发明授权
- 专利标题: Access control for networks
- 专利标题(中): 网络访问控制
-
申请号: US09174200申请日: 1998-10-16
-
公开(公告)号: US06219706B1公开(公告)日: 2001-04-17
- 发明人: Serene Fan , Steve Truong
- 申请人: Serene Fan , Steve Truong
- 主分类号: G06F15173
- IPC分类号: G06F15173
摘要:
An access control system (a firewall) controls traffic to and from a local network. The system is implemented on a dedicated network device such as a router positioned between a local network and an external network, usually the Internet, or between one or more local networks. In this procedure, access control items are dynamically generated and removed based upon the context of an application conversation. Specifically, the system dynamically allocates channels through the firewall based upon its knowledge of the type of applications and protocol (context) employed in the conversation involving a node on the local network. Further, the system may selectively examine packet payloads to determine when new channels are about to be opened. In one example, the firewall employs different rules for handling SMTP (e-mail using a single channel having a well-known port number) sessions, FTP sessions (file transfer using a single control channel having a well known port number and using one or more data channels having arbitrary port numbers), and H.323 (video conferencing using multiple control channels and multiple data channels, which use arbitrary port numbers) sessions.
信息查询