Generate application-based proxy auto-configuration

Automatically generate PAC files through network devices, and dynamically select access methods based on application signatures and policy, the problems of error-prone and high resource consumption in the existing technology are solved, and flexible business processing and user experience are achieved.

CN115883316BActive Publication Date: 2025-08-15HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211573489.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2018-11-28
Filing Date
2019-06-27
Publication Date
2025-08-15
Estimated Expiration
2039-06-27

AI Technical Summary

Technical Problem

The existing PAC file generation process is prone to errors, causing the proxy server to become a bottleneck, affecting the delay and user experience of web applications, and inflexible rules increase resource consumption and cost.

Method used

Network devices automatically generate PAC files, dynamically select access methods based on application signatures and policies, and configure client devices to flexibly use proxy servers or communicate directly with application platforms.

Benefits of technology

It reduces the delay between client devices and application platforms, reduces the processing load of proxy servers, saves resources, and provides flexible business processing methods, improves user experience and reduces costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115883316B_ABST
    Figure CN115883316B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to generating an application-based proxy auto-configuration. A network device may identify an application signature associated with a web application and may determine, based on an application-based policy associated with the web application, an access method to be used to send services associated with the web application. The network device may generate a proxy auto-configuration (PAC) file using the application signature associated with the web application and the access method to be used to send services associated with the web application. The network device may provide the PAC file to a client device to allow the client device to send services associated with the web application based on the PAC file.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Divisional Application Instructions

[0002] This application is a divisional application of the Chinese invention patent application with the application date of June 27, 2019, application number 201910570409.X, and name “Generating Application-Based Proxy Automatic Configuration”. Background Art

[0003] A proxy auto-configuration (PAC) file can configure a client device to use a specific access method to send traffic to a server device and / or receive traffic from a server device. Examples of access methods include sending and / or receiving traffic via a proxy server device, sending and / or receiving traffic without using a proxy server device (e.g., by communicating directly with the server device), and the like. Summary of the Invention

[0004] According to some implementations, a network device may include: one or more memories, and one or more processors communicatively coupled to the one or more memories, configured to identify an application signature associated with a web application and to determine, based on an application-based policy associated with the web application, an access method to be used to send traffic associated with the web application. The one or more processors may generate a Proxy Auto-Configuration (PAC) file using the application signature associated with the web application and the access method to be used to send traffic associated with the web application. The one or more processors may provide the PAC file to a client device to allow the client to send traffic associated with the web application based on the PAC file.

[0005] According to some implementations, a non-transitory computer-readable medium may store one or more instructions that, when executed by one or more processors of a network device, cause the one or more processors to identify an application signature associated with a web application and, based on an application-based policy associated with the web application, determine an access method to be used to send traffic associated with the web application. The one or more instructions may cause the one or more processors to generate a proxy auto-configuration (PAC) file using the application signature associated with the web application and the access method to be used to send traffic associated with the web application. The one or more instructions may cause the one or more processors to associate the PAC file with a uniform resource locator (URL) and, upon receiving a request specifying the URL from the client device, provide the PAC file to the client device.

[0006] According to some implementations, a method may include identifying multiple application signatures, wherein respective application signatures in the multiple application signatures are associated with respective web applications in a plurality of web applications, and determining multiple access methods to be used for sending traffic associated with the multiple web applications, wherein respective access methods in the multiple access methods are to be used for sending traffic associated with the respective web applications. The method may include generating a proxy auto-configuration (PAC) file using each application signature in the multiple application signatures and the respective access method to be used for sending traffic associated with the respective web applications. The method may include providing the PAC file to a client device. BRIEF DESCRIPTION OF THE DRAWINGS

[0007] Figure 1A-1E is a diagram of an example implementation described herein.

[0008] Figure 2 is a diagram of an example application signature.

[0009] Figure 3 is a diagram of an example PAC file.

[0010] Figure 4 is an illustration of an example environment in which the systems and / or methods described herein may be implemented.

[0011] Figure 5A and Figure 5B yes Figure 2 An illustration of example components of one or more devices.

[0012] Figures 6-10 is a flow chart of an example process for generating an application-based proxy auto-configuration. DETAILED DESCRIPTION

[0013] The following detailed description of example implementations refers to the accompanying drawings, in which the same reference numerals in different drawings may identify the same or similar elements.

[0014] In some cases, an entity (e.g., an organization) may manually generate a PAC file that is used to configure one or more client devices communicatively connected to a network associated with the entity. For example, a network administrator, information technology (IT) personnel, etc. associated with the entity may select one or more access methods to be used to send and / or receive services associated with one or more server devices, may incorporate the one or more access methods into a PAC file, and may provide the PAC file to one or more client devices. However, generating a PAC file is a cumbersome process prone to errors (e.g., a PAC file may be generated using an incorrect proxy server address, a PAC file may be generated such that a particular type of service is associated with an incorrect access method, etc.). Furthermore, some PAC files may be generated using inflexible rules that cause all or most of the services sent and / or received by a client device to be sent and / or received via a proxy server device. As the number of client devices connected to an entity's network increases, the proxy server device may become a bottleneck for certain web application services (e.g., such as services associated with web applications that require low latency and / or high bandwidth), which may result in delays between the client devices associated with the web application and the application platform, which in turn may cause a degraded user experience of the web application, degraded service quality of the web application, periodic disconnections between the client device and the application platform, increased service processing time at the proxy server device, lost packets at the proxy server, and the like.

[0015] Some implementations described herein provide a network device capable of automatically generating an application-based PAC file. In some implementations, the network device may identify an application signature associated with a web application and may determine, based on an application-based policy associated with the web application, an access method to be used to send services associated with the web application. The network device may generate a PAC file that may include information specifying an association between the application signature associated with the web application and the access method to be used to send services associated with the web application. The network device may provide the PAC file to a client device to allow the client device to send services associated with the web application based on the PAC file.

[0016] In this way, a network device can generate a PAC file that configures a client device to send traffic associated with multiple different web applications using various access methods. In this way, a PAC file can configure a client device to send traffic associated with a specific web application so that the traffic is sent using a proxy server device, and can configure a client device to send traffic associated with another web application so that the traffic associated with the other application is sent without using a proxy server device or using a different proxy server device, which supports application-specific traffic processing. In addition, for traffic that is to be sent to the application platform without using a proxy server device, this reduces the latency between the client device to which the traffic is to be sent and the destination, which in turn improves the user experience associated with the client device and the web application associated with the traffic. In addition, allowing traffic associated with certain web applications to be sent without using a proxy server device reduces the number of packets to be processed by the proxy server device, which reduces the processing, memory, and networking resource usage of the proxy server device, reduces the time spent at the proxy server device to process traffic (e.g., because the processing queue at the proxy server is reduced), and allows the proxy server device to use processing and / or memory resources of the proxy server device that would otherwise be used to process traffic for other purposes. In addition, the PAC file can be configured so that traffic associated with a particular web application can be sent to different proxy server devices, which can provide different types of value-added services related to logging, forensic auditing, etc., which allows web applications that require detailed logging to be routed to a specific proxy server. Furthermore, the PAC file can be configured so that cost savings can be achieved by reducing traffic on expensive leased line / MPLS links that may be used between the proxy server device and the client device.

[0017] Figure 1A-1E is a diagram of an example implementation described herein. Figure 1A As shown, implementation 100 may include various devices, such as one or more client devices, a network device, one or more data stores (e.g., an application signature store, a security policy store, an application cache, etc.), a proxy server device, an application platform, etc. The number and configuration of devices illustrated in implementation 100 are examples, and implementation 100 may include more, fewer, and / or different device configurations.

