IP Library Granted Patent US 11,012,419
Granted Patent B2
US 11,012,419 · App. 16/357,515 · Granted May 18, 2021

Systems and methods for management of software connections

Inventors: Chen-Chung Lee (Taoyuan, TW); Chia-Hung Lin (Taoyuan, TW); Cheng-Yao Wang (Taoyuan, TW); Jen-Hung Chang (Taoyuan, TW); Ming-Jen Chen (Taoyuan, TW)
Assignee: QUANTA COMPUTER INC.
H04L63/0281H04L63/0236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,012,419
App. No.
16/357,515
Granted
May 18, 2021
Kind
B2
Abstract

A system including a network communication device, a storage device, and a controller is provided. The storage device stores first mappings between IP addresses and devices, and second mappings between software and devices. The controller obtains a connection log from the proxy server or the firewall device via the network communication device, uses the first mappings and the second mappings to analyze the connection log to determine one or more different connections between connections of devices on which first software is installed and connections of devices on which the first software is not installed, determines whether the first software functions normally on a first device blocking the different connections, and adds destination addresses of the different connections into a blocking list in response to the first software functioning normally on the first device, such that the proxy server or the firewall device blocks all connections towards the destination addresses.

Claims (24)

1. A system, comprising:

a network communication device, configured to provide a network connection to at least a proxy server or a firewall device;

a storage device, configured to store first mappings between Internet Protocol (IP) addresses and devices, and second mappings between software and devices; and

a controller, configured to obtain a connection log from the proxy server or the firewall device via the network communication device, use the first mappings and the second mappings to analyze the connection log to determine one or more different connections between connections of devices on which first software is installed and connections of devices on which the first software is not installed, determine whether the first software functions normally on a first device blocking the different connections, and add destination addresses of the different connections into a blocking list in response to the first software functioning normally on the first device, such that the proxy server or the firewall device blocks all connections towards the destination addresses.

2. The system of claim 1 , wherein the controller is further configured to add the destination addresses into a monitoring list in response to the first software not functioning normally on the first device, such that the proxy server or the firewall device monitors all connections towards the destination addresses.

3. The system of claim 1 , wherein the controller is further configured to determine whether the different connections are associated with the first software, and the determining of whether the first software functions normally on the first device blocking the different connections is performed in response to the different connections being associated with the first software.

4. The system of claim 1 , wherein the controller is further configured to obtain information of a second connection from a second device on which only the first software is installed, and include the second connection in the different connections.

5. The system of claim 1 , wherein the first mappings further include periods of time in which the first software functions on the devices, and the controller is further configured to exclude, from the different connections, connections which are not logged during the periods of time, prior to determining whether the first software functions normally on the first device blocking the different connections.

6. A method, executed by a controller of a system connected to a proxy server or a firewall device, comprising:

obtaining a connection log from the proxy server or the firewall device;

obtaining first mappings and second mappings, wherein the first mappings are mappings between devices and Internet Protocol (IP) or Media Access Control (MAC) addresses, and the second mappings are mappings between software and devices;

using the first mappings and the second mappings to analyze the connection log to determine one or more different connections between connections of devices on which first software is installed and connections of devices on which the first software is not installed;

determining whether the first software functions normally on a first device blocking the different connections; and

adding destination addresses of the different connections into a blocking list in response to the first software functioning normally on the first device, such that the proxy server or the firewall device blocks all connections towards the destination addresses.

7. The method of claim 6 , further comprising:

adding the destination addresses into a monitoring list in response to the first software not functioning normally on the first device, such that the proxy server or the firewall device monitors all connections towards the destination addresses.

8. The method of claim 6 , further comprising:

determining whether the different connections are associated with the first software;

wherein the determining of whether the first software functions normally on the first device blocking the different connections is performed in response to the different connections being associated with the first software.

9. The method of claim 6 , further comprising:

obtaining information of a second connection from a second device on which only the first software is installed; and

including the second connection in the different connections.

10. The method of claim 6 , wherein the first mappings further include periods of time in which the first software functions on the devices, and the method further comprises:

excluding connections which are not logged during the periods of time from the different connections, prior to determining whether the first software functions normally on the first device blocking the different connections.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2019
From: LEE, CHEN-CHUNG; LIN, CHIA-HUNG; WANG, CHENG-YAO; CHANG, JEN-HUNG; CHEN, MING-JEN
To: QUANTA COMPUTER INC.
Reel/Frame 048632/0630 →
Priority Claims (1)
TW 107142171 · Nov 27, 2018 · national
Continuity (1)
Related Publication 20200169537A1 · May 28, 2020