Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

135 results about "Network address translation" patented technology

Network address translation (NAT) is a method of remapping one IP address space into another by modifying network address information in the IP header of packets while they are in transit across a traffic routing device. The technique was originally used as a shortcut to avoid the need to readdress every host when a network was moved. It has become a popular and essential tool in conserving global address space in the face of IPv4 address exhaustion. One Internet-routable IP address of a NAT gateway can be used for an entire private network.

Attack chain restoration method and system based on large language model and traditional AI model

The invention provides an attack link restoration method and system based on a large language model and a traditional AI model, and effectively solves the problem that attack link restoration is incomplete and inaccurate when a current attack link restoration scheme faces complex factors such as network address translation. The method comprises the following steps: acquiring an attack semantic knowledge base containing an attack context knowledge matrix, wherein the knowledge base is generated by processing an attack framework, a security log and a traceability report by a generative large model; obtaining an asset access relation graph generated by analyzing the metadata of the target network infrastructure by the large model and reasoning in combination with an attack semantic knowledge base; regularly acquiring security alarm logs in a first time window and scoring, and acquiring context logs if the security alarm logs exceed a threshold value; based on a time sequence diagram attention network model, determining the confidence degree that edges in an asset access relation graph corresponding to logs containing access pairs in the alarm logs and the context logs belong to attack links; and performing sub-graph extraction in the atlas to obtain candidate sub-graphs, and then determining a target attack link.
Owner:ULTRAPOWER SOFTWARE +1

Controller-based traffic filtering and address modification

In communication with components of a cloud platform, namely a software-defined network constructed to overlay at least one public cloud network, a controller features a virtual processor and a data store. The data store includes network address translation (NAT) processing logic configured to determine whether a control plane message from tenant resources is associated with a network address overlapping condition, which represents a first network address included in the control plane message overlaps a network address range relied upon by either (a) at least one of the components of the cloud platform or (b) a component associated with other tenant resources. The NAT processing logic is further configured to alter routing data stores that maintain routing information for each of the components of the cloud platform to substitute the first network address with a first virtual network address for subsequent data message routing.
Owner:AVIATRIX SYSTEMS INC

Intelligent DNS load balancing using combination of dynamic DNAT pool and application probing in connector based solution for private application access

PendingUS20260032115A1Securing communicationDomain nameFully qualified domain name
The present application discloses a method, system, and computer system for providing intelligent DNS load balancing using a combination of a dynamic DNAT pool and application providing in a connector-based solution for private application access. The method includes: (a) performing a DNS re-resolution for resolving an application Fully Qualified Domain Name (FQDN) to obtain a plurality of IP addresses for a plurality of application servers, (b) performing periodic application server probing, and (c) dynamically updating a destination network address translation (DNAT) to provide DNS load balancing for application traffic. The DNAT is updated based at least in part on one or more of the DNS re-resolution and the application server probing.
Owner:PALO ALTO NETWORKS INC

Method for Configuring Network Address Translation Gateway and Cloud Management Platform

A method for configuring a network address translation NAT gateway based on a public cloud service including: a cloud management platform obtains NAT gateway creation information that is input by a tenant; The cloud management platform creates the NAT gateway in the first VPC based on the NAT gateway creation information; The cloud management platform obtains configuration information that is input by the tenant and applied to the NAT gateway; The cloud management platform sets, based on the identifier of the second VPC, the NAT gateway to be connected to the second VPC, and sends the first NAT rule to the NAT gateway, where the first NAT rule is used to indicate the NAT gateway to: bind a first network segment in the first VPC to a first elastic IP address EIP; and bind the first network segment in the first VPC to a first transit private IP address.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Application-agnostic puncturing of network address translation (NAT) services

