IP Library › Granted Patent US 7,100,201
Granted Patent B2
US 7,100,201 · App. 10/056,629 · Granted Aug 29, 2006

Undetectable firewall

Assignee: Arxceo Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,100,201
App. No.
10/056,629
Granted
Aug 29, 2006
Kind
B2
Abstract

An undetectable firewall for network protection has been developed. The invention includes a method of preventing unauthorized access to a computer system. The firewall receives a data packet and copies its contents exactly. Next, the firewall analyzes the data packet and determines if it is authorized to access the network. If the packet is authorized to access the network, it is sent on to its destination. If the packet is unauthorized to access the network, it is dropped by the firewall.

Claims (39)

1. A method of preventing unauthorized access to a computer system, comprising:

receiving a data packet at a firewall, where the data packet comprises a frame field, a header, a body, and a trailer;

passively copying the data packet at the firewall, where the passive copying leaves the frame field, the header, the body, and the trailer of the data packet unchanged so that there is no indication of the firewall in the data packet;

analyzing the passively copied data packet with the firewall to determine if the data packet is authorized to access the computer system;

sending an authorized data packet to the computer system; and

denying access of an unauthorized data packet to the computer system.

2. The method of claim 1 , further comprising:

dropping the unauthorized data packet.

3. The method of claim 1 , further comprising:

logging the attempted access to the computer system of the unauthorized data packet.

4. The method of claim 1 , wherein the computer system is a network.

5. The method of claim 1 , wherein the data packet is analyzed by a pattern matching system.

6. A method of preventing unauthorized access to a computer system, comprising:

step for receiving data;

step for passively copying the data, where the passive copying leaves the data unchanged so that there is no indication of the firewall in the data packet;

step for analyzing the passively copied data for authorization to access the computer system;

step for allowing access to the computer system for authorized data; and

step for denying access to the computer system for unauthorized data.

7. The method of claim 6 , further comprising:

step dropping unauthorized data.

8. The method of claim 6 , further comprising:

step for logging an attempt to access the computer system by unauthorized data.

9. A method of remotely managing a firewall, comprising:

receiving a control data packet at the firewall from a remote location;

passively copying the control data packet at the firewall, where the passive copying leaves all content of the control data packet unchanged so that there is no indication of the firewall in the control data packet;

analyzing the passively copied control data packet to determine if the control data packet is authorized to access the firewall; and

allowing an authorized control data packet to control the firewall.

10. The method of claim 9 , further comprising:

dropping the authorized control data packet.

11. The method of claim 9 , wherein the control data packet is analyzed for a password.

12. The method of claim 9 , wherein the control data packet contains a false origination address.

13. The method of claim 9 , wherein the control data packet contains a destination address that is protected by the firewall.

14. A method of remotely managing a firewall, comprising:

step for receiving control data at the firewall from a remote location;

step for passively copying the control data, where the passive copying leaves all content of the control data unchanged so that there is no indication of the firewall in the control data;

step for analyzing the passively copied control data to determine if the control data is authorized to access the firewall; and

step for allowing authorized control data to access the firewall.

15. The method of claim 14 , further comprising:

step for dropping the authorized control data.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2004
From: ANGUS ADAIR WOLFGANG, INC.
To: ARXCEO CORPORATION
Reel/Frame 014865/0640 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2002
From: IZATT, DAVID
To: ANGUS ADAIR WOLFGANG INC.
Reel/Frame 012913/0981 →
Continuity (1)
Related Publication 20030140248A1 · Jul 24, 2003