发明名称 Methods and apparatus for testing dynamic network firewalls
摘要 A test method for Internet-Protocol packet networks that verifies the proper functioning of a dynamic pinhole filtering implementation as well as quantifying network vulnerability statistically, as pinholes are opened and closed is described. Specific potential security vulnerabilities that may be addressed through testing include: 1) excessive delay in opening pinholes, resulting in an unintentional denial of service; 2) excessive delay in closing pinholes, creating a closing delay window of vulnerability; 3) measurement of the length of various windows of vulnerability; 4) setting a threshold on a window of vulnerability such that it triggers an alert when a predetermined value is exceeded; 5) determination of incorrectly allocated pinholes, resulting in a denial of service; 6) determining the opening of extraneous pinhole/IP address combinations through a firewall which increase the network vulnerability through unrecognized backdoors; and 7) determining the inability to correlate call state information with dynamically established rules in the firewall.
申请公布号 US7076393(B2) 申请公布日期 2006.07.11
申请号 US20030678779 申请日期 2003.10.03
申请人 VERIZON SERVICES CORP. 发明人 ORMAZABAL GASTON S.;HARVEY EDWARD P.;SYLVESTER JAMES E.
分类号 G06F19/00;H04L29/06 主分类号 G06F19/00
代理机构 代理人
主权项
地址