IP Library Granted Patent US 7,437,482
Granted Patent B2
US 7,437,482 · App. 10/853,294 · Granted Oct 14, 2008

Method and apparatus for facilitating client server communications over a network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,437,482
App. No.
10/853,294
Granted
Oct 14, 2008
Kind
B2
Abstract

An apparatus and method for enhancing the infrastructure of a network such as the Internet is disclosed. Multiple edge servers and edge caches are provided at the edge of the network so as to cover and monitor all points of presence. The edge servers selectively intercept domain name translation requests generated by downstream clients, coupled to the monitored points of presence, to subscribing Web servers and provide translations which either enhance content delivery services or redirect the requesting client to the edge cache to make its content requests. Further, network traffic monitoring is provided in order to detect malicious or otherwise unauthorized data transmissions.

Claims (84)

1. An apparatus for facilitating communications between a client and a plurality of servers over a network, said network comprising a first sub-network comprising said client, said apparatus comprising:

a proxy server coupled with said first sub-network and operative to selectively proxy said communications between said client and said plurality of servers;

a filter coupled between said sub-network and said proxy server and operative to receive, from a first entity operating a first server of said plurality of servers, first criteria for intercepting and modifying said communications, and receive, from a second entity different from said first entity and operating a second server of said plurality of servers, second criteria for intercepting and modifying said communications, said filter being further operative to selectively intercept said communications prior to receipt by said proxy server based on said first and second criteria; and

a request modifier coupled with said filter and operative to modify said selectively intercepted communications based on said first and second criteria.

2. The apparatus of claim 1 , wherein said filter is further operative to filter out said communications originating from a second sub-network different from said first sub-network.

3. The apparatus of claim 2 , wherein said filter is further operative to identify an originating sub-network of said communications based on an internet protocol address associated with said communications.

4. The apparatus of claim 1 , wherein said filter is further operative to filter out communications not originating from said client.

5. The apparatus of claim 1 , wherein said filter is further operative to filter out malicious program code within said communications.

6. The apparatus of claim 1 , wherein said filter is further operative to filter out unauthorized program code within said communications.

7. The apparatus of claim 1 further comprising a first cache server coupled with said proxy server and said filter and operative to cache said communications from said plurality of servers to said client.

8. The apparatus of claim 7 , wherein said first cache server is proximate to said client.

9. The apparatus of claim 8 , wherein said first cache server is geographically proximate to said client.

10. The apparatus of claim 8 , wherein said first cache server is logically proximate to said client based on a topology of said first sub-network.

11. The apparatus of claim 7 , wherein said first cache server is further operative to share cached data with a second cache server.

12. The apparatus of claim 7 , wherein said communications further comprises a request generated by said client to one of said plurality of servers, and further wherein said filter is further operative to attempt to satisfy said request from said cache server before sending said request to said proxy server.

13. The apparatus of claim 1 further operative to prevent said client from directly communicating with said first and second servers and not prevent said client from directly communicating with others of said plurality of servers.

14. The apparatus of claim 1 , wherein said proxy server is not bound to said client.

15. The apparatus of claim 1 , wherein said filter and said proxy server are coupled with an address translator, said address translator operative to selectively substitute an address associated with said proxy server and return said address to said client to direct communications from said client to said proxy server instead of said plurality of servers.

16. The apparatus of claim 1 , wherein said proxy server is selectively bound to said at least one of said plurality of servers.

17. The apparatus of claim 16 wherein at least one other server of said plurality of servers is not bound with said proxy server and wherein said filter is further operative to filter out communications between said client and said other server and allow communications between said client and said at least one server to reach said proxy server.

18. The apparatus of claim 1 , wherein said communications further comprises a request generated by said client to one of said said plurality of servers, said filter being further operative to validate said request and validate said one of plurality of servers.

19. The apparatus of claim 1 further comprising a point of presence.

20. An apparatus for facilitating communications between a client and a plurality of servers over a network, said network comprising a first sub-network comprising said client, said apparatus comprising:

a request interceptor coupled with said first sub-network and operative to selectively intercept a first request prior to receipt by a first server of said plurality of servers, the first request being generated by said client and directed by said client to said first server;

a request transmitter operative to transmit said intercepted first request to said first server as if originated by said apparatus;

a response receiver operative to receive a response from said first server in response to said originated intercepted first request;

a response transmitter operative to transmit said response to said client;

a request filter coupled between said request interceptor and said request transmitter and operative to receive, from a first entity operating said first server of said plurality of servers, first criteria for intercepting and modifying said communications, and receive, from a second entity different from said first entity and operating a second server of said plurality of servers, second criteria for intercepting and modifying said communications, said filter being further operative to selectively filter said intercepted first request, based on said first and second criteria, prior to said request transmitter acting on said request; and

a request modifier coupled with said request filter and operative to modify said intercepted first request, prior to said request transmitter acting on said request, based on said first and second criteria.

