Methods, systems and computer-readable medium that facilitate resolving endpoint hostnames in testing-environment with firewalls, network address translations () or clouds
Abstract
The invention relates to a method, a system and a computer-readable medium intended to facilitate the resolving of endpoint hostnames in testing environments with firewall devices, network address translation devices or clouds. According to the invention, the method applies at the level of a registration server including at least one processor, the registration server being configured to operate within a public network, and it comprises: receiving a data packet from a first endpoint, where the data packet includes a payload containing a first address and a hostname which are associated with the first endpoint, identifying a second address in a header of the data packet, initiating, by using the second address, a connection to the first endpoint, determining whether the connection is successfully accomplished and associating the hostname of the first endpoint with either the first or the second address, based on the determination results. The system, as claimed by the invention, comprises at least one processor and one registration server including a processor, the registration server being configured to operate in a public network, where the registration server is configured to perform the steps of the method, as claimed. The claimed computer-readable medium has stored thereon computer-executable instructions which, when executed by a processor, control the computer as to perform the steps of the method, as claimed, at the level of a registration server configured to operate in a public network.

Term
No projected expiry on record.
- Priority and filed
- Published
- Today
21 claims: 3 independent, 18 dependent
- 1CLAIMS REVENDICĂRI 1. A method for facilitating resolving a host name of an endpoint, the method comprising:1. Metodă pentru facilitarea rezolvării unui nume gazdă a unui punct de capăt, metoda cuprinzând: la un server de înregistrare care include cel puțin un procesor, serverul de înregistrare configurat să funcționeze într-o rețea publică: on a recording server that includes at least one processor, the recording server configured to work on a public network: receiving, from a first endpoint, a data packet that includes a payload that contains a first address and host name associated with the first endpoint;recepționarea, de la un prim punct de capăt, a unui pachet de date care include o sarcină utilă care conține o primă adresă și un nume gazdă asociate cu primul punct de capăt;identificarea unei a doua adrese dintr-un antet al pachetului de date;inițierea, folosind a doua adresă, unei conexiuni la primul punct de capăt;identifying a second address from a data packet header;initiating, using the second address, a connection to the first endpoint;determinarea dacă conexiunea este de success;și asocierea numelui gazdă a primului punct de capăt cu una dintre prima adresă și cea de a doua adresă, pe baza rezultatelor determinării. determining whether the connection is successful;and associating the host name of the first endpoint with one of the first and second addresses, based on the results of the determination.
- 11System to facilitate the resolution of a host name of an endpoint, the system comprising:11. Sistem pentru a facilita rezolvarea unui nume gazdă a unui punct de capăt, sistemul cuprinzând: at least one processor;cel puțin un procesor;a recording server that includes a processor, the recording server being configured to operate on a public network., wherein the recording server is configured to: un server de înregistrare care include un processor, serverul de înregistrare fiind configurat să funcționeze într-o rețea publică., în care serverul de înregistrare este configurat să: receive, from a first endpoint, a packet that includes a payload that contains a first address and a host name associated with the first endpoint, identifies a second address from a header of the data packet, to initiate, Using the second address, a connection to the first endpoint, determines if the connection is successful, associates the host name of the first endpoint with one of the first and second addresses, based on the results of the determination. recepționeze, de la un prim punct de capăt, un pachet care include o sarcină utilă care conține o primă adresă și un nume gazdă asociate cu primul punct de capăt, identifice o a doua adresă de la un antet al pachetului de date, pentru a iniția, folosind a doua adresă, o conexiune la primul punctde capăt, determine dacă conexiunea este de succes, asocieze numele gazdă al primului punct de capăt cu unul din prima adresă și cea de a doua adresă, pe baza rezultatelor determinării.
- 21Non-transient computer-readable support that has computer-executable instructions stored on it, which, when executed by the processor, commands the computer to complete the steps:21. Suport non-tranzitoriu care poate fi citit de calculator care are stocate pe acesta instrucțiuni executabile de computer, care atunci când sunt executate de către processor, comandă computerul să punctul de capătueze pașii: la un server de înregistrare care include cel puțin un procesor, serverul de înregistrare configurat să funcționeze într-o rețea publică: on a recording server that includes at least one processor, the recording server configured to work on a public network: receiving, from a first endpoint, a data packet that includes a payload that contains a first address and host name associated with the first endpoint;recepționarea, de la un prim punct de capăt, a unui pachet de date care include o sarcină utilă care conține o primă adresă și un nume gazdă asociate cu primul punct de capăt;identificarea unei a doua adrese dintr-un antet al pachetului de date;inițierea, folosind a doua adresă, unei conexiuni la primul punct de capăt;identifying a second address from a data packet header;initiating, using the second address, a connection to the first endpoint;determinarea dacă conexiunea este de success;și asocierea numelui gazdă a primului punct de capăt cu una dintre prima adresă și cea de a doua adresă, pe baza rezultatelor determinării. determining whether the connection is successful;and associating the host name of the first endpoint with one of the first and second addresses, based on the results of the determination.
Independent claims3
136 paragraphs in 4 sections, as filed
The present invention relates to the testing of network devices. More specifically, the present invention relates to methods, systems, and computer readable media for facilitating endpoint hostname resolution in testing environments with firewall devices, network address translation (NAT) devices, or clouds.
PREVIOUS STAGE OF THE TECHNIQUE
When testing the network, in order to run data traffic from host A to host B, it is necessary to find a path to host B. If host B is identified by Internet Protocol (IP), the standard network devices (from for example, routers, switches) addresses the problem of finding a path to host B. But, using IP addresses to identify hosts for testing creates dependency on network configuration, so it is preferable to use a name to identify the host. Hostname B can usually be a fully qualified hostname, domain name, or domain name, so resolving hostname B is required on host A.
Conventional solutions for resolving a host B name are to request entity or host A to query a domain name system (DNS) server to resolve the domain name of host B stored in the company, on public or semi-public networks. . However, querying a DNS server can lead to difficulties. In particular, in addition to the fact that DNS infrastructure is not always set up on all machines in all environments, in a cloud-based network, for example, the host name is different from the fully qualified domain name designated by the cloud infrastructure, and tools are required. external, first to get the fully qualified domain name in addition, where
V2 0 1 5 - - 000860 8 -fl2- 2015 host B is in the private area, it may not be possible for it to be a detector from host A, as it is not necessary for a domain name of host B to be published by to a local DNS server.
As a result, there is a need for computer-readable methods, systems, and support to facilitate troubleshooting endpoint host names in testing environments with firewall devices, network address translation (NAT) devices, or clouds, and that allows running of tests between hosts, whether they are on cloud, public or corporate networks.
SHORT EXPOSURE OF THE INVENTION f
Methods, systems and computer readable support for recording the hostname of the endpoints are presented. According to an example method, it takes place on a recording server configured to work on a public network. The method includes receiving, from a first endpoint, a data packet that includes a payload that contains a first address and a host name associated with the first endpoint. The method also includes identifying a second address in a data packet header. The method also includes initiating, using the second address, a connection to the first endpoint. The method also includes determining whether the connection is successful. The method also includes associating the host name of the first endpoint with one of the first address and the second address, based on the results of the determination.
