IP Library Granted Patent US 8,826,411
Granted Patent B2
US 8,826,411 · App. 11/376,917 · Granted Sep 2, 2014

Client-side extensions for use in connection with HTTP proxy policy enforcement

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,826,411
App. No.
11/376,917
Granted
Sep 2, 2014
Kind
B2
Abstract

A Web browser is configured to participate with a proxy server in enforcing traffic policies within a computer network. This may include modifying the Web browser to report contextual information regarding requests for Web documents to the proxy server and/or causing the Web browser to report information concerning Web documents requested through the proxy server to the proxy server.

Claims (33)

1. A method, comprising:

receiving at a proxy server a request for a Web document, said request originating from a client application executing on a client device communicably coupled to the proxy server;

retrieving, by the proxy server, a copy of the requested Web document, the proxy server modifying the requested Web document by inserting a set of computer-readable instructions which when executed by a processor of the client device on which the client application runs cause the client application to perform one or more activities associated with network traffic policy enforcement, including reporting, to the proxy server, information concerning the Web document;

downloading, from the proxy server to the client application, a modified version of the requested Web document that includes the set of computer-readable instructions;

receiving, at the proxy server and from the client application responsive to execution of the set of computer-readable instructions by the processor of the client device on which the client application runs, the information concerning the Web document, the proxy server using said information to determine whether the Web document is subject to an existing network traffic policy; and

if the Web document is subject to the existing network traffic policy, enforcing the existing network traffic policy in connection with subsequent requests for the Web document; otherwise, not enforcing the existing network traffic policy in connection with subsequent requests for the Web document.

2. The method of claim 1 , wherein the client application comprises a Web browser.

3. The method of claim 1 , wherein the computer-readable instructions are embodied as a plug-in application for the client application.

4. The method of claim 1 , wherein the computer-readable instructions are embodied as executable JavaScript.

5. The method of claim 1 , wherein the computer-readable instructions are embodied as executable Active-X controls.

6. The method of claim 1 , wherein the computer-readable instructions are embodied as executable Java instructions.

7. The method of claim 2 , wherein when the computer-readable instructions are executed by said processor, said instructions cause the client application to report, to the proxy server, contextual information regarding requests for Web documents made by the Web browser.

8. A method as in any one of claims 1 - 6 , wherein when the computer-readable instructions are executed by said processor, said instructions cause the client application to report, to the proxy server, information regarding requests made by the client application.

9. A method as in any one of claims 1 - 6 , wherein when the computer-readable instructions are executed by said processor, said instructions cause the client application to report, to the proxy server, information about a current state of the client application.

10. A method as in any one of claims 1 - 6 , wherein when the computer-readable instructions are executed by said processor, said instructions cause the client application to report, to the proxy server, an indication of a source of a uniform resource locator (URL) to which one or more requests made by the client application are directed.

11. A method as in any one of claims 1 - 6 , wherein when the computer-readable instructions are executed by said processor, said instructions cause the client application to report, to the proxy server, information identifying an object referenced by a uniform resource locator (URL) to which one or more requests by the client application are directed.

12. A method as in any one of claims 1 - 6 , wherein when the computer-readable instructions are executed by said processor, said instructions cause the client application to report, to the proxy server, information about (i) a current state of the client application, and (ii) a context in which a request by the client application is being made.

13. A method as in any one of claims 1 - 6 , wherein when the computer-readable instructions are executed by said processor, said instructions cause the client application to take one or more actions to enforce the network traffic policy locally.

14. A method as in any one of claims 1 - 6 , wherein when the computer-readable instructions are executed by said processor, said instructions cause the client application to report, to the proxy server, information identifying an object referenced by a uniform resource locator (URL) to which one or more requests by the client application are directed, the URL indicating an embedded image in the Web document.

15. A method as in any one of claims 1 - 6 , wherein when the computer-readable instructions are executed by said processor, said instructions cause the client application to report, to the proxy server, information identifying an object referenced by a uniform resource locator (URL) to which one or more requests by the client application are directed, the URL indicating an embedded object in the Web document.

16. A method as in any one of claims 1 - 6 , wherein when the computer-readable instructions are executed by said processor, said instructions cause the client application to report, to the proxy server, information identifying an object referenced by a uniform resource locator (URL) to which one or more requests by the client application are directed, the URL naming a script.

17. A method as in any one of claims 1 - 6 , wherein when the computer-readable instructions are executed by said processor, said instructions cause the client application to report, to the proxy server, information identifying an object referenced by a uniform resource locator (URL) to which one or more requests by the client application are directed, the URL identifying a style sheet.

18. A method as in any one of claims 1 - 6 , wherein when the computer-readable instructions are executed by said processor, said instructions cause the client application to report, to the proxy server, information identifying an object referenced by a uniform resource locator (URL) to which one or more requests by the client application are directed, the URL referenced by a <frame> or <iframe> tag.

19. A proxy server, comprising: a processor; a storage device connected to the processor; and

a first set of computer-readable instructions on the storage device, said first set of instructions being executable by the processor and including: a first module configured to

receiving a request for a Web document, said request originating from a client application executing on a client device communicably coupled to the proxy server;

retrieve a copy of the requested Web document;

modify the requested Web document by inserting a second set of computer-readable instructions which when executed by a processor of the client device on which the client application runs cause the client application to perform one or more activities associated with network traffic policy enforcement, including reporting, to the proxy server, information concerning the Web document; and

send to the client application a modified version of the Web document that includes the second set of computer-readable instructions;

a second module configured to receive from the client application, responsive to execution of the second set of computer-readable instructions by the processor of the client device on which the client application runs, said information concerning the Web document;

a third module configured to use said information to determine whether the Web document is subject to an existing network traffic policy; and

a fourth module configured to (i) enforce, if the Web document is subject to the existing network traffic policy, the existing network traffic policy in connection with subsequent requests for the Web document, otherwise, (ii) not enforce the existing network traffic policy in connection with subsequent requests for the Web document.

20. The proxy server of claim 19 , wherein the proxy server receives said information concerning the Web document at an address specified by the second set of computer-readable instructions.

Assignments (11)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 27727/0144 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035798/0006 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT R/F 027727/0178 Recorded Oct 16, 2012
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 029140/0170 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0144 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2006
From: MOEN, DOUG; CAMPBELL, ALEX
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 017797/0755 →