21. The apparatus of claim 20 , wherein said request filter is further operative to filter out a second request originating from a second sub-network different from said first sub-network.

22. The apparatus of claim 21 , wherein said request filter is further operative to identify an originating sub-network of said second request based on an internet protocol address associated with said second request.

23. The apparatus of claim 20 , wherein said request filter is further operative to filter out a second request not originating from said client.

24. The apparatus of claim 20 , wherein said request filter is further operative to filter out malicious program code within said request.

25. The apparatus of claim 20 , wherein said request filter is further operative to filter out unauthorized program code within said request.

26. The apparatus of claim 20 further comprising a first cache server coupled with said response receiver, said response transmitter and said request filter and operative to cache said response from said first server to said response receiver.

27. The apparatus of claim 26 , wherein said first cache server is proximate to said client.

28. The apparatus of claim 27 , wherein said first cache server is geographically proximate to said client.

29. The apparatus of claim 27 , wherein said first cache server is logically proximate to said client based on a topology of said first sub-network.

30. The apparatus of claim 26 , wherein said first cache server is further operative to share cached data with a second cache server.

31. The apparatus of claim 26 , wherein said filter is further operative to attempt to satisfy said request from said cache server before sending said request to said request transmitter.

32. The apparatus of claim 20 further operative to prevent said client from directly communicating with said first and second servers and not prevent said client from directly communicating with others of said plurality of servers.

33. The apparatus of claim 20 , wherein said client intends said request to be received by said first server.

34. The apparatus of claim 20 further comprising an address translator, said address translator operative to selectively substitute an address associated with said request interceptor and return said address to said client to direct said request from said client to said request interceptor instead of said first server.

35. The apparatus of claim 20 , wherein said request filter is selectively affiliated with said first and second servers.

36. The apparatus of claim 35 wherein said plurality of servers includes a third server not affiliated with said request filter and wherein said request filter is further operative to filter out communications between said client and said third server and allow communications between said client and said first and second servers to reach said request transmitter.

37. The apparatus of claim 20 , wherein said filter is further operative to validate said request and validate said first server.

38. The apparatus of claim 20 further comprising a point of presence.

39. A method for facilitating communications between a client and a plurality of servers over a network, said network comprising a first sub-network comprising said client, said method comprising:

(a) receiving, from a first entity operating a first server of said plurality of servers, first criteria for intercepting and modifying said communications, and receiving, from a second entity different from said first entity and operating a second server of said plurality of servers, second criteria for intercepting and modifying said communications;

(b) intercepting, selectively, a first data transmission prior to receipt by said first server, the first data transmission being generated by said client and directed by said client to said first server;

(c) filtering said selectively intercepted first data transmission based on said first and second criteria;

(d) modifying said selectively intercepted first data transmission based on said first criteria; and

(e) proxying said modified selectively intercepted first data transmission based on said modifying.

40. The method of claim 39 , wherein (c) further comprises filtering out a second request originating from a second sub-network.

41. The method of claim 39 , wherein (c) further comprises filtering out malicious program code within said selectively intercepted first data transmission.

42. The method of claim 39 , wherein (c) further comprises filtering out unauthorized program code with said selectively intercepted first data transmission.

43. The method of claim 39 , further comprising:

(f) caching, selectively, a second data transmission generated by said first server in a cache server.

44. The method of claim 43 , wherein said selectively intercepted first data transmission further comprises a request, and wherein (c) further comprises attempting to satisfy said request from said cache server.

45. The method of claim 39 , further comprising:

(f) preventing said client from directly communicating with said first and second servers.

46. The method of claim 39 , wherein (b) further comprises said selective intercepting being implemented by a transmission interceptor, said method further comprising:

(f) directing said client to send said first data transmission to said transmission interceptor.

47. The method of claim 39 , wherein (c) further comprises validating said first data transmission and validating said first server.

48. The method of claim 39 , wherein (b) further comprises selectively intercepting said first data transmission at a point of presence.

