EP0807347B1

A system for securing the flow of and selectively modifying packets in a computer network

Abstract

This record has no abstract on file.

EP0807347B1, drawing sheet 1
Sheet 1 of 41

Term

Term ended

Expired 16 June 2016, 10.3 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

20 claims: 2 independent, 18 dependent

  1. 1
    A method of inspecting and selectively modifying inbound and outbound data packets in a computer network (100,120), the inspection of said data packets occurring in accordance with a security rule (302-308), the method comprising the steps of:generating a definition of each aspect of the computer network (100, 120) inspected by said security rule (302-308), generating said security rule (302-308) in terms of said aspect definitions, said security rule (302-308) controlling at least one of said aspects, converting said security rule (302-308) into a set of packet filter language instructions (400) for controlling an operation of a packet filter module (204, 520) which inspects said data packets in accordance with said security rule (302-308), coupling said packet filter module (204-520) to said computer network (100, 120) for inspecting said data packets in accordance with said security rule (302-308), said packet filter module (204, 520) implementing a virtual packet filtering machine (600), and said packet filter module (204, 520) executing said packet filter language instructions for operating said virtual packet filtering machine (600) to either accept or reject the passage of said data packets into and out of said network computer (100, 120), characterized in that a selective modification of said data packets occurs in accordance with said security rule (302-308), said packet filter module (204, 520) controlled by said filter language instructions (400) selectively modifying said data packets in accordance with said security rule (302-308), and in that said virtual packet filtering machine (600) either accepting or rejecting the passage of said data packets is operated to selectively modify said data packets so accepted.
  2. 19
    A security system for inspecting and selectively modifying inbound and outbound data packets in a computer network (100, 120), said security system inspecting said data packets passing through said computer network (100, 120) in accordance with a security rule (302-308), where each aspect of said computer network (100, 120) controlled by said security rule (302-308) has been previously defined, said security rule (302-308) being previously defined in terms of said aspects and converted into packet filter language instructions (400), said security system comprising:a packet filter module (204, 520) coupled to said computer network (100, 120) said packet filter module (204, 520) operating in accordance with said security rule (302-308), said packet filter module implementing a virtual packet filtering machine (600) inspecting said data packets passing into and out of said computer network (100, 120), and processing means for reading and executing said packet filter language instruction (400), integral with said packet filter module (204, 520), said processing means operating said packet filtering module (204, 520) to either accept or reject the passage of said packets into and out of said computer network (100, 120), characterized in that said security system selectively modifies said data packets passing through said computer network (100, 120) in accordance with said security rule (302-308), with said virtual packet filtering machine (600) inspecting and selectively modifying said data packets passing into and out of said computer network (100, 120), and said packet filtering module (204, 520) either accepting or rejecting the passage of said packets being operated to selectively modify said data packets so accepted.