METHOD OF MANAGING CONNECTIONS IN FIREWALL Russian patent published in 2014 - IPC H04L12/66 

Abstract RU 2517411 C1

FIELD: information technology.

SUBSTANCE: method involves receiving packets from an external network; creating a table of connections; determining the total number of currently established connections; determining the load level of the firewall by comparing the number of established connections with a threshold; determining new and established connections based on two-way exchange of packets between a client and a server; determining connection termination based on processing ICMP messages on errors or flags in the TCP header; dynamically determining current connection timeout values based on the type of the network protocol, the connection status and load level of the firewall; changing the timestamp of processing the last packet if any packet is transmitted within a given connection or within a group of connections; terminating a connection if the timestamp of processing the last packet differs from the current time more than the timeout of said connection.

EFFECT: high reliability of established connections and providing maximum throughput with a high load.

1 tbl

Similar patents RU2517411C1

Title Year Author Number
FIREWALL OPERATING METHOD 2018
  • Oladko Aleksej Yurevich
RU2679227C1
METHOD OF PROTECTING COMPUTING NETWORK FROM UNAUTHORIZED SCANNING AND BLOCKING NETWORK SERVICES 2017
  • Oladko Aleksej Yurevich
RU2648949C1
METHOD OF OPERATING A FIREWALL 2017
  • Oladko Aleksej Yurevich
RU2667805C1
SYSTEM AND METHOD FOR ANALYSING INCOMING TRAFFIC FLOW 2023
  • Chereshnev Vladimir Sergeevich
  • Samokhvalov Viktor Evgenevich
  • Puts Aleksej Yurevich
  • Penikov Pavel Viktorovich
  • Sadovnikov Vladimir Vladimirovich
  • Vaskov Egor Ruslanovich
RU2812087C1
METHOD OF DETECTION OF COMPUTER ATTACKS IN INFORMATION AND TELECOMMUNICATION NETWORK 2013
  • Dement'Ev Vladislav Evgen'Evich
  • Vasjukov Dmitrij Jur'Evich
  • Kotsynjak Mikhail Antonovich
  • Kotsynjak Mikhail Mikhajlovich
  • Lauta Aleksandr Sergeevich
  • Lauta Oleg Sergeevich
RU2531878C1
METHOD FOR PROTECTING INFORMATION AND TELECOMMUNICATION NETWORK FROM PASSIVE COMPUTER ATTACKS 2016
  • Biryukov Andrej Anatolevich
  • Gretsev Valerij Petrovich
  • Davydov Aleksandr Viktorovich
  • Dyakov Sergej Vyacheslavovich
  • Kiselev Oleg Nikolaevich
  • Kuzin Pavel Igorevich
  • Pankin Andrej Alekseevich
  • Potapov Ilya Aleksandrovich
RU2642403C1
METHOD FOR PROCESSING NETWORK PACKETS TO DETECT COMPUTER ATTACKS 2005
  • Agranovskij Aleksandr Vladimirovich
  • Aliev Aleksandr Tofikovich
  • Repalov Sergej Anatol'Evich
  • Selin Roman Nikolaevich
  • Khadi Roman Akhmedovich
RU2304302C2
SYSTEM FOR AGGREGATION OF NETWORK DATA IN COMPUTER NETWORKS 2019
  • Marchenkov Aleksej Aleksandrovich
  • Esin Anton Anatolevich
RU2694025C1
SOFTWARE AND HARDWARE COMPLEX FOR ENSURING SECURED DATA EXCHANGE BETWEEN TECHNICAL EQUIPMENT OF TERMINAL AUTOMATED SYSTEMS 2023
  • Vasinev Dmitrii Aleksandrovich
  • Semenov Aleksei Konstantinovich
RU2809234C1
METHOD OF PROTECTING COMPUTER NETWORKS FROM UNAUTHORISED SCANNING AND BLOCKING OF NETWORK SERVICES (VERSIONS) 2011
  • Avramenko Vladimir Semenovich
  • Kij Andrej Vjacheslavovich
  • Kozlenko Andrej Vladimirovich
  • Kopchak Jan Milanovich
RU2469390C1

RU 2 517 411 C1

Authors

Ivanov Aleksandr Vjacheslavovich

Dates

2014-05-27Published

2012-10-24Filed