IP Library Granted Patent US 9,009,461
Granted Patent B2
US 9,009,461 · App. 13/966,900 · Granted Apr 14, 2015

Selectively performing man in the middle decryption

Inventor: Paul Michael Martini (San Diego, CA)
Assignee: iboss, Inc.
H04L63/0471
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,009,461
App. No.
13/966,900
Granted
Apr 14, 2015
Kind
B2
Abstract

A HTTP request addressed to a first resource on a second device outside the network is received from a first device within the network. The HTTP request is redirected to a third device within the network. A first encrypted connection is established between the first device and the third device, and a second encrypted connection between the third device and the second device. The third device retrieves the first resource from the second device. The first resource is modified to change pointers within the first resource to point to location in a domain associated with the third device within the network. The third device serves, to the first device, the second resource.

Claims (62)

1. A method performed by data processing apparatus, the method comprising:

receiving, by a gateway on a network, from a client device within the network, a Hypertext Transfer Protocol (HTTP) request addressed to a first resource on a server outside the network;

determining, by the gateway, a class of network traffic of which the received HTTP request is a member, the determining being based on a comparison of the first resource with a rule defining destinations associated with encrypted communication traffic for each class;

selecting, by the gateway, a man-in-the-middle gateway within the network from a plurality of available man-in-the-middle gateways within the network, wherein each available man-in-the-middle gateway is associated with a class of network traffic and wherein the selected man in the selected middle gateway is selected based on having a class that is the same as the determined class of the HTTP request;

sending, from the gateway to the client device, a message redirecting the HTTP request to the selected man-in-the-middle-gateway within the network;

establishing a first encrypted connection between the client device and the selected man-in-the-middle-gateway, and a second encrypted connection between the selected man-in-the-middle-gateway and the server;

retrieving, by the selected man-in-the-middle-gateway, the first resource from the server;

modifying the first resource to change pointers within the first resource to point to location in a domain associated with the selected man-in-the-middle-gateway within the network; and

serving, by the selected man-in-the-middle-gateway to the client device, the modified first resource.

2. The method of claim 1 , wherein the selected man-in-the-middle-gateway is selected based on a comparison of the first resource with a rule defining destinations associated with encrypted communication traffic.

3. The method of claim 1 , wherein the selected man-in-the-middle-gateway is selected based on hardware performance.

4. The method of claim 1 , the method further comprising:

receiving, from a fourth device within the network, a second HTTP request addressed to an address of a second resource on a fifth device outside the network; and

routing the HTTP request to the address of the second resource.

5. The method of claim 1 , the method further comprising modifying the first resource to conform with the security policy.

6. The method of claim 1 , the method further comprising modifying the first resource comprises replacing the resource with a different resource.

7. The method of claim 1 , the method further comprising modifying the first resource comprises replacing HTTP links in the resource with different HTTP links.

8. The method of claim 1 , the method further comprising modifying the first resource comprises replacing the resource with an HTTP status code object.

9. The method of claim 1 , the method further comprising determining that a security policy of the network identifies the first resource for inspection upon entry to the network.

10. The method of claim 1 , wherein the determined class of network traffic of which the received HTTP request is a member of HTTP or Hypertext Transfer Protocol Secure (HTTPS) protocol.

11. A non-transitory computer storage media encoded with computer program instructions that, when executed by one or more processors, cause a computer device to perform operations comprising:

receiving, by a gateway on a network, from a client device within the network, a HTTP request addressed to a first resource on a server outside the network;

determining, by the gateway, a class of network traffic of which the received HTTP request is a member, the determining being based on a comparison of the first resource with a rule defining destinations associated with encrypted communication traffic for each class;

selecting, by the gateway, a man-in-the-middle gateway within the network from a plurality of available man-in-the-middle gateways within the network, wherein each available man-in-the-middle gateway is associated with a class of network traffic and wherein the selected man in the selected middle gateway is selected based on having a class that is the same as the determined class of the HTTP request;

sending, from the gateway to the client device, a message redirecting the HTTP request to the selected man-in-the-middle-gateway within the network;

establishing a first encrypted connection between the client device and the selected man-in-the-middle-gateway, and a second encrypted connection between the selected man-in-the-middle-gateway and the server;

retrieving, by the selected man-in-the-middle-gateway, the first resource from the server;

modifying the first resource to change pointers within the first resource to point to location in a domain associated with the selected man-in-the-middle-gateway within the network; and

serving, by the selected man-in-the-middle-gateway to the client device, the modified first resource.