Two electronic devices attempt to communicate and exchange Internet Protocol (IP) packets over a cellular communication network, and at least one of the two devices is behind a symmetric Network Address Translation (NAT) service. At least one of the two devices executes a Session Traversal Utilities for NAT (STUN) protocol, which provides to that device a pair of external IP address and port of that device; which that device then informs to a Message Broker Unit that is accessible to both devices via the public Internet. The Message Broker Unit provides the external IP address and port of that device, to the other device; which then connects to a Virtual Private Network (VPN) server and sends to the first device one or more User Datagram Protocol (UDP) packets that penetrate or puncture the NAT service in an application-agnostic manner.
Owner:LIVEU

Flow entropy management using network address translation scheme

PendingUS20250365234A1TransmissionPathPingEngineering
Devices, systems, methods, and processes for flow entropy management using network address translation (NAT) scheme are described herein. Typically, due to fewer flows and high bandwidth demands in backend data center networks, hash distribution algorithms may exhibit bias, leading to congestion on certain network paths while others remain underutilized, a phenomenon known as low flow entropy. To address the low flow entropy problem, a network interface controller (NIC) decomposes a traffic flow into multiple flowlets and applies a NAT operation on each flowlet. In the NAT operation, an actual source port value of a flowlet is replaced with a unique unused source port value to make the flowlet look like a different traffic flow to a switch. Thus, the switch processes each flowlet as a different traffic flow and uses load balancing schemes to distribute the flowlets across various network paths. Thus, improving the flow entropy of the network.
Owner:CISCO TECHNOLOGY INC

Data processing method and device, electronic equipment and medium

The embodiment of the invention discloses a data processing method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining a network address translation type, a power consumption level and network topology information of network equipment when a registration request of the network equipment is received, and carrying out the registration of the network equipment according to the network address translation type, the power consumption level and the network topology information, generating equipment associated information; when a connection request of a client is received, analyzing a target device identifier in the connection request, and determining a target network device corresponding to the target device identifier and pre-stored device association information; and determining an adaptive point-to-point transmission strategy according to the equipment association information, and establishing point-to-point direct connection between the target network equipment and the client based on the determined point-to-point transmission strategy and an interactive enhanced session description protocol between the target network equipment and the client, and the scheme can provide a hole digging success rate.
Owner:SHENZHEN STARCAM TECH

Port mapping method and device for sharing elastic public network IP by multiple private clouds

The embodiment of the invention relates to the technical field of virtual network resource scheduling, and provides a port mapping method and device for multiple private clouds to share an elastic public network IP, and the method comprises the steps: creating multiple private clouds in a Cloud platform, and configuring and sharing one elastic public network IP for the multiple private clouds; an ARP pickup flow table of the elastic public network IP is configured on a gateway node of the elastic public network IP through a breip network bridge of the Cloud pods platform, the ARP pickup flow table is used for guiding a data center network to guide the flow accessing the elastic public network IP to the gateway node of the elastic public network IP, the gateway node is a node deployed in a centralized manner on the Cloud pods platform, and the flow of the elastic public network IP is guided by the data center network to the gateway node of the elastic public network IP. The public network flow processing module is used for uniformly processing public network flow of all private clouds sharing an elastic public network IP; and configuring a network address translation rule on the breip network bridge, and mapping a specified port of the elastic public network IP to an intranet IP of the target virtual machine in the corresponding private cloud and a port of the corresponding service. An elastic public network IP is shared in a virtual machine service scene of multiple tenants and multiple private clouds.
Owner:ZHONGKE ZIDONG TAICHU (BEIJING) TECH CO LTD

Methods, systems, and computer readable media for providing stream control transmission protocol (SCTP) multihoming between a kubernetes environment and a non-kubernetes environment

A method for providing stream control transmission protocol (SCTP) multihoming between a Kubernetes environment and a non-Kubernetes environment includes receiving, at an SCTP multihoming router (SMR) deployed as a pod within the Kubernetes environment and from a client in the non-Kubernetes environment, an SCTP INIT message for establishing a multi-homed SCTP association between first and second Internet protocol (IP) addresses of the client and first and second local IP addresses of the SMR. The first and second local IP addresses of the SMR are added to an SCTP header of the SCTP INIT message. Source and destination network address translations (NATs) are performed to change a source IP address and a destination IP address in an IP header of an IP datagram carrying the SCTP INIT message to a third local IP address of the SMR and a service IP address of a service in the Kubernetes environment, respectively.
Owner:ORACLE INT CORP