[0018] In some implementations, one or more components included in implementation 100 may be included in one or more local networks. For example, client devices, network devices, and data storage may be included in a first local network; a proxy server device may be included in the first local network or a second local network; and so on. The one or more local networks may include various types of wired and / or wireless local area networks (LANs), such as wired LANs, wireless LANs (WLANs), home networks, office networks, campus networks, and so on. In some implementations, the one or more local networks may be associated with the same entity (such as an enterprise, a company, a government agency, an educational institution, and so on). In some implementations, the one or more local networks may be associated with different offices, different locations, different networks, and so on of the entity.

[0019] The network device may include various types of network devices capable of sending services to the application platform, receiving services from the application platform, etc. For example, the network device may receive services from a client device and send services to the application platform. As another example, the network device may receive services from the client device via a proxy server device and send services to the application platform.

[0020] The proxy server device may include various types of devices that can act as an intermediary between the client device and the application platform. For example, the proxy server device may send services to the application platform for the client device, may send services to the client device for the application platform, and so on. In some implementations, services may include web pages, electronic files, and / or any other type of electronic content. In some implementations, services may include requests for electronic content, such as hypertext transfer protocol (HTTP) requests, file transfer protocol (FTP) requests, and the like, which may also be encapsulated using secure socket layer (SSL) protocols, transport layer security (TLS) protocols, and the like to provide secure delivery of services.

[0021] In some implementations, the proxy server device can perform various security functions for traffic sent by the client device and traffic to be received by the client device. For example, the proxy server device can include a threat detection and / or intrusion detection proxy server device that analyzes traffic sent by the client device and / or analyzes traffic to be received by the client device to determine whether the client device exhibits malicious behavior, whether another device with which the client device is communicating exhibits malicious behavior, and so on. As another example, the proxy server device can include a deep packet inspection proxy server device that performs deep packet inspection on traffic sent by the client device and / or traffic to be received by the client device. In this way, the proxy server device can apply and / or enforce network, data, and / or computer security policies on traffic sent by the client device and / or traffic to be received by the client device.

[0022] The data store can store information associated with various web applications, such as web-based productivity applications (e.g., word processing applications, spreadsheet applications, email applications, etc.), web-based client management applications, computer-aided design applications, etc. Web applications can include client-server applications that exchange data using network protocols such as HTTP / HTTP Secure (HTTPS). The application platform can reside on the Internet / cloud, and the client device can include a web browser or custom software that communicates with the application platform.

[0023] In some implementations, the application signature store may include information identifying an application signature associated with a web application (e.g., information that can be used by a network device to identify traffic associated with the web application). The application signature of a web application may include information identifying one or more host domain names associated with the web application, one or more addresses associated with the web application (e.g., a source address associated with a device that originates traffic associated with the application, a destination address associated with a device that is a destination for traffic associated with the application, a port identifier associated with a source and / or destination of packets associated with the application, etc.), information identifying one or more communication protocols associated with the application (e.g., a communication protocol that a client device and / or application platform can use to send and / or receive packets associated with the application), etc. The application signature store may store application signatures associated with a particular web application in an electronic file (e.g., an Extensible Markup Language (XML) file, a JavaScript Object Notation (JSON) file, etc.) in a database, and / or the like.

[0024] Figure 2 , wherein the application signature for application 1 includes information identifying three rules by which traffic associated with application 1 can be identified. According to rule 1, traffic associated with application 1 can be identified based on the traffic using HTTP and the destination being an application platform associated with the host domain name xyz.com. According to rule 2, traffic associated with application 1 can be identified based on the traffic using the Secure Sockets Layer (SSL) protocol and / or the Transport Layer Security (TLS) protocol and the destination being an application platform associated with the host domain name secure.xyz.com. According to rule 3, traffic associated with application 1 can be identified based on the traffic using HTTP and being associated with a user agent sent by a client device identified in an HTTP header request.

[0025] return Figure 1AIn some implementations, the security policy store may store information identifying one or more application-based policies associated with a web application. For example, the one or more application-based policies may include an access method policy specifying traffic associated with the web application, a quality of service (QoS) policy specifying traffic associated with the web application, an inspection policy specifying traffic associated with the application to be rate-limited, a policy rule specifying traffic associated with the application to be dropped, and the like.

[0026] In some implementations, once traffic has been identified as belonging to a particular web application based on the corresponding web application signature, the application cache can store network endpoint information associated with the web application so that signature rule matching for traffic destined for that network endpoint can be avoided. In this way, since application signature matching can be a memory and / or processor intensive task, memory and / or processor resources of the network device can be saved by reducing the amount of repeated signature evaluations for traffic to the same network endpoint.

[0027] In some implementations, the network endpoint information may include a destination Internet Protocol (IP) address, a port name / number / identifier, a protocol used by the network endpoint, a virtual router identifier associated with the network endpoint, and / or a rule from an application signature store that identifies a web application. In some implementations, an application cache may have hundreds or thousands of entries for a particular web application. Each entry may have a different destination IP address, port identifier, etc., while the application signature store may include a single entry for the web application that associates the web application with a rule to identify the web application.

[0028] Go to Figure 1B In some implementations, the network device may use information stored in the application signature store, information stored in the security policy store, and / or information stored in the application cache to automatically generate and update a PAC file. For example, the network device may automatically generate a PAC file based on determining that information associated with a web application has been added to the application signature store, the security policy store, and / or the application cache, based on determining that information associated with a web application has been updated in the application signature store, the security policy store, and / or the application cache, and / or the like. In some implementations, the network device may generate and update a PAC file based on receiving an instruction to generate a PAC file (e.g., via input from a user, from another network device, etc.), based on receiving an instruction to update a PAC file, and / or the like.

[0029] like Figure 1BIn the embodiment of the present invention and as indicated by reference numeral 102, the network device may identify an application signature associated with a web application based on information stored in an application signature store. For example, the network device may identify a database, electronic file, etc. stored in the application signature store that includes application signatures associated with the web application. As explained above, the application signature associated with the web application may include information identifying a host domain associated with the web application, a protocol associated with the web application, a user agent associated with the web application, an address associated with the web application, etc.

[0030] Go to Figure 1C , and as shown in the figure numeral 104, the network device can identify an access method for the web application. For example, the network device can identify the access method based on information associated with the web application stored in the security policy store. The information associated with the web application and stored in the security policy store may include an application-based policy that specifies an access method for sending and / or receiving traffic associated with the web application. For example, the access method for the web application can specify that traffic associated with the web application is to be sent to the application platform via a proxy server device, can specify that traffic associated with the web application is to be sent to the application platform via another proxy server device, can specify that traffic associated with the web application is to be sent directly to the application platform (e.g., without sending the traffic to the proxy server device), and so on.

[0031] In some implementations, an access method to be used for services associated with a web application can be automatically selected (e.g., by another network device, by a proxy server device, etc.) based on various factors. For example, the another device can automatically select an access method based on whether the web application is a particular type of web application (e.g., a productivity web application, a social media web application, etc.), based on usage information associated with the web application (e.g., the number of users associated with the entity using the application, the volume of web application traffic within the entity, peak sessions and usage times associated with the application within the entity), based on the latency requirements of the web application, and so on. For example, the another device can determine that the web application is a video conferencing application requiring low latency and, therefore, can select an access method for the web application that specifies that services associated with the application be sent directly to the application platform (e.g., without sending the services via the proxy server device) in order to reduce latency associated with the web application. As another example, the another device can determine that the web application has specific peak usage times and can select an access method for the web application that specifies that services associated with the web application be sent to the application platform via the proxy server device during peak usage times, where the services can be sent to the application platform without using the proxy server device.

