Ethernet, Gigabit Ethernet, Token Ring, FDDI, and ATM. In the case of ATM, certain NICs access to an ATM wide area network provide.
modems are external devices that are on devices via serial or parallel Interfaces install. Generally, they allow the terminal, the PSTN or non-brokered power lines to be used for data transport.
Usually are NICs and modems simple devices more on performance are optimized as to additional features.
Maybe the first NIC security feature, the widespread acceptance has won, is the NIC BootROM. Originally meant to be a floppy-less to enable booting from network servers, has a BootROM the interesting security side effect that the execution of vertrauenswür<?page 12?>DIGEM Bootcode guaranteed. With some support software, this is used, to untrusted code in the terminal to invite the then the NIC for safe operation configured.
On increasingly popular feature with security implications is filtering. The Use of filtering is motivated by several goals. On the LAN level filtering used to NICs and hubs before resource depletion problems to protect, consisting of the unrestricted Sending of frames occur. The structures which have been developed for this kind of filtering disposal question about, are known as VLANs. More general schemes above the layer 2 operate, allow filtering across routers. These schemes are usually known as VnetS.
The Using filtering Security purposes can occur in NICs, switches, repeaters, routers and remote access devices. Filtering within a NIC can be used to ensure that the source MAC addresses it sends are valid and that the source addresses, it receives, from trusted terminals submitted. However, NIC filtering can for others in the same way valid purposes be used, such. as the unloading or moving VLAN enforcement processing from Hubs, the implementation of all existing multi-layer firewalls, and providing hardware support for security protocols higher Levels.
On protected Communication feature for NICs and modems is unique, is the high level of transmission security, the provided certain physical communication channels becomes. In particular, reduces the use of optical fiber Lines the threat of passive eavesdropping by an intruder.
Finally, many customers increasingly about that worried that their internal networks against intruders vulnerable are extending physical access to communication ports and terminal equip- procure. For example, extend corporate intranets, the delicate protected Include data about wide geographical areas from which remote research and sales offices associated with them. These remote offices do not offer the same Degree of physical security, which is found in the typical premises.
Both NICs and modems Features provide that support network access control. modems can require that a user enters a password, a token plug-in card used or otherwise provides the proof that he authorized is to start a connection before the dialing sequence is executed. modems the callback functionality in Access Servers support, allow only connections from authorized phone numbers.
the Security policy backend sets safety rules in NICs, z. For example, by storing updated NIC boot code in an associated network server and by signaling to the NIC that it restarts, firmly. In modem driver code is updated and the configuration register be written with new values through communication with modem management code.
repeater
hubs are star network devices to which NICs connect to Frames to other terminals transferred to and order for connectivity in the layer <figref>2</figref> the protocol hierarchy to care. It is possible and common to build hierarchical networks by connecting hubs, to form a tree of connections.
repeater are hubs that frame a, they receive, send to all their lines (except the Line on which the data transmission block arrived). They are in the construction of low cost interconnect structures useful. However, once increases the number of associated repeaters increases also the interference at between the connected devices. Therefore, the number of terminals that directly using can be connected by repeaters, limited.
repeater are simple transmitter devices, which are generally technical keep features to a minimum in order to minimize costs. There are However, security features that are implemented in them.
Protected communications in layer 2 are a natural Security issue that is at least partially addressed by repeaters can be. Among other things, some repeaters make the data in frames, which segments be sent to the frame not adres<?page 13?>Siert is unrecognizable. This ensures that sniffers that these segments are connected, the data within these frames not can see and guarantees yet that collision detection algorithms continue working properly.
qualitatively quality repeater could sophisticated protected implement communication schemes, such as, for. example, those in which IEEE 802.10 standard have been defined, or others that are less complicated. Such schemes utilize cryptographic techniques to transfer blocks of data transported to protect data. would such protection useful when implementing system security features such as pervasive Multilayer firewalls and network access control mechanisms, and in providing protection of terminal data.
That's why building the security policy backend configuration data in a Repeater by updating an adjacent node management or of management resources in the repeater itself.
switches
switches are hubs that source and destination addresses (and perhaps other information) in a frame investigate to determine which of their lines they use intended to forward a received frame. The advantage over a switch a repeater is that it through the traffic to terminals sending frames only over the Lines that lie on a path to the destination is reduced. In the case of broadcast frames, can Switches decide it based on certain lines of policy information are held within the switch not to repeat.
It Switches are made of a variety of properties and costs, including ATM, Ethernet, Fast Ethernet and Token Ring switches. ATM switches are far more complicated than switches that made for other LAN types are. In particular, if ATM switches are connected, they move Frames over virtual Circuits that build the switches between terminals. this requires the shifting of the control information from the terminal to the Switch and between switches. This type of traffic is from Switches other access technologies is not required.
