IP Library Granted Patent US 12,438,845
Granted Patent B2
US 12,438,845 · App. 18/592,333 · Granted Oct 7, 2025

Systems and methods for internal secure network resolution

Inventors: Weining Wu (Burnaby, CA); Kunal Marwah (Burnaby, CA); Jinhai Yang (Burnaby, CA); Xu Zheng (Burnaby, CA)
Assignee: Fortinet, Inc.
H04L63/0236H04L41/12H04L63/0876H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,845
App. No.
18/592,333
Granted
Oct 7, 2025
Kind
B2
Abstract

Systems, devices, and methods are discussed for limiting exposure of internal network operations beyond the boundary of a secure network.

Claims (44)

1. A method comprising:

intercepting, by an endpoint security application of an endpoint device associated with a secured network, a request to access a particular network resource within the secured network, wherein the request for the particular network resource includes a domain name corresponding to the particular network resource;

accessing, by the endpoint security application, an internal list of domain names maintained within the secure network, wherein the internal list of domain names includes a plurality of domain names each identifying a given network resource of a plurality of network resources accessible on the secured network and corresponding to an internet protocol (IP) address of the given network resource;

based at least in part on determining that the particular network resource is included in the internal list of domain names, limiting exposure of internal network operations of the secured network, by locally resolving, by the endpoint security application, the IP address of the particular network resource with reference to the internal list of domain names; and

returning, by the endpoint security application, a response to the request including the IP address in a format used by a domain name system (DNS).

2. The method of claim 1 , further comprising receiving, by the endpoint security application, the internal list of domain names from a network resource within the secured network.

3. The method of claim 2 , wherein the network resource comprises an endpoint management system (EMS) with which the endpoint device is registered.

4. The method of claim 3 , wherein each network resource of the plurality of network resources accessible on the secured network is registered with the EMS, has a trust certificate issued by the EMS to the registered network resource, and is included on a zero-trust network access (ZTNA) access control list maintained by a network security appliance of the secured network.

5. The method of claim 1 , further comprising:

intercepting, by the endpoint security application, a second request to access a second particular network resource within the secured network, wherein the second request for the second particular network resource includes a second domain name corresponding to the second particular network resource;

accessing, by the endpoint security application, the internal list of domain names; and

based at least in part on determining that the second particular network resource is absent from the internal list of domain names, forwarding, by the endpoint security application, a domain name server request for the second domain name to a domain server outside of the secured network.

6. The method of claim 5 , further comprising:

receiving, by the endpoint security application, an IP address corresponding to the second domain name from the domain server; and

providing, by the endpoint security application, the corresponding IP address for use by the endpoint device.

7. An endpoint device for deployment within a secured network, the endpoint device comprising:

one or more processing resources;

a non-transitory computer-readable medium, coupled to the one or more processing resources, having stored therein instructions that when executed by the one or more processing resources cause the endpoint device to:

intercept, by an endpoint security application of the endpoint security device, a request to access a particular network resource within the secured network, wherein the request for the particular network resource includes a domain name corresponding to the particular network resource;

access, by the endpoint security application, an internal list of domain names maintained within the secure network, wherein the internal list of domain names includes a plurality of domain names each identifying a given network resource of a plurality of network resources accessible on the secured network and corresponding to an internet protocol (IP) address of the given network resource;

based at least in part on a determination that the particular network resource is included in the internal list of domain names, limit exposure of internal network operations of the secured network, by locally resolving the IP address of the particular network resource with reference to the internal list of domain names; and

return a response to the request including the IP address in a format used by a domain name system (DNS).

8. The endpoint device of claim 7 , wherein the instructions further cause the endpoint device to receive the internal list of domain names from a network resource within the secured network.

9. The endpoint device of claim 8 , wherein the network resources comprises an endpoint management system (EMS) with which the endpoint device is registered.

10. The endpoint device of claim 9 , wherein each network resource of the plurality of network resources accessible on the secured network is registered with the EMS, has a trust certificate issued by the EMS to the registered network resource, and is included on a zero-trust network access (ZTNA) access control list maintained by a network security appliance of the secured network.

11. The endpoint device of claim 7 , wherein the instructions further cause the system endpoint device to:

intercept a second request to access a second particular network resource within the secured network, wherein the second request for the second particular network resource includes a second domain name corresponding to the second particular network resource;

access the internal list of domain names; and

based at least in part on a determination that the second particular network resource is absent from the internal list of domain names, forward a domain name server request for the second domain name to a domain server outside of the secured network.

12. A non-transitory computer-readable storage medium embodying instructions, which when executed by one or more processing resources of an endpoint device associated with a secured network, cause an endpoint security application of the endpoint device to:

intercept a request by to access a particular network resource within the secured network, wherein the request for the particular network resource includes a domain name corresponding to the particular network resource;

access an internal list of domain names maintained within the secure network, wherein the internal list of domain names includes a plurality of domain names each identifying a given network resource of a plurality of network resources accessible on the secured network and corresponding to an internet protocol (IP) address of the given network resource;

based at least in part on a determination that the particular network resource is included in the internal list of domain names, limit exposure of internal network operations of the secured network, by locally resolving the IP address of the particular network resource with reference to the internal list of domain names; and

return a response to the request including the IP address in a format used by a domain name system (DNS).

13. The non-transitory computer-readable storage medium of claim 12 , wherein the instructions further cause the endpoint security application to receive the internal list of domain names from a network resource within the secured network.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the network resource comprises an endpoint management system (EMS) with which the endpoint device is registered.

15. The non-transitory computer-readable storage medium of claim 14 , wherein each network resource of the plurality of network resources accessible on the secured network is registered with the EMS, has a trust certificate issued by the EMS to the registered network resource, and is included on a zero-trust network access (ZTNA) access control list maintained by a network security appliance of the secured network.

16. The non-transitory computer-readable storage medium of claim 12 , wherein the instructions further cause the endpoint security application to:

intercept a second request to access a second particular network resource within the secured network, wherein the second request for the second particular network resource includes a second domain name corresponding to the second particular network resource;

access the internal list of domain names; and

based at least in part on a determination that the second particular network resource is absent from the internal list of domain names, forward a domain name server request for the second domain name to a domain server outside of the secured network.

17. The non-transitory computer-readable storage medium of claim 16 , wherein the instructions further cause the endpoint security application to:

receive an IP address corresponding to the second domain name from the domain server; and

provide the corresponding IP address for use by the endpoint device.

Continuity (2)
Continuation 17463787 · Sep 1, 2021
Related Publication 20240205189A1 · Jun 20, 2024
References Cited (12)
US 6118768A · Bhatia · 2000 [cited by examiner]
US 7725921B2 · Trutner · 2010 [cited by examiner]
US 11394746B2 · Buck · 2022 [cited by examiner]
US 11956211B2 · Wu · 2024 [cited by examiner]
US 20160197898A1 · Hozza · 2016 [cited by examiner]
US 20170279846A1 · Osterweil · 2017 [cited by examiner]
US 20180167361A1 · Xiao · 2018 [cited by examiner]
US 20180205734A1 · Wing · 2018 [cited by examiner]
US 20200252374A1 · Bosch · 2020 [cited by examiner]
US 20200351244A1 · Moore · 2020 [cited by examiner]
US 20220353293A1 · Buck · 2022 [cited by examiner]
US 20230049547A1 · Glazemakers · 2023 [cited by examiner]