[0032] In addition, Figure 1C And as shown by reference numeral 106, the network device can generate a PAC file. In some implementations, the PAC file can include information specifying an association between an application signature of the web application and an access method for services associated with the web application, information specifying an association between network endpoint information associated with the application in the application cache and an access method for services associated with the web application, etc. In this way, the client device, when configured by the PAC file, can identify services associated with the web application based on the application signature included in the PAC file, and can identify the access method to be used for the services associated with the web application.

[0033] In some implementations, a PAC file may include information associated with multiple web applications. For example, a PAC file may include information specifying an association between an application signature of a first web application and an access method for the first web application, may include information specifying an association between an application signature of a second web application and an access method for the second web application, and / or the like. In some implementations, the access methods used for different web applications may be the same access method, may be different access methods, and so on. In some implementations, a PAC file may also include a default access method to be used for services that are not associated with any web application identified in the PAC file.

[0034] An example of a PAC file is Figure 3 As shown in the figure. Figure 3 As shown, the example PAC file includes information that specifies an association between an application signature of a first web application (e.g., application 1) and an access method for the first web application (e.g., an association that specifies that traffic associated with host domain names xyz.com and secure.xyz.com is to be sent directly to the application platform associated with application 1). Additionally, the example PAC file includes information that specifies an association between an IP / pattern-based rule identified for the first web application in the application signature store, a network endpoint associated with the IP / pattern-based rule identified for the first web application identified in the application cache, and an access method for the first web application, which may be identified by dynamically generating a pattern for the network endpoint. Additionally, the example PAC file includes information that specifies an application signature of a second web application (e.g., application 2) (which may be similar to Figure 2The embodiment includes information on the association between the application signature (structured according to the application signature illustrated in FIG) and the access method for the second web application (for example, an association specifying that services associated with the host domain names abc.com and secure.abc.com are to be sent via a proxy server device to the application platform associated with application 2), and includes information specifying a default access method (for example, services not associated with application 1 or application 2 are to be sent via another proxy server device).

[0035] Go to Figure 1D , and as indicated by reference numeral 108, the network device may provide the PAC file to the client device. In some implementations, the network device may automatically provide the PAC file to the client device based on generating the PAC file, based on updating the PAC file, and so forth. In this manner, when new and / or updated PAC files become available, the client device automatically receives the latest PAC file. In some implementations, the network device may provide the PAC file to the client device based on receiving a request for the PAC file from the client device. For example, the network device may act as a PAC file server and, therefore, may associate the PAC file with an address (e.g., a Uniform Resource Identifier (URI), a Uniform Resource Locator (URL), and so forth) and host the PAC file at that address. In this manner, the client device may provide the request in the form of an HTTP request identifying the address, an FTP request identifying the address, and so forth, and the network device may provide the PAC file to the client device based on receiving the request. In some implementations, the network device may provide the PAC file to another device acting as a PAC file server, and the client device may request the PAC file from this other PAC file server.

[0036] Go to Figure 1E , and as shown by reference numeral 110, the client device can receive the PAC file and can configure the client device based on the PAC file to send services to the application platform. For example, the client device can receive an instruction to send a request for a webpage, file, etc. to the application platform (e.g., via a web browser application on the client device), and the client device can determine, based on information included in the PAC file, whether to send the request to the application platform via a proxy server device or directly to the application platform (e.g., without sending the request via the proxy server device). In this manner, the client device can analyze the request to determine a host domain name associated with the request, determine an access method associated with the request based on an association between the host domain name and the access method specified in the PAC file, and send the request based on the access method.

[0037] In this way, a network device can generate and / or update a PAC file that configures a client device to use various access methods for sending traffic associated with multiple different web applications. In this way, a PAC file can configure a client device to send traffic associated with a specific web application so that the traffic is sent using a proxy server device, and can configure a client device to send traffic associated with another web application so that traffic associated with other applications is sent without using a proxy server device, thereby increasing the flexibility of generating a PAC file. In addition, for traffic to be sent to an application platform without using a proxy server device, this reduces the latency between the client device sending the traffic and the destination, which in turn improves the user experience associated with the client and the web application associated with the traffic. In addition, allowing traffic associated with certain web applications to be sent without using a proxy server device reduces the number of packets to be processed by the proxy server device, which reduces the processing, memory, and networking resource usage of the proxy server device, reduces the time spent at the proxy server device processing traffic (e.g., because the processing queue at the proxy server device is reduced), and allows the proxy server device to use processing and / or memory resources of the proxy server device that would otherwise be used to process traffic for other purposes.

[0038] As mentioned above, Figure 1A-1E It is provided as an example only. Other examples may differ from the Figure 1A-1E described.

[0039] Figure 4 is a diagram of an example environment 400 in which the systems and / or methods described herein may be implemented. Figure 4 As shown, environment 400 may include a client device 410, multiple data storage devices 420 (e.g., application signature storage 420-1, security policy storage 420-2, application cache 420-3, etc., collectively referred to as "data storage devices 420" and individually as "data storage devices 420"), a network device 430, and an application platform 440 in a cloud computing environment 442. Application platform 440 includes a collection of computing resources 444, a network 450, a proxy server device 460, etc. The devices of environment 400 may be interconnected via wired connections, wireless connections, or a combination of wired and wireless connections.

[0040] Client device 410 includes one or more devices capable of receiving, generating, storing, processing, and / or providing data associated with generating application-based proxy auto-configuration. For example, client device 410 may include a mobile phone (e.g., a smartphone, wireless phone, etc.), a laptop computer, a tablet computer, a handheld computer, a gaming device, a wearable communication device (e.g., a smartwatch, smart glasses, etc.), a desktop computer, and / or similar devices. Client device 410 may receive a PAC file from network device 430, send services to network device 430 based on the PAC file, and so on.

[0041] The data storage device 420 includes one or more devices, such as storage devices, memory devices, etc., which are capable of receiving, generating, storing, processing and / or providing data associated with generating application-based agent automatic configuration. For example, the application signature storage 420-1 may include a storage device, a memory device, etc., which stores information associated with one or more applications, such as information associated with various web applications (e.g., web-based productivity applications or client management applications, computer-aided design applications, etc.). For example, the signature storage 420-1 may store information identifying the web application, information identifying the application signature associated with the web application (e.g., information identifying one or more host domain names, addresses and / or communication protocols associated with the application). The security policy storage 420-2 may include a storage device, a memory device, etc., which stores information identifying one or more application-based policies associated with the web application.

[0042] In some implementations, data storage device 420 may be a standalone device, may be included in a network device (eg, network device 430 ) or another device, and so on.

[0043] The network device 430 includes one or more devices that can receive, generate, store, process, and / or provide data associated with generating application-based proxy auto-configuration. In some implementations, the network device 430 may include a firewall, a router, a gateway, a switch, a bridge, a wireless access point, a base station (e.g., an eNodeB, a NodeB, a gNodeB, etc.), and the like. In some implementations, the network device 430 may be implemented as a physical device implemented within a housing (such as a rack). In some implementations, the network device 430 may be implemented as a virtual device implemented by one or more computer devices in a cloud computing environment or a data center.

