×

Advanced data guard having independently wrapped components

  • US 6,584,508 B1
  • Filed: 12/30/1999
  • Issued: 06/24/2003
  • Est. Priority Date: 07/13/1999
  • Status: Expired due to Fees
First Claim
Patent Images

1. A computer system that defines a security barrier between a first computer network region and a second computer network region, the computer system comprising:

  • a graphical user interface for presenting a template to a user and receiving content limitations via said template of said graphical user interface, said content limitations including rules and values;

    a first proxy agent running on the computer system, said first proxy agent being operative to communicate with a first computer network region;

    a second proxy agent running on the computer system, said second proxy agent being operative to communicate with a second computer network region;

    a content-based filter application running on the computer system, said content-based filter application being operative to review information that is passed between said first proxy agent and said second proxy agent, wherein the manner in which said content-based filter application reviews said information is user-configurable utilizing said content limitations received via said template of said graphical user interface;

    one or more software wrappers that are operative to constrain behavior of said first proxy agent, said second proxy agent, and said content-based filter application;

    wherein said first proxy agent and said second proxy agent are application level proxy agents;

    wherein said content-based filter application is a protocol-independent analysis application;

    wherein said first proxy agent and said second proxy agent generate and pass files to said content-based filter application;

    wherein said files include extensible markup language code;

    wherein said first proxy agent and said second proxy agent pass information to said content-based filter application using shared memory;

    wherein said content-based filter application modifies said information based on said review;

    wherein components that are positioned between said first and sad second proxy agents and said content-based filter application;

    are queued and dequeued;

    wherein said first proxy agent, said second proxy agent, and said content-based filter application are running on a commercial off the shelf operating system;

    wherein said content-based filter application generates application-specific alerts for an intrusion detection system in response to said review based on said rules and said values of said content limitations.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×