IP Library Granted Patent US 8,875,220
Granted Patent B2
US 8,875,220 · App. 12/828,874 · Granted Oct 28, 2014

Proxy-based network access protection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,875,220
App. No.
12/828,874
Granted
Oct 28, 2014
Kind
B2
Abstract

In certain embodiments, a method includes receiving, at a proxy, a request for access to a network from an application on an endpoint. The method also includes determining, by the proxy, information about the application on the endpoint by examining one or more headers of the request received at the proxy from the application. The method further includes determining, by the proxy, whether the one or more headers comprise expected information based on the determined information about the application. In response to determining that the one or more headers do not comprise the expected information, the method includes denying, by the proxy, the request for access to the network. In addition, in response to determining that the one or more headers comprise the expected information, the method includes forwarding, by the proxy, the request to the network on behalf of the application.

Claims (56)

1. A method, comprising:

receiving, at a proxy controlling access to a network, a request for access to the network from an application on an endpoint;

analyzing headers of the request received at the proxy from the application;

identifying, by the proxy, the application on the endpoint sending the request based on the analysis of the headers of the request received at the proxy from the application;

selecting a policy to reference for indication of characteristics of the application to be considered compliant for granting access to the network based on the analysis of the headers;

determining, by the proxy, whether the one or more headers of the request received at the proxy from the application on the endpoint include characteristics of the application to be considered compliant for granting access to the network based on the analysis by the proxy of one or more headers;

in response to determining that the one or more headers do not include characteristics of the application to be considered compliant for granting access to the network, denying, by the proxy, the request for access of the endpoint to the network; and

in response to determining that the one or more headers include characteristics of the application to be considered compliant for granting access to the network, forwarding, by the proxy, the request of the endpoint to the network on behalf of the application,

wherein determining that the one or more headers do not include characteristics of the application to be considered compliant for granting access to the network comprises determining:

that at least one expected header is missing;

that the one or more headers comprises at least one typographical error; and

that the one or more headers comprises MIME types that are inconsistent with the determined information about the application, and

wherein forwarding the request to the network on behalf of the application in response to determining that the one or more headers include characteristics of the application considered compliant for granting access to the network comprises:

determining, by the proxy, that the one or more headers comprise the characteristics of the application considered compliant for granting access to the network;

receiving, at the proxy, a key from the application; and

forwarding, in response to validating the received key by the proxy, the request to the network on behalf of the application.

2. A system, comprising:

at least one memory;

at least one processor operable to:

receive, at a proxy controlling access to a network, a request for access to the network from an application on an endpoint;

analyze headers of the request received at the proxy from the application;

identify the application on the endpoint sending the request based on the analysis of the headers of the request received at the proxy from the application;

select a policy to reference for indication of characteristics of the application to be considered compliant for granting access to the network based on the analysis of the headers;

determine, by the proxy, whether the one or more headers of the request received at the proxy from the application on the endpoint include characteristics of the application to be considered compliant for granting access to the network based on the analysis by the proxy of one or more headers;

in response to determining that the one or more headers do not include characteristics of the application to be considered compliant for granting access to the network, deny, by the proxy, the request for access of the endpoint to the network; and

in response to determining that the one or more headers include characteristics of the application considered compliant for granting access to the network, forward, by the proxy, the request of the endpoint to the network on behalf of the application,

wherein the at least one processor determines that the one or more headers do not include characteristics of the application to be considered compliant for granting access to the network by determining:

that at least one expected header is missing;

that the one or more headers comprises at least one typographical error; and

that the one or more headers comprises MIME types that are inconsistent with the determined information about the application, and

wherein the at least one processor forwards the request to the network on behalf of the application in response to determining that the one or more headers include characteristics of the application considered compliant for granting access to the network by:

determining, by the proxy, that the one or more headers comprise the characteristics of the application considered compliant for granting access to the network;

receiving, at the proxy, a key from the application; and

forwarding, in response to validating the received key by the proxy, the request to the network on behalf of the application.

3. The system of claim 2 , wherein the application comprises a Web browser.

4. The system of claim 2 , wherein the at least one processor is operable to:

determine version information about the application by examining the one or more headers;

determine whether the application complies with at least one policy based on the determined version information about the application;

in response to determining that the application does not comply with the at least one policy, deny, by the proxy, the request for access to the network; and

in response to determining that the application does comply with the at least one policy, forward, by the proxy, the request to the network on behalf of the application.

5. At least one non-transitory computer-readable medium comprising code, that, when executed, is operable to:

receive, at a proxy controlling access to a network, a request for access to the network from an application on an endpoint;

analyze headers of the request received at the proxy from the application;

identify the application on the endpoint sending the request based on the analysis of the headers of the request received at the proxy from the application;

select a policy to reference for indication of characteristics of the application to be considered compliant for granting access to the network based on the analysis of the headers;

determine, by the proxy, whether the one or more headers of the request received at the proxy from the application on the endpoint include characteristics of the application to be considered compliant for granting access to the network based on the analysis by the proxy of one or more headers;

in response to determining that the one or more headers do not include characteristics of the application to be considered compliant for granting access to the network, deny, by the proxy, the request for access of the endpoint to the network; and

in response to determining that the one or more headers include characteristics of the application considered compliant for granting access to the network, forward, by the proxy, the request of the endpoint to the network on behalf of the application,

wherein determining that the one or more headers do not include characteristics of the application to be considered compliant for granting access to the network comprises determining:

that at least one expected header is missing;

that the one or more headers comprises at least one typographical error; and

that the one or more headers comprises MIME types that are inconsistent with the determined information about the application, and

wherein forwarding the request to the network on behalf of the application in response to determining that the one or more headers include characteristics of the application considered compliant for granting access to the network comprises:

determining, by the proxy, that the one or more headers comprise the characteristics of the application considered compliant for granting access to the network;

receiving, at the proxy, a key from the application; and

forwarding, in response to validating the received key by the proxy, the request to the network on behalf of the application.

Assignments (12)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070585/0625 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0309 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: FORCEPOINT FEDERAL LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0460 →
CHANGE OF NAME Recorded Feb 16, 2016
From: RAYTHEON CYBER PRODUCTS, LLC
To: FORCEPOINT FEDERAL LLC
Reel/Frame 037821/0818 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
CHANGE OF NAME Recorded Jun 2, 2015
From: RAYTHEON CYBER PRODUCTS, INC.
To: RAYTHEON CYBER PRODUCTS, LLC
Reel/Frame 035806/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2015
From: RAYTHEON COMPANY
To: RAYTHEON CYBER PRODUCTS, INC.
Reel/Frame 035774/0322 →