According to an example system, the system includes a recording server that includes a processor. The registration server is configured to work on a public network. The registration server is also configured to receive, from a first endpoint, a packet that includes a payload that contains a first address and a host name associated with the first endpoint, to identify a second address from a data packet header, to initiate, using the second address, a connection at the first endpoint, to determine if the connection is successful, and to associate the host name of the first endpoint with one of the first address and the second address, based on the results of the determination, <V 2 0 1 5 - - 0 0 0 Β 6 0 9 -02-2015
The objects described here can be implemented in software in combination with hardware and / or firmware. For example, the objects described here can be implemented in software executed by a processor. In one implementation example, the objects described herein may be implemented using a non-transient readable computer that has computer-executable instructions stored on it, which, when executed by the processor, commands the computer to reach the point. steps. Computer-readable media suitable for implementing the subject matter described herein include non-transient devices, such as disk memory devices, chip memory devices, programmable logic devices, and application-specific integrated circuits. In addition, a computer readable environment that implements the object described herein may be located on a single computing device or platform or may be distributed on multiple computing devices or platforms.
As used herein, the term "node" refers to a physical computing platform that includes one or more processors, network interfaces and memory.
As used herein, each of the terms function and module refers to hardware, firmware or software in combination with hardware and / or firmware for implementing the features described in this specification.
BRIEF DESCRIPTION OF THE EXPLANATORY DRAWINGS
The objects of the present invention will be further explained in connection with the attached Figures, which represent
Figure 1 is a diagram illustrating a computing platform for recording a host name of an endpoint, according to an embodiment of the present invention;
Figure 2 is a diagram illustrating the registration of a hostname of an endpoint where the endpoint is hosted on a public network, in accordance with an embodiment of the present invention;
Figure 3 is a diagram illustrating the registration of a hostname of an endpoint where the endpoint is hosted <C2Q 1 5 - 0 0 0 8 6 0 9 -02-2015 on a private network, according to with an embodiment of the present invention;
J
Figure 4 is a diagram illustrating the registration of a hostname of an endpoint where the endpoint is hosted on a cloud-type network, in accordance with an embodiment of the present invention;
Figure 5 is a table illustrating a recording data structure, according to an embodiment of the present invention;
Figure 6 is a diagram illustrating resolving an endpoint host name using the registration data structure of Figure 5, according to an embodiment of the present invention;
Figure 7 is a diagram illustrating the initiation of connections between the endpoints hosted in different types of network, according to an embodiment of the present invention; and
Figure 8 is a process flowchart illustrating a process for registering an endpoint host name according to an embodiment of the present invention.
DETAILED DESCRIPTION
The objects of the present invention relate to methods, systems and computer readable media for facilitating the endpoint hostname resolution in testing environments with firewall devices, network address translation (NAT) devices or clouds. When preparing to test network endpoints, test operators usually need to resolve the endpoint host name for an Internet Protocol (IP) address before providing test setup information to the endpoints. end. Solving a hostname of an endpoint is usually done by an entity that requests a domain name server (DNS) query, which results in the mapping, on the DNS server, of a host name received at the associated IP address using its internal table. However, if the internal table of a DNS server cannot resolve a domain or host name to the IP address (for example, if
Ar 2 0 1 5 - - 0 0 0 8 6 0 9 -02- 2015 endpoint is hosted on a private network and its host name is not published), DNS server must manually contact other DNS servers on the Internet or intranet to resolve hostname of host B.
In accordance with some aspects of the objects of the present invention, in order to initiate test connections between the different endpoints, techniques for facilitating endpoint hostname resolution may include recording the hostname of the endpoint at a node configured to function. on a public network, for example, a public record server (RS), so that a requesting entity can easily obtain a resolved endpoint host name, for an end point the requesting entity is interested in testing. For example, a registration server may be used to identify and transmit IP information (for example, IP address, host machine location, etc.) corresponding to a host name of the endpoint registered to a requesting entity. The registration server can be separated from a DNS server.
Advantageously, in accordance with some aspects of the objects described, by using a registration server to record the endpoint host names and associated IP addresses, they can be provided and received by a requesting entity independent of the existence of a DNS server , a dynamic host configuration protocol (DHCP) derder, or other external instrument, and regardless of the location of the endpoint host machine; thus allowing test connections from one end point to another on an appropriate route.
References will be made in detail to the illustrative embodiments of the objects of the invention described herein, which examples are illustrated in the appended figures. Whenever possible, the same reference numbers will be used throughout the figures for reference to the same parts.
Further details regarding the test media and related functionalities that can be found in this application refer to US patent application series no. December 2014, as well as the US patent application (to be awarded), METHODS, COMPUTER READABLE SYSTEMS FOR IDENTIFYING NETWORK LOCATIONS ASSOCIATED WITH POINTS <2 0 1 5 - 0 0 0 8 6
8 -02- 2015 end, filed on the same date, whose descriptions are incorporated herein by reference, in their entirety.
Figure 1 is a diagram illustrating a computing platform 100 for recording a host name of an endpoint, according to an embodiment of the object described herein. Referring to Figure 1, a public network may include a computing platform 100.
The computing platform 100 may represent a network device, a network module, a node, or a system of devices, nodes, and / or modules. For example, the computing platform 100 may be an endpoint operating on a public network (for example, not located behind one or more associated security devices, such as a firewall or a NAT device). In some embodiments, the computing platform 100 may be a single node or may include functionality distributed over computing platforms or multiple nodes.
The computing platform 100 may include or access a registration module (RM) 102. The RM 102 may represent any appropriate entity or entities (for example, a computing platform, the execution software on a processor, etc.) for making one. or more aspects related to recording information about the hostname of the endpoint. Thus, RM 102 may include the functionality to interact with other users, systems, endpoints and / or nodes. For example, RM 102 may include one or more communication interfaces for receiving and transmitting different types of messages; such as IP messages, messages, IP version 4 (IPv4), messages IP version 6 (IPv6), messages through the Transmission Control Protocol (TCP), messages through the data flow control protocol (SCTP) ), messages via real-time transport protocol (RTP), messages via reliable data protocol (RDP), messages via tracking protocol (GTP) switched packet service for mobile communications (GPRS), messages using another tunneling protocol , and / or any reallocation examples thereof.
In some embodiments, the computing platform 100 and / or RM 102 may i nclude functionality associated with a recording server in a test environment. For example, a test environment may involve numerous endpoints (for example, nodes and / or applications hosted on or <kl 2 o 1 5 - - 000860 8 -02- 2CÎ5 executed through computing platforms) configured to transmit traffic for testing purposes. In this example, the computing platform 100 and / or RM 102 can be configured to receive periodic and / or aperiodic recording information (for example, dynamically) from endpoints to provide endpoint information to a test operator, for example, through a test console.
In some embodiments, the computing platform 100 and / or RM 102 may include the functionality of determining or automatically identifying the locations of the network associated with the endpoints. For example, RM 102 may include the detection logic of the location of the detection network and / or a relevant algorithm to determine if an endpoint is accessible through the associated IP addr ess information. In this example, RM 102 may attempt to initiate or establish a connection (for example, a TCP connection), with an endpoint and to deduce a network location associated with the endpoint, based, in part, on the connection's success. . Continuing with this example, RM 102 may use the result of the connection test and other information (for example, the logic implemented in the software which assumes that an endpoint behind a firewall in the private network 110 will not be able to receive incoming connections. from RM 102) to determine or identify a network location, such as public network 120, private network 110, or semi-public network 116.