[0044] In some implementations, network device 430 may identify an application signature associated with a web application (e.g., based on information stored in data storage device 420), may generate a PAC file, may provide the PAC file to client device 410, may receive services from client device 410 based on the PAC file, and / or may update the PAC file.

[0045] The application platform 440 includes one or more devices that are capable of receiving, generating, storing, processing, and / or providing data associated with generating application-based proxy auto-configuration. For example, the application platform 440 may include a server device (e.g., a host server, a network server, an application server, etc.), a data center device, and / or the like. The application platform 440 may receive packets from the network device 430, store packets, send packets to another location, modify packets, send one or more packets to a client device, analyze packets, and the like. In some implementations, the application platform 440 may be associated with an application and may receive the application, services associated with the application, packets associated with the application, and the like.

[0046] In some implementations, as shown, the application platform 440 can be hosted in a cloud computing environment 442. Notably, while the implementations described herein depict the application platform 440 as being hosted in a cloud computing environment 442, in some implementations, the application platform 440 may not be cloud-based (i.e., may be implemented outside of a cloud computing environment) or may be partially cloud-based.

[0047] Cloud computing environment 442 includes an environment that hosts application platform 440. Cloud computing environment 442 can provide computing, software, data access, storage, and / or other services. As shown, cloud computing environment 442 can provide a set of computing resources 444 (collectively, "computing resources 444" and individually, "computing resources 444").

[0048] Computing resources 444 include one or more personal computers, workstation computers, server devices, or another type of computing and / or communication device. In some implementations, computing resources 444 can host application platform 440. Cloud resources can include computing instances running on computing resources 444, storage devices provided on computing resources 444, data transmission devices provided by computing resources 444, and the like. In some implementations, computing resources 444 can communicate with other computing resources 444 via wired connections, wireless connections, or a combination of wired and wireless connections.

[0049] like Figure 4As further shown, the computing resources 444 may include a set of cloud resources, such as one or more applications ("APP") 444-1, one or more virtual machines ("VM") 444-2, one or more virtualized storage ("VS") 444-3 and / or one or more hypervisors ("HYP") 444-4.

[0050] Applications 444-1 include one or more software applications that can be provided to or accessed by one or more devices in environment 400. Applications 444-1 can eliminate the need to install and run software applications on devices in environment 400. For example, applications 444-1 can include software associated with application platform 440 and / or any other software that can be provided via cloud computing environment 442. In some implementations, one application 444-1 can send information to / receive information from one or more other applications 444-1 via virtual machine 444-2. In some implementations, applications 444-1 can include software applications associated with one or more databases and / or operating systems. For example, applications 444-1 can include enterprise applications, functional applications, analytical applications, etc.

[0051] Virtual machine 444-2 includes a software implementation of a machine (e.g., a computer) that runs programs similar to physical machines. Virtual machine 444-2 can be a system virtual machine or a process virtual machine, depending on the use and correspondence of virtual machine 444-2 to any real machine. A system virtual machine can provide a complete system platform that supports the operation of a complete operating system ("OS"). A process virtual machine can run a single program and can support a single process. In some implementations, virtual machine 444-2 can run on behalf of a user (e.g., a user of client 410 and / or an operator of application platform 440) and can manage the infrastructure of cloud computing environment 442, such as data management, synchronization, or long-term data transmission.

[0052] Virtualized storage 444-3 includes one or more storage systems and / or one or more devices using virtualization technology within the storage system or the device of computing resource 444. In some implementations, in the context of a storage system, the types of virtualization may include block virtualization and file virtualization. Block virtualization may refer to the abstraction (or separation) of logical storage from physical storage so that the storage system can be accessed without regard to physical storage or heterogeneous structures. Separation may allow administrators of the storage system flexibility in how the administrator manages storage for end users. File virtualization may eliminate the dependency between data accessed at the file level and the location of the physical storage of the file. This may support optimization of storage usage, server consolidation, and / or performance of non-disruptive file migration.

[0053] Hypervisor 444-4 provides hardware virtualization technology that allows multiple operating systems (e.g., "guest operating systems") to run simultaneously on a host computer (such as computing resource 444). Hypervisor 444-4 can present a virtual operating platform to the guest operating systems and can manage the operation of the guest operating systems. Multiple instances of various operating systems can share virtualized hardware resources.

[0054] The network 450 includes one or more wired and / or wireless networks. For example, the network 450 may include: a mobile network (e.g., a long-term evolution (LTE) network, a code division multiple access (CDMA) network, a 3G network, a 4G network, a 5G network, other types of next-generation networks, etc.), a public land mobile network (PLMN), a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a telephone network (e.g., a public switched telephone network (PSTN)), a private network, an ad hoc network, an intranet, the Internet, a fiber-optic-based network, a cloud computing network, etc., and / or a combination of these or other types of networks.

[0055] Proxy server device 460 includes one or more physical and / or virtual devices that are capable of receiving, generating, storing, processing, and / or providing data associated with generating application-based proxy auto-configuration. In some implementations, proxy server device 460 may include a network device, a server device, a client device, etc. In some implementations, proxy server device 460 may include various types of devices that can act as an intermediary between client device 410 and application platform 440. For example, proxy server device 460 may send traffic to application platform 440 on behalf of client device 410, send traffic to client device 410 on behalf of application platform 440, and so on. In some implementations, proxy server device 460 may perform various security functions, such as threat detection and / or intrusion detection, deep packet inspection, and so on, for traffic sent by client device 410 and traffic to be received by client device 410.

[0056] Figure 4 The number and arrangement of devices and networks shown in FIG are provided as examples only. In practice, additional devices and / or networks, fewer devices and / or networks, different devices and / or networks, or different devices and / or networks may exist. Figure 4 In addition, the devices and / or networks shown in FIG. Figure 4 Two or more of the devices shown in FIG may be implemented in a single device, or Figure 4 The single device shown in FIG400 may be implemented as multiple, distributed devices. Additionally or alternatively, a set of devices (eg, one or more devices) of environment 400 may perform one or more functions described as being performed by another set of devices of environment 400.

[0057] Figure 5A and Figure 5B yes Figure 4 An illustration of example components of one or more devices. Figure 5A is a diagram of example components of a device 500. Device 500 may correspond to client device 410, data storage device 420, network device 430, application platform 440, proxy server device 460, etc. In some implementations, client device 410, data storage 420, network device 430, application platform 440, proxy server device 460, etc. may include one or more devices 500 and / or one or more components of device 500. Figure 5A As shown in , device 500 may include a bus 505 , a processor 510 , a memory 515 , a storage component 520 , an input component 525 , an output component 530 , and / or a communication interface 535 .

[0058] The bus 505 includes components that allow communication between the various components of the device 500. The processor 510 is implemented in hardware, firmware, and / or a combination of hardware and software. The processor 510 takes the form of a central processing unit (CPU), a graphics processing unit (GPU), an accelerated processing unit (APU), a microprocessor, a microcontroller, a digital signal processor (DSP), a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), and / or other types of processing components. In some implementations, the processor 510 includes one or more processors that can be programmed to perform functions. The memory 515 includes random access memory (RAM), read-only memory (ROM), and / or other types of dynamic or static storage devices (e.g., flash memory, magnetic memory, and / or optical memory) that store information and / or instructions for use by the processor 510.

[0059] The storage component 520 stores information and / or software related to the operation and use of the device 500. For example, the storage component 520 may include a hard disk (e.g., a magnetic disk, an optical disk, a magneto-optical disk, and / or a solid-state disk), a compact disk (CD), a digital versatile disk (DVD), a floppy disk, a cassette, a magnetic tape, and / or other types of non-transitory computer-readable media and corresponding drives.

