IP Library Granted Patent US 10,225,177
Granted Patent B2
US 10,225,177 · App. 15/363,660 · Granted Mar 5, 2019

Network proxy detection

Inventors: Na Li (Austin, TX); Lan Li (Austin, TX); Chris O'Brien (Austin, TX)
Assignee: SOLARWINDS WORLDWIDE, LLC
H04L45/26H04L43/10H04L43/106H04L45/124H04L67/28
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,225,177
App. No.
15/363,660
Granted
Mar 5, 2019
Kind
B2
Abstract

A method includes detecting a first path between a user equipment and a first network entity. The method also include detecting a second path between the user equipment and a second network entity, where the first path is longer than the second path. In addition, the method includes determining whether the second network entity is a proxy server located between the user equipment and the first network entity based on an estimated value of the first path and an estimated value of the second path.

Claims (45)

1. A method comprising:

detecting a first path between a user equipment and a first network entity;

detecting a second path between the user equipment and a second network entity, wherein the first path is longer than the second path;

determining whether the second network entity is a proxy server located between the user equipment and the first network entity based on an estimated value of the first path and an estimated value of the second path;

identifying an error at the proxy server;

estimating at least the value of the first path, wherein the value of the first path comprises an initial time-to-live value of a response packet from the first network entity, by adding the time-to-live value of the first network entity and a hop count value of the first network entity, and subtracting the added values by one; and

estimating at least the value of the second path, wherein the value of the second path comprises an initial time-to-live value of a response packet from the second network entity, by adding a time-to-live value of the second network entity and a hop count value of the second network entity, and subtracting the added values by one,

wherein when the estimated value of the first network entity is equal to the second value of the second network entity, the second network entity is not a proxy server of the first path, and

wherein when the estimated value of the first network entity is not equal to the second value of the second network entity, the second network entity is a proxy server of the first path.

2. The method according to claim 1 , wherein the estimated value of the first path and the estimated value of the second path are time-to-live values.

3. The method according to claim 1 , wherein the first path and the second hop share at least one hop.

4. The method according to claim 1 , wherein all of the hops of the second path are included in the first path.

5. The method according to claim 1 , further comprising:

comparing the estimated value of the first path and the estimated value of the second path to a predetermined list of values of devices or operating systems.

6. The method according to claim 5 , wherein when the estimated value of the first path and the estimated value of the second path match to the values of device or operating systems in the predetermined list, the second network entity is the proxy server.

7. The method according to claim 1 , wherein a traceroute probe is used to determine the first path and the second path.

8. The method according to claim 7 , wherein connection-based probing or standard-based probing are used to determine at least the first path or the second path.

9. The method according to claim 8 , wherein the connection-based probing is used to determine the second path and the standard-based probing is used to determine the first path.

10. The method according to claim 1 , wherein when the second network entity is the proxy located in the first path, the second network entity does not let any probing packets through to the first entity.

11. The method according to claim 1 , wherein the first entity and the second entity have the same IP address.

12. An apparatus, comprising:

at least one memory comprising computer program code;

at least one processor;

wherein the at least one memory and the computer program code are configured, with the at least one processor, to cause the apparatus at least to:

detect a first path between a user equipment and a first network entity;

detect a second path between the user equipment and a second network entity, wherein the first path is longer than the second path; and

determine whether the second network entity is a proxy server located between the user equipment and the first network entity based on an estimated value of the first path and an estimated value of the second path;

identify an error at the proxy server;

estimate at least the value of the first path, wherein the value of the first path comprises an initial time-to-live value of a response packet from the first network entity, by adding the time-to-live value of the first network entity and a hop count value of the first network entity, and subtracting the added values by one; and

estimate at least the value of the second path, wherein the value of the second path comprises an initial time-to-live value of a response packet from the second network entity, by adding the time-to-live value of the second network entity and a hop count value of the second network entity, and subtracting the added values by one,

wherein when the estimated value of the first network entity is not equal to the value of the second network entity, the second network entity is the proxy server, and

wherein when the estimated value of the first path and the estimated value of the second path match values of a device or operating systems in a predetermined list, the second network entity is the proxy server.

13. The apparatus according to claim 12 , wherein the estimated value of the first path and the estimated value of the second path are time-to-live values.

14. The apparatus according to claim 12 , wherein all of the hops of the second path are included in the first path.

15. The apparatus according to claim 12 , wherein a traceroute probe is used to determine the first path and the second path.

16. The apparatus according to claim 12 , wherein the first entity and the second entity have the same IP address.

17. A non-transitory computer-readable medium encoding instructions that, when executed in hardware, perform a process, the process comprising:

detecting a first path between a user equipment and a first network entity;

detecting a second path between the user equipment and a second network entity, wherein the first path is longer than the second path; and

determining whether the second network entity is a proxy server located between the user equipment and the first network entity based on an estimated value of the first path and an estimated value of the second path;

identifying an error at the proxy server;

estimating at least the value of the first path, wherein the value of the first path comprises an initial time-to-live value of a response packet from the first network entity, by adding the time-to-live value of the first network entity and a hop count value of the first network entity, and subtracting the added values by one; and

estimating at least the value of the second path, wherein the value of the second path comprises an initial time-to-live value of a response packet from the second network entity, by adding a time-to-live value of the second network entity and a hop count value of the second network entity, and subtracting the added values by one,

wherein when the estimated value of the first network entity is equal to the second value of the second network entity, the second network entity is not a proxy server of the first path, and

wherein when the estimated value of the first network entity is not equal to the second value of the second network entity, the second network entity is a proxy server of the first path.

Assignments (9)
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL 066489/FRAME 0329 Recorded Apr 17, 2025
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: SOLARWINDS WORLDWIDE, LLC
Reel/Frame 070884/0714 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 17, 2025
From: SOLARWINDS WORLDWIDE, LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 070884/0832 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Apr 17, 2025
From: SOLARWINDS WORLDWIDE, LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 070884/0846 →
ASSIGNMENT OF FIRST LIEN SECURITY INTEREST IN PATENT COLLATERAL Recorded Feb 5, 2024
From: CREDIT SUISSE AG, NEW YORK BRANCH
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 066489/0329 →
ASSIGNMENT OF FIRST LIEN SECURITY INTEREST IN PATENT COLLATERAL Recorded Dec 27, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: CREDIT SUISSE AG, NEW YORK BRANCH
Reel/Frame 062230/0301 →
RELEASE OF SECURITY INTEREST Recorded Nov 1, 2018
From: WILMINGTON TRUST, NATIONAL ASSOCIATION
To: AJAX ILLINOIS CORP.; SOLARWINDS WORLDWIDE, LLC
Reel/Frame 047383/0693 →
SECURITY INTEREST Recorded Mar 20, 2018
From: AJAX ILLINOIS CORP.; SOLARWINDS WORLDWIDE, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 045284/0502 →
SECURITY INTEREST Recorded Mar 12, 2018
From: SOLARWINDS WORLDWIDE LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 045176/0552 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2016
From: LI, NA; LI, LAN; O'BRIEN, CHRIS
To: SOLARWINDS WORLDWIDE, LLC
Reel/Frame 040755/0010 →
Continuity (1)
Related Publication 20180152375A1 · May 31, 2018
Cited By (1)
US 12,621,269