In some embodiments, an endpoint located or hosted on either a public, private or semi-public network (eg, cloud type) may initiate a connection to the computing platform 100 and / or RM 102 . For example, an endpoint A 106 located in a public network 120, the public network 120 being the same or a public network different from the public network 120, which computing platform 100 and / or RM 102 are located inside, may send a data packet or message (for example, a registration message or a TCP message valid from the computing platform 100 and / or RM 102. Endpoint A 106 may insert in the data packet or message a payload that contains an IP address (for example, an IPv4 or IPv6 address), associated with endpoint A 106, and a host name associated with endpoint A 106. Such information may be preconfigured by a user or may be retrieved by endpoint A 106, although the specification ^ -2015-- 000860 9 -02-22CI5 of this retrieval is outside the scope of the present invention. After receiving the packet or message, RM 102 can inspect the information from the payload of the data packet or message to obtain the IP address (for example, the first IP address) and the host name of the endpoint. RM 102 can also inspect a packet or message header and deduce or identify the source address information (for example, a second IP address) associated with the A106 endpoint in the header.
In some embodiments, RM 102 may be configured to initiate a connection to endpoint A 106, using the address information in the header identified from the header of the data packet or message. For example, RM 102 may send a connection request (for example, a TCP SYN message) addressed to the second IP address associated with the endpoint A 106 (for example, a source IP address located in a packet header of a recording message sent from end point A). In this example, if endpoint A 106 receives and accepts the connection request, it can send a connection response message (for example, a TCP ACK message) to RM 102. In response to a successful connection, RM 102 can be configured to associate either the first IP address of the data packet payload, or the second IP address of the data packet header with the host name of endpoint A 106, and for determine a network location (eg, public network 120) of endpoint A 106.
Alternatively, the endpoint in question cannot be hosted on a public network. Instead, the end point in question may be located, for example, on a private network or a cloud-type network. In Figure 1, the endpoint B 108 is hosted on a private or corporate network 110 that is behind one or more security devices 112, such as a firewall device or a network address translation device ( NAT). The security device (s) 112 may be any appropriate entity or monitoring entities and / or possibly affecting communication between entities in the private network 110 and entities elsewhere, for example, in the public network 120 or the semi-public network 116 . For example, the security device (s) 112 may include a firewall device configured to block all connection requests received from public network 120 or from semi-public network 116 to private network 110, but
Α-2015-- 000860 9 -02- «15 configured to allow connection output requests from the private network 110 to the public network 120 or the public semi-network 116. In another example, the associated security device (s) 112 may include a NAT device that performs NAT-related functions by replacing the private address information (for example, a private IP address useful for routing packets on the private network 110) in the a packet data header with public address information (for example, a public IP address useful for routing packets on the public network 120). For example, because the computing platform 100 and / or RM 102 are located on the public network 120, the endpoint B 108 may prevent any attempt to initiate the connection (for example, a connection request message) from RM 102. In response to a connection initiation attempt failure, RM 102 can be configured to associate the first IP address of the packet data payload with the host name of the B 108 endpoint and determine a network location (eg network private or company 110) of the end point B 108.
Also, in Figure 1, the C 114 endpoint is hosted on a cloud service network 116 (for example, Amazon Cloud Drive, Microsoft Azure, etc.), which is behind one or more mobile devices. security 118. In some embodiments, the security device (s) 118 may include a NAT device that performs NAT-related functions by replacing the private address information (for example, a private IP address useful for routing packets on the semi-public network 116) in -a packet data header with public address information (for example, a public IP address that can be used to route packets on the public network 120), for example, so that the inbound traffic is received by the endpoints in the semi-public network 116. For example, because the computing platform 100 and / or RM 102 are located in a public network, the endpoint C 114 may accept an attempt to initiate connection (for example, a connection request message) from RM 102. In response to a successful connection, RM 102 can be configured to associate the second IP address in the data packet header with the host name of the C 114 endpoint and determine a network location (for example, the cloud 116 network). ) of endpoint C 114. Thus, independently of a DNS server, RM 102 may be able to associate a host name of a point
0: 2015-- 000860 9 -02- 2015 / y / end with an IP address and with the network location of the end point (for example, AC end points), regardless of an end point location.
In some embodiments, the computing platform 100 and / or RM 102 may be configured to record or store the IP address associated with the hostname of the endpoint received from communication with the respective endpoint. In addition, the computing platform 100 and / or RM 102 can be configured to record and store the network location of the endpoint. In this way, when a requesting entity contacts platform 100 and / or calculation module 102, to resolve the hostname of the endpoint to the Internet Protocol (IP) address information for connection initiation purposes, such associated information is already stored in a storage device (for example, the RM 104 storage device), integrated with or accessible through RM 102, the computing platform 100, or through the appropriate modules. In some embodiments, the RM 104 storage device may be located at a node other than RM 102 and / or the computing platform 100. For example, the RM 104 storage device may be associated with a separate storage device from the computing platform 100 .
The RM 104 storage device may represent any appropriate entity (for example, a non-transient computer readable media, a built-in memory, or a memory device) for storing data associated with message flows, messages, test traffic, test results, statistics and / or related test information. The data stored in the RM 104 storage device may include endpoint host name information, endpoint network location information, address information, port information, proxy information, node identification information, test setup information, test results , statistics, and / or other information.
In some embodiments, the computing platform 100 and / or RM 102 may provide the host name and IP address information regarding the endpoint, to allow a requesting entity, or a second endpoint or node, to intrude upon. first end point to initiate a test connection and / or session with a second end point. For example, a requesting entity may transmit to RM 102, in a test configuration message, a host name of at least one endpoint, which entity ^ -2015--00086fl on -02-2015 is interested in using in a test configuration. The test configuration message may include a request to the computing platform 100 and / or RM 102 to resolve the hostname of the endpoint to the associated IP address that was previously received, and subsequently stored, via RM 102. RM 102 may then include functionality for resolving the endpoint host name to the associated IP address and for transmitting the resolved hostname and associated IP address for the endpoint back to the requesting entity so that the requesting entity can configure a connection or connection. test session between two end points. Alternatively, RM 102 may transmit said resolved host name and associated IP address for the endpoint back to a second endpoint, so that the latter may configure a test connection between itself and the other endpoint.
In some embodiments, the requesting entity may use the resolved host name and associated IP address for the endpoint when instructing either the endpoint or a second endpoint to initiate a test connection or session between them, wherein each of the two endpoints can be hosted by a machine located on another network (for example, public, private, cloud). However, since initiating the test connection depends on the location of each endpoint involved (for example, an endpoint located on a public or cloud network cannot initiate a test connection with a node located on a network. private), the requesting entity may use the resolved host name, associated IP address, and / or network location, to determine which endpoint should initiate the connection. Alternatively, if the requesting entity is a second endpoint, it may initiate a test connection with the first endpoint. This aspect of the subject matter of the present invention will be explained in detail below, with reference to Figure 7.
It should be noted that the computing platform 100 and / or RM 102 and the components and functionalities described may constitute a special purpose computing device, which enhances the technological field of network testing by recording, at a node, the host names of the endpoints and the IP addresses associated with them, so, at the request of a requesting entity, the host name can be resolved to the IP address of the endpoint and a
Λ. 2 0 1 5 - - 000860 9 -02- 2015 connection can be initiated between that endpoint and a second endpoint, independent of a domain name server and regardless of network location of each endpoint. end..
It will be appreciated that Figure 1 is for illustrative purposes and that several nodes, their locations, and / or their functions described above in connection with Figure 1 may be changed, modified, added or removed. For example, some nodes and / or functions can be combined into one entity.
Figures 2-4 are message flow charts illustrating communications between a registration module (RM) 102 and an endpoint for recording endpoint host names, according to an embodiment of the described object. Figures 2-4 illustrate each endpoint hosted in a different environment and techniques for associating an endpoint host name with an IP address, regardless of the endpoint location.
