EP0743777A2

System for packet filtering of data packets at a computer network interface

Abstract

A system for screening data packets transmitted between a network to be protected, such as a private network, and another network, such as a public network. The system includes a dedicated computer with multiple (specifically, three) types of network ports: one connected to each of the private and public networks, and one connected to a proxy network that contains a predetermined number of the hosts and services, some of which may mirror a subset of those found on the private network. The proxy network is isolated from the private network, so it cannot be used as a jumping off point for intruders. Packets received at the screen (either into or out of a host in the private network) are filtered based upon their contents, state information and other criteria, including their source and destination, and actions are taken by the screen depending upon the determination of the filtering phase. The packets may be allowed through, with or without alteration of their data, IP (internet protocol) address, etc., or they may be dropped, with or without an error message generated to the sender of the packet. Packets may be sent with or without alteration to a host on the proxy network that performs some or all of the functions of the intended destination host as specified by a given packet. The passing through of packets without the addition of any network address pertaining to the screening system allows the screening system to function without being identifiable by such an address, and therefore it is more difficult to target as an IP entity, e.g. by intruders.

EP0743777A2, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Projected expiry passed 15 May 2016, 10.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

17 claims: 7 independent, 10 dependent

  1. 1
    A method for screening data packets arriving at a screening system connected between a first computer network and a second computer network and for executing actions in a proxy system connected to the screening system, including the steps of:(1) receiving a first said packet directed from the first network to the second network as a current packet;(2) determining from contents of the current packet whether the current packet is of a predetermined type for being allowed to pass to the second network;(3) if the determination of step 2 is positive, then determining a destination address within the second network as specified by the current packet, and passing the current packet to an ersatz address substituting for said destination address, the ersatz address residing in the proxy system;(4) determining whether at least one action requested by the current packet is of a type predetermined to be allowed, and if not then rejecting the current packet and proceeding to step 6, and if so then proceeding to step 5;(5) taking the action specified by the current packet in at least one of the screening system and the proxy system;(6) determining whether another packet has arrived at the screening system, and if so then receiving that packet as the current packet and proceeding to step 1, and if not then ending the method.
  2. 4
    A screening system connected to a first computer network and a second computer network for screening data packets transmitted between the first and second networks, including:a processor;a memory coupled to the processor;input and output circuits for transmitting and receiving data packets to and from, respectively, said first and second networks;and program instructions stored in said memory for controlling flow of data packets between the first and second networks, including: a first program module for determining whether a first data packet transmitted from the first network to the second network meets predetermined criteria;a second program module for passing the first data packet to the second network if the predetermined criteria are met: a third program module for preventing passage of the first data packet to the second network, if the predetermined criteria are not met.
  3. 6
    A method for screening data packets arriving at a screening system connected between a first computer network and a second computer network and for executing actions in a proxy system connected to the screening system, including the steps of:(1) receiving a first said packet from the first network at the second network as a current packet: (2) determining from contents of the first data packet a requested operation. a source address and a destination address for the first data packet;(3) determining, based upon at least one predetermined criterion, an action to be taken in response to the requested operation;(4) passing the current packet to a proxy host substituting for said destination address, the proxy host residing in the proxy system;and (5) in the proxy system, taking the determined action.
  4. 12
    A proxy system coupled to a screening system connected between a first computer network and a second computer network for screening data packets sent from said first network to said second network, at least one said data packet including a first field specifying an intended recipient system for the data packet and further including a second field specifying a requested operation for said intended recipient system to execute, the proxy system including:a processor;a memory connected to said processor configured for storing instruction modules specifying operations to be executed by said processor;a plurality of action modules stored in said memory including instructions specifying a predetermined set of actions to be taken with respect to at least a first said data packet received at said screening system, based upon predetermined criteria with respect to contents of said first data packet;a screening module including instructions for the screening system to block passage of said first data packet to said second computer network;and an operation module controlling said plurality of action modules to select one of said actions to be taken by said proxy system processor in lieu of said requested operation.
  5. 13
    A method for inhibiting targeting of a screening system coupled between a first computer network and a second computer network, including the steps of:receiving at the screening system at least one data packet directed from the first network to the second network, the data packet including a source address identifying the first network and a destination address identifying the second network;inspecting the packet based upon a predetermined criterion;if the predetermined criterion is met, passing the packet through to the second network with the source and destination addresses unaltered;and if the predetermined criterion is not met, then discarding the packet while preventing any response by the screening system to the first network.
  6. 14
    A protection system for inhibiting targeting of a screening system coupled between a first computer network and a second computer network, the screening system including a processor, a memory coupled to the processor and storing instruction modules executable by the processor, a first network interface coupling the screening system to the first network and a second network interface coupling the screening system to the second network, the protection system including:a first said module configured for receiving at least one data packet directed from the first network to the second network, the data packet including a source address identifying the first network and a destination address identifying the second network;a second said module configured for inspecting the packet based upon a predetermined criterion;a third said module configured for passing the packet through to the second network with the source and destination addresses unaltered, if the predetermined criterion is met;a third said module configured for discarding the packet while preventing any response by the screening system to the first network, if the predetermined criterion is not met.
  7. 15
    A system for inhibiting targeting of a first computer network, including:a screening system coupled between the first computer network and a second computer network, the screening system including a processor, a first network interface coupling the screening system to the first network, and a second network interface coupling the screening system to the second network;and a proxy network coupled to the screening system via a third network interface and including at least one proxy host having an internetwork address with a domain in common with the first computer network;the screening system further including a memory coupled to the processor, the memory storing instruction modules executable by the processor, the modules including: a first said module for receiving a data packet via said first network interface, the data packet including a destination address including said domain;and a second said module for passing the packet to said proxy host if said destination address pertains to said proxy host.