All Functions implemented by repeaters can also in switches may be implemented (see previous section). Furthermore is a switch, a suitable place to various filter functions perform. Some switches are to already in the form of VLAN support in the situation. additionally for providing security to reduce the amount of VLANs traffic, of over a Switch / Repeater Communication Structure flows, by blocking of broadcasting of frames over segments, to which no member of the VLAN exists.
filtering schemes to lead usual Way an access permission decision based on various Properties of the data transmission block by, on which the filtering is applied. However, there are more sophisticated Uses of filtering that the control and / or data in the frame to convert. For example, could the implementation of all existing multilayer firewall encapsulating a data transmission block within a protected other data frame require, creating a secure Layer 2 tunneling is implemented. Layer 2 tunneling by ATM switches (LAN emulation) are already implemented and LAN traffic, the ATM cell transmits (CIF). The concept of a secure tunnel goes through these schemes by protecting the Tunnel traffic addition, as it traverses the tunnel medium. A Another category of conversion filtering is the layer 2 address translation, their application in the implementation of a ubiquitous firewall could have.
switches are the natural Place where to place headend network access control functionality, such. as proxy interaction with authentication, authorization and auditing (AAA) servers, such. as RADIUS, TACACS + and Netware NDS. In conjunction with repeaters can they monitor port separations and -wiederverbindungen by this report to network management applications.
switches are also useful Places to settle there safety assist features. For example, they can System authentication protocols implement to ensure that only trusted servers terminals provide them with boot images. You can decide to withhold certain information security infrastructure and distribute such. as top-level certificates, which in cryptography public key USAGE<?page 14?>be used, provided that in the highest public key a certification hierarchy contains.
the Security policy backend updates switch security constructs by the management communication channel, such. as SNMP used which is implemented in the switch, or by peer-to-peer connection protocols used in the application layer.
router
router are devices move packets between their interfaces to these packages promoting between their source and their destination. The routing decision usually based on the source and destination network layer address of the packet and on other information (eg. as the quality of service or quality of service the package, the security option data and the hop count). router be distinguished from switches by several characteristics, including: 1) They move data between interfaces with different Access media are connected, 2) they route based on information transmitted in the layer 3 packet be, and not based on layer 2 control information and 3) they broadcast normally no data on tragungsblöcke all interfaces.
On However novel trend in the networking industry is the integration of switch and router functionality in the same network device. Some networking companies manufacture switches between different Access media frame formats translate whereby they will allow, that they move data between interfaces with different Access technologies are connected. Furthermore, layer 3 broadcast protocols such. B. IP multicast increasingly popular. Consequently, lead Router now from broadcasting functions that are very similar to switches. In order to seems a remaining crucial difference between routers and switches to exist, namely where (ie, the protocol layer) they get their information, to perform the function.
In addition to This relaxation of the differences between routers and switches coming products from different companies on the market, perform both routing and switching functionality in the same device. From special mention in this regard is the router / switch of Ipsilon Networks of Sunnyvale, California, routes of IP packets while monitoring traffic patterns. If the Traffic between a particular source and a target a specific reaches threshold, the router creates a layer 2 passthru connection, which enables packets between these systems, relatively expensive IP routing processing bypass.
router offer many of the same security services that provide switches, but do so in the layer 3 in the protocol hierarchy. It there are a lot of activity, protected Communication parameters defined in the layer. 3 This activity is in the IPSEC Working Group IETF centered. IPSEC is a set of standards, published both as well as in the development, describes how terminals and routers Authentication, integrity and trust services the IP protocol to provide. Such services can be used to both an end-to-end protection and the protection of the tunnel between intermediate routers and between a router and a terminal to offer.
The usual allow filtering services that are provided by routers available, it also means that they operate them as components of a firewall. Generally lead Firewalls two functions, packet filtering at the network layer, the transport layer and the application layer, as well as the use of proxy servers in applications (Application proxying). router generally provide only the first service ready. The trend in the firewall technology, however, state machines within the Routers provide, keep track of packets that pass through the router will be forwarded, such. as the FTP control traffic and the TCP connection opening packets, and this-retaining use condition in order to drive the filtration process. This feature can the distinction between packet filtering and applying a proxy server for applications blur.
The appropriate use of filtering allows customers to virtual Networks (VnetS) to implement. VnetS are the equivalent VLANs in the layer 3. disconnect the Verk ore, via the layer 3 compound structure was moved into separate domains. Terminals and LAN segments, which do not belong to a VNET, not see the traffic.
The Communication between the security policy backend and the Router is typically peer-to-peer connection in the application layer. Naturally can also management channels, such. as SNMP can also be used.
<?page 15?>
Remote access device (Remote Access Equipment)
On Fernzugriftsgerät converts data communication that is sent over serial lines is. in routed traffic About that support beyond they spare protocol processing (Protocol surrogates Processing) such. as SPX keepalive, local node emulation, etc.
Terminals can directly with remote access devices (Z. B. Terminal Server) or via the switched telecommunications network (Public Switched Telephone Network; PSTN) line. The general situation is the connection the PSTN, which requires the use of Access Servers.
It are two main applications of the access server devices. The first is for provide private intranets remotely. In such cases, the access server located within the private intranet, and it allows remote access through single terminals and remote office router through the PSTN. The second application of remote access products is within ISP (Internet Service Provider) networks. These give the participants Access to the ISP content facilities, and to the Internet connections the ISP. These two applications have slightly different Security requirements, the more fully below explained will.
