发明名称 Incorporating network connection security levels into firewall rules
摘要 Embodiments of the present invention are directed to establishing and/or implementing firewall rules that may employ parameters based on connection security levels for a connection between devices. A firewall may thus provide greater granularity of security and integrate more closely with other security methods to provide better overall security with fewer conflicts.
申请公布号 US8776208(B2) 申请公布日期 2014.07.08
申请号 US201213427436 申请日期 2012.03.22
申请人 Microsoft Corporation 发明人 Yariv Eran;Diaz-Cuellar Gerardo;Abzarian David
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人 Sanders Andrew;Minhas Micky
主权项 1. A method of regulating transmissions using a firewall, the method comprising: receiving a first transmission at the firewall, the firewall being associated with at least a first multi-parameter firewall rule and at least one other multi-parameter firewall rule, each of the first multi-parameter firewall rule and the at least one other multi-parameter firewall rule having at least a first parameter, a connection security parameter relating to one or more types of connection security, a first field that specifies an action for that multi-parameter firewall rule, and another field that specifies whether transmissions not meeting the connection security parameter should be blocked; determining that properties of the first transmission do not meet the first parameter of the first multi-parameter firewall rule; handling the first transmission according to the at least one other multi-parameter firewall rule without determining whether the properties of the first transmission meet the connection security parameter of the first multi-parameter firewall rule; receiving a second transmission at the firewall; determining that properties of the second transmission meet the first parameter of the first multi-parameter firewall rule and do not meet the connection security parameter of the first multi-parameter firewall rule; blocking the second transmission with the firewall without determining whether the properties of the second transmission meet parameters of the at least one other multi-parameter firewall rule if the other field of the first multi-parameter firewall rule specifies that transmissions not meeting the connection security parameter should be blocked; receiving a third transmission at the firewall; determining that properties of the third transmission meet the first parameter of the first multi-parameter firewall rule and meet the connection security parameter of the first multi-parameter firewall rule; and taking an action regarding the third transmission that is specified by the first field of the first multi-parameter firewall rule.
地址 Redmond WA US