发明名称 MULTI-LAYER BASED METHOD FOR REALIZING A NETWORK FIRE WALL, PARTICULARLY CONCERNED WITH PERMITTING NON-REQUEST COMMUNICATION WITH A TRUSTED NETWORK DEVICE WHILE CUTTING OFF NON-REQUEST COMMUNICATION FROM OTHER NETWORK DEVICE
摘要 PURPOSE: A multi-layer based method for realizing a network fire wall is provided to include plural layers in a fire wall framework, so that each layer can process packets according to a layer protocol while requesting a fire wall policy to be applied to the packets, then to include a fire wall engine in the firewall framework. CONSTITUTION: A requesting layer for identifying packet parameters issues a classification request for predetermined packets(452). Filters matched with the packet parameters of the classification request are identified(454). Based on the matched filters, whether to drop the packets is determined(456). If so, the packets are dropped. If the packets are not dropped, the requesting layer processes the packets, and changes a packet context data structure(458). If an additional layer does not exist(460), the process is completed.
申请公布号 KR20040105602(A) 申请公布日期 2004.12.16
申请号 KR20040041339 申请日期 2004.06.07
申请人 MICROSOFT CORP. 发明人 PALL, GURDEEP SINGH;RAO, NAGAMPALLI S. S. NARASIMHA;SWANDER, BRIAN D.
分类号 G06F13/00;H04L9/32;H04L12/22;H04L12/66;H04L29/06;(IPC1-7):H04L12/22 主分类号 G06F13/00
代理机构 代理人
主权项
地址