IP Library Patent Application 14093142
Patent Application
App. No. 14/093,142

POLICY-BASED CONTENT FILTERING

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/093,142
Abstract

Methods and systems for processing application-level content of network service protocols are described. According to one embodiment, a firewall device maintains a policy database including multiple policies. The policies includes information regarding an action to take with respect to a network session based on a set of source internet protocol (IP) addresses, a set of destination IP addresses and/or a network service protocol. When the action is to allow the network session, the policy also includes information regarding a configuration scheme defining administrator-configurable content filtering processes to be performed on traffic associated with the network session. Policy-based content filtering is performed by the firewall device by (i) identifying a matching policy for the network session at issue; (ii) identifying multiple content filtering processes to be performed on the traffic based on the configuration scheme associated with the matching policy; and (iii) applying the identified content filtering processes on the traffic.

Claims (32)

1 . A computer-implemented method comprising:

maintaining, by a firewall device, a security policy database including information defining a plurality of firewall security policies, wherein the information defining the plurality of firewall security policies includes, for each firewall security policy of the plurality of firewall security policies, an action to take with respect to a particular network session based on one or more of a set of one or more source internet protocol (IP) addresses, a set of one or more destination IP addresses and a network service protocol;

when the action to take for a firewall security policy of the plurality of firewall security policies is to allow the particular network session to pass through the firewall device, then the firewall security policy also includes information regarding a configuration scheme defining a set of administrator-configurable content filtering processes to be performed on traffic associated with the particular network session; and

performing, by the firewall device, policy-based content filtering of a plurality of network sessions by, for each network session of the plurality of network sessions:

identifying a firewall security policy from among the plurality of firewall security policies that matches traffic associated with the network session;

identifying a plurality of content filtering processes to be performed on the traffic based on the configuration scheme associated with the matching firewall security policy; and

applying the identified plurality of content filtering processes on the traffic.

2 . The method of claim 1 , further comprising:

processing application-level content of a packet stream associated with the network session by

reassembling the application-level content from a plurality of packets of the packet stream; and

scanning the application-level content based on the identified plurality of content filtering processes.

3 . The method of claim 2 , wherein the network service protocol comprises at least one of a group consisting of HyperText Transfer Protocol (HTTP), File Transfer Protocol (FTP), Simple Mail Transfer Protocol (SMTP), Post Office Protocol 3 (POP3), Internet Message Access Protocol (IMAP) and Server Message Block/Common Internet File System (SMB/CIFS).

4 . The method of claim 3 , further comprising receiving from a network administrator, by the firewall device, via a graphical user interface, selections indicative of the content filtering processes to be performed on the traffic associated with the particular network session.

5 . The method of claim 4 , wherein content filtering options available to the network administrator via the graphical user interface include at least antivirus scanning, Uniform Resource Locator (URL) blocking and file blocking.

6 . The method of claim 5 , wherein the content filtering options available to the network administrator via the graphical user interface further include one or more of banned word filtering and spam blocking.

7 . The method of claim 5 , wherein the file blocking comprises blocking transmission of specific file types.

8 . A non-transitory computer-readable storage medium tangibly embodying a set of instructions, which when executed by one or more processors of a firewall system, cause the one or more processors to perform a method comprising:

maintaining a security policy database including information defining a plurality of firewall security policies, wherein the information defining the plurality of firewall security policies includes, for each firewall security policy of the plurality of firewall security policies, an action to take with respect to a particular network session based on one or more of a set of one or more source internet protocol (IP) addresses, a set of one or more destination IP addresses and a network service protocol;

when the action to take for a firewall security policy of the plurality of firewall security policies is to allow the particular network session to pass through the firewall device, then the firewall security policy also includes information regarding a configuration scheme defining a set of administrator-configurable content filtering processes to be performed on traffic associated with the particular network session; and

performing policy-based content filtering of a plurality of network sessions by, for each network session of the plurality of network sessions:

identifying a firewall security policy from among the plurality of firewall security policies that matches traffic associated with the network session;

identifying a plurality of content filtering processes to be performed on the traffic based on the configuration scheme associated with the matching firewall security policy; and

applying the identified plurality of content filtering processes on the traffic.

9 . The computer-readable storage medium of claim 8 , wherein the method further comprises:

processing application-level content of a packet stream associated with the network session by

reassembling the application-level content from a plurality of packets of the packet stream; and

scanning the application-level content based on the identified plurality of content filtering processes.

10 . The computer-readable storage medium of claim 9 , wherein the network service protocol comprises at least one of a group consisting of HyperText Transfer Protocol (HTTP), File Transfer Protocol (FTP), Simple Mail Transfer Protocol (SMTP), Post Office Protocol 3 (POP3), Internet Message Access Protocol (IMAP) and Server Message Block/Common Internet File System (SMB/CIFS).

11 . The computer-readable storage medium of claim 10 , wherein the method further comprises receiving from a network administrator via a graphical user interface selections indicative of the content filtering processes to be performed on the traffic associated with the particular network session.

12 . The computer-readable storage medium of claim 11 , wherein content filtering options available to the network administrator via the graphical user interface include at least antivirus scanning, Uniform Resource Locator (URL) blocking and file blocking.

13 . The computer-readable storage medium of claim 12 , wherein the content filtering options available to the network administrator via the graphical user interface further include one or more of banned word filtering and spam blocking.

14 . The computer-readable storage medium of claim 12 , wherein the file blocking comprises blocking transmission of specific file types.