US2001014150A1PendingUtilityA1

Tightly integrated cooperative telecommunications firewall and scanner with distributed capabilities

Priority: Dec 11, 1998Filed: Jan 16, 2001Published: Aug 16, 2001
Est. expiryDec 11, 2018(expired)· nominal 20-yr term from priority
H04L 63/20H04L 63/0218Y10S707/99939H04M 3/22H04M 2203/2066H04M 3/42314H04L 63/0263H04L 63/1408H04M 7/0078H04M 3/436H04M 3/38
38
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method for implementing a fully integrated and cooperative telecommunications firewall/scanner that can be deployed either as a standalone device, or over a large-scale distributed client-server architecture is described. In addition to providing enhanced telecommunications firewall and scanner security capabilities, the integrated telecommunications firewall/scanner provides the capability to ensure implementation of a corporate-dictated security structure, and event visibility and report consolidation requirements, across a globally-distributed enterprise, using policy-based enforcement of a Security Policy. In the most basic configuration, the integrated firewall/scanner performs continuous security access monitoring and control functions, keyword and content monitoring and control functions, and remote access authentication, initiating coordinated vulnerability assessments, as well as automatic synchronous adjustments to the Security Policy in response to the vulnerability assessment results. Additionally, firewall and scanner actions, assessment results, and responses can be consolidated in detailed or summary reports for use by security administrators for trend analysis and security posture decision-making. The same Security Policy is used by both the firewall and the scanner components of the integrated firewall/scanner during both their cooperative and independent operations. between end-user stations and their respective circuits into the public switched telephone network (“PSTN”), with coordinated system identification. Vulnerability assessment scanning, and automatic security policy update capabilities.

Claims

exact text as granted — not AI-modified
What is claimed is:  
     
         1 . An integrated telephony firewall and scanner system for controlling and logging access between an enterprise's end-user stations and their respective circuits into a public switched telephone network (“PSTN”) via a plurality of extensions, the system comprising 
 means for defining a security policy comprising a security rule base, a results response policy, and groups of extensions, wherein the security rule base comprises security rules specifying actions to be taken based upon at least one attribute of a call on an extension, the results response policy comprises results response rules specifying actions to be taken based on results of a vulnerability assessment (“VA”)performed on an extension, and the groups of extensions each comprise a set of extensions having at least one feature in common:  
 means for detecting a call on an extension to determine attributes associated with the call;  
 means for performing actions based upon the call attributes in accordance with the security rules defined for the extension;  
 means for requesting a VA on the extension;  
 means responsive to the VA request for performing a VA on the extension and generating VA results; and  
 means for updating the security policy based on the VA results in accordance with the results response policy.  
 
     
     
         2 . The system of    claim 1    wherein the means for updating the security policy comprises means for updating the security policy by moving the extension from a first one of the groups of extensions to a second one of the groups of extension.  
     
     
         3 . The system of    claim 1    wherein the groups of extensions include an voice-only group comprising extensions designated exclusively for voice calls, a secure modem group comprising extensions having connected thereto modems that have been deemed authorized and secure, an insecure modem group comprising extensions having connected thereto modems that have been deemed insecure, and an unauthorized modem group comprising extensions having connected thereto modems that have not been deemed insecure, but that are not authorized.  
     
     
         4 . The system of    claim 1    wherein the means for performing a VA on the extension comprises means for attempting to penetrate a modem connected to the extension.  
     
     
         5 . The system of    claim 4    wherein the VA results indicate whether or not the penetration attempt was successful.  
     
     
         6 . The system of    claim 1    further comprising means responsive to the VA request for building a profile, the profile defining the type of VA to be performed.  
     
     
         7 . The system of    claim 1    wherein the VA results indicate that the penetration attempt was successful and the updating the security policy comprises moving the extension from a first group to an insecure modem group.  
     
     
         8 . The system of    claim 1    wherein the results response rules specify actions selected from the group consisting of update the security policy, log the VA results, and notify a designated person of the VA results.  
     
     
         9 . The system of    claim 1    wherein the at least one call attribute is the call-type and wherein the security rules specify the actions of permitting or denying a call.  
     
     
         10 . The system of    claim 1    wherein the at least one call attribute is selected from the group consisting of call-type, call date, call time, call duration, station extension, inbound number, and outbound number dialed.  
     
     
         11 . The system of    claim 1    wherein security rules specify actions selected from the group consisting of permit or deny the call, redirect the call, log the call, and notify a designated person.  
     
     
         12 . A method of implementing an integrated telephony firewall and scanner system for controlling and logging access between an enterprise's end-user stations and their respective circuits into a public switched telephone network (“PSTN”) via a plurality of extensions, the method comprising: 
 defining a security policy comprising a security rule base, a results response policy, and groups of extensions wherein the security rule base comprises security rules specifying actions to be taken based upon at least one attribute of a call on an extension, the results response policy comprises results response rules specifying actions to be taken based on results of a vulnerability assessment (“VA”) performed on an extension, and the groups of extensions each comprise a set of extensions having at least one feature in common;  
 detecting a call on an extension to determine attributes associated with the call;  
 performing actions based upon the call attributes in accordance with the security rules defined for the extension;  
 requesting a VA on the extension;  
 performing a VA on the extension and generating VA results responsive to the VA request; and  
 updating the security policy based on the VA results in accordance with the results response policy.  
 
