IP Library Granted Patent US 9,548,966
Granted Patent B2
US 9,548,966 · App. 14/503,299 · Granted Jan 17, 2017

Validating visitor internet-based security threats

Inventors: Matthew Browning Prince (San Francisco, CA); Lee Hahn Holloway (Santa Cruz, CA); Ian Gerald Pye (Santa Cruz, CA)
Assignee: CLOUDFLARE, INC.
H04L63/0281G06F15/16G06F17/30861G06F21/00G06F21/552G06Q30/0251G06Q30/0277H04L61/1511H04L61/2007H04L63/0236H04L63/0245H04L63/0254H04L63/083H04L63/0861H04L63/102H04L63/126H04L63/1433H04L63/1441H04L63/1458H04L63/1466H04L67/02H04L67/146H04L67/28H04L67/2804H04L67/2842H04L69/40H04L29/12066
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,548,966
App. No.
14/503,299
Granted
Jan 17, 2017
Kind
B2
Abstract

A validating server receives from a client device a first request that does not include a cookie for a validating domain that resolves to the validating sever. The first request is received at the validating server as a result of a proxy server redirecting the client device to the validating domain upon a determination that a visitor belonging to the client device is a potential threat based on an IP (Internet Protocol) address assigned to the client device used for a second request to perform an action on an identified resource hosted on an origin server for an origin domain. The validating server sets a cookie for the client device, determines a set of characteristics associated with the first client device, and transmits the cookie and a block page to the client device that has been customized based on the set of characteristics, the block page indicating that the second request has been blocked.

Claims (12)

1. A method in a proxy server for validating visitor Internet-based security threats, comprising

receiving, from a client device, a request to perform an action on an identified resource that is hosted at an origin server for a domain as a result of a DNS (Domain Name System) request for the domain resolving to the proxy server, wherein the origin server is one of a plurality of origin servers that belong to different domains that resolve to the proxy server and are owned by different entities, and wherein the proxy server and the plurality of origin servers are owned by different entities;

determining, based on an IP (Internet Protocol) address assigned to the client device and associated with the request, that a visitor belonging to the client device is a potential threat; and

causing a validating domain server to determine whether the visitor is a threat based on a cookie associated with the visitor for a validating domain, the causing including transmitting a response to the client device that includes a redirection to the validating domain that resolves to the validating domain server.

2. The method of claim 1 , wherein determining that the visitor is a potential threat includes determining that the IP address assigned to the client device is included in an IP restricted list.

3. The method of claim 1 , wherein the response includes a script that when executed by a client network application of the client device causes a request for a resource to be generated and issued to the validating domain.

4. A non-transitory machine-readable storage medium that provides instructions that, when executed by a processor of a proxy server, cause said processor to perform operations comprising:

receiving, from a client device, a request to perform an action on an identified resource that is hosted at an origin server for a domain as a result of a DNS (Domain Name System) request for the domain resolving to the proxy server, wherein the origin server is one of a plurality of origin servers that belong to different domains that resolve to the proxy server and are owned by different entities, and wherein the proxy server and the plurality of origin servers are owned by different entities;

determining, based on an IP (Internet Protocol) address assigned to the client device and associated with the request, that a visitor belonging to the client device is a potential threat; and

causing a validating domain server to determine whether the visitor is a threat based on a cookie associated with the visitor for a validating domain, the causing including transmitting a response to the client device that includes a redirection to the validating domain that resolves to the validating domain server.

5. The non-transitory machine-readable storage medium of claim 4 , wherein determining that the visitor is a potential threat includes determining that the IP address assigned to the client device is included in an IP restricted list.

6. The non-transitory machine-readable storage medium of claim 4 , wherein the response includes a script that when executed by a client network application of the client device causes a request for a resource to be generated and issued to the validating domain.

Assignments (1)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
Continuity (3)
Continuation 13078900 · Apr 1, 2011
Provisional Application 61397721 · Apr 1, 2010
Related Publication 20150207814A1 · Jul 23, 2015