IP Library › Granted Patent US 11,831,542
Granted Patent B2
US 11,831,542 · App. 17/720,133 · Granted Nov 28, 2023

Platform for routing internet protocol packets using flow-based policy

Inventors: Guy Lewin (New York, NY); Vikrant Arora (UP, IN); Ofir Yakovian (Tel-Aviv, IL)
Assignee: Microsoft Technology Licensing, LLC
H04L45/38H04L12/4633H04L45/566H04L45/745
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,831,542
App. No.
17/720,133
Granted
Nov 28, 2023
Kind
B2
Abstract

Policy-based routing of internet protocol (IP) packets using flow context. A system intercepts an event associated with creation of a network connection by an operating system (OS). The system identifies a flow context, including a flow tuple, associated with the network connection. Based on the flow context, and based on a flow-based routing policy, the system determines a provider associated with the network connection. The system records, in a state database, an association between the flow tuple and the provider, and instructs the OS to initiate the network connection. After the creation of the network connection, the system intercepts an IP packet associated with the network connection. Based on a header of the IP packet, the system identifies the flow tuple and, based on a result of querying the state database for the flow tuple, and initiates a provider-based action for the IP packet.

Claims (66)

1. A method, implemented at a computer system that includes a processor, for policy-based routing of IP (internet protocol) packets using flow context, the method comprising:

intercepting an event associated with creation of a network connection by an OS (operating system);

identifying a flow context associated with the network connection, the flow context including a flow tuple;

based on the flow context, and based on a flow-based routing policy:

determining a provider at the computer system that is associated with the network connection,

recording, in a state database, an association between the flow tuple and the provider, and

instructing the OS to initiate the network connection;

after the creation of the network connection, intercepting an IP packet associated with the network connection;

based on a header of the IP packet, identifying the flow tuple; and

based on a result of querying the state database for the flow tuple, initiating a provider-based action for the IP packet.

2. The method of claim 1 , wherein the provider is a tunnel component, the IP packet is an outbound packet, and the provider-based action comprises routing the IP packet to the provider.

3. The method of claim 1 , wherein the provider is a tunnel component, the IP packet is an inbound packet, and the provider-based action comprises routing the IP packet to the OS.

4. The method of claim 1 , wherein the provider is a firewall component, and the provider-based action comprises dropping the IP packet.

5. The method of claim 1 , wherein the provider is a firewall component, and the provider-based action comprises one or more of modifying the IP packet or passing the IP packet.

6. The method of claim 1 , wherein the flow context also includes at least one of a process identifier of a process initiating the event, an owning user of the process initiating the event, a user of an interactive session associated with the process initiating the event, a destination domain, or a destination domain category.

7. The method of claim 1 , wherein the flow tuple includes one or more of a source IP address, a source port, a destination IP address, a destination port, or a protocol.

8. The method of claim 1 , further comprising:

determining that the network connection has been destroyed; and

removing, from the state database, the association between the flow tuple and the provider.

9. The method of claim 1 , further comprising:

intercepting a second event associated with creation of a second network connection by the OS;

identifying a second flow context of the second network connection, the second flow context including a second flow tuple; and

based on the second flow context, and based on the flow-based routing policy:

determining a block action for the second network connection, and

terminating the creation of the second network connection.

10. The method of claim 9 , further comprising recording, in the state database, an association between the second flow tuple and the block action.

11. The method of claim 1 , further comprising:

intercepting a second event associated with creation of a second network connection by the OS;

identifying a second flow context of the second network connection, the second flow context including a second flow tuple;

based on the second flow context, and based on the flow-based routing policy:

determining a bypass action for the second network connection, and

instructing the OS to proceed with the creation of the second network connection;

after the creation of the second network connection, intercepting a second IP packet associated with the second network connection;

based on a second header of the second IP packet, identifying the second flow tuple; and

based on a result of querying the state database for the second flow tuple, routing the second IP packet to a network stack.

12. The method of claim 11 , wherein routing the second IP packet to the network stack is based on the result of querying the state database for the second flow tuple comprising a failure to locate the second flow tuple in the state database.

13. The method of claim 11 , further comprising:

recording, in the state database, an association between the second flow tuple and the bypass action,

wherein routing the second IP packet to the network stack is based on the result of querying the state database for the second flow tuple identifying the bypass action for the second flow tuple.

14. The method of claim 1 , further comprising grouping a plurality of network connections into a channel, based on each of the plurality of network connections being associated with a common network identity.

15. A computer system for policy-based routing of IP (internet protocol) packets using flow context, comprising:

a processor; and

a computer storage media that stores computer-executable instructions that are executable by the processor to cause the computer system to at least:

intercept an event associated with creation of a network connection by an OS (operating system);

identify a flow context associated with the network connection, the flow context including a flow tuple;

based on the flow context, and based on a flow-based routing policy:

determine a provider at the computer system that is associated with the network connection,

record, in a state database, an association between the flow tuple and the provider, and

instruct the OS to initiate the network connection;

after the creation of the network connection, intercept an IP packet associated with the network connection;

based on a header of the IP packet, identify the flow tuple; and

based on a result of querying the state database for the flow tuple, initiate a provider-based action for the IP packet.

16. The computer system of claim 15 , wherein the provider is a tunnel component, the IP packet is an outbound packet, and the provider-based action comprises routing the IP packet to the provider.

17. The computer system of claim 15 , wherein the provider is a tunnel component, the IP packet is an inbound packet, and the provider-based action comprises routing the IP packet to the OS.

18. The computer system of claim 15 , wherein the provider is a firewall component, and the provider-based action comprises dropping the IP packet.

19. The computer system of claim 15 , wherein the provider is a firewall component, and the provider-based action comprises one or more of modifying the IP packet or passing the IP packet.

20. A computer program product comprising a computer storage media that stores computer-executable instructions that are executable by a processor to cause a computer system to implement policy-based routing of IP (internet protocol) packets using flow context, the computer-executable instructions including instructions that are executable by the processor to cause the computer system to at least:

intercept an event associated with creation of a network connection by an OS (operating system);

identify a context of the network connection, the context including a flow tuple;

based on the context, and based on a flow-based routing policy:

determine a provider at the computer system that is associated with the network connection,

record, in a state database, an association between the flow tuple and the provider, and

instruct the OS to initiate the network connection;

after the creation of the network connection, intercept an IP packet associated with the network connection;

based on a header of the IP packet, identify the flow tuple; and

based on a result of querying the state database for the flow tuple, initiate a provider-based action for the IP packet.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2022
From: LEWIN, GUY; ARORA, VIKRANT; YAKOVIAN, OFIR
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 059590/0681 →
Continuity (1)
Related Publication 20230336465A1 · Oct 19, 2023