The two features of remote access devices, providing the management services and packet processing, are traditionally within the same housing implemented. Recent changes public on customer requirements, in particular the desire to use WANs to implement virtual private networks, the producers have led to to separate these functions into two different products, the management server (Line Server) and the package Server. If customers use these products, the line server on one side to the PSTN (or perhaps directly with terminals) and on the other side with a WAN. The package server is on one side connected to a private Inteanet or an ISP device, and on the other side to the WAN. For each compound, produces the Management server a protected Tunnel through the WAN through (usually using Cryptography technology) to the packet server. Connections to the Line servers either stand-alone devices or remote office routing equipment come.
Three Fernzugriftskonfigurationen characteristic.
The first, WAN access, is used by ISPs to access via the public Telecommunications network (PSTN) to their internal resources and the provide Internet. An access server is connected to the PSTN, by allowing customers to connect to stand-alone devices.
The second is the Remote Office Access Configuration (Remote Office Access Configuration), the remote offices and Teleworkers are access to a private network. The Fernzugriftsrouter uses the PSTN to be one with an access server on the premises to join the company or other organization. Access Server passes then the network traffic from the remote access router in the private Inteanet continue.
The third configuration, split server access (Split Server Access) separates the Leitungsserver- and package server functions into separate Devices on. The management server handles the serial line management and the data connection threads, while the package server interface edited between the WAN and the private intranet.
all three configurations require some type of network access control. The WAN access case authenticates and authorizes users before granting them access to the WAN. Those ISPs that also access to local resources (eg. B. locally managed content, e-mail services, web sites) in addition to deploy, authenticate and authorize Internetzugrift Users also before they allow them to local resources to use.
Remote office access authentication and authorization needs of a remote Offices perform before will allow him to make his traffic through the private intranet flows. Since the Router itself does not represent a user, the authentication must and authorization during an initial Connection sequence occur. Typically, this requires that a user (who acts in the role of a system administrator) authenticated at the remote access device which, after implementation an authorization check, a open path in the private intranet.
<?page 16?>
Of the divided or split up tete service access may require two network access control decisions. The first allows a user access to the management server and the second allows him access to the package server and thus to the private intranet. In order to avoid that the user is a double saddled Login is, can Network models, the split-Service Access (Split Service Access), using access control resources, managed by the package server or private intranet, to users to the management server permit. cooperate in such cases the management server and the package Server / private intranet to to grant the user access to both servers.
On further for remote access important security is the filtering. access server (Either in their integrated or split configuration) are natural Points to there to arrange firewall functionality. This can be a of two forms. The simplest one is, a traditional Firewall packet filtering in Access Servers and package servers (in provide the case of shared service access). Such filtering rules are applicable to all the traffic that passes through the device.
The advanced form of filtering sets Filtenegeln determined that applicable per connection. Ie. If a user sends a connect through built access server, a set of filter rules, the for this User is determined, drawn from a filtering database. These Rules are then set in the access server, which applies only to traffic, of over this connection is made.
Finally, a protected Communication an important service that the remote access to disposal provides. This can occur in two places. In some situations, , the physical security provided by the PSTN will be insufficient to appropriate safeguards for the user / private Intranet to offer. In such cases, the Modem / Remote Access Router of cryptographically its data communication with the access / management server support. This requires cryptographic protocols that run over serial lines.
On general case arises from the necessity of protecting Data communication via the WAN. In this situation the tunneling protocol used is to move serial line traffic over the WAN, through Cryptography protected. This may be the result of security support within of the tunnel protocol or as the result of using security features happen that are provided by the network protocol, that is used by the WAN. An important example of the latter is the use of IPSEC to data communications of an IP WAN to protect, thereby forming a virtual private network (VPN).
Network Management
Nearly all Network intermediate systems and NICs must be configured or otherwise Way somehow managed. In general, this is accomplished by the Simple Network Management Protocol (SNMP) is achieved, which assumes that each managed device implements an agent functionality, which is controlled by remote management software. Usually will station more agents of a given management work managed.
Network equipment normally provide an SNMP agent, the to "get" - and "set" queries responds by an SNMP manager, which site administrators allow network devices manage from an integrated system perspective and not on a device-by-device basis.
A is important characteristic of some network management systems the provision of distributed remote monitoring (Distributed Remote Monitoring, dRMON). The remote monitoring provides network managers with statistical and alarm information of "feelers" that is connected to the LAN device are. However, once the number of LAN segments increases, the Resources of the sensor over its Power limit also claimed that in the delivery of incomplete information due to the management workstation software. This problem addressing, distributed dRMON some of the sensor functionality in NICs and Hubs, which allows is that the remote monitoring functionality scaled if the size of the LAN grows.