According to Figure 2, a diagram illustrating the registration of a hostname of the endpoint and IP address is described here, if the endpoint is in a public network, in accordance with an embodiment of the subject matter of the present invention. . In some embodiments, the communication between an endpoint A 106 hosted on a public network 120 and a registration module (RM) 102, hosted on a public network 120 for recording or storing a host name of the point is illustrated. end A 106 with RM 102. In some embodiments, the end point A 106 may be hosted on a network other than RM 102. Endpoint A 106 may represent a node (for example, a computing platform, module, or node) for receiving test setup information and for generating test traffic.
In step 1, endpoint A 106 may obtain or otherwise determine a host name and IP address information (eg, IPv4 or IPv6 address) for other nodes to communicate with endpoint A 106. IP address information may it comprises the local IP address of the machine or node hosting the endpoint A 106. Such information may be preconfigured by a user or may be retrieved by the endpoint A 106. For example, endpoint A 106 may be configured to ^ -2 0 1 5 - 0 0 0 8 6 0 9 -02- 2C15 use an IPv4 address assigned by a network operator or an access assurance entity.
In step 2, endpoint A 106 may send a data packet or message (for example, a recording message, a UDP message, a TCP SYN message, or a valid TCP message) that contains address information from the platform. for calculation 100 and / or RM 102. For example, endpoint A 106 may include, in the data or message packet, a payload that contains a first IP address (for example, a local IP address associated with endpoint A 106), as well as a host name. Here, since the endpoint A 106 is hosted on a public network, the first IP address will be a public, local IP address. Referring to Figure 2, the payload of the package may include (IP = '121.16.0.16', hostname = A). In this example endpoint A 106 may also include in a packet or message header a second IP address associated with endpoint A 106 as a value of the source address parameter. Here, since the endpoint A 106 is hosted on a public network, the second IP address will be a public IP source address. Referring to Figure 2, the package header may include (IP = '121.16.0.16').
In step 3, after receiving the data packet or message, RM 102 can inspect the information from the payload of the packet or message, to obtain the first IP address (for example, a public local IP address, associated with the endpoint A 106 ) and the hostname of the endpoint (for example, A). RM 102 can also inspect a packet or message header and deduce or identify the second IP address (for example, the value of the public source address parameter, associated with endpoint A 106) in the header. Referring to Figure 2, for example, RM 102 can identify the packet header as including the second IP address (IP = '121.16.0.16').
In step 4, after deduction or identification of the second IP address in the packet header, RM 102 can be configured to initiate a connection with endpoint A 106 using the second IP address identified in the packet header. For example, RM 102 may send a connection request (for example, a TCP SYN message) addressed to the second IP address associated with endpoint A 106 (for example, the value of the public source address parameter located in a packet header of a recording message initiated by endpoint A 106).
<sub>Μ</sub> ^ 2 0 1 5 - 0 0 0 8 6 0 3 -02- ΣΒ15 In some embodiments, RM 102 can determine whether the second IP address in the header (for example, the value of the public source address parameter, associated with the end A 106) is identical to the first IP address (for example, the public, local IP address associated with end point A 106) of the payload. For example, if the payload IP address is the same as the IP address in the header, then RM 102 can be configured to determine or deduce that the respective endpoint A 106 is associated with the public network 120, for example, without trying to initiate a connection using the address information received.
In step 5, the end point may respond to the initiation attempt. For example, endpoint A 106 may receive and accept the connection request and may send a connection response message (for example, a TCP ACK- message) to RM 102. In response, RM 102 may be configured to establish or infer that endpoint A 106 is associated with the public network of 120.
In step 6, in response to a successful connection, RM 102 may be configured to associate the host name of endpoint A 106 with either the first IP address of the payload of the packet or the second IP address of the packet header. For example, RM 102 can compare the first IP address of the payload of the packet with the second IP address of the packet header and can determine that they are identical. Consequently, in this example, while the first IP address and the second IP address are both 121.16.0.16, RM 102 can establish that there is no firewall and / or NAT device and the endpoint A 106 is located in a public network (for example, 120).
In some embodiments, associating a host name of the endpoint A 106, either with the first IP address or with the second IP address, includes storing or registering the associated IP address and the host name at a storage location, for example, the RM docking device. 104. In addition, the network location of the endpoint A 106 may also be stored the storage location. For example, RM 102 can store an A name, an IP address 121.16.0.16, as well as a public network location indicates that the endpoint A 106 is located in the public network 120 and / or that the endpoint is accessible by the associated IP address.
^2015-- 000860 9 -02- 2015
It will be appreciated that Figure 2 is for illustrative purposes and that different and / or additional actions may be used. It will also be appreciated that the different actions described here may occur in a different order or sequence.
Referring to Figure 3, a diagram illustrating the registration of a hostname of the endpoint and IP address is described, if the endpoint is in a private network, in accordance with an embodiment of the subject matter of the present invention. . In some embodiments, the communication between endpoint B 108, hosted on a private network 110, and RM 102 hosted on public network 120 for recording or storing a host name of endpoint B 108 with RM 102 is illustrated. In such embodiments, endpoint B 108 and computing platform 100 and / or RM 102 may attempt to communicate with one another, so that endpoint B 108 may attempt to register a host name and IP address with the host platform. calculation 100 and / or RM 102 and the computing platform 100 and / or RM 102 may attempt an Ideconnection initiation with endpoint B 108. However, since endpoint B 108 is hosted on a private network, the associated security device (s) 112 may be located between RM 102 and end point B 108, and may end point firewall-related functions. and / or NAT, thus preventing a connection initiation attempt through the computing platform 100 and / or RM 102.
In step 1, endpoint B 108 may obtain or otherwise determine a host name and IP address (for example, IPv4 or IPv6 address) for other nodes to communicate with endpoint B 108. The IP address information may include the address The local IP of the machine or node hosting the B108 endpoint. Such information may be preconfigured by a user or may be retrieved by the B 108 endpoint. For example, endpoint B 108 can be configured to use an IPv4 address assigned by a network operator or access provider.
In step 2, endpoint B 108 may send a packet or message (for example, a registration message, a UDP message, a SYN TCP message, or a valid TCP message) that contains address information from the computing platform 100. and / or RM 102. For example, endpoint B 108 may include, in the package or message, a payload containing a premium
A 2 Q 1 5 - - 000860 8 -02- 2C15 IP address (for example, a local IP address associated with endpoint B 108), as well as a host name. Here, since endpoint B 108 is hosted on a private network, the first IP address will be a private local IP address. Referring to Figure 3, the payload of the package may include (IP = '10.205.12.120 host name = B). In this example, endpoint B 108 may also include in a packet or message header a second IP address associated with endpoint B 108 as a value of the source address parameter. Here, since endpoint B 108 is hosted on a private network, the second IP address will be a private source IP address. Referring to Figure 3, the package header may include (IP = '10.205.12.120 ').
In step 3, the security device (s) 112 may perform NAT-related functions associated with the packet or message sent from endpoint B 108. For example, before being received by RM 102, the security device (s) 112 may modify a packet or message header by replacing the second IP address (for example, a source, private IP address associated with endpoint B 108), in the header with information about another address (for example, a public IP address associated with security device (s) 112). Referring to Figure 3, the associated security device (s) 112 may modify the packet header so that it may now include a second IP address, which is a public IP address associated with the security device (s) 112, (IP = '10.18 .0.16 ').