Resource sharing between cloud-hosted virtual networks

Techniques for resource sharing between cloud-hosted virtual networks are described. A first network address of a first virtual network is associated with a resource connected to a second virtual network, the first and second virtual networks within a cloud provider network. A service of the cloud provider network receives a message destined for the first network address. The service translates the first network address to a second network address of the resource in the second virtual private network. The service sends the message to the resource at the second network address in the second virtual network.
Owner:AMAZON TECH INC

External network access method and apparatus, and computer device, readable storage medium and product

PCT designated stageWO2026108800A1TransmissionAccess methodNetwork addressing
The present application relates to an external network access method and apparatus, and a computer device, a readable storage medium and a product. The method comprises: upon receiving an external network access request sent by at least one internal network device, acquiring the priority with which each external network access request is transmitted to each of at least two gateway servers, wherein the priority is determined on the basis of connection attributes between the gateway servers and the internal network device (S202); sending the external network access request to a first gateway server having the highest priority, and performing network address translation (S204); when an anomaly occurs in the first gateway server during the process of network address translation, sending the external network access request to a second gateway server having the highest priority among the gateway servers other than the first gateway server (S206); performing network address translation (S208); and when the second gateway server converts an internal network address of the internal network device into a public network address of an external network indicated by the external network access request, obtaining an external network access result (S210).
Owner:CHINA TELECOM CLOUD TECH CO LTD

A method of processing and a routing device for controlling a session

The specification provides a processing method and a routing device for controlling a session, the method comprising: an NPU receiving a first control packet, converting a first source address in the first control packet into a second source address according to a network address translation (NAT) rule, the NPU uploading the first control packet and the second source address to a CPU kernel state, the NPU receiving a second control packet sent by the CPU kernel state, converting a first destination address in the second control packet into a second destination address according to the NAT rule, the NPU uploading the second control packet and the second destination address to the CPU kernel state, and the NPU receiving a takeover notification sent by the CPU kernel state and a control packet converted by a user state to process a session. By the method, the technical problem that the processing logic is limited by the NPU hardware and that the IP can be converted only once in each flow processing and the twice NAT conversion in the NAT hairpin scene cannot be implemented is avoided.
Owner:NEW H3C TECH CO LTD

Client IP persistence for traffic egressing from a distributed service access service edge (SASE) infrastructure for language localization

Techniques for providing language localization for traffic egressing from a distributed Service Access Service Edge (SASE) infrastructure are disclosed. In some embodiments, a system, a process, and / or a computer program product for providing client IP persistence for traffic egressing from a distributed SASE infrastructure includes receiving traffic associated with a user application (app) session at a Secure Access Service Edge (SASE) cloud network via a proxy node; processing the traffic associated with the user app session using a security processing node (SPN), and wherein a source network address translation (SNAT) rule is configured for the SPN; and egressing the traffic associated with the user app session from the SASE cloud network to its original destination using a fixed public IP address based on the SNAT rule to facilitate language localization for all network connections associated with the user app session.
Owner:PALO ALTO NETWORKS INC

Security scanning method and system based on cloud proxy

According to the security scanning method and system based on the cloud proxy, the resource-intensive scanning task is transferred to the cloud server to be executed, the client only needs to run the lightweight proxy plug-in, the requirement for client hardware resources is lowered, resource-limited equipment can bear comprehensive scanning, and the problems that gateway resources are limited, and the scanning efficiency is low are solved. And a scanner which consumes resources cannot be built in. The isolation limitation of network address translation equipment and a firewall is broken through by utilizing a reverse connection and cloud proxy mechanism, and the penetration scanning of an intranet target without a public network IP is realized; meanwhile, tasks can be uniformly configured according to the cloud, multiple client nodes are scheduled, scanning results are integrated, and large-scale concurrent scanning is achieved by combining the high-performance computing power of the cloud; client deployment is further simplified, and distributed deployment and maintenance of a complex scanning tool can be avoided only by installing a single proxy plug-in; moreover, the scanning flow of a cloud source can enhance the operation concealment, and improves the tracking and tracing difficulty.
Owner:SUZHOU MAXNET NETWORK SECURITY TECH CO LTD