Two Network management issues are of significant security issues characterized. The first is the network management security, ie ensuring that the network management subsystem does not is undermined. An important issue is how to secure VLAN, implemented VNET or other groupings, what an access control function represents. In general, a part of this<?page 17?>activity central administrated and part is left to the discretion of the user. In order to control access to group membership is a two-step process. In the first step, a system administrator is the Group and sets the policy that allows users or systems take part. In the second step determines a user, at the participate or group decides to arrange a system in the group. The access control mechanism then questioned the Policy data that belong to the group and determines whether the proposed Membership request valid is. Each step of this access control management must ensure be.
Other Forms of network management security to control access a management information database (Management Information Base, MIB), the protected Data communication of sensitive network management data such. B. captured packets and providing access to network management workstations.
the second important network management problem is the security policy management. Each of the product categories described above has security features on, the policy data for its correct and safe operation require. The filter rules for NICs, Switches, routers and remote access devices are produced, distributed, modified and viewed. be, even in a network of moderate size these management positions untenable, unless there is a coordinated control over the filter data. This requires the use of a safe and robust security policy management system. Similar Requirements exist for managing security policy data, with a protected data communication access control and security assist features connected are.
There the number of network devices, the security policy data contain such. as filter parameters, and the protected Kommunikationsinfrastruktunnformationen rise, is the coherent and coordinated management of security policy data in increasingly important. According to the present Invention are tools provided with which an administrator is able to input security policy statements, and the Data corresponding to such information are distributed to agents, which are distributed in the network in which to implement the Directive is.
Security policy data, the various equipment control in a network, interact diverse Way. Therefore, the configuration interface provides a Administrator preferably different views that the are critical to correct management of the multiple layers of firewall functionality. For example, filtering data displayed in a router through the source address are. by the TCP header information or by the source / destination address pairs Each view gives the administrator different information about that, is rejected, accepted or transformed what traffic.
Of the Configuration driver of the present invention provides high-level security policy data, the desired describe behavior in security policy data of the individual Network devices from. Therefore, the high-level description Directive shall be in two sets sets over of low level configuration data. The configuration data then to the appropriate network devices distributed using z. B. a the Simple Network Management Protocol (SNMP) similar protocol, Telnet, Trivial File Transfer Protocol (TFTP) or other device-specific Protocols. Therefore, the network topology data base is important for the Purposes of translation and distributing the configuration data according to the security policy statements, which are provided at the configuration interface.
For simple Networks, the system administrator, the topology information enter them manually. For most networks of any size is this However, no practical option. As a result, conventional network management tools, flying the required topology information, are used to the topology database information for use with the configuration driver definition of the present invention. The degree of interaction, between the topology information by conventional Network management tools are recognized, and the security policy enforcement strategies the present invention depends of the sophistication of the multilayer firewall from being implemented. For example, changes on the network topology, the association between the high-level security policy data and distributed to the constituent institutions security policy data invalidate. sophisticated Multilayer firewall is configured to messages Network management systems always obtained when a change occurs in the topology, and that they Directive data and their constituent bodies accordingly reconfigured.
<?page 18?>
Finally, Security policy management tools-only, so they do not invaders be able to use, to attack the network. This requires the use of proprietary data communications between the security policy configuration driver and the Agents that are distributed in the network, in accordance with appropriate access control procedures.
Lots Components of the network support Zugriffskotrolle. Not support all components However, the same kind of access control mechanisms. It is advantageous to a general network access control functionality for so many Facilities as possible provide in the network. For example, widely used set up authentication, authorization and accounting server are to a large manage variety of network devices. Furthermore provide network operating systems such. B. NetWare some AAA services ready.
Furthermore are network devices capable of access control decisions according to the present Invention to be used together. In a simple example, access control to a management server to the server package be delegated by the management server in a part of the access configuration connected is. This provides not only a consistent behavior the distributed remote access system, make sure it also reduces its complexity and increased its reliability.
The traditional security doctrine dictates that protected communications End-to-end occurs. but this is sometimes suboptimal by operating conditions. For example, could waste do not support end-to-end security protocols. Securing the message traffic requires between these systems or between them and non-legacy non-intrusive protection mechanisms such. as routers or switches, as substitute for the legacy act. This approach is inherently not end-to-end.
Some devices can together in a highly secure common physical environment be housed. In such environments, there is no additional benefit an end-to-end protection between devices outside the security area and devices within it. To minimize the expense of protection at the the physical security boundary, eliminating the need for the support of eliminates expensive hardware and software for all internal systems becomes.
The support of security protocols may require the use of expensive cryptographic hardware. In some cases is economically not feasible, all Systems to be fitted with this hardware. This means that the protected end communications path to a system or device needs, the cryptographic hardware somewhere before the final destination of the data is implemented.
Around to consider these situations it is necessary for communications by different means on individual segments of the path between a source and destination to protect. Some of the segments protected Traffic of layer turn three ver, whereas other layer use 2-protection. Coordinating the protection provided by each Segment is defined in a way that an adequate end-to-end security ensures requiring that these segments cooperate with each other. The present invention provides tools by which a Such cooperation can be managed.
<figref idrefs="S57">3</figref> provides a flow chart of the method is used to, a Multilayer firewall according to the present execute invention. As mentioned above, can in the <figref idrefs="S57">3</figref> designated node of a large variety corresponding network equipment, devices and functions, running in network devices and end, the case of several Protocol layers within the network are working.
