US2017126624A1PendingUtilityA1

Firewall with two-phase filtering

Assignee: MICROSOFT TECHNOLOGY LICENSING LLCPriority: Feb 28, 2000Filed: Jan 12, 2017Published: May 4, 2017
Est. expiryFeb 28, 2020(expired)· nominal 20-yr term from priority
H04L 45/74H04L 63/0263H04L 63/0245H04L 63/105Y02T10/86
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Two-phase filtering for a firewall is disclosed. In the first, general phase, a request is filtered to verify one or more of: that the request is pursuant to a supported protocol, that a command of the request is allowed, that the length of the request does not exceed the allowed maximum for the command, and that characters of the request are of an allowable type. Upon first-phase verification, a second phase is invoked that is particular to the protocol of the request. In the second, specialized phase, the request is filtered to verify one or more of the source, the destination, and the content of the request. Upon second-phase verification, the request is allowed to pass. If either first- or second-phase verification fails, then the request is denied.

Claims

exact text as granted — not AI-modified
We claim: 
     
         1 . A method performed on at least one network security device that comprises a processor and memory, the method comprising:
 receiving, by the at least one network security device from a source network, network traffic;   first verifying, by the at least one network security device in response to a protocol of the received network traffic being supported by the at least one network security device, the protocol; and   second verifying, by the at least one network security device in response to the verified protocol and further in response to content of the received network traffic conforming to the verified protocol, the content.   
     
     
         2 . The method of  claim 1  further comprising forwarding, by the at least one network security device in response to the verified content, the received network traffic to a destination network indicated by the received network traffic. 
     
     
         3 . The method of  claim 1  further comprising changing, by the one or more network security devices in response to the verified content, the received network traffic. 
     
     
         4 . The method of  claim 1  where the source network or the destination is a local area network (“LAN”). 
     
     
         5 . The method of  claim 1  where the source network or the destination network is a wide area network (“WAN”). 
     
     
         6 . The method of  claim 1  where the first verifying is further in response to a command comprised by the network traffic being allowable pursuant to the protocol, a length of a request comprised by the network traffic conforming to a maximum length pursuant to the protocol, or characters of the request conforming to those allowable pursuant to the protocol. 
     
     
         7 . The method of  claim 1  where the second verifying is based on a source of the network traffic, a destination of the network traffic, or the content relative to the protocol. 
     
     
         8 . At least one hardware security device comprising:
 one or more processors;   memory;   one or more network interfaces via which the at least one hardware security device is configured for receiving, from a source network, network traffic into the memory;   a first-phase filter via which the hardware security device is configured for first verifying, in response to a protocol of the received network traffic being supported by the at least one hardware security device, the protocol; and   a second-phase filter via which the hardware security device is configured for second verifying, in response to the verified protocol and further in response to content of the received network traffic conforming to the verified protocol, the content.   
     
     
         9 . The at least one hardware security device of  claim 8  further configured for forwarding, via any of the one or more network interfaces in response to the verified content, the received network traffic to a destination network indicated by the received network traffic. 
     
     
         10 . The at least one hardware security device of  claim 8  further configured for changing, via any of the one or more processors in response to the verified content, the received network traffic. 
     
     
         11 . The at least one hardware security device of  claim 8  where the source network or the destination is a local area network (“LAN”). 
     
     
         12 . The at least one hardware security device of  claim 8  where the source network or the destination network is a wide area network (“WAN”). 
     
     
         13 . The at least one hardware security device of  claim 8  where the first verifying is further in response to a command comprised by the network traffic being allowable pursuant to the protocol, a length of a request comprised by the network traffic conforming to a maximum length pursuant to the protocol, or characters of the request conforming to those allowable pursuant to the protocol. 
     
     
         14 . The at least one hardware security device of  claim 8  where the second verifying is based on a source of the network traffic, a destination of the network traffic, or the content relative to the protocol. 
     
     
         15 . At least one hardware computer-readable medium that includes computer-executable instructions that, based on execution by at least one network security device, configure the at least one network security device to perform actions comprising:
 receiving, by the at least one network security device from a source network, network traffic;   first verifying, by the at least one network security device in response to a protocol of the received network traffic being supported by the at least one network security device, the protocol; and   second verifying, by the at least one network security device in response to the verified protocol and further in response to content of the received network traffic conforming to the verified protocol, the content.   
     
     
         16 . The at least one hardware computer-readable medium of  claim 15 , the actions further comprising forwarding, by the at least one network security device in response to the verified content, the received network traffic to a destination network indicated by the received network traffic. 
     
     
         17 . The at least one hardware computer-readable medium of  claim 15 , the actions further comprising changing, by the one or more network security devices in response to the verified content, the received network traffic. 
     
     
         18 . The at least one hardware computer-readable medium of  claim 15  where the source network or the destination is a local area network (“LAN”) or a wide area network (“WAN”). 
     
     
         19 . The at least one hardware computer-readable medium of  claim 15  where the first verifying is further in response to a command comprised by the network traffic being allowable pursuant to the protocol, a length of a request comprised by the network traffic conforming to a maximum length pursuant to the protocol, or characters of the request conforming to those allowable pursuant to the protocol. 
     
     
         20 . The at least one hardware computer-readable medium of  claim 15  where the second verifying is based on a source of the network traffic, a destination of the network traffic, or the content relative to the protocol.

Join the waitlist — get patent alerts

Track US2017126624A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.