File-Driven Content Filtering for Secure Network Servers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current content filtering systems between networks of different security levels are expensive to develop and maintain due to customized software filters, requiring rewriting of executable software for rule changes, which is inefficient and costly.

Innovation Solution

A file-driven approach using a filtering language for describing policies, supported by a high-assurance software implementation that enables filtering of data between networks, allowing for flexible and affordable content filtering across security domains, including XML, email, and well-formatted binary messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If customized software filters are used for content filtering between networks of different security levels, then filtering functionality is achieved, but development and maintenance costs are high

Engineering Contradiction:
Improvefiltering functionalityVSAvoiddevelopment and maintenance cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments the filtering system into two independent parts: a trusted filtering engine that enforces security policies and a separate filter description language that defines filtering rules. This segmentation allows the filtering logic to be modified by simply changing the description language files rather than rewriting the entire software filter, significantly reducing development and maintenance costs while maintaining reliable filtering functionality.

Inventive Principle:
Principle #1Segmentation

2Reliability

If customized software filters are used for content filtering, then filtering rules can be enforced, but rule changes require rewriting executable software

Engineering Contradiction:
Improvefiltering rule enforcementVSAvoidrule change flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the filtering rules from the executable software and places them in a separate filter description language. This extraction allows filtering rules to be modified independently by simply updating the description language files, eliminating the need to rewrite executable software while maintaining secure rule enforcement through the trusted filtering engine.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent combines a trusted filtering engine with a flexible filter description language into an integrated system. The filtering engine provides secure rule enforcement while the description language provides easy rule modification capability. This merging resolves the contradiction by allowing both reliable rule enforcement and flexible rule changes to coexist in a unified architecture.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of manufacture

If file-driven filtering approach is implemented, then development cost is reduced, but system assurance level must be maintained

Engineering Contradiction:
Improvedevelopment costVSAvoidsystem assurance level
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces a filter description language as an intermediary between the untrusted filter rules and the trusted filtering engine. This intermediary allows inexpensive file-driven rule definitions while the trusted engine verifies and enforces these rules, maintaining system assurance levels despite using a cost-effective file-driven approach.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8185944B2High-assurance file-driven content filtering for secure network server
Publication Date: 2012.05.22 THE BOEING CO
  • US8185944B2 patent drawing
  • US8185944B2 patent drawing
  • US8185944B2 patent drawing

AI summary

A server for transferring data between networks. The server is programmed to perform the following steps: (a) creating a receiving process, a filtering process and a forwarding process, the filtering process being dictated by a file that specifies filtering rules, wherein: (b) the receiving process receives data transmitted from a source host; (c) the filtering process filters the transmitted data based on the filtering rules; and (d) the forwarding process forwards only filtered data to a destination host.