In step 4, the associated security device (s) 112 may send the packet or message containing the modified header address information from the computing platform 100 and / or RM 102. For example, the packet or message may include a payload that contains a host name and a first IP address associated with endpoint B 108 and a header containing a second modified IP address, associated with Security Idea device (s) 112.
In step 5, after receiving the packet or message, RM 102 can inspect the payload information of the packet or message to obtain the first IP address (for example, a private ocalIP address associated with endpoint B 108), as well as hostname of the endpoint (for example, B). RM 102 may also inspect a packet or message header and deduce or identify a second modified IP address, (for example, a public IP address associated with the security device (s)
0 1 5 - - 0 0 0 8 6 q 9 -02- 2015
112 from the header. Referring to Figure 3, for example, RM 102 can identify the packet or message header as including the second changed IP address, (IP = '10.18.0.16 ').
In step 6, after deducing or identifying information about the second IP address, RM 102 can be configured to initiate a connection to the B 108 endpoint using the second modified IP address, identified from a packet data header. For example, RM 102 may send a connection request (for example, a TCP SYN message) to the second modified IP address, (for example, the public IP address associated with the security device (s) 112.
In some embodiments, for example, in the case of calculating platform 100 and / or RM 102 they are located on a public network 120 or semi-public network 116, the security device (s) 112 may receive a connection request from the calculation 100 and / or RM 102 and may download or otherwise prevent the communication request from being received by the endpoint B 108. Instead, a connection error request message may be sent back to RM 102, it may pause, or another indication may be received or set to indicate that that connection has not been made.
In step 7, RM 102 may receive an indication of a failed connection with endpoint B 108 or otherwise establish that a connection request has succeeded. In response, RM 102 can be configured to establish or deduce that endpoint B 108 is associated with private network 110.
In step 8, in response to an unsuccessful connection attempt, RM 102 may be configured to associate the host name of endpoint B 108 with the first IP address. For example, because RM 102 can establish that endpoint B 108 is hosted on a private network, RM 102 can store the first IP address (for example, the private local IP address, associated with endpoint B108).
In some embodiments, associating a host name of endpoint B 108 with the first IP address, comprises storing the associated IP address and host name at a storage location, for example, the storage device RM 104. In addition, the location of the point network end B 108 may also be stored in the storage location. For example, RM 102 can store
0 1 5 - - 0 0 0 8 6 0 3 -02- 2815 a host name of B, an IP address '10.205.12.120, as well as a network location of the private network indicating that the endpoint B 108 is located in private network 110 and / or that the endpoint is accessible only from other endpoints hosted on the same private network. Similarly, in this example, endpoint B 108 is unattainable by the IP address associated with other endpoints hosted on public or cloud networks.
It will be appreciated that Figure 3 is for illustrative purposes and that different and / or additional actions may be used. It will also be appreciated that the different actions described here may occur in a different order or sequence.
Referring to Figure 4, a diagram illustrating the registration of a hostname of the endpoint and the IP address is described, if the endpoint is in a public or cloud type network, according to an embodiment of the object of this present invention. the present invention exhibit. In some embodiments, the communication between a C 114 endpoint hosted on a semi-public network 116 and RM 102 is illustrated, hosted on the public network 120 for recording or storing a host name of the C 114 endpoint with RM 102 . In such embodiments, the C 114 endpoint and the computing platform 100 and / or RM 102 may attempt to communicate with each other, so that the C 114 endpoint may attempt to register a host name and IP address with the platform. computing 100 and / or RM 102 and computing platform 100 and / or RM 102 may attempt a connection initiation with the C 114 endpoint. However, since the C 114 endpoint is hosted on a semi-public network, an associated security device 118 (s) can be located between RM 102 and the C 114 endpoint and the endpoint can be achieved. farallall functions and / or related NAT functions; which may or may not prevent a connection initiation test via computing platform 100 and / or RM 102.
In step 1, endpoint C 114 may obtain or otherwise determine a host name and IP address (eg, IPv4 or IPv6 address) for other nodes to communicate with endpoint C 114. The IP address information may include the address The local IP of the machine or node hosting the C114 endpoint. Such information may be preconfigured by a user or may be retrieved by the C 114 endpoint. For example, endpoint C 114 can be configured to use an address /%>
ο; <sup>2</sup> 0 1 5 - - 000860 2 -02- 2CÎ5
ΙΡν4 assigned by a network operator or an access assurance entity.
In step 2, endpoint C 114 may send a data packet or message (for example, a recording message, a UDP message, a TCP SYN message, or a valid TCP message) that contains address information from the platform. for calculation 100 and / or RM 102. For example, endpoint C 114 may include, in the data or message packet, a payload containing a first IP address (for example, a local IP address associated with endpoint C). 114), as well as a host name. Here, since the C 114 endpoint is hosted on a semi-public network, the first IP address will be a private, local IP address. Referring to Figure 4, the payload of the package may include (IP = '10.210.12.120 ', hostname = C). In this example, the C 114 endpoint may also include, in a packet or message header, a second IP address associated with the C 114 endpoint as a value of the source address parameter. Here, since the C 114 endpoint is hosted on a semi-public or cloud type network, the second IP address will be a private IP source address. Referring to Figure 4, the packet header may include (IP = '10.210.12.120 ').
In step 3, the security device (s) 118 may perform NAT-related functions associated with the packet or message sent from the C 114 endpoint. For example, before being received by RM 102, the security device (s) 118 may modify a packet or message header by replacing the second IP address (for example, a source, private IP address associated with endpoint C 114), in the header with information about another address (for example, a public IP address associated with the security device (s) 118). Referring to Figure 4, the associated security device (s) 118 can modify the packet header so that it can now include a second IP address, which is a public IP address associated with the security device (s) 112 (IP = 74.20.0.16 ').
In step 4, the associated security device 118 (s) may send the packet or message containing the modified header address information from the computing platform 100 and / or RM 102. For example, the packet or message may include a payload that contains a host name and a premium λ-2015-- 00086Β 9 -02- HN »
IP IP address associated with endpoint C 114 and a header containing a second modified IP address, associated with device (s) Security Idea 118.
In step 5, after receiving the packet or message, RM 102 can inspect the payload information of the packet or message to obtain the first IP address (for example, a local, private IP address associated with endpoint C 114), as well as and the host name of the endpoint (for example, C). RM 102 may also inspect a packet or message header and deduce or identify a second modified IP address, (for example, a public IP address associated with the security device (s) 118) in the header Referring to Figure 4, for example, RM 102 can identify the packet or message header as including the second modified IP address, (IP = 74.20.0.16 ').
In step 6, after deducing or identifying information about the second IP address, RM 102 can be configured to initiate a connection with the C 114 endpoint using the second modified IP address, identified from a data packet header. For example, RM 102 may send a connection request (for example, a TCP SYN message) to the second modified IP address (for example, the public IP address associated with the security device (s) 118).
In step 7, the associated security device (s) 118 may perform NAT functions associated with the packet or message sent by the C 114 endpoint. For example, before being received by RM 102, the associated security device (s) 118 may modify a packet or message header by replacing the second modified IP address (for example, a public IP address associated with the associated security device (s) 118 in the header with a private source IP address (for example, a private IP address associated with the C 114 endpoint) stored on the associated security device (s) 118 in this example, the security device 118 can modify the packet header by replacing the second modified IP address (IP = 74.20.0.16 ') with the private source IP address (IP = '10.210.20.120').