12. The computer storage media of claim 11 , wherein the selected man-in-the-middle-gateway is selected based on a comparison of the first resource with a rule defining destinations associated with encrypted communication traffic.

13. The computer storage media of claim 11 , wherein the selected man-in-the-middle-gateway is selected based on hardware performance.

14. The computer storage media of claim 11 , the instructions further comprising:

receiving, from a fourth device within the network, a second HTTP request addressed to an address of a second resource on a fifth device outside the network; and

routing the HTTP request to the address of the second resource.

15. The computer storage media of claim 11 , the instructions further comprising modifying the first resource to conform with the security policy.

16. The computer storage media of claim 11 , the instructions further comprising modifying the first resource comprises replacing the resource with a different resource.

17. The computer storage media of claim 11 , the instructions further comprising modifying the first resource comprises replacing HTTP links in the resource with different HTTP links.

18. The computer storage media of claim 11 , the instructions further comprising modifying the first resource comprises replacing the resource with an HTTP status code object.

19. The computer storage media of claim 11 , the instructions further comprising determining that a security policy of the network identifies the first resource for inspection upon entry to the network.

20. The computer storage media of claim 11 , wherein the determined class of network traffic of which the received HTTP request is a member of HTTP or HTTPS protocol.

21. A system comprising:

one or more processors configured to execute computer program instructions; and

computer storage media encoded with computer program instructions that, when executed by one or more processors, cause a computer device to perform operations comprising:

receiving, by a gateway on a network, from a client device within the network, a Hypertext Transfer Protocol (HTTP) request addressed to a first resource on a server outside the network;

determining, by the gateway, a class of network traffic of which the received HTTP request is a member, the determining being based on a comparison of the first resource with a rule defining destinations associated with encrypted communication traffic for each class;

selecting, by the gateway, a man-in-the-middle gateway within the network from a plurality of available man-in-the-middle gateways within the network, wherein each available man-in-the-middle gateway is associated with a class of network traffic and wherein the selected man in the selected middle gateway is selected based on having a class that is the same as the determined class of the HTTP request;

sending, from the gateway to the client device, a message redirecting the HTTP request to the selected man-in-the-middle-gateway within the network;

establishing a first encrypted connection between the client device and the selected man-in-the-middle-gateway, and a second encrypted connection between the selected man-in-the-middle-gateway and the server;

retrieving, by the selected man-in-the-middle-gateway, the first resource from the server;

modifying the first resource to change pointers within the first resource to point to location in a domain associated with the selected man-in-the-middle-gateway within the network; and

serving, by the selected man-in-the-middle-gateway to the client device, the modified first resource.

22. The system of claim 21 , wherein the selected man-in-the-middle-gateway is selected based on a comparison of the first resource with a rule defining destinations associated with encrypted communication traffic.

23. The system of claim 21 , wherein the selected man-in-the-middle-gateway is selected based on hardware performance.

24. The system of claim 21 , the operations further comprising:

receiving, from a fourth device within the network, a second HTTP request addressed to an address of a second resource on a fifth device outside the network; and

routing the HTTP request to the address of the second resource.

25. The system of claim 21 , the operations further comprising modifying the first resource to conform with the security policy.

26. The system of claim 21 , the operations further comprising modifying the first resource comprises replacing the resource with a different resource.

27. The system of claim 21 , the operations further comprising modifying the first resource comprises replacing HTTP links in the resource with different HTTP links.

28. The system of claim 21 , the operations further comprising modifying the first resource comprises replacing the resource with an HTTP status code object.

29. The system of claim 21 , the operations further comprising determining that a security policy of the network identifies the first resource for inspection upon entry to the network.

30. The system of claim 21 , wherein the determined class of network traffic of which the received HTTP request is a member of HTTP or HTTPS protocol.

Assignments (7)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0219 →
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
SECURITY INTEREST Recorded Dec 16, 2020
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 054789/0680 →
CHANGE OF NAME Recorded Apr 23, 2014
From: PHANTOM TECHNOLOGIES, INC.
To: IBOSS, INC.
Reel/Frame 032745/0646 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2013
From: MARTINI, PAUL MICHAEL
To: PHANTOM TECHNOLOGIES, INC.
Reel/Frame 031367/0946 →
Continuity (1)
Related Publication 20150052345A1 · Feb 19, 2015