[0060] Input components 525 include components that allow device 500 to receive information, such as via user input (e.g., a touch screen display, a keyboard, a keypad, a mouse, buttons, switches, and / or a microphone). Additionally or alternatively, input components 525 may include sensors for sensing information (e.g., a global positioning system (GPS) component, an accelerometer, a gyroscope, and / or an actuator). Output components 530 include components that provide output information from device 500 (e.g., a display, a speaker, and / or one or more light emitting diodes (LEDs)).

[0061] The communication interface 535 includes components similar to a transceiver (e.g., a transceiver and / or a separate receiver and transmitter) that enable the device 500 to communicate with other devices, such as via a wired connection, a wireless connection, or a combination of a wired connection and a wireless connection. The communication interface 535 can allow the device 500 to receive information from another device and / or provide information to another device. For example, the communication interface 535 can include an Ethernet interface, an optical interface, a coaxial interface, an infrared interface, a radio frequency (RF) interface, a universal serial bus (USB) interface, a Wi-Fi interface, a cellular network interface, and the like.

[0062] Device 500 can perform one or more processes described herein. Device 500 can perform these processes based on processor 510 running software instructions stored by non-transitory computer-readable media (such as memory 515 and / or storage component 520). Computer-readable media is defined herein as non-transitory memory devices. Memory devices include memory space within a single physical storage device or memory space across multiple physical storage devices.

[0063] The software instructions may be read from another computer-readable medium or from another device into the memory 515 and / or storage component 520 via the communication interface 535. When executed, the software instructions stored in the memory 515 and / or storage component 520 may cause the processor 510 to perform one or more processes described herein. Additionally or alternatively, hard-wired circuitry may be used in place of or in combination with software instructions to perform one or more processes described herein. Thus, the implementations described herein are not limited to any specific combination of hardware circuitry and software.

[0064] Figure 5A The number and arrangement of components shown in FIG5 are provided as examples only. In practice, device 500 may include additional components, fewer components, different components, or components that are different from those in FIG5 . Figure 5A Additionally or alternatively, a set of components (eg, one or more components) of device 500 may perform one or more functions described as being performed by another set of components of device 500.

[0065] Figure 5B is a diagram of example components of device 550. Device 550 may correspond to network device 430. In some implementations, network device 430 may include one or more devices 550 and / or one or more components of device 550. Figure 5B As shown in , the device 550 may include one or more input components 555-1 to 555-B (B≥1) (hereinafter collectively referred to as input component 555, and individually referred to as input component 555), a switching component 560, one or more output components 565-1 to 565-C (C≥1) (hereinafter collectively referred to as output component 565, and individually referred to as output component 565) and a controller 570.

[0066] The input component 555 can be an attachment point for a physical link and can be an entry point for incoming traffic (such as packets). The input component 555 can process incoming traffic, such as by performing data link layer encapsulation or decapsulation. In some implementations, the input component 555 can send and / or receive packets. In some implementations, the input component 555 can include an input line card that includes one or more packet processing components (e.g., in the form of an integrated circuit), such as one or more interface cards (IFCs), a packet forwarding component, a line card controller component, an input port, a processor, a memory, and / or an input queue. In some implementations, the device 550 can include one or more input components 555.

[0067] The switching component 560 can interconnect the input component 555 with the output component 565. In some implementations, the switching component 560 can be implemented via one or more crossbar switches, via a bus, and / or using shared memory. The shared memory can act as a temporary buffer to store packets from the input component 555 before the packets are ultimately scheduled for delivery to the output component 565. In some implementations, the switching component 560 can enable the input component 555, the output component 565, and / or the controller 570 to communicate.

[0068] The output component 565 can store packets and can schedule packets for transmission on an output physical link. The output component 565 can support data link layer encapsulation or decapsulation, and / or multiple higher layer protocols. In some implementations, the output component 565 can send packets and / or receive packets. In some implementations, the output component 565 can include an output line card, which includes one or more packet processing components (e.g., in the form of an integrated circuit), such as one or more IFCs, packet forwarding components, line card controller components, output ports, processors, memories, and / or output queues. In some implementations, the device 550 can include one or more output components 565. In some implementations, the input component 555 and the output component 565 can be implemented by the same set of components (e.g., the input / output component can be a combination of the input component 555 and the output component 565).

[0069] The controller 570 includes a processor in the form of, for example, a CPU, a GPU, an APU, a microprocessor, a microcontroller, a DSP, an FPGA, an ASIC, and / or other types of processors. The processor is implemented in hardware, firmware, and / or a combination of hardware and software. In some implementations, the controller 570 may include one or more processors that can be programmed to perform functions.

[0070] In some implementations, the controller 570 may include RAM, ROM, and / or other types of dynamic or static storage devices (e.g., flash memory, magnetic storage, optical storage, etc.) that store information and / or instructions for use by the controller 570.

[0071] In some implementations, the controller 570 can communicate with other devices, networks, and / or systems connected to the device 500 to exchange information related to the network topology. The controller 570 can create a routing table based on the network topology information, create a forwarding table based on the routing table, and forward the forwarding table to the input component 555 and / or the output component 565. The input component 555 and / or the output component 565 can use the forwarding table to perform route lookups for incoming packets and / or outgoing packets.

[0072] The controller 570 may perform one or more of the processes described herein. The controller 570 may perform these processes in response to executing software instructions stored by a non-transitory computer-readable medium.

[0073] The software instructions may be read from another computer-readable medium or from another device via a communication interface into a memory and / or storage component associated with the controller 570. When executed, the software instructions stored in the memory and / or storage component associated with the controller 570 may cause the controller 570 to perform one or more processes described herein. Additionally or alternatively, hardwired circuitry may be used in place of or in combination with software instructions to perform one or more processes described herein. Thus, the implementations described herein are not limited to any specific combination of hardware circuitry and software.

[0074] Figure 5B The number and arrangement of components shown in FIG5 are provided as examples only. In practice, device 550 may include additional components, fewer components, different components, or components that are different from those in FIG5 . Figure 5B Additionally or alternatively, a set of components (eg, one or more components) of device 550 may perform one or more functions described as being performed by another set of components of device 550.

[0075] Figure 6 is a flow chart of an example process 600 for generating an application-based proxy auto-configuration. In some implementations, Figure 6 One or more process blocks of may be performed by a network device (e.g., network device 430). In some implementations, Figure 6 One or more process blocks may be performed by another device or group of devices that is separate from or includes the network device, such as a client device (e.g., client device 410), a data storage device (e.g., data storage device 420), an application platform (e.g., application platform 440), a proxy server device (e.g., proxy server device 460), and the like.

[0076] like Figure 6 As shown in , process 600 may include identifying an application signature associated with a web application (block 610). For example, as described above, a network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switch component 560, output component 565, controller 570, etc.) may identify an application signature associated with a web application.

[0077] like Figure 6As further shown in FIG6 , process 600 may include determining, based on an application-based policy associated with the web application, an access method to be used for sending traffic associated with the web application (block 620). For example, as described above, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switch component 560, output component 565, controller 570, etc.) may determine, based on an application-based policy associated with the web application, an access method to be used for sending traffic associated with the web application.

[0078] like Figure 6 As further shown in FIG6 , process 600 may include generating a proxy auto-configuration (PAC) file using an application signature associated with the web application and an access method to be used to send traffic associated with the web application (block 630). For example, as described above, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, controller 570, etc.) may generate a PAC file using an application signature associated with the web application and an access method to be used to send traffic associated with the web application.

