Firewall with two-phase filtering
Abstract
Two-phase filtering for a firewall is disclosed. In the first, general phase, a request is filtered to verify one or more of: that the request is pursuant to a supported protocol, that a command of the request is allowed, that the length of the request does not exceed the allowed maximum for the command, and that characters of the request are of an allowable type. Upon first-phase verification, a second phase is invoked that is particular to the protocol of the request. In the second, specialized phase, the request is filtered to verify one or more of the source, the destination, and the content of the request. Upon second-phase verification, the request is allowed to pass. If either first- or second-phase verification fails, then the request is denied.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A method performed on at least one network security device that comprises a processor and memory, the method comprising:
receiving, by the at least one network security device from a source network, network traffic; first verifying, by the at least one network security device in response to a protocol of the received network traffic being supported by the at least one network security device, the protocol; and second verifying, by the at least one network security device in response to the verified protocol and further in response to content of the received network traffic conforming to the verified protocol, the content.
2 . The method of claim 1 further comprising forwarding, by the at least one network security device in response to the verified content, the received network traffic to a destination network indicated by the received network traffic.
3 . The method of claim 1 further comprising changing, by the one or more network security devices in response to the verified content, the received network traffic.
4 . The method of claim 1 where the source network or the destination is a local area network (“LAN”).
5 . The method of claim 1 where the source network or the destination network is a wide area network (“WAN”).
6 . The method of claim 1 where the first verifying is further in response to a command comprised by the network traffic being allowable pursuant to the protocol, a length of a request comprised by the network traffic conforming to a maximum length pursuant to the protocol, or characters of the request conforming to those allowable pursuant to the protocol.
7 . The method of claim 1 where the second verifying is based on a source of the network traffic, a destination of the network traffic, or the content relative to the protocol.
8 . At least one hardware security device comprising:
one or more processors; memory; one or more network interfaces via which the at least one hardware security device is configured for receiving, from a source network, network traffic into the memory; a first-phase filter via which the hardware security device is configured for first verifying, in response to a protocol of the received network traffic being supported by the at least one hardware security device, the protocol; and a second-phase filter via which the hardware security device is configured for second verifying, in response to the verified protocol and further in response to content of the received network traffic conforming to the verified protocol, the content.
9 . The at least one hardware security device of claim 8 further configured for forwarding, via any of the one or more network interfaces in response to the verified content, the received network traffic to a destination network indicated by the received network traffic.
10 . The at least one hardware security device of claim 8 further configured for changing, via any of the one or more processors in response to the verified content, the received network traffic.
11 . The at least one hardware security device of claim 8 where the source network or the destination is a local area network (“LAN”).
12 . The at least one hardware security device of claim 8 where the source network or the destination network is a wide area network (“WAN”).
13 . The at least one hardware security device of claim 8 where the first verifying is further in response to a command comprised by the network traffic being allowable pursuant to the protocol, a length of a request comprised by the network traffic conforming to a maximum length pursuant to the protocol, or characters of the request conforming to those allowable pursuant to the protocol.
14 . The at least one hardware security device of claim 8 where the second verifying is based on a source of the network traffic, a destination of the network traffic, or the content relative to the protocol.
15 . At least one hardware computer-readable medium that includes computer-executable instructions that, based on execution by at least one network security device, configure the at least one network security device to perform actions comprising:
receiving, by the at least one network security device from a source network, network traffic; first verifying, by the at least one network security device in response to a protocol of the received network traffic being supported by the at least one network security device, the protocol; and second verifying, by the at least one network security device in response to the verified protocol and further in response to content of the received network traffic conforming to the verified protocol, the content.
16 . The at least one hardware computer-readable medium of claim 15 , the actions further comprising forwarding, by the at least one network security device in response to the verified content, the received network traffic to a destination network indicated by the received network traffic.
17 . The at least one hardware computer-readable medium of claim 15 , the actions further comprising changing, by the one or more network security devices in response to the verified content, the received network traffic.
18 . The at least one hardware computer-readable medium of claim 15 where the source network or the destination is a local area network (“LAN”) or a wide area network (“WAN”).
19 . The at least one hardware computer-readable medium of claim 15 where the first verifying is further in response to a command comprised by the network traffic being allowable pursuant to the protocol, a length of a request comprised by the network traffic conforming to a maximum length pursuant to the protocol, or characters of the request conforming to those allowable pursuant to the protocol.
20 . The at least one hardware computer-readable medium of claim 15 where the second verifying is based on a source of the network traffic, a destination of the network traffic, or the content relative to the protocol.Join the waitlist — get patent alerts
Track US2017126624A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.