Anti-attack method and network equipment

The invention provides an anti-attack method and network equipment, and the method comprises the steps: a carrier level network address translation CGN creates an anti-attack table for an access user, and when the user meets an attack condition, the message flow of the user is processed according to an anti-attack strategy in the anti-attack table of the user. Through the method, the CGN aims at the attack prevention of the user level.
Owner:NEW H3C TECH CO LTD

Controller-based distributed remote access with static public IP avoidance

A method of implementing controller-based distributed remote access may include connecting a plurality of edge devices to a controller via a network. The plurality of edge devices may perform hole punching to traverse a network address translation (NAT) gateway to create a NAT hole. The method may also include connecting a client device to the controller. The client device may be directly connected to one of the plurality of edge devices via the NAT hole in the network. The method may further include directly connecting the client device to one of the plurality of edge devices by receiving a query from the client device and returning public IP / ports of a most relevant edge device to the client device, the most relevant edge device being based on attributes of the client device, attributes of the plurality of edge devices, or combinations thereof.
Owner:CISCO TECHNOLOGY INC

Network attack surface identification optimization method based on network topology and security simulation calculation

The invention discloses a network attack surface identification optimization method based on network topology and security simulation calculation, and relates to the field of network security, and the method comprises the following steps: collecting configuration information of multi-manufacturer network equipment through a remote protocol, executing security simulation calculation on a network topology model, querying an access path from a source address to a destination address, and executing the security simulation calculation on the network topology model; analyzing a strategy matching state, a network address translation rule and route accessibility in the path, and outputting a path on-off state; based on the path on-off state, calculating a whole network data flow relationship, identifying an internal network address and a port which can be directly accessed from an external network, and generating a network attack surface report; and optimizing the strategy rule of the multi-manufacturer network equipment according to the network attack surface report, and outputting an optimized security configuration scheme. According to the network attack surface identification optimization method based on the network topology and the security simulation calculation, the problems that omission risks exist in network security and the network security protection is weak are solved.
Owner:JILIN ELECTRIC POWER RES INST LTD

Configuring application availability using anycast addressing

Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a tenant's network fabric, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port / protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a domain name system entry that resolves the application name to its virtual Internet Protocol (IP) address and destination network address translation rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address. Application network traffic can thus be forwarded to the application via any application connector that advertised the anycast address.
Owner:PALO ALTO NETWORKS INC

Controller-based distributed remote access with static public IP avoidance

A method of implementing controller-based distributed remote access may include connecting a plurality of edge devices to a controller via a network. The plurality of edge devices may perform hole punching to traverse a network address translation (NAT) gateway to create a NAT hole. The method may also include connecting a client device to the controller. The client device may be directly connected to one of the plurality of edge devices via the NAT hole in the network. The method may further include directly connecting the client device to one of the plurality of edge devices by receiving a query from the client device and returning public IP / ports of a most relevant edge device to the client device, the most relevant edge device being based on attributes of the client device, attributes of the plurality of edge devices, or combinations thereof.
Owner:CISCO TECHNOLOGY INC

Kafka cluster access method and device, electronic equipment and storage medium

The embodiment of the invention discloses a Kafka cluster access method and device, electronic equipment and a storage medium. The method comprises the following steps: deploying a proxy server in a Kafka cluster; proxy ports on the proxy server are respectively mapped to ports of nodes in the Kafka cluster; configuring a destination network address translation rule at the client; converting a port address of a node in the Kafka cluster into a proxy port address of a proxy server according to a destination network address conversion rule, so that a client initiates connection through an original port address of the node in the Kafka cluster; according to a connection request initiated by a client, forwarding the connection request to a target node of the corresponding Kafka cluster; and establishing an access connection between the client and the Kafka cluster according to the connection request, so that the client accesses a target node of the Kafka cluster. Through a destination network address translation rule of the proxy server and the client, no matter what address the Kafka cluster returns, the client rewrites the address as the address of the proxy server, and successful access to the Kafka cluster is realized.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Intranet proxy communication method, system and device based on QUIC protocol