[0079] like Figure 6 As further shown in FIG6 , process 600 may include providing a PAC file to a client device to allow the client device to send services associated with the web application based on the PAC file (block 640). For example, as described above, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, switch component 560, output component 565, controller 570, etc.) may provide a PAC file to a client device to allow the client device to send services associated with the web application based on the PAC file.

[0080] Process 600 may include additional implementations, such as any single implementation or any combination of implementations described below and / or in combination with one or more other processes described elsewhere herein.

[0081] In some implementations, when identifying an application signature associated with a web application, the network device may identify the application signature based on information associated with the web application stored in an application signature store. In some implementations, when generating a PAC file, the network device may dynamically generate the PAC file based on an Internet Protocol (IP) address and port identifier associated with the web application identified in an application cache. In some implementations, an application-based policy associated with a web application may specify an access method to be used to send traffic associated with the web application.

[0082] In some implementations, traffic associated with a web application may be sent to an application server associated with the web application via a deep packet inspection proxy server; traffic associated with a web application may be sent to an application server associated with the web application via an intrusion prevention system proxy server; or traffic associated with a web application may be sent to an application server associated with the web application without using a proxy server.

[0083] In some implementations, when providing the PAC file to the client device, the network device may receive a request for the PAC file from the client device and may provide the PAC file to the client device based on receiving the request. In some implementations, the network device may host the PAC file at a uniform resource identifier (URI) associated with the PAC file.

[0084] Although Figure 6 Example blocks of process 600 are shown, but in some implementations, process 600 may include additional blocks, fewer blocks, different blocks, or different Figure 6 Additionally or alternatively, two or more of the blocks of process 600 may be performed in parallel.

[0085] Figure 7 is a flow chart of an example process 700 for generating an application-based proxy auto-configuration. In some implementations, Figure 7 One or more process blocks of may be performed by a network device (e.g., network device 430). In some implementations, Figure 7 One or more process blocks may be performed by another device or group of devices that is separate from or includes the network device, such as a client device (e.g., client device 410), a data storage device (e.g., data storage device 420), an application platform (e.g., application platform 440), a proxy server device (e.g., proxy server device 460), and the like.

[0086] like Figure 7 As shown in , process 700 may include identifying an application signature associated with a web application (block 710). For example, as described above, a network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switch component 560, output component 565, controller 570, etc.) may identify an application signature associated with a web application.

[0087] Further Figure 7As shown, process 700 may include determining, based on an application-based policy associated with the web application, an access method to be used for sending traffic associated with the web application (block 720). For example, as described above, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switch component 560, output component 565, controller 570, etc.) may determine, based on the application-based policy associated with the web application, an access method to be used for sending traffic associated with the web application.

[0088] Further Figure 7 As shown, process 700 may include generating a proxy auto-configuration (PAC) file using an application signature associated with the web application and an access method to be used to send traffic associated with the web application (block 730). For example, as described above, a network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, controller 570, etc.) may generate a PAC file using an application signature associated with the web application and an access method to be used to send traffic associated with the web application.

[0089] Further Figure 7 As shown, process 700 may include associating the PAC file with the URL (block 740). For example, as described above, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switch component 560, output component 565, controller 570, etc.) may associate the PAC file with the URL.

[0090] Further Figure 7 As shown, process 700 may include providing the PAC file to the client device based on receiving a request specifying a network address from the client device (block 750). For example, as described above, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, switch component 560, output component 565, controller 570, etc.) may provide the PAC file to the client device based on receiving a request specifying a network address from the client device.

[0091] Process 700 may include additional implementations, including any single implementation or any combination of implementations described below and / or in combination with one or more other processes described elsewhere herein.

[0092] In some implementations, when generating the PAC file, the network device may dynamically generate the PAC file based on an Internet Protocol (IP) address and a port identifier associated with the web application identified in the application cache. In some implementations, when dynamically generating the PAC file based on the IP address and the port identifier associated with the web application identified in the application cache, the network device may dynamically generate the PAC file based on a determination that information identifying the IP address and the port identifier associated with the web application has been added to the application cache. In some implementations, when dynamically generating the PAC file, the network device may generate JavaScript code corresponding to an association between the IP address and the port identifier associated with the web application and an access method to be used to send traffic associated with the web application.

[0093] In some implementations, when dynamically generating a PAC file based on an IP address and port identifier associated with a web application identified in an application cache, the network device may determine whether a time interval associated with the IP address and port identifier identified in the application cache has expired, and may remove the identified IP address and port identifier from the application cache based on determining that the time interval has expired.

[0094] In some implementations, the application signature includes information identifying a user agent associated with the web application. In some implementations, the information identifying the application signature associated with the web application may be stored in an application cache associated with the network device, and the application signature may include information identifying a host domain name associated with the web application and information identifying an application protocol associated with the web application.

[0095] Although Figure 7 Example blocks of process 700 are shown, but in some implementations, process 700 may include additional blocks, fewer blocks, different blocks, or different Figure 7 Additionally or alternatively, two or more of the blocks in process 700 may be performed in parallel.

[0096] Figure 8 is a flow chart of an example process 800 for generating an application-based proxy auto-configuration. In some implementations, Figure 8 One or more process blocks of may be performed by a network device (e.g., network device 430). In some implementations, Figure 8One or more process blocks may be performed by another device or group of devices that is separate from or includes the network device, such as a client device (e.g., client device 410), a data storage device (e.g., data storage device 420), an application platform (e.g., application platform 440), a proxy server device (e.g., proxy server device 460), and the like.

[0097] like Figure 8 As shown in , process 800 may include identifying a plurality of application signatures, wherein respective application signatures in the plurality of application signatures are associated with respective web applications in a plurality of web applications (block 810). For example, as described above, a network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switch component 560, output component 565, controller 570, etc.) may identify the plurality of application signatures. In some implementations, respective application signatures in the plurality of application signatures may be associated with respective web applications in the plurality of web applications.

[0098] Further Figure 8 As shown, process 800 may include determining a plurality of access methods to be used for sending traffic associated with a plurality of web applications, wherein a corresponding access method in the plurality of access methods is to be used for sending traffic associated with the corresponding web application (block 820). For example, as described above, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switch component 560, output component 565, controller 570, etc.) may determine a plurality of access methods to be used for sending traffic associated with the plurality of web applications. In some implementations, a corresponding access method in the plurality of access methods may be used for sending traffic associated with the corresponding web application.

[0099] Further Figure 8 As shown, process 800 may include generating a proxy auto-configuration (PAC) file using each of a plurality of application signatures and a corresponding access method to be used for sending traffic associated with the corresponding web application (block 830). For example, as described above, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, controller 570, etc.) may generate a PAC file using each of a plurality of application signatures and a corresponding access method to be used for sending traffic associated with the corresponding web application.

[0100] Further Figure 8As shown, process 800 may include providing the PAC file to the client device (block 840). For example, as described above, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, switch component 560, output component 565, controller 570, etc.) may provide the PAC file to the client device.

[0101] Process 800 may include additional implementations, including any single implementation or any combination of implementations described below and / or in combination with one or more other processes described elsewhere herein.

[0102] In some implementations, a first web application in the plurality of web applications can be associated with a first web application type, a second web application in the plurality of web applications can be associated with a second web application type, and the first web application type and the second web application type can be different web application types.

