06550012 is referenced by 353 patents.

System and methodology providing automated or “proactive” network security (“active” firewall) are described. The system implements methodology for verifying or authenticating communications, especially between network security components thereby allowing those components to share information. In one embodiment, a system implementing an active firewall is provided which includes methodology for verifying or authenticating communications between network components (e.g., sensor(s), arbiter, and actor(s)), using cryptographic keys or digital certificates. Certificates may be used to digitally sign a message or file and, in a complementary manner, to verify a digital signature. At the outset, particular software components that may participate in authenticated communication are specified, including creating a digital certificate for each such software component. Upon detection by a sensor that an event of interest that has occurred in the computer network system, the system may initiate authenticated communication between the sensor component and a central arbiter (e.g., “event orchestrator”) component, so that the sensor may report the event to the arbiter or “brain.” Thereafter, the arbiter (if it chooses to act on that information) initiates authenticated communication between itself and a third software component, an “actor” component (e.g., “firewall”). The arbiter may indicate to the actor how it should handle the event. The actor or firewall, upon receiving the information, may now undertake appropriate action, such as dynamically creating or modifying rules for appropriately handling the event, or it may choose to simply ignore the information.

Title
Active firewall system and methodology
Application Number
9/328177
Publication Number
6550012 (B1)
Application Date
June 8, 1999
Publication Date
April 15, 2003
Inventor
Mark James McArdle
San Carlos
CA, US
Michael Kevin Jones
Sunnyvale
CA, US
Gerhard Eschelbeck
Peuerbach
US
Michael David Varga
Santa Clara
CA, US
Adrian Zidaritz
Danville
CA, US
Emilio Villa
Ben Lomond
CA, US
Agent
Christopher J Hamaty
US
Patrick J S Inouye
US
Assignee
Network Associates
CA, US
IPC
G06F 11/30
View Original Source