US2014007216A1PendingUtilityA1

Methods, systems, and computer readable media for adaptive packet filtering

Assignee: GREAT WALL SYSTEMSPriority: Aug 28, 2009Filed: Jul 11, 2013Published: Jan 2, 2014
Est. expiryAug 28, 2029(~3.1 yrs left)· nominal 20-yr term from priority
Inventors:David K. Ahn
H04L 63/0263H04L 63/1416G06F 21/562H04L 63/0227
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods, systems, and computer readable media for adaptive packet filtering are disclosed. One method includes identifying at least one subset of rules and an ordered set of firewall packet filtering rules that defines a firewall policy such that the subset contains disjoint rules. Disjoint rules are defined as rules whose order can be changed without changing integrity of the firewall policy. Rules in the subset are sorted to statistically decrease the number of comparisons that will be applied to each packet that a firewall encounters. Packets are filtered at the firewall using the sorted rules in the subset by comparing each packet to each of the sorted rules in the subset until the packet is allowed or denied and ceasing the comparing for the packet in response to the packet being allowed or denied and thereby achieving sub-linear searching for packets filtered using the sorted rules in the subset.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method, comprising:
 identifying, from among a plurality of rules that define a packet filtering policy, one or more groups of disjoint rules, wherein each of the one or more groups of disjoint rules comprises at least two rules that when applied to a packet either allow the packet to continue toward its destination or prevent the packet from continuing towards its destination irrespective of an order in which the at least two rules are applied to the packet, a first of the at least two rules specifying a set of network addresses for which packets should be allowed to continue toward their respective destinations, and a second of the at least two rules specifying a set of network addresses for which packets should be prevented from continuing toward their respective destinations;   receiving a plurality of packets;   applying the first of the at least two rules to a first portion of the plurality of packets, the first portion of the plurality of packets having network addresses in the set of network addresses for which packets should be allowed to continue toward their respective destinations;   applying the second of the at least two rules to a second portion of the plurality of packets, the second portion of the plurality of packets having network addresses in the set of network addresses for which packets should be prevented from continuing toward their respective destinations;   allowing the first portion of the plurality of packets to continue toward their respective destinations; and   preventing the second portion of the plurality of packets from continuing toward their respective destinations.

Join the waitlist — get patent alerts

Track US2014007216A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.