In step 8, the security device (s) 118 may send the packet or message containing a changed header address (for example, the source IP address, private associated with endpoint C 114) of endpoint ^ -2015- - 000860 9 -02- Σ0ί5
C 114. For example, the packet or message may include a header containing the second IP address (IP = '10.210.20.120 ').
In some embodiments, the connection request may be received at the C 114 endpoint and the C 114 endpoint may respond, by sending a connection request confirmation or any other indication to
I computing platform 100 and / or RM 102 (for example, via the security device (s) 118).
In step 9, RM 102 may receive an indication of a successful connection with endpoint C 114 or may otherwise establish that a connection request has succeeded. In response, RM 102 can be configured to determine or deduce that the respective end point C 114 is associated with the semi-public network 116.
In step 10, in response to a successful connection with the C 114 endpoint, RM 102 may be configured to associate the C 114 endpoint host name with the second IP address associated with the device (s) 118. For example, because RM 102 can determine that the C 114 endpoint is hosted on a semi-public or cloud network, RM 102 can store the second IP address (for example, the public IP address associated with the security device (s) 118).
In some embodiments, associating a host name of the C 114 endpoint with the second IP address comprises storing the associated IP address and host name at a storage location, for example, the storage device RM 104. In addition, the network location of the end point C 114 can be stored in the storage location. For example, RM 102 can store a host name C, an IP address of 74.20.0.16, as well as a semi-public or cloud-type network location, indicating that the C 114 endpoint is located on a type network. cloud 116 and / or that the endpoint is accessible only through the public IP address associated with the security device (s) 118.
It will be appreciated that Figure 4 is for illustrative purposes and that different and / or additional actions may be used. It will also be appreciated that the different actions described may occur in a different order or sequence.
Referring to Figure 5, the hostname data structure 500 recorded as endpoint may be any data structure suitable for recording and / or storing the hostname of the endpoint,
Or 2 0 1 5 - - 0 0 0 8 6 0 3 -02- 2GS
<img file="RO131360A2_D0001.tif" />
associated IP addresses and network locations. For example, the hostname data structure 500 recorded as an endpoint can be stored in a data table. Specifically, each endpoint host name can indicate the IP address associated with the endpoint and the location of the endpoint network, determined by RM 102 which initiates a connection to the endpoint and subsequently associates with either the IP address of the load. Useful (for example, the first address) or the IP address of the header (for example, the second address), with the host name. In some embodiments, the hostname of the endpoint is preconfigured by a user or may be recovered through the endpoint, in a manner outside the scope of the present invention. For example, a first endpoint is listed in a first line of data structure 500 with its host name Obtained, which refers to endpoint A 106 (for example, Figures 1 and 2). In other embodiments, the second and third end points are listed in a second and third line, respectively, of data structure 500. The second end point is listed with the obtained host name B, which refers to at endpoint B 108 (for example, Figures 1 and 3), while the third endpoint is listed with its obtained host name C, which refers to endpoint C 114 (for example, Figures 1 and 4 ).
In some embodiments, the IP address of the endpoint is either the payload IP address or the IP address of the header that have been associated with RM 102 and / or the computing platform 100 with the host name of the endpoint. The IP address that will be associated with the endpoint is determined based on a successful attempt to initiate RM 102 connection to the endpoint. if the connection is unsuccessful, RM 102 associates the payload IP address (for example, the first address) with the host name of the endpoint. For example, the endpoint with host name 'B' is listed with an IP address of '10.205.12.120 associated with its host name in data structure 500. In contrast, if the connection is successful, RM 102 needs to further compare the payload IP address and the IP address of the header, to decide which IP address should be associated (and subsequently stored in the data 500) with the host name. For example, the endpoint with hostname A is listed with an IP address 121.16.0.16, while the endpoint with hostname 'C' is listed with an IP address
Φ · 2 01 5 - - 00086<sup>ν</sup> 0 9-02-2015 '74.20.0.16 While an entity requesting RM 102 to resolve a hostname of the endpoint to an IP address, it is not necessary to know which IP address is stored in the data structure 500, that is, whether it's the payload IP address or the header IP address, such information can be helpful in combination with the successful / unsuccessful knowledge of initiating the connection to the endpoint that establishes a network location. end point.
In some embodiments, the network location, endpoint refers to a network location (for example, public network, private network, or semi-public network) of the machine or node hosting the endpoint. A requesting entity may want such information when trying to set up a test connection between two endpoints. The network location of an endpoint can be determined based on that IP address that is associated with the host name of the endpoint and the success of the connection initiated by RM 102 at the endpoint in question. For example, endpoint A 106 is listed on the first line of data structure 500 with the associated IP address 121.16.0.16. Considering the diagram illustrated in Figure 2, the payload IP address communicated to RM 102 in a payload of the packet transmitted by the endpoint A 106 is 121.16.0.16 (that is, step 2, Fig. 2) and the IP address of header deduced by RM 102 from the packet header transmitted through the endpoint A 106 is 121.16.0.16 (ie, step 3, Fig. 2). Thus, the IP address of the payload (for example, the first address) and the IP address of the header (for example, the second address) are the same. In addition, since the attempt to initiate the connection from RM 102 of the endpoint A 106 was a success (for example, step 5, Fig. 2), the endpoint A 106 can be identified as being housed in a public network (for example, 120, Fig. 1), because the endpoint A 106 connection attempt using the source IP address was not rejected by any type of security device (eg firewall or NAT).
In another example, endpoint B 108 is listed on the second line of data structure 500 with the associated IP address of '10.205.12.120 Given the scale diagram illustrated in Figure 3, the payload IP address communicated to RM 102 in a payload of the transmitted packet the point of B 108 is '10 .205.12.120 (for example, steps 2-4, fig. 3) and the IP address of ¢ -2015-- 000860 9 -02- ΣΒ15 header deducted by RM 102 from the packet header transmitted by endpoint B 108 is '10.18.0.16 (for example, step 5, Fig. 3). In addition, the attempt to initiate the connection from RM 102 to the endpoint B 108 was successful (for example, step 7, Fig. 3). As a result, endpoint B 108 can be identified as being hosted on a private network (for example, 110, Fig. 1), because the attempt to connect to endpoint B 108 using the second IP address (for example, the public IP address associated with the security device 112) was rejected by a security device 112 (for example, a firewall or NAT device ).
In another example, endpoint C 114 is listed on the third line of data structure 500 with the associated IP address of 74.20.0.16. Considering the scale diagram illustrated in Figure 4, the payload IP address communicated to RM 102 in a payload of the packet transmitted by the C 114 endpoint is 10.210.12.120 (that is, steps 2-4, Fig. 4 ) and IP address of the header deducted by RM 102 from the packet header transmitted by the endpoint O 114 is' 74.20.0.16 (for example, step 5, Fig. 4). In addition, since the attempt to initiate the connection of the C 114 endpoint from RM 102 was a success (for example, step 9, Fig. 4), the C 114 endpoint can be identified as being hosted on a network. semi-public or cloud (for example, 116, Fig. 1 ), because the endpoint connection attempt C 114, using the second IP address (for example, the public IP address associated with the security device 118), was accepted, despite the presence of a security device 118 (for example, a firewall or NAT device).
