Patent · US Expired

Security system for network address translation systems

US7113508B1 · kind B1 · utility

5Cited by
32References
14Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMay 31, 2002
Grant dateSep 26, 2006
Priority date
Expiry dateJul 24, 2023

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/0227
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A system and method are provided for translating local IP addresses to globally unique IP addresses. This allows local hosts in an enterprise network to share global IP addresses from a limited pool of such addresses available to the enterprise. The translation is accomplished by replacing the source address in headers on packets destined for the Internet and by replacing destination address in headers on packets entering the local enterprise network from the Internet. Packets arriving from the Internet are screened by an adaptive security algorithm. According to this algorithm, packets are dropped and logged unless they are deemed nonthreatening. DNS packets and certain types of ICMP packets are allowed to enter local network. In addition, FTP data packets are allowed to enter the local network, but only after it has been established that their destination on the local network initiated an FTP session.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.