[0103] In some implementations, each of the plurality of web applications may be associated with a different web application group type. In some implementations, when generating the PAC file, the network device may dynamically generate the PAC file based on an Internet Protocol (IP) address and a port identifier associated with the web application identified in the application cache. In some implementations, when dynamically generating the PAC file, the network device may dynamically generate the PAC file based on determining that information identifying the IP address and port identifier associated with the web application has been added to the application cache. In some implementations, when dynamically generating the PAC file, the network device may generate JavaScript code corresponding to an association between the IP address and port identifier associated with the web application and an access method to be used to send traffic associated with the web application.

[0104] Although Figure 8 Example blocks of process 800 are shown, but in some implementations, process 800 may include additional blocks, fewer blocks, different blocks, or different Figure 8 Additionally or alternatively, two or more of the blocks in process 800 may be performed in parallel.

[0105] Figure 9 is a flow chart of an example process 900 for statically generating an application-based proxy auto-configuration. In some implementations, Figure 9 One or more process blocks of may be performed by a network device (e.g., network device 430). In some implementations, Figure 9One or more process blocks may be performed by another device or group of devices that is separate from or includes the network device, such as a client device (e.g., client device 410), a data storage device (e.g., data storage device 420), an application platform (e.g., application platform 440), a proxy server device (e.g., proxy server device 460), and the like.

[0106] like Figure 9 As shown in FIG, process 900 may include obtaining a next application signature associated with a web application from an application signature store (block 902). For example, a network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switch component 560, output component 565, controller 570, etc.) may obtain a next application signature associated with a web application from an application signature store.

[0107] Further Figure 9 As shown, process 900 may include deriving a next application signature rule from the application signature (block 904). For example, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switch component 560, output component 565, controller 570, etc.) may derive a next application signature rule from the application signature.

[0108] Further Figure 9 As shown, process 900 may include determining whether the application signature rule is a host-based pattern rule (block 906). For example, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, switching component 560, output component 565, controller 570, etc.) may determine whether the application signature rule is a host-based pattern rule. If the application signature rule is not a host-based pattern rule (e.g., the application signature rule includes rules other than server host name or server URL rules) (block 906-No), the network device may ignore the application signature rule and may return to block 904 to obtain the next application signature rule from the application signature.

[0109] Further Figure 9 As shown, if the application signature rule has a pattern for a server host name or a server URL (block 906-yes), process 900 may include extracting the application signature rule from the application signature (block 908). For example, a network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, switch component 560, output component 565, controller 570, etc.) may extract the application signature rule from the application signature.

[0110] Further Figure 9 As shown, process 900 may include extracting an access method policy associated with a web application from a security policy store (block 910). For example, a network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switch component 560, output component 565, controller 570, etc.) may extract an access method policy associated with a web application from a security policy store.

[0111] Further Figure 9 As shown, process 900 may include generating JavaScript code for the extracted application signature rules and access method policies (block 912). For example, a network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switching component 560, output component 565, controller 570, etc.) may generate JavaScript code for the extracted application signature rules and access method policies. In some implementations, the extracted application signature rules may include a pattern for a server host name (or server URL), and the generated JavaScript code may include a pattern similar to Figure 3 The pattern shown in the figure.

[0112] Further Figure 9 As shown, process 900 may include determining whether there are any remaining application signature rules in the application signature (block 914). For example, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switch component 560, output component 565, controller 570, etc.) may determine whether there are any remaining application signature rules in the application signature. If the network device determines that there are remaining application signature rules in the application signature (block 914-yes), process 900 may return to block 904 so that the next application signature rule can be extracted.

[0113] Further Figure 9As shown, if the network device determines that there are no remaining application signature rules in the application signature (block 914-No), process 900 may include determining whether there are any remaining application signatures included in the application signature store to be processed (block 916). For example, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, switching component 560, output component 565, controller 570, etc.) may determine whether there are any remaining application signatures included in the application signature store to be processed. If the network device determines that there are any remaining application signatures included in the application signature store to be processed (block 916-Yes), process 900 may return to block 902 so that the next application signature can be processed. If the network device determines that there are no remaining application signatures included in the application signature store to be processed (block 916-No), process 900 may end.

[0114] Process 900 may include additional implementations, such as any single implementation or any combination of implementations described below and / or in combination with one or more other processes described elsewhere herein. Figure 9 Example blocks of process 900 are shown, but in some implementations, process 900 may include additional blocks, fewer blocks, different blocks, or different Figure 9 Additionally or alternatively, two or more of the blocks in process 900 may be performed in parallel.

[0115] Figure 10 is a flow chart of an example process 1000 for dynamically generating an application-based proxy auto-configuration. In some implementations, Figure 10 One or more process blocks of may be performed by a network device (e.g., network device 430). In some implementations, Figure 10 One or more process blocks may be performed by another device or group of devices that is separate from or includes the network device, such as a client device (e.g., client device 410), a data storage device (e.g., data storage device 420), an application platform (e.g., application platform 440), a proxy server device (e.g., proxy server device 460), and the like.

[0116] like Figure 10As shown in , process 1000 may include determining whether a web application is a new web application added to an application cache (block 1002). For example, a network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switch component 560, output component 565, controller 570, etc.) may determine whether a web application is a new web application added to an application cache.

[0117] Further Figure 10 As shown, if the web application is a new web application being added to the application cache (block 1002 —Yes), process 1000 may include determining whether a corresponding rule for adding an entry to the application cache that is configured in the PAC file for the web application does not have a server hostname pattern or a server URL pattern and is therefore ignored during static PAC file generation (block 1004). For example, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switch component 560, output component 565, controller 570, etc.) may determine whether a corresponding rule for adding an entry to the application cache that is configured in the PAC file does not have a server hostname pattern or a server URL pattern and is therefore ignored during static PAC file generation.

[0118] Further Figure 10 As shown, if the rule for adding the entry to the application cache does not correspond to a rule with a server host name or URL and is therefore ignored during static PAC file generation (block 1004 —Yes), process 1000 may include generating JavaScript code for the IP address and port identifier rule associated with the web application and the access method policy associated with the web application (block 1006). For example, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, controller 570, etc.) may generate JavaScript code for the IP address and port identifier rule associated with the web application and the access method policy associated with the web application.

[0119] Further Figure 10As shown, if the web application is not a new web application added to the application cache (block 1002 —No), process 1000 may include determining whether a time interval associated with a cache entry for the web application in the application cache has expired (block 1008). For example, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, switch component 560, output component 565, controller 570, etc.) may determine whether a time interval associated with a cache entry for the web application in the application cache has expired.

[0120] Further Figure 10 As shown, if the time interval has expired, process 1000 may include deleting the cache entry for the web application from the application cache (block 1010). For example, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switch component 560, output component 565, controller 570, etc.) may delete the cache entry for the web application from the application cache.

[0121] Further Figure 10 As shown, process 1000 may include determining whether a cache entry in an application cache for a web application was used to generate a PAC file (block 1012). For example, a network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switch component 560, output component 565, controller 570, etc.) may determine whether a cache entry in an application cache for a web application was used to generate a PAC file.

[0122] Further Figure 10 As shown, if a cache entry for a web application in the application cache is used to generate a PAC file, process 1000 may include removing JavaScript code that applies the signature rule for a matching IP address and port identifier from the PAC file (block 1014). For example, the network device (e.g., using computing resources 444, processor 510, memory 515, storage component 520, communication interface 535, input component 555, switch component 560, output component 565, controller 570, etc.) may remove JavaScript code that applies the signature rule for a matching IP address and port identifier from the PAC file.

