发明授权
- 专利标题: Methods for packet filtering including packet invalidation if packet validity determination not timely made
- 专利标题(中): 包过滤的方法,包括无效的分组有效性确定的包无效
-
申请号: US09611775申请日: 2000-07-07
-
公开(公告)号: US07013482B1公开(公告)日: 2006-03-14
- 发明人: Andrew K. Krumel
- 申请人: Andrew K. Krumel
- 申请人地址: US IL Chicago
- 专利权人: 802 Systems LLC
- 当前专利权人: 802 Systems LLC
- 当前专利权人地址: US IL Chicago
- 代理机构: Loudermilk & Associates
- 主分类号: H04L9/00
- IPC分类号: H04L9/00 ; G06F15/16
摘要:
Methods and systems for firewall/data protection that filters data packets in real time and without packet buffering are disclosed. A data packet filtering hub, which may be implemented as part of a switch or router, receives a packet on one link, reshapes the electrical signal, and transmits it to one or more other links. During this process, a number of filters checks are performed in parallel, resulting in a decision about whether each packet should or should not be invalidated by the time that the last bit is transmitted. To execute this task, the filtering hub performs rules-based filtering on several levels simultaneously, preferably with a programmable logic or other hardware device. Various methods for packet filtering in real time and without buffering with programmable logic are disclosed. The system may include constituent elements of a stateful packet filtering hub, such as microprocessors, controllers, and integrated circuits. The system may be reset, enabled, disabled, configured, and/or reconfigured with toggles or other physical switches. Audio and visual feedback may be provided regarding the operation and status of the system.
信息查询