As out <figref idrefs="S57">3</figref> visible is the first step, a network topology to determine and safety rules (step <figref>300</figref>). These Information is through the configuration interface and the topology data store in the system of <figref idrefs="S55">1</figref> provided.
As next all active nodes and passive nodes are identified in the network (Step <figref>301</figref>). For each active node to identify the passive node, the are connected to it, without active node in between (Step <figref>302</figref>). This defines the set of active nodes together with the corresponding passive nodes in the translation the configuration data are to be used. For example, under include with reference to <figref idrefs="S56">2</figref> the active node those Nodes where a policy enforcement be implemented can. Passive nodes include nodes at which policy enforcement<?page 19?>not is present or not is trustworthy. Therefore include passive node, the terminal <figref>143</figref>. repeater <figref>142</figref>, The switch <figref>141</figref>, The switch network <figref>140</figref>. the Switch <figref>124</figref>, The repeater <figref>125</figref> and other facilities in the network.
For each security policy rule are the source and destination sets the end stations identified (step <figref>303</figref>). The Source and target sentences can each a single end station or a group of end stations exhibit. Next the method determines whether the rule can be enforced (step <figref>304</figref>). As mentioned above, This includes, for. example, determining whether there is a path from any passive node in the source set to any passive node are in the target block, which crosses no active node operates in a protocol layer in which the control animals to implemen is. If a link between passive node in the source and target rates is determined, then the rule can not be enforced. That's why is if the rule can not be enforced, then the security procedures notified (step <figref>305</figref>) And the algorithm determines whether there are more rules that are set up (step <figref>306</figref>). If no more rules left are to be drawn up, then the algorithm ends as step <figref>307</figref> indicated. If more rules in the security policy exist, then the algorithm loops back to step <figref>303</figref>,
If at step <figref>304</figref> it is determined that the rule identified with the active node can be enforced in the set, it is determined whether the rule is intended to be enforced at the source, at the destination or at both. If the rule determines that they at the source is to be enforced, then the active node, lying between the nodes in the source sentence and those in the target block, identified and the rule is in the configuration data for the active converted nodes for which there is a source node in its associated set and is on this node set (step <figref>310</figref>).
If enforce the rule at the destination, or both at the destination and at the source is, then, for each active node connected to a node in the target block, which usually translates into configuration data for this active node and then set at this node (step <figref>311</figref>).
After at least one of the steps <figref>310</figref> and <figref>311</figref> certainly the algorithm determines whether more rules exist that translate (step <figref>312</figref>). If no rules exist, then the algorithm is terminated (step <figref>307</figref>). If more rules left are that translate , then the algorithm loops back to step <figref>303</figref>. continue to the process.
As soon as the source and target sentences are identified, the method of determining whether a path exists between passive node of a no crossing active node requires to reach a node in the target block, by considering Private network <figref>102</figref> and the stand-alone routed terminal <figref>103</figref> Roger that be that the WAN <figref>100</figref> are coupled. Nodes in these Network segments are unsuitable or untrustworthy guidelines enforce. Therefore, when a node in the private network<figref>102</figref> and the lone routed terminal <figref>103</figref> in the Source and target sets of nodes for a particular rule are, this rule between these nodes are not enforced. However, if the node<figref>103</figref> and the private network <figref>102</figref> both in the source set of nodes for a particular rule are, whereas all of the nodes in the private network <figref>101</figref> in the target rate to a specific rule are, then it is likely that the rule will be enforced , since, in order to communicate between the source sentence and the target sentence, all Traffic to either the router <figref>107</figref>, The package server <figref>108</figref> or rout <figref>109</figref> must traverse, which are all suitable guidelines enforce.
<figref idrefs="S58">4</figref> illustrated a method by which a multilayer firewall under certain improved circumstances can be. Eg branches at step<figref>303</figref> in <figref idrefs="S57">3</figref> the Method, a "minimum Vertex set (Minimal Cut Set Vertex) "of active nodes in the path or to identify the paths between nodes in the source and target sentence (Step <figref>400</figref>). A cut vertex set consists of a Set of active nodes, which, if removed, isolate the source and target sentences would. A minimal cut vertex set is such a set, of the smallest number of nodes for given source and destination sets having. This is ??? with reference to<figref idrefs="S56">2</figref> z. B. if the source sentence the terminal <figref>113</figref>. <figref>114</figref>. <figref>116</figref> and <figref>117</figref> includes, and the target set, the single routed terminal <figref>103</figref> is, then the minimum vertex set of active nodes from the remote access router <figref>112</figref>,
There on each of the paths through the remote access router <figref>112</figref> themselves are less active nodes than in the active node to the source sentence (<figref>112</figref> and <figref>115</figref>) Belong and in the active node to the destination set (<figref>104</figref> and <figref>106</figref>) belong, be found, it is possible in some instances, a security policy to the <?page 20?>to implement active node of articulation rate effective as in one implementation, the security policy enforcement, distributed to all active nodes in the source and target sets. Therefore determined the algorithm next, whether the rule in the minimal cut vertex set of active nodes can be effectively enforced (step <figref>401</figref>). If not, then the algorithm returns to step <figref>304</figref> out <figref idrefs="S57">3</figref> back as by step <figref>402</figref> indicated. If the rule in the minimum Vertex set can be enforced by the active node, is the rule in the configuration data for the active node in the translated vertex set and set up in such knots (step <figref>403</figref>). After step <figref>403</figref> the method returns to step <figref>304</figref> in the algorithm <figref idrefs="S57">3</figref> back.