The invention discloses an internal network proxy communication method, system and device based on a QUIC protocol, and belongs to the technical field of computer networks. The method comprises the following steps: a proxy gateway receives a client request and converts the client request into a preset format; sending to a QUIC connector deployed at a back-end server side in a stream form through the established QUIC connection; the QUIC connector forwards the request to a local back-end service through the loopback address; the response is returned along the original path. The system includes a proxy gateway, a QUIC connection, and a QUIC connector. According to the method and the device, a plurality of client requests are multiplexed into a small number of QUIC connections, and the multiplexing characteristic of the QUIC protocol is utilized, so that the occupation of the NAT table item is reduced from O (N) to O (1), the technical problem that the NAT table item is exhausted in a high-concurrency scene is solved, meanwhile, the connection processing capability of the proxy server is remarkably improved, the delay is reduced, and the system resource consumption is reduced.
Owner:HUBEI LITTLE UMBRELLA TECHNOLOGY CO LTD

Low-altitude blind area access method and system based on multi-network fusion unmanned aerial vehicle network

This invention discloses a method and system for low-altitude blind zone access based on a multi-network converged UAV network. The system includes an embedded device configured with a cellular communication module and a self-organizing network interface card (NIC) as a gateway node, an embedded device configured with a self-organizing NIC as a relay node, and an embedded device configured with multiple self-organizing NICs as access nodes. The system operates by including the following steps: after power-on, nodes automatically perform network configuration, identify new nodes, and assign IP addresses; access nodes achieve transparent forwarding of user data by setting up special connections between NICs; the topology is maintained using self-organizing network protocols, enabling seamless roaming and session persistence for terminals between access points; and the gateway node forwards internal traffic to the cellular network for internet access through network address translation and routing rules. This invention addresses the problems of high cost and difficult deployment of traditional low-altitude blind zone access solutions by employing low-cost equipment and self-organizing network technology, achieving rapid, self-organizing, stable, and reliable network access.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

Methods, systems, and computer readable media for providing stream control transmission protocol (SCTP) multihoming between a kubernetes environment and a non-kubernetes environment

A method for providing stream control transmission protocol (SCTP) multihoming between a Kubernetes environment and a non-Kubernetes environment includes receiving, at an SCTP multihoming router (SMR) deployed as a pod within the Kubernetes environment and from a client in the non-Kubernetes environment, an SCTP INIT message for establishing a multi¬ homed SCTP association between first and second Internet protocol (IP) addresses of the client and first and second local IP addresses of the SMR. The first and second local IP addresses of the SMR are added to an SCTP header of the SCTP INIT message. Source and destination network address translations (NATs) are performed to change a source IP address and a destination IP address in an IP header of an IP datagram carrying the SCTP INIT message to a third local IP address of the SMR and a service IP address of a service in the Kubernetes environment, respectively.
Owner:ORACLE INT CORP

Request processing method and device and server cluster

The invention provides a request processing method and device and a server cluster, and is applied to a first data center, the method comprises the following steps: obtaining a first request of a private network service of the first data center, the first data center comprising a first gateway; a network address of a first network segment carried by the first request is converted into a network address of a virtual network segment through the first gateway according to a first mapping rule, a virtual request is obtained, the virtual network segment is different from the first network segment, and the first network segment is a network segment used by the first data center; and the virtual request is sent to a second gateway of the second data center, so that the second gateway converts a network address of a virtual network segment carried by the virtual request into a network address of a second network segment, the virtual network segment is different from the second network segment, and the second network segment is a network segment used by the second data center.
Owner:SANGFOR TECH INC

Method for refreshing flow table of network address translation and related device

