×

Security system for network address translation systems

  • US 5,793,763 A
  • Filed: 11/03/1995
  • Issued: 08/11/1998
  • Est. Priority Date: 11/03/1995
  • Status: Expired due to Term
First Claim
Patent Images

1. A method for translating network addresses on packets destined for local hosts on a private network from hosts on an external network, the method comprising the following steps:

  • identifying a global IP destination address on an inbound packet arriving at the private network;

    determining whether the global IP destination address corresponds to any local host on the private network by determining if a translation slot data structure exists for the global IP destination address, which translation slot associates the global IP destination address to a corresponding local IP address for a particular local host which has sent an outbound packet to an external network host on the external network within a defined time period;

    if the inbound packet is found to be intended for the particular local host on the private network which has sent the outbound packet to the external network host within said defined time period, determining whether the inbound packet meets defined security criteria;

    if the inbound packet meets said security criteria, replacing the inbound packet'"'"'s global IP destination address with the corresponding local IP address for the particular local host to which the inbound packet was addressed; and

    forwarding the inbound packet to the particular local host to which the inbound packet was addressed.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×