<figref idrefs="S59">5</figref> illustrated a method for setting up the configuration data in the security policy agents, the above the network are distributed.
especially the method of establishing a rule in a node transmitting the configuration data to the node, storing it in a persistent storage and that you can identify the nodes that the data has been updated so that it can start the new run rule. Not all distributed in the network security agents but will be directly connected to a permanent memory, such as z. B. a disk drive or a nonvolatile flash memory device. For example, it is possible to that a repeater <figref>133</figref> no permanent storage capability having. The Switch<figref>123</figref> However, preferably the or end station <figref>126</figref>Which provides a part of the Policy Management Station, , a disk drive or other persistent storage capability exhibit. In this scenario, it is possible, the configuration data the Switch <figref>123</figref>, The end station <figref>126</figref> or to ask another server in the network is available, and then the repeater <figref>133</figref> to signal that the configuration data refreshed. A to the repeater<figref>133</figref> related Management Agent is the configuration data from the Switch <figref>123</figref> or the end station <figref>126</figref> determine when you restart or during other Processes in which the configuration data are updated have to.
Accordingly, the Procedures to set up a rule in a node in <figref idrefs="S59">5</figref> starting to step <figref>500</figref> shown. The method determines first determines whether the node subject of the configuration data, permanent configuration memory includes (step <figref>501</figref>). If so, then the configuration data to the permanent are Memory in the node sent (step <figref>502</figref>). If the node no permanent storage features, then the configuration data to permanent memory sent to a node of the node that is subject of the Configuration data is accessible (step <figref>503</figref>). Next, the node that is the subject of the configuration data is signaled by a change is specified (step <figref>504</figref>). After receiving the signal, that a change is done, the node determines the updated configuration data (Step <figref>505</figref>). After the configuration data to the node either by step <figref>502</figref> or by Step <figref>505</figref> provided were leading the node the new rule based on the configuration data, he has received, (step <figref>506</figref>).
Thus specifies the security policy management configuration driver Rules in nodes by communicating the configuration data for these Rules laid at her. For example, shares, if the node has a permanent memory which the security policy management configuration driver the rules directly the node using a standard protocol such. as Telnet or Trivial File Transfer Protocol (TFTP) with, or uses a protocol that is particularly suitable for this purpose was created as part of the multilayer firewall.
If the node has no permanent memory, the security policy management configuration driver communicate the rules to a persistent storage device which accessible from the node is then signal to the node using z. B. SNMP or other protocol and inform the node that its security policy rules refreshed. The node could then new security policy rules from persistent storage determine. Furthermore, use of the security policy management configuration driver in alternative systems an approach of distributed database, to update the node policy. For example, the security policy management configuration driver write data to a file or database record, for the node a cached copy features. The consistency of the distributed algorithm Database heap then notifies the Node that its cached copy is no longer valid, by motivated him, the mother data (master copy) reread.
The explained above Algorithms for determining the rules active at each node be enforced, are illustrative of the performance the multilayer firewall system of the present invention. Other algorithms are possible. Z. B. can Security policy statements in a limited hours<?page 21?>th security policy rule be broken down into parts to different active node must be enforced. This requires a path analysis between the Node to the source sentence and those in the target block, a determination the semantics supported at each active node in this path, and the implementation of various segments of the policy rule or redundant versions of the policy rule on the active node in this sentence. As a sequential application of security policy rules may be suitable in this active node ge to the Directive implement, where they at the source, destination or active vertex set node could not be implemented, can this rule implementation approach in a distributed way for a more effective firewall to care. About that addition, the disassembly of the policy rule enforcement along a sequential path from node bring efficiencies by implementing the active source, destination or cut vertex set node not possible are.
Two with reference to the <figref idrefs="S60">6</figref> and <figref idrefs="S61">7</figref> (as <figref idrefs="S56">2</figref>) Examples described illustrate how the multilayer firewall works in practice. In the<figref idrefs="S60">6</figref> and <figref idrefs="S61">7</figref> consists The Host Group One <figref>600</figref> from a large number of terminals <figref>601</figref>. <figref>602</figref>. <figref>603</figref>. ..., the above repeater (<figref>604</figref> and <figref>605</figref>) And switches (<figref>606</figref> and <figref>607</figref>) with one of two site routers <figref>608</figref> are connected. The Host Group Two <figref>610</figref> consists of two terminals (<figref>611</figref> and <figref>612</figref>) the above a repeater <figref>613</figref> and the switch <figref>614</figref> with the another site router <figref>615</figref> are connected. The two Site router are a switch <figref>620</figref> connected with each other.