In some embodiments, the data stored in the data structure 500 may be accessible from the RM 104 storage device or from another storage device that is integrated with and / or accessible through RM 102, the computing platform 100 or the corresponding module through - a requesting entity. Referring to Figure 6, a diagram illustrating the resolution of the hostname of the endpoint is described, according to an embodiment of the present invention. For example, registration module (RM) 102 may receive from a requesting entity 600 a request message containing a request to resolve the host name of an endpoint to its associated address. In some respects, in response to receiving a request to resolve the hostname of an endpoint to the associated address, RM 102 may obtain the address ^ 2015-- 000860 9-02-2015
IP, as well as location point network information from data structure 500 and can transmit the resolved host name and IP address information in a response message back to the requesting entity 600.
In some embodiments, the requesting entity 600 may receive the host name of the resolved endpoint and the associated IP address, as well as a network location of the endpoint from RM 102. In this example, the requesting entity 600 may use the host name of unresolved endpoint, associated IP address and / or network location to train either the endpoint in question or a second endpoint to initiate a test connection between itself and the other endpoint. The end point instructed to initiate the test connection depends on the location of the network, on each end point in the test configuration, as described in detail below.
Figure 7 is a diagram illustrating the test connection setting for endpoints, varying network locations, according to an embodiment of the object described here. In some embodiments, after receiving a resolved endpoint host name request and the associated IP address for a first endpoint, the requesting entity 600 may instruct the first endpoint or a second endpoint for initiate a test connection.
Referring to Figure 7, the AC end points (for example, 106, 108, 114) are illustrated and correspond to the AC end points described above. As illustrated in Figure 1, endpoint A 106 is hosted on a public network 120, endpoint B 108 is hosted on a private or company network 110 behind a security device 112, and the endpoint C 114 is hosted on a semi-public network or cloud 116 behind a security device 118. Depending on the location of the network at each endpoint in the test connection, the requesting entity 600 may be configured to train only the endpoint capable of initiating connections to initiate the connection, even if the test traffic will flow from the other endpoint.
In a first example, a test connection between endpoint A 106 and endpoint B 108 may be desirable. In this regard, the requesting entity 600 may send a request message of RM 102, which includes the requests to resolve the host name of both the endpoint A 106 and
VI 0 1 5 - - 00086o 9 -02- 2015 of endpoint B 108. RM 102 can be configured to resolve the host name of each endpoint with the associated IP address (see, for example, Fig. 6) and to transmit a response message back to the requesting entity 600, or to a second endpoint or node, which includes the resolved host name (for example, associated IP address and network location) of both endpoint A 106 and of the end point B 108. Thus, prior to instructing each endpoint to initiate a connection, the requesting entity 600 may establish that endpoint A 106 is hosted on the public network 120, while endpoint B 108 is hosted on the private network 110 behind the device. Security 112. whereas security device 112 may prevent any attempt to initiate test connection from endpoints outside the private network 110, for a test connection to be initiated between end point A 106 and end point B 108, point end B 108 must be the end point to initiate the connection. In this example, regardless of how the test traffic (for example, TCP or UDP) will flow between endpoints, the requesting entity 600 might need to train endpoint B 108 to initiate a test connection with end point A 106.
Also, in another example, a test connection between endpoint B 108 and endpoint C 114. may be desirable. In this respect, the requesting entity 600 may transmit a request message of RM 102, which includes requests to resolve the host name of both endpoint B 108 and endpoint C 114. RM 102 can be configured to resolve the host name of each endpoint with the associated IP address (see, for example, Fig. . 6) and to send a response message back to the requesting entity 600, or to a second endpoint or node, which includes the resolved host name (for example, associated IP address and network location) of the endpoint B 108 as well as the end point C 114. Thus, prior to instructing each endpoint to initiate a connection, the requesting entity 600 may determine that endpoint B 108 is hosted on a private network 110, while endpoint C 114 is hosted on a semi network. -public or cloud 116 behind the security device 118. whereas security device 112 may prevent any ^ -2015--00086q 8 -02- 2015 attempts to initiate test connection from endpoints outside the private network 110, for a test connection to be initiated between the point end B 108 and end point C 114, end point B 108 must be the end point to initiate the connection. In this example, regardless of how the test traffic (for example, TCP or UDP) will flow between endpoints, the requesting entity 600 might need to train endpoint B 108 to initiate a test connection with end point C 114, using the associated IP address (for example, the second IP address associated with the security device 118) to the end point C 114.
In addition, in an example where a test connection between endpoint B 108 and endpoint D (not shown) is desired, where D is also the endpoint hosted on the private network 110, the entity applicant 600 can send a request message to RM 102, which includes requests to resolve host name of both endpoint B 108 and endpoint D. RM 102 can be configured to resolve the host name of each endpoint with the associated IP address (see, for example, Fig. 6) and to send a response message back to the requesting entity 600, or to a second point endpoint or node, which includes resolved hostname (for example, associated IP address and network location) of both endpoint B 108 and endpoint D. Thus, before training, either endpoint to initiate a connection, the requesting entity 600 may establish that both endpoint B and D are hosted on the private network 110. whereas both endpoint B 108 and end point end D are hosted on the private network 110, each of which can initiate the connection to other end points. In this example, the requesting entity 600 may indicate the end point from which the traffic will flow to be the end point that initiates the test connection; although each endpoint can be trained to initiate a connection.
In another example, a test connection between endpoint A 106 and endpoint C 114. may be desirable. To this end, the requesting entity 600 may send a request message to RM 102, which includes requests to resolve the host name of both endpoint A 106 and endpoint C 114. RM 102 can be configured to resolve
A 2 0 1 5 - - 00086g 9 -02- *<sup>c</sup>'<sup>5</sup> / 6} the host name of each endpoint with the associated IP address (see, for example, Fig. 6) and sends a response message back to the requesting entity 600 or a second endpoint or node, which includes the name resolved host (eg, associated IP address and network location) both endpoint A 106 and endpoint C 114. Thus, prior to instructing each endpoint to initiate a connection, the requesting entity 600 may determine that endpoint A 106 is hosted on a public network 120, while endpoint C 114 is hosted on a network. semi-public or cloud 116, behind a security device 118. Since the endpoint A 106 is hosted on a public network, the endpoint C 114 can initiate a connection of the endpoint A 106 using the associated IP address (for example, either the first or second IP address associated with the endpoint A 106). end A 106).
Instead, for endpoint A 106 to initiate a connection with endpoint C 114, endpoint A 106 must initiate connection of endpoint C 114, using the associated IP address (for example, the second IP address associated with the security device 118). Based on the architecture illustrated in Figure 4 (for example, step 5, Fig, 4), RM 102 may be configured to associate the C 114 endpoint with the second IP address or the IP address associated with the security device 118. Thus, when RM 102 sends a response message back to the requesting entity 600, the response message will contain the associated IP address, which allows an endpoint outside the semi-public network or cloud 116 to initiate a connection with the endpoint C 114.
Figure 8 is a diagram illustrating a method 800 for facilitating the resolution of host endpoint names, according to an embodiment of the present invention. In some examples, the process or portions thereof, can be accomplished by the computing platform 100 or RM 102 and / or another node or module. In some embodiments, the process 800 may include steps 802, 804, 806, 808, and / or 810.
Referring to process 800, at step 802, a packet that includes a payload that contains a first address and a host name associated with a first endpoint can be received on a registration server that includes at least one configured processor. to operate on a public network. From ^ - 2 0 1 5 - 000860 9 -02- * δί5 for example, an endpoint can send a request for registration (for example, a registration message or a TCP-valid message), in the form of a data pack . A payload of the packet may contain an address via the Internet protocol and an azdname of the endpoint that is inserted at the endpoint in an IP payload of the packet for a registration module (RM) 102. The endpoint may also includes a second address in a packet header. This includes a source IP address, entered either through the first endpoint or by a NAT in an IP header of the packet. In particular, the packet may be in the form of a TCP or UDP packet.
