DNS-based determining whether a device is inside a network
    1.
    发明授权
    DNS-based determining whether a device is inside a network 有权
    基于DNS的确定设备是否在网络内

    公开(公告)号:US09313085B2

    公开(公告)日:2016-04-12

    申请号:US12970371

    申请日:2010-12-16

    IPC分类号: H04L29/00 H04L29/12 H04L29/06

    摘要: In a computing device a domain name system (DNS) query is generated and sent, and a check is made as to whether a verified DNS response to the DNS query is received. The computing device is determined to be inside a particular network if a verified DNS response is received, and is determined to be outside that particular network if a verified DNS response is not received. A DNS response can be determined to be verified if both the DNS response has an expected value and the DNS response is digitally signed by a trusted authority, and otherwise can be determined to be not verified.

    摘要翻译: 在计算设备中,生成并发送域名系统(DNS)查询,并且检查是否接收到对DNS查询的经过验证的DNS响应。 如果接收到已验证的DNS响应,则计算设备被确定在特定网络内,并且如果未接收到经验证的DNS响应,则确定该外部在该特定网络之外。 如果DNS响应具有预期值并且DNS响应由可信管理机构进行数字签名,则可以确定DNS响应以被验证,否则可以被确定为不被验证。

    DNS-BASED DETERMINING WHETHER A DEVICE IS INSIDE A NETWORK
    3.
    发明申请
    DNS-BASED DETERMINING WHETHER A DEVICE IS INSIDE A NETWORK 有权
    基于DNS的确定,无论设备在网络内

    公开(公告)号:US20120159636A1

    公开(公告)日:2012-06-21

    申请号:US12970371

    申请日:2010-12-16

    IPC分类号: G06F15/173 G06F21/00

    摘要: In a computing device a domain name system (DNS) query is generated and sent, and a check is made as to whether a verified DNS response to the DNS query is received. The computing device is determined to be inside a particular network if a verified DNS response is received, and is determined to be outside that particular network if a verified DNS response is not received. A DNS response can be determined to be verified if both the DNS response has an expected value and the DNS response is digitally signed by a trusted authority, and otherwise can be determined to be not verified.

    摘要翻译: 在计算设备中,生成并发送域名系统(DNS)查询,并且检查是否接收到对DNS查询的经过验证的DNS响应。 如果接收到已验证的DNS响应,则计算设备被确定在特定网络内,并且如果未接收到经验证的DNS响应,则确定该外部在该特定网络之外。 如果DNS响应具有预期值并且DNS响应由可信管理机构进行数字签名,则可以确定DNS响应以被验证,否则可以被确定为不被验证。

    Determining whether a device is inside a network
    8.
    发明授权
    Determining whether a device is inside a network 有权
    确定设备是否在网络内

    公开(公告)号:US08949411B2

    公开(公告)日:2015-02-03

    申请号:US12970298

    申请日:2010-12-16

    IPC分类号: G06F15/173 H04L29/12

    CPC分类号: H04L61/2007

    摘要: A network address of a computing device is obtained, and an unencrypted request is sent to a resource access manager of a particular network. If both a response is received from the resource access manager and the computing device has a network address within a desired range of network addresses, then a determination is made that the computing device is inside the particular network. Otherwise, a determination is made that the computing device is outside the particular network.

    摘要翻译: 获得计算设备的网络地址,将未加密的请求发送到特定网络的资源访问管理器。 如果从资源访问管理器接收到响应并且计算设备具有期望的网络地址范围内的网络地址,则确定计算设备在特定网络内。 否则,确定计算设备在特定网络之外。

    Monitoring remote access to an enterprise network
    9.
    发明授权
    Monitoring remote access to an enterprise network 有权
    监控企业网络的远程访问

    公开(公告)号:US08775614B2

    公开(公告)日:2014-07-08

    申请号:US13299975

    申请日:2011-11-18

    IPC分类号: G06F15/173

    摘要: Techniques to provide an improved representation of remote network access for a network administrator managing and controlling access to resources on an enterprise network. The representation indicates resources accessed by a remote computer or by a user of that computer and provides associated information useful for managing remote network access. To create the representation, multiple security associations formed between a remote client computer and resources on the enterprise network are associated with entity sessions, based on identical session identifiers generated for each security association within an entity session. The entity sessions may be aggregated into a to DirectAccess “connection” between the remote client computer and the enterprise network, based on an identity of the remote client computer. Resources accessed over the connection may be identified using a session identifier of each entity session so that security associations in that entity session may be matched with the resources.

    摘要翻译: 为网络管理员提供远程网络访问的改进表示的技术,管理和控制对企业网络上的资源的访问。 该表示指示由远程计算机或该计算机的用户访问的资源,并提供对管理远程网络访问有用的相关信息。 为了创建表示,基于为实体会话期间的每个安全关联生成的相同的会话标识符,在远程客户端计算机和企业网络上的资源之间形成的多个安全关联与实体会话相关联。 基于远程客户端计算机的身份,实体会话可以聚合到远程客户端计算机和企业网络之间的DirectAccess“连接”中。 可以使用每个实体会话的会话标识符来识别通过连接访问的资源,使得该实体会话中的安全关联可以与资源匹配。