Firewall providing enhanced network security and user transparency
Abstract
The present invention, generally speaking, provides a firewall that achieves maximum network security and maximum user convenience. The firewall employs “envoys” that exhibit the security robustness of prior-art proxies and the transparency and ease-of-use of prior-art packet filters, combining the best of both worlds. No traffic can pass through the firewall unless the firewall has established an envoy for that traffic. Both connection-oriented (e.g., TCP) and connectionless (e.g., UDP-based) services may be handled using envoys. Establishment of an envoy may be subjected to a myriad of tests to “qualify” the user, the requested communication, or both. Therefore, a high level of security may be achieved. The usual added burden of prior-art proxy systems is avoided in such a way as to achieve fall transparency-the user can use standard applications and need not even know of the existence of the firewall. To achieve full transparency, the firewall is configured as two or more sets of virtual hosts. The firewall is, therefore, “multi-homed,” each home being independently configurable. One set of hosts responds to addresses on a first network interface of the firewall. Another set of hosts responds to addresses on a second network interface of the firewall. In one aspect, programmable transparency is achieved by establishing DNS mappings between remote hosts to be accessed through one of the network interfaces and respective virtual hosts on that interface. In another aspect, automatic transparency may be achieved using code for dynamically mapping remote hosts to virtual hosts in accordance with a technique referred to herein as dynamic DNS, or DDNS.
Claims
exact text as granted — not AI-modified1 . A method of operating a system for selectively facilitating a connection between a first computer and a second computer, the method comprising:
receiving a request from the first computer for the connection, the request including a name of the second computer; and initiating one or more verification checks in response to the request including the name, the one or more verification checks for selectively facilitating the connection of the first computer to the second computer.
2 . The method of claim 1 , further comprising:
identifying a network address of the second computer based upon the name of the second computer.
3 . The method of claim 1 , further comprising:
mapping the name of the second computer to one or more network addresses associated with the system.
4 . The method of claim 1 , further comprising:
mapping the name of the second computer to one or more private IP addresses associated with the system.
5 . The method of claim 1 , further comprising:
channel processing any information passed between the first computer and the second computer, wherein the channel processing includes one or more acts of encrypting, decrypting, encoding, decoding, compression, decompression, content filtering, image enhancement, sound enhancement, data enhancement, or virus detection.
6 . A method of operating a third computer network in processing a request from a first computer network for connection to a second computer network, said method comprising:
receiving a request from the first computer network for the connection to the second computer network, the request including a domain name associated with the second computer network; and initiating one or more verification checks in response to the reception of the request including the domain name, the one or more verification checks for selectively facilitating the connection of the first computer network to the second computer network.
7 . The method of claim 6 , further comprising:
identifying one or more network addresses associated with second computer network based upon the domain name associated with the second computer network.
8 . The method of claim 6 , further comprising:
mapping the domain name associated with the second computer network to one or more network addresses associated with the second computer network.
9 . The method of claim 6 , further comprising:
mapping the domain name associated with the second computer network to one or more private IP addresses associated with the second computer network.
10 . The method of claim 6 , further comprising:
channel processing any information passed between the first computer network and the second computer network, wherein the channel processing includes one or more acts of encrypting, decrypting, encoding, decoding, compression, decompression, content filtering, image enhancement, sound enhancement, data enhancement, or virus detection.
11 . A method of communicating data, comprising:
receiving a data unit, said data unit includes a destination address and a first set of information representing a first domain name, said destination address corresponds to each entity in a set of two or more entities, said domain name corresponds to a first entity in the set of two or more entities; translating said first domain name to a first address, said first address corresponds to said first entity and does not correspond to any other entity in said set of two or more entities; and sending said data unit to said first entity using said first address.
12 . A method according to claim 11 , wherein:
said first set of information includes said first domain name.
13 . A method according to claim 11 , wherein:
said first set of information includes said first domain name and a second domain name, said second domain name associated with a source of said data unit.
14 . A method according to claim 11 , wherein:
said first set of information includes a compressed form of said first domain name.
15 . A method according to claim 11 , wherein:
said first set of information includes a encoded form of said first domain name.
16 . A method according to claim 11 , wherein:
said first set of information includes an encrypted form of said first domain name.
17 . A method according to claim 11 , wherein:
said step of translating includes finding a record in a table associated with said first domain name, said record in said table includes first address; and said steps of receiving, translating and sending are performed by a firewall.
18 . A method according to claim 11 , wherein:
said step of sending includes sending said data unit to a firewall.
19 . A method according to claim 11 , wherein:
said destination address is a global address; and said first address is a local address.
20 . A method according to claim 19 , further comprising the step of:
replacing said global address in said data unit with said local address, said step of replacing being performed after said step of translating.
21 . A method according to claim 11 , wherein:
said step of receiving is performed by a second entity, said second entity corresponds to said destination address.Join the waitlist — get patent alerts
Track US2003196122A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.