49. A method for facilitating communications between a client and a plurality of servers over a network, said network comprising a first sub-network comprising said client, said method comprising:

(a) receiving, from a first entity operating a first server of said plurality of servers, first criteria for intercepting and modifying said communications, and receiving, from a second entity different from said first entity and operating a second server of said plurality of servers, second criteria for intercepting and modifying said communications;

(b) filtering a first data transmission prior to receipt by said first server, the first data transmission being generated by said client and directed by said client to said first server, to selectively intercept said first data transmission based on said first and second criteria;

(c) modifying said selectively intercepted first data transmission based on said first and second criteria;

(d) originating said modified filtered intercepted first data transmission to said first server based on said modifying;

(e) receiving a response from said first server in response to said originated modified filtered intercepted first data transmission; and

(f) transmitting said response to said client.

50. The method of claim 49 , wherein (b) further comprises filtering out a second data transmission originating from a second sub-network.

51. The method of claim 49 , wherein (b) further comprises filtering out malicious program code within said selectively intercepted first data transmission.

52. The method of claim 49 , wherein (b) further comprises filtering out unauthorized program code with said selectively intercepted first data transmission.

53. The method of claim 49 , further comprising:

(g) caching, selectively, said response in a cache server.

54. The method of claim 53 , wherein said selectively intercepted first data transmission further comprises a request, and wherein (b) further comprises attempting to satisfy said request from said cache server.

55. The method of claim 49 , further comprising:

(g) preventing said client from directly communicating with said first server.

56. The method of claim 49 , wherein (b) further comprises said selective intercepting being implemented by a transmission interceptor, said method further comprising:

(g) directing said client to send said first data transmission to said transmission interceptor.

57. The method of claim 49 , wherein (b) further comprises validating said first data transmission and validating said first server.

58. The method of claim 49 , wherein (b) further comprises selectively intercepting said first data transmission at a point of presence.

Assignments (14)
RELEASE OF SECURITY INTEREST Recorded May 16, 2024
From: STIFEL BANK
To: LOOKINGGLASS CYBER SOLUTIONS, LLC
Reel/Frame 067429/0361 →
RELEASE OF SECURITY INTEREST Recorded Apr 17, 2024
From: EASTWARD FUND MANAGEMENT, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.; CLOUDSHIELD TECHNOLOGIES, LLC; CYVEILLANCE, INC.
Reel/Frame 067131/0715 →
RELEASE OF SECURITY INTEREST Recorded Apr 17, 2024
From: EASTWARD FUND MANAGEMENT, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.; CLOUDSHIELD TECHNOLOGIES, LLC; CYVEILLANCE, INC.
Reel/Frame 067131/0803 →
RELEASE OF SECURITY INTEREST Recorded Mar 3, 2023
From: SILICON VALLEY BANK
To: CLOUDSHIELD TECHNOLOGIES, LLC
Reel/Frame 062872/0851 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2023
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.
Reel/Frame 062847/0569 →
SECURITY INTEREST Recorded May 11, 2022
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: EASTWARD FUND MANAGEMENT, LLC
Reel/Frame 059892/0963 →
SECURITY INTEREST Recorded Aug 24, 2021
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: SILICON VALLEY BANK
Reel/Frame 057274/0638 →
SECURITY INTEREST Recorded Jul 12, 2021
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: EASTWARD FUND MANAGEMENT
Reel/Frame 056823/0269 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2018
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.
Reel/Frame 047205/0192 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2017
From: SILICON VALLEY INTERNET CAPITAL, INC.
To: CLOUDSHIELD TECHNOLOGIES, INC.
Reel/Frame 043102/0566 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2017
From: JUNGCK, PEDER J.
To: SILICON VALLEY INTERNET CAPITAL, INC.
Reel/Frame 043102/0360 →
RELEASE OF SECURITY INTEREST Recorded Jul 21, 2016
From: PACIFIC WESTERN BANK
To: CLOUDSHIELD TECHNOLOGIES, LLC
Reel/Frame 039214/0024 →
SECURITY INTEREST Recorded Nov 19, 2015
From: CLOUDSHIELD TECHNOLOGIES, LLC
To: PACIFIC WESTERN BANK
Reel/Frame 037094/0199 →
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2015
From: VENTURE LENDING & LEASING IV, INC.; VENTURE LENDING & LEASING V, INC.
To: CLOUDSHIELD TECHNOLOGIES, LLC
Reel/Frame 037094/0291 →