In Both examples show that the multilayer firewall with a policy rule configured: <img img-content="tb" img-format="tif" he="11" wi="160" file="00390001.tif" />
These Rule by a security administrator at the Multilayer Firewall Policy Management Station <figref>625</figref> entered.
In the first example (<figref idrefs="S60">6</figref>) Are two switches <figref>606</figref> and <figref>607</figref> With Host Group One <figref>600</figref> via the repeater <figref>604</figref> and <figref>605</figref> connected, they are capable of a firewall enforcement perform and the site router <figref>615</figref>Which via a switch <figref>614</figref> and a repeater <figref>613</figref> with the Host Group Two <figref>610</figref> connected is also capable of a firewall rule enforcement perform.
The Multilayer Firewall Policy Management Workstation <figref>625</figref> decomposed the Multilayer Firewall policy rule into two node specific Policy rules, one for the site router <figref>615</figref> and one for the two switches <figref>606</figref> and <figref>607</figref> (it it is assumed that both switches, the same device specific policy rules accept). Since the "enforced both "specified in" entry ", invites the Multilayer Firewall Policy Management Station <figref>625</figref> the node specific policy rules to both the site router <figref>615</figref> among Using a protocol such as, for. Example, TFTP, as well as for both switches <figref>606</figref> and <figref>607</figref> using a protocol, such. as TFTP or SNMP without lower layer. If that would have "prevailed at" entry "source" determined, would have the Multilayer Firewall Policy Management Station <figref>625</figref> only the policy rule the site router <figref>615</figref> downloaded. If that would have "prevailed at" entry "target" determined, would have the Multilayer Firewall Policy Management Station <figref>625</figref> only the policy rule the switches <figref>606</figref> and <figref>607</figref> downloaded.
the second example (<figref idrefs="S61">7</figref>) Has the same network topology as the first on. However, the policy enforcement is a different ways achieved as in the first example. In particular, both the switches, the repeater on the <figref>604</figref> and <figref>605</figref> With the Host Group One 600 connected terminals are, and the NICs in these devices capable of node-specific enforce policy rules. In addition, the switch<figref>614</figref>. of over repeater <figref>613</figref> with the Host Group Two <figref>610</figref> connected is enforcing node specific policy rules capable of whereas the site router <figref>615</figref> to unable is.
The Multilayer firewall policy management workstation <figref>625</figref> decomposed the Multilayer Firewall policy rule into two node specific Policy rules, one for the Switch <figref>614</figref>, On the the repeater with the Host Group Two <figref>610</figref> connected is, and one for the two switches <figref>606</figref> and <figref>607</figref>Associated with the host group One <figref>600</figref> are connected (again, it is assumed that both of these switches, the same device-specific policy rules accept). Since the "enforced both "specified in" entry ", invites the Multilayer Firewall Policy Management Station <figref>625</figref> the node-specific security policies both to the switch <figref>614</figref> the Host Group Two <figref>610</figref> as well as to the two switches <figref>606</figref> and <figref>607</figref> the host group One <figref>600</figref> down. If that would have "prevailed at" entry "source" specifies, would have more<?page 22?>layer firewall policy management workstation <figref>625</figref> only the appropriate policy rule to the switch <figref>614</figref> the Host Group Two <figref>610</figref> downloaded. If that would have "prevailed at" entry "target" determined, would have the Multilayer Firewall Policy Management Station only the appropriate policy rule to the switches <figref>606</figref> and <figref>607</figref> the Host Group One <figref>600</figref> downloaded.
This Example also demonstrates a way as NICs participate in the Multilayer Firewall. When each switch <figref>606</figref> and <figref>607</figref>Associated with the host group One <figref>600</figref> are connected, its node-specific Policy rule receives, he broadcasts the policy rule information to each terminal <figref>601</figref>. <figref>602</figref> and <figref>603</figref> in Host Group One <figref>600</figref>With which it is connected. Z. B. could the node specific policy rule for the switches <figref>606</figref> and <figref>607</figref> the Host Group One <figref>600</figref> be: <img img-content="tb" img-format="tif" he="63" wi="156" file="00410001.tif" />
In This table is each terminal <figref>611</figref> and <figref>612</figref> in Host Group Two <figref>610</figref> especially as a source for each Host in the Host Group One <figref>600</figref> listed as the destination. In an actual Implementation is a more efficient representation of these rules possible by listing the subnet addresses that in the terminals of the Host Group Two <figref>610</figref> and Host Group One <figref>600</figref> connected are.
If each NIC, such. as the NIC at the terminal <figref>601</figref> these rules receives, discards all these node specific policy rules for their terminal (Z. B. <figref>601</figref>) Is not a goal. They then used the remaining Rules to the packets addressed to the terminal (z. B. <figref>601</figref>) arrive, filtering. would in this example the terminal <figref>601</figref>. <figref>602</figref> and <figref>603</figref>. when the NICs to enforce node specific policy rules, not in able to any traffic except FTP requests from end systems <figref>611</figref> and <figref>612</figref> in Host Group Two <figref>610</figref> to recieve.
