Invention Grant
- Patent Title: Domain-name-based network-connection attestation
-
Application No.: US16253238Application Date: 2019-01-22
-
Publication No.: US11677713B2Publication Date: 2023-06-13
- Inventor: Kanika Nema , Daniel G. Wing , Goresh Musalay
- Applicant: VMWARE, INC.
- Applicant Address: US CA Palo Alto
- Assignee: VMware, Inc.
- Current Assignee: VMware, Inc.
- Current Assignee Address: US CA Palo Alto
- Priority: IN 1841037840 2018.10.05
- Main IPC: H04L61/4511
- IPC: H04L61/4511 ; H04L61/2514 ; H04L61/10 ; H04L61/58 ; H04L61/5007

Abstract:
A domain-name-based network-connection attestation system provides for more user friendly and less error prone (compared to IP-address-based attestation systems) updating of a whitelist used to determine whether or not to allow a requested network connection. A guest agent extracts from a DNS reply a domain name, and an IP address mapped to a domain name. The agent enters these values in an agent DNS cache. When a process requests a connection to an IP address, the agent uses the IP address to determine the domain name from the agent DNS cache. The agent then determines whether the IP address is mapped to the process identity in a domain-name-based whitelist. If it is, the connection is attested to and allowed; if it is not, a secondary IP address whitelist can be checked.
Information query