IP Library Granted Patent US 9,325,738
Granted Patent B2
US 9,325,738 · App. 12/363,696 · Granted Apr 26, 2016

Methods and apparatus for blocking unwanted software downloads

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,325,738
App. No.
12/363,696
Granted
Apr 26, 2016
Kind
B2
Abstract

Methods and systems for blocking unwanted software downloads within a network. Such methods may thereby prevent (i) downloads of spyware from one or more identified locations, and/or (ii) certain outbound communications from the network and/or may also permit software downloads only from specified locations. In general, the policies are defined by rules specified by a network administrator or other user.

Claims (33)

1. A method for a network device communicatively coupled to a public network and a private network, the method comprising:

receiving, by the network device, a content delivery mechanism from the public network;

determining, by the network device, a category of a source Uniform Resource Locator (URL) of the content delivery mechanism;

determining, by the network device, at least one of an object tag and a script content delivery mechanism;

determining, by the network device, whether at least one of the object tag and the script tag are permitted for the determined category of the source URL; and

if at least one of the object tag and the script tag are not permitted for the determined category of the source URL, transforming, by the network device, the content delivery mechanism by removing at least one of the object tag and the script tag from the content delivery mechanism.

2. The method of claim 1 , wherein transforming the content delivery mechanism comprises removing all object tags from the content delivery mechanism if the determined category of the source URL is a suspicious category.

3. The method of claim 1 , wherein the content delivery mechanism comprises a Web page.

4. The method of claim 1 , wherein the content delivery mechanism comprises an Extensible Markup Language (XML) document.

5. A network device, the network device communicatively coupled to a public network and a private network, the network device comprising:

a receiver configured to receive a content delivery mechanism from the public network;

a processor; and

a data storage device having stored thereon instructions that, when executed by the processor, cause the processor to:

receive a content delivery mechanism from the public network;

determine a category of a source Uniform Resource Locator (URL) of the content delivery mechanism;

determine at least one of an object tag and a script tag of the content delivery mechanism;

determine whether at least one of the object tag and the script tag are permitted for the determined category of the source URL; and

if at least one of the object tag and the script tag are not permitted for the determined category of the source URL, transform the content delivery mechanism by removing at least one of the object tag and the script tag from the content delivery mechanism.

6. The network device of claim 5 , wherein the data storage device further stores instructions that, when executed by the processor, cause the processor to further transform the content delivery mechanism by removing all object tags from the content delivery mechanism if the determined category of the source URL is a suspicious category.

7. The network device of claim 5 , wherein the content delivery mechanism comprises a Web page.

8. The network device of claim 5 , wherein the content delivery mechanism comprises an Extensible Markup Language (XML) document.

9. A non-transitory machine-readable storage medium for a network device communicatively coupled to a public network and a private network, the non-transitory machine-readable storage medium comprising software instructions that, when executed by a processor of the network device, cause the network device to:

receive a content delivery mechanism from the public network;

determine a category of a source Uniform Resource Locator (URL) of the content delivery mechanism;

determine at least one of an object tag and a script tag of the content delivery mechanism;

determine whether at least one of the object tag and the script tag are permitted for the determined category of the source URL; and

if at least one of the object tag and the script tag are not permitted for the determined category of the source URL, transform the content delivery mechanism by removing at least one of the object tag and the script tag from the content delivery mechanism.

10. The non-transitory machine-readable storage medium of claim 9 , wherein the non-transitory machine-readable storage medium further comprises software instructions that, when executed by the processor, cause the processor to transform the content delivery mechanism by removing all object tags from the content delivery mechanism if the determined category of the source URL is a suspicious category.

11. The non-transitory machine-readable storage medium of claim 9 , wherein the content delivery mechanism comprises a Web page.

12. The non-transitory machine-readable storage medium of claim 9 , wherein the content delivery mechanism comprises an Extensible Markup Language (XML) document.

13. The method of claim 1 , wherein the network device is one or more of a proxy server, a firewall, a router and a bridge.

14. The network device of claim 5 , wherein the network device is one or more of a proxy server, a firewall, a router and a bridge.

15. The non-transitory machine-readable storage medium of claim 13 , wherein the network device is one or more of a proxy server, a firewall, a router and a bridge.

Assignments (11)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 27727/0144 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035798/0006 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT R/F 027727/0178 Recorded Oct 16, 2012
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 029140/0170 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0144 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2011
From: CAMPBELL, ALEXANDER WADE; DOLSEN, LEE THOMAS; OSITIS, VILIS; SMITH, CAMERON CHARLES
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 027313/0247 →