IP Library Patent Application 12247602
Patent Application
App. No. 12/247,602

METHOD AND SYSTEM FOR DETECTING, BLOCKING AND CIRCUMVENTING MAN-IN-THE-MIDDLE ATTACKS EXECUTED VIA PROXY SERVERS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/247,602
Abstract

A method for detecting and blocking a Man-in-the-Middle phishing attack carried out on a client connection which has been fraudulently routed through an anonymous proxy server. An agent downloaded to the client device opens a client direct connection to the security host protecting against the attack and sends a client direct connection ID to the security host for validation. By comparing IP addresses correlated via the validated client direct connection ID, the security host determines whether the original connection is direct (secure) or indirect (attack via phishing proxy). The detection and blocking can be performed by the service provider's server or by a third-party validation server handling all security without additional requirements on the service provider server. In addition to detecting and blocking such attacks, methods for client direct connection ID, as well as automatic transparent and seamless attack circumvention and preemptive circumvention are disclosed.

Claims (51)

1 . A method for detecting a Man-in-the-Middle attack during a session over a network connection between a client device having an IP address and a security host, the method comprising:

installing an agent within the client device, wherein said agent is configured to open a direct network connection to the security host;

receiving, by the security host, of an original network connection from the client device for a session login request, said original network connection having a sender with a sender IP address;

determining, by the security host, of said sender IP address;

sending, by the security host to said agent, a client direct connection ID request;

opening, by said agent, a new direct network connection from the client device to the security host;

generating, by said agent, a client direct connection ID in response to said request, and sending said client direct connection ID to the security host via said direct network connection;

determining, by the security host, of the IP address of the client device according to said new direct network connection;

comparing, by the security host, the IP address of the client device and said sender IP address according to said client direct connection ID; and

if according to said comparison said sender IP address does not match the IP address of the client device, then issuing a notification that a Man-in-the-Middle attack has been detected.

2 . The method of claim 1 , wherein said installing an agent within the client device is done prior to said receiving, by the security host, of an original network connection opened by the client device.

3 . The method of claim 1 , wherein said installing an agent within the client device is done subsequent to said receiving, by the security host, of an original network connection opened by the client device.

4 . The method of claim 1 , wherein the security host is a service provider server.

5 . The method of claim 1 , wherein the security host is a validation server providing protection for a service provider server against a Man-in-the-Middle attack.

6 . The method of claim 1 , further comprising validating said client direct connection ID by the security host.

7 . The method of claim 1 , further for blocking said Man-in-the-Middle attack, and further comprising, upon issuing a notification that a Man-in-the-Middle attack has been detected, terminating said original connection.

8 . The method of claim 1 , further for circumventing said Man-in-the-Middle attack, and further comprising:

signaling to switch the session to said new direct network connection;

switching, by the security host to said new direct network connection;

terminating, by the security host of said original network connection;

switching, by said agent to said new direct network connection;

terminating, by said agent of said original network connection; and

continuing the session over said new direct network connection.

9 . A method for preemptively circumventing a Man-in-the-Middle attack during a session over a network connection between a client device and a security host, the method comprising:

installing an agent within the client device, wherein said agent is configured to open a direct network connection to the security host;

receiving, by the security host, an original network connection opened by the client device for the session between the client device and the security host;

signaling, by the security host, said agent to open a new direct network connection to the security host;

validating, by the security host, that said new direct network connection is a direct network connection;

signaling to switch the session from said original network connection to said new direct network connection;

switching, by the security host to said new direct network connection;

terminating, by the security host of said original network connection;

switching, by said agent to said new direct network connection;

terminating, by said agent of said original network connection; and

continuing the session over said new direct network connection.

10 . The method of claim 9 , wherein said installing an agent within the client device is done prior to said receiving, by the security host, of an original network connection opened by the client device.

11 . The method of claim 9 , wherein said installing an agent within the client device is done subsequent to said receiving, by the security host, of an original network connection opened by the client device.

12 . The method of claim 9 , wherein said validating further comprises:

sending, by the security host, a client direct connection ID request to said agent;

generating, by said agent, a client direct connection ID in response to said client direct connection ID request;

sending, by said agent, said client direct connection ID to said security host over said direct network connection;

receiving, by the security host, said client direct connection ID; and

validating, by the security host; said client direct connection ID.

13 . A method for authenticating a network connection between a security host and a client device as a direct network connection, to protect against a Man-in-the-Middle attack, the method comprising:

installing an agent within the client device;

sending, by the security host, a client direct connection ID request to said agent;

opening, by said agent, a direct network connection to the security host;

generating, by said agent, a client direct connection ID in response to said client direct connection ID request;

sending, by said agent, said client direct connection ID to said security host over said direct network connection;

receiving, by the security host, said client direct connection ID; and

validating, by the security host; said client direct connection ID;

thereby authenticating said direct network connection as a direct network connection.

Assignments (5)
CHANGE OF NAME Recorded Feb 23, 2011
From: ALADDIN KNOWLEDGE SYSTEMS LTD.
To: SAFENET DATA SECURITY (ISRAEL) LTD.
Reel/Frame 025848/0923 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Aug 30, 2010
From: ALLADDIN KNOWLEDGE SYSTEMS LTD.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS COLLATERAL AGENT
Reel/Frame 024900/0702 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 27, 2010
From: ALLADDIN KNOWLEDGE SYSTEMS LTD.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS COLLATERAL AGENT
Reel/Frame 024892/0677 →
CORRECTIVE ASSIGNMENT TO CORRECT THE EXECUTION DATE OF INVENTOR MOSHE BRODY PREVIOUSLY RECORDED ON REEL 021652 FRAME 0280. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 15, 2008
From: MICHAELY, RONY; ELZAM, OFER; BRODY, MOSHE
To: ALADDIN KNOWELDGE SYSTEMS LTD.
Reel/Frame 021683/0041 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2008
From: MICHAELY, RONY; ELZAM, OFER; BRODY, MOSHE
To: ALADDIN KNOWELDGE SYSTEMS LTD.
Reel/Frame 021652/0280 →