[0123] Process 1000 may include additional implementations, such as any single implementation or any combination of implementations described below and / or in conjunction with one or more processes described elsewhere herein. Figure 10 Example blocks of process 1000 are shown, but in some implementations, process 1000 may include additional blocks, fewer blocks, different blocks, or different Figure 10 Additionally or alternatively, two or more of the blocks in process 1000 may be performed in parallel.

[0124] As used herein, "traffic" or "content" may include a collection of packets. A packet may refer to a communication structure for conveying information, such as a protocol data unit (PDU), a network packet, a datagram, a segment, a message, a block, a cell, a frame, a subframe, a timeslot, a symbol, a portion of any of the foregoing, and / or other types of formatted or unformatted data units capable of transmission over a network.

[0125] The foregoing disclosure provides illustration and description, but is not intended to be exhaustive or to limit the implementations to the precise forms disclosed. Modifications and variations are possible in light of the above disclosure or may be acquired from practice of the implementations.

[0126] As used herein, the term "component" is intended to be broadly interpreted as hardware, firmware, and / or a combination of hardware and software.

[0127] It will be apparent that the systems and / or methods described herein can be implemented in various forms of hardware, firmware, and / or a combination of hardware and software. The actual dedicated control hardware or software code used to implement these systems and / or methods does not limit the implementation. Thus, the operation and behavior of the systems and / or methods are described herein without reference to specific software code—it should be understood that software and hardware can be designed to implement the systems and / or methods based on the description herein.

[0128] Although particular combinations of features are recited in the claims and / or disclosed in the specification, these combinations are not intended to limit the disclosure of the various implementations. In fact, many of these features can be combined in ways not specifically recited in the claims and / or disclosed in the specification. Although each dependent claim listed below may directly depend on only one claim, the disclosure of the various implementations includes each dependent claim in combination with every other claim in the claim set.

[0129] None of the elements, behaviors or instructions used herein should be interpreted as critical or necessary unless explicitly described as such. Moreover, as used herein, the articles "one", "an" are intended to include one or more items and can be used interchangeably with "one or more". In addition, as used herein, when only one item is meant, the term "only one" or similar language is used. Moreover, as used herein, the terms "have", "have", "have" or the like are intended to be open terms. The term "set" is intended to include one or more items (e.g., related items, unrelated items, a combination of related items and unrelated items, etc.) and can be used interchangeably with "one or more". In addition, the phrase "based on" is intended to mean "based at least in part on", unless otherwise explicitly stated.

Claims

1. An access method, comprising: Applying, by the network device, a signature rule from an application signature identifier associated with the web application; When the network device determines that the application signature rule is not a host-based pattern rule when the application signature rule is not a server host name rule and is not a server uniform resource locator URL rule: Ignore the application signature rule when the application signature rule is not a host-based pattern rule; as well as Determine whether there are other application signature rules remaining; as well as When the network device determines that the application signature rule is a host-based pattern rule when the application signature rule is a server host name rule or a server uniform resource locator URL rule: extracting, by the network device, the application signature rule from the application signature; Extracting, by the network device, an access method policy associated with the web application from a security policy repository; as well as The network device generates JavaScript code for the extracted application signature rule and the extracted access method policy.

2. The method according to claim 1, comprising: The application signature associated with the web application is obtained from an application signature repository.

3. The method of claim 1 , wherein the application signature rule comprises a first application signature rule; and The method further comprises: Obtain a second application signature rule from the application signature; Determining that the second application signature rule is not the host-based pattern rule; as well as A third application signature rule is obtained from the application signature. The method of claim 1 , wherein the extracted application signature rules include patterns for server host names. The method of claim 1 , wherein the extracted application signature rules include a pattern for a server URL.

6. The method according to claim 1, further comprising: determining that no application signature rules remain in the application signature; determining that another application signature is associated with the web application; as well as The other application signature is processed by identifying another application signature rules from the other application signature.

7. The method of claim 1 , wherein the generated JavaScript code includes information specifying an association between: pattern-based rules identified for the web application, network endpoints associated with the pattern-based rules identified in an application cache, and the access method policy for the web application.

8. A device comprising: one or more memories; as well as One or more processors communicatively coupled to the one or more memories, configured to: applying a signature rule from a plurality of application signature rules according to an application signature identifier associated with the web application; Determining that the application signature rule is a host-based pattern rule; Extracting the application signature rule from the application signature; Retrieving an access method policy associated with the web application; Generate JavaScript code for the extracted application signature rule and the extracted access method policy; Determining that no application signature rule among the plurality of application signature rules remains in the application signature; as well as Another application signature is processed by identifying another application signature rules from another application signature associated with the web application.

9. The apparatus of claim 8, wherein the one or more processors are further configured to: The application signature associated with the web application is obtained from an application signature repository.

10. The apparatus of claim 8, wherein the application signature rule comprises a first application signature rule; and wherein the one or more processors are further configured to: Obtain a second application signature rule from the application signature; determining that the second application signature rule is not the host-based pattern rule; and A third application signature rule is obtained from the application signature. 11 . The apparatus of claim 8 , wherein the extracted application signature rule comprises a pattern for a server host name or a pattern for a server uniform resource locator (URL).

12. The apparatus of claim 8, wherein the access method policy is used to transmit traffic associated with the web application.

13. The apparatus of claim 8, wherein the generated JavaScript code further comprises specifying a network endpoint associated with the host-based pattern rule identified in an application cache.

14. The apparatus of claim 8, wherein the access method policy specifies one of the following: Traffic associated with the web application is to be transmitted to an application server associated with the web application via a deep packet inspection proxy server, The traffic associated with the web application is to be transmitted to the application server associated with the web application via another proxy server, or Traffic associated with the web application is to be transferred to the application server associated with the web application without using a proxy server.

15. A non-transitory computer-readable medium storing instructions, the instructions comprising: One or more instructions that, when executed by one or more processors, cause the one or more processors to: Applying signature rules from an application signature identifier associated with the web application; Determine whether the application signature rule is a server host name rule or a server uniform resource locator URL rule; Extracting the application signature rule from the application signature; Retrieving an access method policy associated with the web application; as well as generating code for the extracted application signature rule and the extracted access method policy, The generated code includes information specifying an association between pattern-based rules identified for the web application and the access method policy for the web application.

16. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, when executed by the one or more processors, further cause the one or more processors to: The application signature associated with the web application is obtained from an application signature repository.

17. The non-transitory computer-readable medium of claim 15, wherein the application signature rule comprises a first application signature rule; and Wherein the one or more instructions, when executed by the one or more processors, further cause the one or more processors to: Obtain a second application signature rule from the application signature; Determining that the second application signature rule is neither the server host name rule nor the server URL rule; and A third application signature rule is obtained from the application signature. 18 . The non-transitory computer-readable medium of claim 15 , wherein the extracted application signature rules include host-based pattern rules for a server host name or a server URL.

19. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, when executed by the one or more processors, further cause the one or more processors to: determining that no application signature rules remain in the application signature; determining that another application signature is associated with the web application; and The other application signature is processed by identifying another application signature rules from the other application signature.

20. The non-transitory computer-readable medium of claim 15, wherein the generated code further comprises the information specifying a network endpoint associated with the pattern-based rule identified in an application cache.

Citation Information

Patent Citations

  • Methods and devices for implementing network policy mechanisms

    US20110107391A1

  • Access control system for a mobile device

    US20130340031A1