System and method of resolving discrepancies between diverse firewall designs
    1.
    发明授权
    System and method of resolving discrepancies between diverse firewall designs 失效
    解决不同防火墙设计之间的差异的系统和方法

    公开(公告)号:US07954142B2

    公开(公告)日:2011-05-31

    申请号:US11444017

    申请日:2006-05-31

    IPC分类号: G06F9/00 G06F15/16 G06F17/00

    CPC分类号: H04L63/0263

    摘要: A system, computer-implementable method, and computer-usable medium for resolving discrepancies between diverse firewall designs. In a preferred embodiment of the present invention, a firewall design manager receives at least two designs for a rule-based system and computing at least one functional discrepancy between the at least two designs utilizing decision diagrams.

    摘要翻译: 一种系统,计算机可实现的方法和用于解决不同防火墙设计之间的差异的计算机可用介质。 在本发明的优选实施例中,防火墙设计管理器接收用于基于规则的系统的至少两个设计,并且使用决策图来计算所述至少两个设计之间的至少一个功能差异。

    Method and apparatus for identifying redundant rules in packet classifiers
    2.
    发明授权
    Method and apparatus for identifying redundant rules in packet classifiers 失效
    用于识别分组分类器中的冗余规则的方法和装置

    公开(公告)号:US07793344B2

    公开(公告)日:2010-09-07

    申请号:US11444022

    申请日:2006-05-31

    IPC分类号: G06F15/16

    CPC分类号: H04L63/0263

    摘要: A system, method, and computer-usable medium for removing redundancy from packet classifiers. In a preferred embodiment of the present invention, a packet classifier is implemented as a sequence of rules. A redundancy manager marks at least one upward redundant rule and at least one downward redundant rule. The redundancy manager removes at least one rule marked as upward redundant and at least one rule marked as downward redundant.

    摘要翻译: 用于从分组分类器中去除冗余的系统,方法和计算机可用介质。 在本发明的优选实施例中,分组分类器被实现为一系列规则。 冗余管理器标记至少一个向上的冗余规则和至少一个向下的冗余规则。 冗余管理器删除标记为向上冗余的至少一个规则,以及标记为向下冗余的至少一个规则。

    System and method of firewall design utilizing decision diagrams
    3.
    发明授权
    System and method of firewall design utilizing decision diagrams 失效
    使用决策图的防火墙设计的系统和方法

    公开(公告)号:US07818793B2

    公开(公告)日:2010-10-19

    申请号:US11386365

    申请日:2006-03-22

    IPC分类号: G06F9/00

    CPC分类号: H04L63/0263

    摘要: A system, method and computer-usable medium for designing a firewall to protect a data processing system. A user first specifies a firewall decision diagram. The firewall decision diagram is then reduced and marked. Finally, a firewall is generated from the marked firewall decision diagram.

    摘要翻译: 一种用于设计防火墙以保护数据处理系统的系统,方法和计算机可用介质。 用户首先指定防火墙决策图。 然后减少并标记防火墙决策图。 最后,从标记的防火墙决策图生成防火墙。