In some embodiments, the local IP address and host name associated with the endpoint may be preconfigured by a user or may be retrieved from the endpoint, although the specificity of this retrieval is outside the scope of the present invention, in some examples In embodiment, RM 102 may extract the local IP address (for example, TCP / IP) and the host name associated with the endpoint of the payload of the packet.
In step 804, a second address can be identified from a packet header. For example, RM 102 can receive the endpoint in step 802 and can deduce and / or identify a source IP address from the packet header.
At step 806, a connection to the endpoint can be initiated using the second address obtained from the packet IP header. For example, RM 102 may initiate a payload with the endpoint using the source IP address in the packet IP header in this example, RM 102 may send a connection request (for example, a TCP SYN message) to the source IP address identified in end point packet header.
In step 808, the connection can be determined to be successful or unsuccessful. For example, after RM 102 sends a connection request message to the endpoint, it may either receive and accept the connection request or prevent the connection request. In this example, a successful connection depends on a network location of the endpoint. Depending on the network location of the endpoint, it can receive and accept the connection request and send back a connection response message.
^> 2 0 1 5 - 00086ο 9 -02- ΣΒ15 / £ / In some embodiments, if the endpoint receives and accepts the connection request, the endpoint may send a connection response message (e.g. , a TCP message ACK-) back to RM
102.
In some embodiments, the endpoint may impede the connection request if the endpoint is behind a firewall and / or NAT device of a private network.
In step 810, the host name of the endpoint may be associated with one of the first address and the second address, based on the results of the determination (for example, step 808). For example, RM 102 may associate either the IP address (for example, the first address) except the source IP address (for example, the second address), with the host name associated with the endpoint, based on determining whether the connection is successful.
In some embodiments, the first address can be compared to the second address, if the connection to the endpoint is successful. For example, if RM 102 receives a connection response message (for example, a TCP ACK- message) back from the endpoint, after RM 102 has sent a connection initiation message (for example, a TCP SYN message), then RM 102 can continue comparing the IP address of the packet payload (for example, the first address) of the endpoint with the IP address of the packet data header (for example, two addresses).
In this example, if the comparison between the first address and the second address of the endpoint results, in a determination that the first and second addresses of the endpoint are different, then the host name of the endpoint it can be associated with the second address or the packet header address.
Alternatively, in this example, if the comparison between the first address and the second address of the end point results, in a determination that the first address and the second address of the end point are identical, then the host name of the end point may be associated with the second address or with the first address.
In some embodiments, if the endpoint connection is unsuccessful, then the hostname of the endpoint may be associated with the first address. For example, if the end point rejects a fl 1 5 - - 0 0 0 8 6 0 3 -02- 2CJ5 /
registration request message from RM 102, then RM 102 can associate the hostname of the endpoint with a first IP address because the endpoint is behind a security device that prevented the attempt to initiate connection from RM 102 in some embodiments, a network location of an endpoint hosting machine may be determined based on the failure of the endpoint connection and whether the first and second addresses are different or identical. For example, RM 102 can determine a network location of the endpoint, using the information provided in steps 808 and 810. In this example, if the connection attempt fails, RM 102 can determine that an endpoint network location is behind a security device on a private or company network.
Alternatively, in this example, if the connection attempt is successful, RM 102 can then look at whether the comparison of the first address with the second address led to a determination that the two addresses were similar or identical. In particular, if the two addresses are identical, RM 102 may determine that a network location of the endpoint is public, while if the two addresses are different, RM 102 may determine that a network location of the point the end is in a semi-public network or cloud.
In some embodiments, after associating the hostname of the endpoint with either the first or second address, a requesting entity may communicate with the registration server to resolve the hostname of the endpoint to the associated address, for the purpose of training or the end point is a second end point, to initiate a test connection between itself and the other end point. For example, a requesting entity 600 may send a request message to RM 102, the request message containing a request to resolve the hostname of the endpoint to the associated address. RM 102 can then resolve the hostname of the endpoint to the associated address and send back to the requesting entity 600 a response message containing the address associated with the host name of the endpoint. Subsequently, the requesting entity 600 may indicate the endpoint or a second endpoint to initiate a test connection. Alternatively, RM 102 may send back to a second endpoint a reply message containing the address associated with the host name of the other endpoint.
0 15-- a ϋ U «6 0 3 -β- 2fl15 end, to allow the second end point to initiate a test connection with the first end point.
In some embodiments, initiating a test connection between the first end point and the second end point comprises transmitting the test packets from the second end point to the first end point using the address associated with the first end point.
In some embodiments, the host name, the address associated with the endpoint and a network location of a machine hosting the endpoint may be stored in the data storage device. For example, RM 102 can store the host name, address associated with the endpoint and a network location of a machine that hosts the endpoint in the data storage device in a data structure, for example, 500, which is accessible through RM 102, as well as other nodes or entities (for example, the requesting entity 600).
It will be appreciated that process 800 is for illustrative purposes and that different and / or additional actions may be used. It will also be appreciated that the different actions described here may occur in a different order or sequence.
The objects described for registering a hostname of the endpoint provide hostname of the endpoint and their IP address associated with a requesting entity, independent of a DNS server or other external instrument, and regardless of the host machine the location of the host of the endpoint, thus allowing test connections from one end point to another on an appropriate route. It should also be noted that a computing platform that implements the objects described herein may comprise a special computing device (for example, requesting the module to be executed on a computing platform) that can be used to record and host the point of host end and its associated IP addresses.
It will be understood that different details of the objects described herein may be modified without departing from the scope of the present invention. Moreover, the above description is for illustrative purposes only, and not for the purpose of limitation, so that the objects described are defined by the claims set forth below.
Contents4
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
7 members in 4 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 201500086 | Romania | A | |
| RO20150000086 | – | – | – |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| US2016234163A1 | United States of America | A1 | |
| WO2016130280A1 | World Intellectual Property Organization (WIPO) | A1 | |
| RO131360A2This record | Romania | A2 | |
| US9769291B2 | United States of America | B2 | |
| EP3219087A1 | European Patent Office (EPO) | A1 | |
| EP3219087A4 | European Patent Office (EPO) | A4 | |
| EP3219087B1 | European Patent Office (EPO) | B1 |
Numbers
- Publication
- 131360
- Publication, DOCDB
- 131360
- Publication, EPODOC
- RO131360
- Application
- 86
- Application, DOCDB
- 201500086
- Application, EPODOC
- RO20150000086
Titles2
- English
- METHODS, SYSTEMS AND COMPUTER-READABLE MEDIUM THAT FACILITATE RESOLVING ENDPOINT HOSTNAMES IN TESTING-ENVIRONMENT WITH FIREWALLS, NETWORK ADDRESS TRANSLATIONS () OR CLOUDS
- Romanian
- METODE, SISTEME SI SUPORT CITIBIL PE CALCULATOR PENTRU FACILITAREA REZOLVARII NUMELOR GAZDA ALE PUNCTULUI DE CAPAT ÎN MEDIUL DE TESTARE CU FIREWALL-URI, TRADUCERI DE ADRESE DE RETEA () SAU CLOUD-URI
Classification
- CPC, 6
- H04L69/22
- H04L61/1511
- H04L61/2076
- H04L61/2514
- H04L61/2567
- H04L61/15