File-Driven Content Filtering for Secure Network Servers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current content filtering systems between networks of different security levels are expensive to develop and maintain due to customized software filters, requiring rewriting of executable software for rule changes, which is inefficient and costly.
Innovation Solution
A file-driven approach using a filtering language for describing policies, supported by a high-assurance software implementation that enables filtering of data between networks, allowing for flexible and affordable content filtering across security domains, including XML, email, and well-formatted binary messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If customized software filters are used for content filtering between networks of different security levels, then filtering functionality is achieved, but development and maintenance costs are high
Solution Approach 1:
The patent segments the filtering system into two independent parts: a trusted filtering engine that enforces security policies and a separate filter description language that defines filtering rules. This segmentation allows the filtering logic to be modified by simply changing the description language files rather than rewriting the entire software filter, significantly reducing development and maintenance costs while maintaining reliable filtering functionality.
2Reliability
If customized software filters are used for content filtering, then filtering rules can be enforced, but rule changes require rewriting executable software
Solution Approach 1:
The patent extracts the filtering rules from the executable software and places them in a separate filter description language. This extraction allows filtering rules to be modified independently by simply updating the description language files, eliminating the need to rewrite executable software while maintaining secure rule enforcement through the trusted filtering engine.
Solution Approach 2:
The patent combines a trusted filtering engine with a flexible filter description language into an integrated system. The filtering engine provides secure rule enforcement while the description language provides easy rule modification capability. This merging resolves the contradiction by allowing both reliable rule enforcement and flexible rule changes to coexist in a unified architecture.
3Ease of manufacture
If file-driven filtering approach is implemented, then development cost is reduced, but system assurance level must be maintained
Solution Approach 1:
The patent introduces a filter description language as an intermediary between the untrusted filter rules and the trusted filtering engine. This intermediary allows inexpensive file-driven rule definitions while the trusted engine verifies and enforces these rules, maintaining system assurance levels despite using a cost-effective file-driven approach.
Data Source
AI summary
A server for transferring data between networks. The server is programmed to perform the following steps: (a) creating a receiving process, a filtering process and a forwarding process, the filtering process being dictated by a file that specifies filtering rules, wherein: (b) the receiving process receives data transmitted from a source host; (c) the filtering process filters the transmitted data based on the filtering rules; and (d) the forwarding process forwards only filtered data to a destination host.