The application provides a network address conversion flow table refreshing method and related equipment, including: based on the obtained address update configuration information, determining a target conversion IP address in a conversion IP address configuration table, and deleting the target conversion IP address from the conversion IP address configuration table, and generating a deletion chain table corresponding to the address update configuration information; deleting the configuration serial number of the target conversion IP address corresponding to the address update configuration information in the deletion chain table; executing a timing refreshing task, deleting invalid flow table data in the flow table according to the configuration serial number of the target conversion IP address in each deletion chain table, completing flow table refreshing, and the flow table containing flow table data generated after a message triggers network address conversion. The configuration serial number of the deleted conversion IP address is used to generate a deletion chain table, and invalid flow table data in the flow table is deleted according to the deletion chain table, and the process of refreshing the flow table does not affect message forwarding, and the message forwarding performance is ensured.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Method and device for detecting network address translation type

PendingCN121173709ATransmissionSTUNEngineering
The invention provides a network address translation type detection method and device. The method comprises the following steps: sending a detection packet carrying first detection step information and a first timestamp to STUN service; if a response packet fed back by the STUN service is received within the first timeout time and the first detection step information is consistent with second detection step information in the response packet, determining communication time consumption according to a current timestamp and a second timestamp; recording the communication time consumption into a linked list, determining a second timeout time according to all the communication time consumption in the linked list, and configuring the second timeout time as a first timeout time of a next detection step of the current detection step; determining a network address translation type or next detection step information according to the detection step information, the feedback information, the public network information and the intranet information; according to the method, the reasonable timeout time of the post step is dynamically calculated according to the communication time consumption of the pre-step, and the detection speed is increased while the network address translation type is accurately detected by dynamically adjusting the timeout time.
Owner:HUNAN HAPPLY SUNSHINE INTERACTIVE ENTERTAINMENT MEDIA CO LTD

Implementing a service mesh in the hypervisor

A packet is received by a hypervisor from a first container, the packet to be provided to a second container, the packet including a header including a first network address associated with the second container. A network policy is identified for the packet in view of the first network address. A second network address corresponding to the second container is determined in view of the network policy. A network address translation is performed by the hypervisor to modify the header of the packet to include the second network address corresponding to the second container.
Owner:RED HAT LLC

Method, apparatus and electronic device for determining network address translation type

This application provides a method, apparatus, and electronic device for determining network address translation (NAT) types. The method includes: sending a first detection message to a first server based on address information of a first server, and sending a second detection message to a second server based on address information of a second server; and determining, based on the received response message, the NAT type used by the network where the client is located when performing NAT on the client. This method can quickly determine the NAT type used by the network where the client is located when performing NAT on the client, improving the efficiency of NAT detection.
Owner:SHUXING TECH (BEIJING) CO LTD

Reference station network, reference station network node public network security access method and device

The application relates to the technical field of reference station network, and discloses a reference station network and a node public network security access method and device thereof, wherein a reference station is connected with a reference station gateway, the reference station gateway is connected with a data center VPN gateway through a VPN encryption tunnel on a public network, and multiple in-station devices of the reference station are connected with a data center server through the VPN encryption tunnel; the method comprises the following steps: a data center server initiates an access request for a specified in-station device; a data center VPN gateway performs network address translation on an original source address of the data center server in an access request data packet according to preconfiguration; the data center VPN gateway judges whether an address pair of a new source address of the data packet and a destination address of the specified in-station device matches a preconfigured VPN interest flow, and sends the access request data packet to the specified in-station device; wherein the preconfigured VPN interest flow does not contain the original source address of the data center server.
Owner:QIANXUN SPATIAL INTELLIGENCE INC

Train data transmission system and method, apparatus, and medium

A train data transmission system and method, an apparatus, and a medium are disclosed. The method includes: acquiring, by a train data acquisition device, train-related data; receiving the train-related data from an onboard central control device and forwarding the train-related data to a database server by a network address translation (NAT) server; and in response to a web server receiving access information of an access terminal accessing a web service port exposed by a public network, acquiring, by the web server, target data from the train-related data stored in the database server according to the access information; and receiving, by the access terminal, the target data from the web server.
Owner:WUYI UNIV