Firewall with application packet classifier

The invention relates to a firewall with an application packet classifier. An improved system for establishing rules in a firewall (104) for an industrial network is disclosed. Rules are established at an application level, identifying, for example, actions to occur between two devices (100, 108). T...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: BALASUBRAMANIAN SIVARAM, BATKE BRIAN A, JASPER TARYL, PTACEK PETR
Format: Patent
Sprache:chi ; eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:The invention relates to a firewall with an application packet classifier. An improved system for establishing rules in a firewall (104) for an industrial network is disclosed. Rules are established at an application level, identifying, for example, actions to occur between two devices (100, 108). The action may be, for example, read data table or get attribute, and each action may require multiple message packets to be transmitted between the two devices (100, 108) in order to complete. A network device (60) executing the firewall (104) is configured to receive message packets from a sending device and to inspect the message packets to determine which action the sending device is requesting to perform. If the action corresponds to a rule in the database (82), the network device (60) manages communications between the two devices (100, 108) until all message packets have been transmitted. Thus, a single action, or application, may be defined in the rule database (82) to permit multiple data packets to be comm