EP1535186A2

System, method and computer program product for monitoring and controlling network connections from a supervisory operating system

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 19 August 2023, 3.1 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

30 claims: 6 independent, 24 dependent

  1. 1
    Claims of equivalent WO 2004019162 A2 What is Claimed is:1. A method, comprising: configuring a processing device to include a supervisory operating system and a secondary operating system, wherein the secondary operating system provides network services to network clients;and providing network control software in the supervisory operating system, wherein the network control software is configured to monitor and/or control network operations in the secondary operating system.
  2. 8
    A processing system, comprising:a supervisory operating system;a secondary operating system, provides network services to network clients;and network control software that executes as an application of the supervisory operating system, wherein the network control software is configured to monitor and/or control network operations in the secondary operating system.
  3. 17
    In a processing system comprising a network device for connecting the processing system to a communications medium, a supervisory operating system, and a secondary operating system, a method comprising:receiving a data packet from the network device;and invoking an event handler after receiving the data packet, wherein the event handler is a task of the supervisory operating system and wherein the event handler performs a method comprising: examining at least one field of the data packet;and determining whether or not to pass the data packet to an application of the secondary operating system, wherein the determination is based at least in part on the content of the at least one field.
  4. 21
    A processing system, comprising:a supervisory operating system;a secondary operating system that provides network services to network clients;network control software that executes as an application of the supervisory operating system;and a control database, wherein the control database enables the network control software to define arbitrary logical connections, wherein the network control software is configured to monitor and/or control network operations in the secondary operating system.
  5. 27
    A processing system, comprising:a supervisory operating system;a secondary operating system, wherein the secondary operating system is executed as an application of the supervisory operating system;and means for monitoring and or controlling network operations in the secondary operating system, wherein the means executes as an application of the supervisory operating system kernel.
  6. 28
    A computer program embodied on a computer readable medium for defeating a denial of service attack, wherein the computer program runs as an application of a realtime supervisory operating system, which runs a secondary operating system as an application thereof, the computer program comprising:a computer code segment that scans all TCP control blocks in the secondary operating system;a computer code segment that, for each of said control blocks, performs the following acts: determines whether the control block indicates that the state of the TCP port associated with the control block is SYN_RECEIVED and increments a counter if it is determined that the state of the TCP port is SYN_RECEIVED;a computer code segment that determines whether the value of the counter is greater than a first configurable threshold;and a computer code segment that sets a denial of service attack warning flag to TRUE if the counter is determined to be greater than the first configurable threshold.