     
     
         13 . The method of    claim 12    wherein the updating the security policy comprises updating the security policy by moving the extension from a first one of the groups of extensions to a second one of the groups of extension.  
     
     
         14 . The method of    claim 12    wherein the groups of extensions include an voice-only group comprising extensions designated exclusively for voice calls, a secure modem group comprising extensions having connected thereto modems that have been deemed authorized and secure, an insecure modem group comprising extensions having connected thereto modems that have been deemed insecure, and an unauthorized modem group comprising extensions having connected thereto modems that have not been deemed insecure, but that are not authorized.  
     
     
         15 . The method of    claim 12    wherein the performing a VA on the extension comprises attempting to penetrate a modem connected to the extension.  
     
     
         16 . The method of    claim 15    wherein the VA results indicate whether or not the penetration attempt was successful.  
     
     
         17 . The method of    claim 12    further comprising building a profile responsive to the VA request, the profile defining the type of VA to be performed.  
     
     
         18 . The method of    claim 12    wherein the VA results indicate that the penetration attempt was successful and the updating the security policy comprises moving the extension from a first group to an insecure modem group.  
     
     
         19 . The method of    claim 12    wherein the results response rules specify actions selected from the group consisting of update the security policy, log the VA results, and notify a designated person of the VA results.  
     
     
         20 . The method of    claim 12    wherein the at least one call attribute is the call-type and wherein the security rules specify the actions of permitting or denying a call.  
     
     
         21 . The method of    claim 12    wherein the at least one call attribute is selected from the group consisting of call-type, call date, call time, call duration, station extension, inbound number, and outbound number dialed.  
     
     
         22 . The method of    claim 12    wherein security rules specify actions selected from the group consisting of permit or deny the call, redirect the call, log the call, and notify a designated person.  
     
     
         23 . An integrated telephony firewall and scanner system for controlling and logging access between an enterprise's end-user stations and their respective circuits into a public switched telephone network (“PSTN”) via a plurality of extensions, the system comprising: 
 a firewall/scanner client for defining a security policy comprising a security rule base, a results response policy, and groups of extensions, wherein the security rule base comprises security rules specifying actions to be taken based upon at least one attribute of a call on an extension, the results response policy comprises results response rules specifying actions to be taken based on results of a vulnerability assessment (“VA”) performed on an extension, and the groups of extensions each comprise a set of extensions having at least one feature in common;  
 a line sensor connected to said firewall/scanner client via a firewall management server for detecting a call on an extension to determine attributes associated with the call, performing actions based upon the call attributes in accordance with the security rules defined for the extension, and notifying the firewall management server that the actions have been performed, responsive to which notification the firewall management server requests a VA on the extension;  
 a scanner management server for receiving the VA request and, responsive to the VA request, building a profile and pushing the profile to a dialer for performing a VA on the extension and generating VA results to the firewall management server;  
 wherein the firewall management server updates the security policy based on the VA results in accordance with the results response policy.  
 
     
     
         24 . The system of    claim 23    wherein the firewall management server updates the security policy by moving the extension from a first one of the groups of extensions to a second one of the groups of extension.  
     
     
         25 . The system of    claim 23    wherein the groups of extensions include an voice-only group comprising extensions designated exclusively for voice calls, a secure modem group comprising extensions having connected thereto modems that have been deemed authorized and secure, an insecure modem group comprising extensions having connected thereto modems that have been deemed insecure, and an unauthorized modem group comprising extensions having connected thereto modems that have not been deemed insecure, but that are not authorized.  
     
     
         26 . The system of    claim 23    wherein the dialer performs a VA on the extension by attempting to detect, identify, and penetrate a modem connected to the extension.  
     
     
         27 . The system of    claim 26    wherein the VA results indicate whether or not the penetration attempt was successful.  
     
     
         28 . The system of    claim 23    wherein the VA results indicate that the penetration attempt was successful and the updating the security policy comprises moving the extension from a first group to an insecure modem group.  
     
     
         29 . The system of    claim 23    wherein the results response rules specify actions selected from the group consisting of update the security policy, log the VA results, and notify a designated person of the VA results.  
     
     
         30 . The system of    claim 23    wherein the at least one call attribute is the call-type and wherein the security rules specify the actions of permitting or denying a call.  
     
     
         31 . The system of    claim 23    wherein the at least one call attribute is selected from the group consisting of call-type, call date, call time, call duration, station extension, inbound number, and outbound number dialed.  
     
     
         32 . The system of    claim 23    wherein security rules specify actions selected from the group consisting of permit or deny the call, redirect the call, log the call, and notify a designated person.

Join the waitlist — get patent alerts

Track US2001014150A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.