The switches <figref>606</figref> and <figref>607</figref> Host Group One <figref>600</figref> use also these rules, but only for traffic from the terminals <figref>601</figref>. <figref>602</figref> and <figref>603</figref> in Host Group One <figref>600</figref> comes. In particular, they can be drop all packets that are not FTP responses for devices <figref>611</figref> and <figref>612</figref> in Host Group Two <figref>610</figref> are determined. These switches<figref>606</figref> and <figref>607</figref> discard all node-specific rules that determine the destination addresses for terminals with which they no over the repeater <figref>604</figref> and <figref>605</figref> are connected.
Of the in this example demonstrated benefit is that the NICs for enforcing responsible of the multilayer firewall policy rule for incoming traffic are while the switches for enforcing the rule outgoing traffic are responsible. Splitting the responsibility for this Enforcement takes some processing load of the switches <figref>606</figref> and <figref>607</figref> the Host Group One <figref>600</figref> away. This is done by leaving the NICs that their terminals protect against hostile traffic.
In two examples share the multilayer Firewal management workstation <figref>625</figref> the device-specific Policy rules directly to institutions. This approach simplifies the discussion, but can add complexity in the multilayer firewall management protocols to lead. Other implementation strategies are possible and may be desirable. For example, could instead the node specific policy rules directly to the Facilities distribute the multilayer firewall management workstation <figref>625</figref> they store in a persistent store and then each Means signal to retrieve their new policies. In the second example could the switches <figref>606</figref> and <figref>607</figref> Host Group One <figref>600</figref> a Message to the NICs of the terminals <figref>601</figref>. <figref>602</figref> and <figref>603</figref> broadcast, whereby they are informed that they made their new policy to retrieve the persistent store instead of the node-specific Directive directly to send them.
<?page 23?>
The Multilayer firewall functionality of the present invention is as an object-based management system in one embodiment, implemented, and with other programming techniques for the purposes of Providing the configuration of a distributed multilayer firewall in other embodiments.
The present invention provides a framework for providing a coordinated multi-layer and ubiquitous firewall prepared in a network consisting of a great variety of network devices and terminals consists. The system provides an easy-to-manage frontend based on a configuration interface enabling the security policy rules be determined at a high level. These rules are then in decomposes the actual configuration data for nodes in the network, which are affected by the rule. The configuration data subsequently furnished to the nodes in the network to implement the rule. By performing this process on a rule-by-rule basis by information about the Topology of the network and the types of security features, , Are running on the nodes in the network used, is a coordinated, everywhere existing multilayer firewall system provided. According to the present Invention is the distribution of roles for different elements a firewall in one or more intelligent management systems combined, preferably by easy to use features such as graphical user interface and high-level scripting be implemented.
The Multilayer firewall of the present invention provides a security infrastructure Network System of unparalleled flexibility ready. also A coherent Frontend available provided, the complexity of the of managing many devices in a wide-ranging makes network possible.
The foregoing description of a preferred embodiment of the invention has been for the purposes of illustration and description. It is not intended to be exhaustive or the invention to the precise embodiments disclosed limits. Obviously, many changes are and variations relevant Professionals clearly. It is intended that the scope of the invention by the following claims and their equivalents is defined.
Contents4
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
14 members in 8 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 86548297 | United States of America | A | |
| 86548297 | United States of America | A | |
| 86548297 | United States of America | – | |
| 9810817 | United States of America | W | |
| 9810817 | United States of America | W | |
| 9810817 | United States of America | – | |
| 865482 | – | – | – |
| PCTUS9810817 | – | – | – |
| US19970865482 | – | – | – |
| WO1998US10817 | – | – | – |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| CA2291158A1 | Canada | A1 | |
| WO9854644A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US5968176A | United States of America | A | |
| GB9928175D0 | United Kingdom | D0 | |
| GB2342020A | United Kingdom | A | |
| EP0990206A1 | European Patent Office (EPO) | A1 | |
| JP2002507295A | Japan | A | |
| GB2342020B | United Kingdom | B | |
| EP0990206A4 | European Patent Office (EPO) | A4 | |
| EP0990206B1 | European Patent Office (EPO) | B1 | |
| AT343818T | Austria | T | |
| ATE343818T1 | Austria | T1 | |
| DE69836271D1 | Germany | D1 | |
| DE69836271T2This record | Germany | T2 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Change of representativeR082 | R082 | |
| No opposition during term of oppositionOpposition8364 | 8364 |
Numbers
- Publication
- 69836271
- Publication, DOCDB
- 69836271
- Publication, EPODOC
- DE69836271T
- Application
- 69836271
- Application, DOCDB
- 69836271
- Application, EPODOC
- DE1998636271T
Titles2
- German
- MEHRSTUFIGES FIREWALL-SYSTEM
- English
- MULTI-STAGE FIREWALL SYSTEM
Classification
- CPC, 6
- H04L63/02
- H04L63/0209
- H04L63/0218
- H04L63/0227
- H04L63/0263
- H04L63/102
- IPC, 3
- G06F11 00
- G06F13 00
- H04L29 06