Real time firewall security
First Claim
1. A method of conducting an analog to analog communication between an originating terminal and a terminating terminal through a packet switched network coupled to a switched telephone network via at least one gateway wherein said terminating terminal is coupled to said switched telephone network;
- comprising;
establishing a static filter device between said gateway and said originating terminal;
transmitting through said filter device to said gateway a request for the establishment of a communication path through said gateway and through said telephone network to said terminating terminal;
engaging in a signaling dialog between said originating terminal and said gateway through said filter device;
generating a real time copy of at least a portion of said signaling dialog;
creating a filter device control signal containing parameters derived from said dialog;
configuring said filter device pursuant to said filter control signal;
conducting said analog to analog communication between said originating terminal and said terminating terminal via packet signaling through said packet switched network and said filter device to said gateway;
filtering said packet signaling through the configured filter device and blocking packet signals that fail to conform to the configuration of said static filter created from said dialog.
5 Assignments
0 Petitions
Accused Products
Abstract
A system and method for conducting a voice communication through a hybrid network which includes a packet internetwork, such as the Internet, connected to a circuit switched telephone network. The packet internetwork is connected to the switched telephone network through a static filter device, a packet switch, and a telephone network controlled gateway. A control processor is connected to the packet switch and to the filter device. The filter device generates a real time copy of call set up signaling dialog between the party requesting connection and the gateway which passes through or to the filter device. This duplicate of set up signaling is delivered from the filter device through the packet switch to the control processor. The control processor generates therefrom a filter device control signal which specifies the filter parameters derived from the set-up signaling dialog. This filter device control signal is delivered to the filter device and reconfigures the filter device to set filter parameters which are customized to the specific communication. The filter device thereupon filters the conversation stream of packetized voice.
85 Citations
33 Claims
-
1. A method of conducting an analog to analog communication between an originating terminal and a terminating terminal through a packet switched network coupled to a switched telephone network via at least one gateway wherein said terminating terminal is coupled to said switched telephone network;
- comprising;
establishing a static filter device between said gateway and said originating terminal;
transmitting through said filter device to said gateway a request for the establishment of a communication path through said gateway and through said telephone network to said terminating terminal;
engaging in a signaling dialog between said originating terminal and said gateway through said filter device;
generating a real time copy of at least a portion of said signaling dialog;
creating a filter device control signal containing parameters derived from said dialog;
configuring said filter device pursuant to said filter control signal;
conducting said analog to analog communication between said originating terminal and said terminating terminal via packet signaling through said packet switched network and said filter device to said gateway;
filtering said packet signaling through the configured filter device and blocking packet signals that fail to conform to the configuration of said static filter created from said dialog. - View Dependent Claims (2, 3, 4, 5, 6)
- comprising;
-
7. A method of conducting a voice communication between an originating terminal and a terminating terminal through a packet switched network coupled to a switched telephone network via at least one gateway wherein said terminating terminal is coupled to said switched telephone network;
- comprising;
establishing a static filter device between said gateway and said originating terminal;
transmitting through said filter device to said gateway a request for the establishment of a communication path through said gateway and through said telephone network to said terminating terminal;
engaging in a call set up signaling dialog between said originating terminal and said gateway through said filter device;
generating a real time copy of at least a portion of said set up signaling dialog;
creating a filter device control signal containing parameters derived from said set up dialog;
configuring said filter device pursuant to said filter device control signal;
conducting said voice communication between said originating terminal and said terminating terminal via packet signaling through said packet switched network and said filter device to said gateway;
filtering said packet signaling through the configured filter device and blocking packet signals that fail to conform to the configuration of said filter device created from said dialog. - View Dependent Claims (8, 9, 10, 11, 12)
- comprising;
-
13. A system for conducting a voice communication through a hybrid network including:
-
a packet internetwork;
a switched telephone network connected to the packet internetwork via a static filter device, a packet switch, and a gateway, said telephone network including a central office switching system connected to a voice terminal; and
a control processor connected to said packet switch and to said filter device;
wherein said filter device generates a real time copy of call set up signaling therethrough, which copy of set up signaling is delivered through said packet switch to said control processor, said control processor generating therefrom a filter device control signal delivered to said filter device and reconfiguring said filter device.- View Dependent Claims (14, 15, 16, 17, 18, 19, 20, 21)
-
-
22. In a communication system comprising a packet internetwork, a switched telephone network connected to the packet internetwork via a static filter device and a gateway, and a control processor connected to said filter device;
-
a method comprising;
transmitting from said filter device to said control processor a real time copy of call set up signaling passing through said filter device, generating in said control processor a filter device control signal and delivering said filter device control signal to said filter device, reconfiguring said filter device in accord with said filter device control signal, and filtering through said reconfigured filter device a packetized voice communication signal. - View Dependent Claims (23, 24)
-
-
25. In a communication system comprising a packet internetwork, a switched telephone network connected to the packet internetwork via a static filter device, a packet switch, and a gateway, and a control processor connected to said filter device;
-
a method comprising;
transmitting from said filter device to said packet switch duplicate streams of call set up signaling;
switching one of said streams to said gateway and the other of said streams to said control processor;
generating in said control processor a filter device control signal and delivering said filter device control signal to said filter device;
reconfiguring said filter device in accord with said filter device control signal; and
filtering through said reconfigured filter device the packetized voice communication set up by said set up signaling. - View Dependent Claims (26, 27, 28, 29, 30, 31, 32)
-
-
33. A firewall device for providing protection of a network object to which said firewall device is connected, comprising a static filter device, a control processor, and a packet switch, said static filter device providing real time duplication of a packet stream passed therethrough and through said packet switch, said static filter device sending the duplicate packet stream through said packet switch to said control processor, said control processor sending a filter device control signal to said filter device based on information obtained from said duplicate packet stream causing said filter device to be reconfigured in accord with said filter device control signal.
Specification