Patent · US Active

Method and system for network security

US7562389B1 · kind B1 · utility

11Cited by
33References
29Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJul 30, 2004
Grant dateJul 14, 2009
Priority date
Expiry dateJul 11, 2026

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1408
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

In accordance with one embodiment of the present invention, a method includes receiving a packet at a physical interface of a network security gateway. The packet is tagged with a first VLAN identifier associated with an external network. The method also includes communicating a copy of the packet to a first processor, analyzing the copy of the packet at the first processor to determine whether the packet violates a security condition, and communicating a reply message from the first processor to the interface. The reply message indicates whether the packet violates a security condition. If the packet does not violate a security condition, the method includes re-tagging the packet with a second VLAN identifier associated with a protected network by using a second processor at the physical interface. The method further includes communicating the re-tagged packet to the protected network if the packet does not violate a security condition.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.