METHOD OF PROTECTING COMPUTING NETWORK FROM UNAUTHORIZED SCANNING AND BLOCKING NETWORK SERVICES Russian patent published in 2018 - IPC G06F12/14 H04L12/66 H04L12/22 

Abstract RU 2648949 C1

FIELD: information technology.

SUBSTANCE: method of protecting a computing network from unauthorized transmission of information, scanning and blocking of network services, where a gateway computer with a firewall is installed on the input of the protected network, in this firewall a set of A allowed for use application-level protocols is defined and it contains a monitoring means configured to determine the application protocol used in the network connection, contains the steps: receiving from the sender with the address S1 for the recipient with the address R1 of the network packet P1 having the number of the encapsulated transport layer protocol corresponding to the TCP protocol number and the set SYN flag; blocking the transmission of the network packet P1 to the recipient with the address R1; sending via the firewall to the sender with the address S1 of the network packet P2 generated in accordance with the TCP protocol, with the SYN and ACK flags set and having the address of the sender R1; receiving from the sender with the address S1 of the network packet P3 with the number of the encapsulated transport level protocol corresponding to the TCP protocol number and the set ACK flag indicating the completion of the procedure for establishing the TCP session; receiving from the sender with the address S1 of the network packet P4, which contains the data D; determination, using the means of monitoring the fact of using in the data D protocol of the application layer from the set A; if the fact of use is established, the network packet P5 generated in accordance with the TCP protocol with the SYN flag set and having the address of the sender S1 sent from the firewall to the recipient with the address R1; receiving from the sender with the address R1 of the network packet P6 with the number of the encapsulated transport level protocol corresponding to the TCP protocol number and the set SYN and ACK flags; sending from the firewall to the recipient with the address R1 of the network packet P7 generated in accordance with the TCP protocol with the ACK flag indicating the completion of the procedure for establishing the TCP session and having the address of the sender S1; sending from the firewall to the recipient with the address R1 of the network packet P8 generated in accordance with the TCP protocol having the address of the sender S1 and containing the data D in an unchanged form; the transparent relay of packets between the sender with the address S1 and the addressee with the address R1; otherwise, the connection between the sender with the address S1 and the addressee with the address R1 is reset.

EFFECT: increased security of the computing network.

5 cl

Similar patents RU2648949C1

Title Year Author Number
METHOD OF OPERATING A FIREWALL 2017
  • Oladko Aleksej Yurevich
RU2667805C1
METHOD FOR PROCESSING NETWORK PACKETS TO DETECT COMPUTER ATTACKS 2005
  • Agranovskij Aleksandr Vladimirovich
  • Aliev Aleksandr Tofikovich
  • Repalov Sergej Anatol'Evich
  • Selin Roman Nikolaevich
  • Khadi Roman Akhmedovich
RU2304302C2
FIREWALL OPERATING METHOD 2018
  • Oladko Aleksej Yurevich
RU2679227C1
METHOD OF PROTECTING COMPUTER NETWORK 2010
  • Grechishnikov Evgenij Vladimirovich
  • Milaja Irina Vladimirovna
  • Sanin Igor' Jur'Evich
  • Starodubtsev Jurij Ivanovich
RU2422892C1
METHOD OF MANAGING CONNECTIONS IN FIREWALL 2012
  • Ivanov Aleksandr Vjacheslavovich
RU2517411C1
METHOD FOR PROCESSING NETWORK TRAFFIC DATAGRAMS FOR DELIMITING ACCESS TO INFORMATIONAL AND COMPUTING RESOURCES OF COMPUTER NETWORKS 2006
  • Khadi Roman Akhmedovich
  • Lezhnev Aleksandr Vasil'Evich
  • Mamaj Vladimir Ivanovich
  • Selin Roman Nikolaevich
RU2314562C1
METHOD OF PROTECTING COMPUTER NETWORKS FROM UNAUTHORISED SCANNING AND BLOCKING OF NETWORK SERVICES (VERSIONS) 2011
  • Avramenko Vladimir Semenovich
  • Kij Andrej Vjacheslavovich
  • Kozlenko Andrej Vladimirovich
  • Kopchak Jan Milanovich
RU2469390C1
METHOD OF PROTECTING COMPUTER NETWORKS 2018
  • Barabanov Vladislav Valerevich
  • Efremov Anton Andreevich
  • Maksimov Roman Viktorovich
  • Orekhov Dmitrij Nikolaevich
  • Voronchikhin Ivan Sergeevich
  • Sokolovskij Sergej Petrovich
RU2696330C1
METHOD OF COMPUTER NETWORKS PROTECTION 2017
  • Maksimov Roman Viktorovich
  • Orekhov Dmitrij Nikolaevich
  • Proskuryakov Igor Sergeevich
  • Sokolovskij Sergej Petrovich
RU2649789C1
METHOD OF PROCESSING NETWORK TRAFFIC DATAGRAMS FOR PROTECTING INFORMATION COMPUTER SYSTEMS (VERSIONS) 2012
  • Andrianov Vladimir Igorevich
  • Balenko Ol'Ga Aleksandrovna
  • Bukharin Vladimir Vladimirovich
  • Dvorjadkin Vladimir Vladimirovich
  • Kir'Janov Aleksandr Vladimirovich
  • Starodubtsev Jurij Ivanovich
  • Truskov Stanislav Sergeevich
RU2472217C1

RU 2 648 949 C1

Authors

Oladko Aleksej Yurevich

Dates

2018-03-28Published

2017-03-10Filed