IP Library Granted Patent US 7,412,539
Granted Patent B2
US 7,412,539 · App. 10/331,806 · Granted Aug 12, 2008

Method and apparatus for resource locator identifier rewrite

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,412,539
App. No.
10/331,806
Granted
Aug 12, 2008
Kind
B2
Abstract

A method for resource locator identifier rewrite in which a network security proxy insures that a resource locator identifier of a response indicates a resource access protocol that should govern a corresponding request. A security device receives from a resource host over a non-secure hypertext transfer protocol (HTTP) session a response to a request received from a client over a secure HTTP session. The response includes a uniform resource locator (URL) that is supposed to be for a resource host, but the URL does not designate a secure resource access protocol and the resource host requires the secure resource access protocol. The URL is located in the response and modified to designate the secure resource access protocol. After modification, the response is transmitted via the secure resource access protocol session to the client.

Claims (52)

1. A method in a network device comprising:

determining if a resource locator identifier (RLI) in a response indicates an appropriate request governing resource access protocol, wherein the appropriate request governing resource access protocol is the resource access protocol to govern a request for a resource indicated by the RLI, wherein the appropriate request governing resource access protocol is determined from a configuration file; and

rewriting the RLI to indicate the appropriate request governing resource access protocol if the RLI does not indicate the appropriate request governing resource access protocol; and

preventing a client that receives the response from relying on the content length indicated in the response by effectively removing a content length field in the response, wherein effectively removing the content length field comprises modifying the content length field in the response to be unrecognizable.

2. The method of claim 1 wherein the appropriate request governing resource access protocol is a secure resource access protocol.

3. The method of claim 1 wherein the appropriate request governing resource access protocol is a non-secure resource access protocol.

4. A method in a network device comprising:

modifying a response with a resource locator identifier (RLI) to indicate a first resource access protocol if the RLI indicates a second resource access protocol and the network device has been configured to insure that a request for a resource indicated by the RLI is in accordance with the first resource access protocol;

effectively removing a content length field in the response, wherein effectively removing the content length field comprises modifying the content length field in the response to be unrecognizable; and

transmitting the modified response to a client.

5. The method of claim 4 wherein the first resource access protocol is a secure resource access protocol and the second resource access protocol is a non-secure resource access protocol.

6. The method of claim 4 further comprising disabling persistent connection and chunked transfer encoding.

7. The method of claim 4 further comprising:

preserving persistent connection and chunked transfer encoding features available to the client; and

disabling chunked transfer encoding features for a resource host transmitting the response.

8. A method in a network security device comprising:

receiving a response with a resource locator identifier (RLI) that indicates a first resource access protocol;

determining that the first resource access protocol should not govern a request for a resource indicated by the RLI;

rewriting the RLI to indicate a second resource access protocol that should govern the request;

encapsulating a set of one or more fragments of the response with transport layer information;

effectively removing a content length field in the response, wherein effectively removing the content length field comprises modifying the content length field in the response to be unrecognizable; and

transmitting the encapsulated set of fragments to a client.

9. The method of claim 8 wherein rewriting the RLI includes adding port information to the RLI.

10. The method of claim 8 wherein the first resource access protocol is a secure resource access protocol and the second resource access protocol is a non-secure resource access protocol.

11. The method of claim 8 further comprising disabling persistent connection and chunked transfer encoding.

12. The method of claim 8 further comprising:

preserving persistent connection and chunked transfer encoding features available to the client; and

disabling chunked transfer encoding features for a resource host transmitting the response.

13. A machine-readable medium that provides instructions, executable by a set of one or more processors to cause said set of processors to perform operations comprising:

receiving a resource response message;

scanning the resource response message for a set of one or more resource locator identifiers and determining if each of the set of resource locator identifiers indicates a resource access protocol that should govern a request for their indicated resource;

rewriting those of the set of resource locator identifiers that are determined to not indicate the resource access protocol that should govern a request for their indicated resource to indicate an appropriate request governing resource access protocol; and

effectively removing a content length indicated in the resource response message, wherein effectively removing the content length field comprises modifying the content length field in the resource response message to be unrecognizable.

14. The machine-readable medium of claim 13 further comprising transmitting the response without scanning and rewriting if the content type of the response is not text.

15. The machine-readable medium of claim 13 further comprising transmitting the response without scanning and rewriting if the header of the response does not include a content encoding field.

16. The machine-readable medium of claim 13 wherein rewriting the set of resource locator identifiers comprises including a corresponding port.

17. The machine-readable medium of claim 13 wherein determining comprises comparing the resource host identifier of each of the set of resource locator identifiers against a configuration file that designates appropriate request governing resource access protocols for resource hosts.

18. A machine-readable medium that provides instructions, executable by a set of one or more processors to cause said set of processors to perform operations comprising:

determining if a resource locator identifier (RLI) in a response indicates an appropriate request governing resource access protocol, wherein the appropriate request governing resource access protocol is the resource access protocol to govern a request for a resource indicated by the RLI, wherein the appropriate request governing resource access protocol is determined from a configuration file; and

rewriting the RLI to indicate the appropriate request governing resource access protocol if the RLI does not indicate the appropriate request governing resource access protocol; and

preventing a client that receives the response from relying on the content length indicated in the response by effectively removing a content length field in the response, wherein effectively removing the content length field comprises modifying the content length field in the response to be unrecognizable.

19. The machine-readable medium of claim 18 wherein the appropriate request governing resource access protocol is a secure resource access protocol.

20. The machine-readable medium of claim 18 wherein the appropriate request governing resource access protocol is a non-secure resource access protocol.

21. A machine-readable medium that provides instructions, executable by a set of one or more processors to cause said set of processors to perform operations comprising:

modifying a response with a resource locator identifier (RLI) to indicate a first resource access protocol if the RLI indicates a second resource access protocol and the network device has been configured to insure that a request for a resource indicated by the RLI is in accordance with the first resource access protocol;

effectively removing the content length field in the response, wherein effectively removing the content length field comprises modifying the content length field in the response to be unrecognizable; and

transmitting the modified response to a client.

22. The machine-readable medium of claim 21 wherein the first resource access protocol is a secure resource access protocol and the second resource access protocol is a non-secure resource access protocol.

23. The machine-readable medium of claim 21 further comprising disabling persistent connection and chunked transfer encoding.

24. The machine-readable medium of claim 21 further comprising:

preserving persistent connection and chunked transfer encoding features available to the client; and

disabling chunked transfer encoding features for a resource host transmitting the response.

Assignments (24)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Apr 2, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 045818/0566 →
CORRECTIVE ASSIGNMENT TO CORRECT THE INCORRECT PATENT NO. 7752386 PREVIOUSLY RECORDED AT REEL: 037281 FRAME: 0007. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Jan 11, 2018
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 045814/0740 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
MERGER Recorded Dec 14, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 037281/0007 →
CONVERSION AND NAME CHANGE Recorded Dec 14, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 037282/0382 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024823/0280 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0126 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024776/0337 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0115 →
SECURITY AGREEMENT Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024776/0337 →
PATENT SECURITY AGREEMENT (SECOND LIEN) Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024823/0280 →
MERGER Recorded Jul 28, 2010
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC.
Reel/Frame 024755/0083 →
CHANGE OF NAME Recorded Jul 28, 2010
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 024755/0091 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2002
From: GMUENDER, JOHN E.; NGUYEN, HUY MINH; LEVY, JOSEPH H.; MASSING, MICHAEL B.; CHEN, ZHONG; TELEHOWSKI, DAVID M.
To: SONICWALL, INC.
Reel/Frame 013629/0754 →