IP Library Granted Patent US 9,148,407
Granted Patent B2
US 9,148,407 · App. 14/682,019 · Granted Sep 29, 2015

Selectively performing man in the middle decryption

Inventor: Paul Michael Martini (San Diego, CA)
Assignee: iboss, Inc.
H04L63/0281H04L63/0428H04L63/10H04L63/168H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,148,407
App. No.
14/682,019
Granted
Sep 29, 2015
Kind
B2
Abstract

An agent on a device within a network receives a request to access a resource outside the network. A first encrypted connection is established between the device and the agent, and a second encrypted connection is established between the agent and the resource, to facilitate encrypted communication traffic between the device and the resource. The agent sends a policy request to a network appliance within the network, the request specifying the resource. The agent receives a policy response indicating that the resource is associated with one or more security policies of the network. Traffic passing between the device and the resource is selectively decrypted and inspected depending on the security policies.

Claims (77)

1. A method performed by data processing apparatus, the method comprising:

receiving, by an agent on a device within a network, a request to access a resource outside the network;

establishing, by the agent, a first encrypted connection between the device and the agent such that the agent is configured to act as a proxy of the resource to the device;

establishing, by the agent, a second encrypted connection between the agent and the resource such that the agent is configured to act as a proxy of the device to the resource;

sending, by the agent in response to receiving the request to access the resource, a policy request to a network appliance within the network, the request specifying the resource;

receiving, by the agent and from the network appliance, a policy response indicating that the resource is associated with one or more security policies of the network;

decrypting and selectively inspecting, by the agent, encrypted communication traffic from the device and addressed to the resource, depending on the security policies;

decrypting and selectively inspecting, by the agent, encrypted communication traffic from the resource and address to the device, depending on the security policies;

receiving, by the agent, a second request to access a second resource outside the network;

determining that the second resource is on a whitelist that lists resources for which man-in-the-middle analysis should not apply; and

causing the establishment, responsive to determining that the second resource is on the whitelist, a third encrypted connection between the device and the second resource to facilitate encrypted communication traffic between the device and the second resource; wherein the first, the second, and the third encrypted connections are separate and have different formats.

2. The method of claim 1 , wherein the device and the network appliance are subject to the same administrative control.

3. The method of claim 1 , wherein inspecting, by the agent, encrypted communication traffic from the device and addressed to the resource includes blocking encrypted communication traffic from the device and addressed to the resource.

4. The method of claim 1 , wherein the request to access the resource is a Hypertext Transfer Protocol (HTTP) or Hypertext Transfer Protocol Secure (HTTPS) GET or POST request.

5. The method of claim 1 , the method further comprising:

removing the device from the network;

receiving, by the agent, a third request to access a third resource outside the network;

establishing, by the agent, a fourth encrypted connection between the device and the agent such that the agent is configured to act as a proxy of the resource to the device;

establishing, by the agent, a fifth encrypted connection between the agent and the third resource such that the agent is configured to act as a proxy of the device to the third resource;

sending, by the agent in response to receiving the third request to access the resource, a third policy request to the network appliance, the request specifying the third resource;

receiving, by the agent and from the network appliance, a third policy response indicating that the third resource is associated with one or more security policies of the network;

decrypting and selectively inspecting, by the agent, encrypted communication traffic from the device and addressed to the third resource, depending on the security policies; and

decrypting and selectively inspecting, by the agent, encrypted communication traffic from the third resource and address to the device, depending on the security policies.

6. The method of claim 1 , wherein the agent is a driver installed in a protocol stack of the device.

7. The method of claim 1 , wherein the agent is configured to receive requests to access resources from a plurality of applications of the device.

8. A non-transitory computer storage media encoded with computer program instructions that, when executed by one or more processors, cause a computer device to perform operations comprising:

receiving, by an agent on a device within a network, a request to access a resource outside the network;

establishing, by the agent, a first encrypted connection between the device and the agent such that the agent is configured to act as a proxy of the resource to the device;

establishing, by the agent, a second encrypted connection between the agent and the resource such that the agent is configured to act as a proxy of the device to the resource;

sending, by the agent in response to receiving the request to access the resource, a policy request to a network appliance within the network, the request specifying the resource;

receiving, by the agent and from the network appliance, a policy response indicating that the resource is associated with one or more security policies of the network;

decrypting and selectively inspecting, by the agent, encrypted communication traffic from the device and addressed to the resource, depending on the security policies;

decrypting and selectively inspecting, by the agent, encrypted communication traffic from the resource and address to the device, depending on the security policies;

receiving, by the agent, a second request to access a second resource outside the network;

determining that the second resource is on a whitelist that lists resources for which man-in-the-middle analysis should not apply; and

causing the establishment, responsive to determining that the second resource is on the whitelist, a third encrypted connection between the device and the second resource to facilitate encrypted communication traffic between the device and the second resource; wherein the first, the second, and the third encrypted connections are separate and have different formats.

9. The computer storage media of claim 8 , wherein the device and the network appliance are subject to the same administrative control.

10. The computer storage media of claim 8 , wherein inspecting, by the agent, encrypted communication traffic from the device and addressed to the resource includes blocking encrypted communication traffic from the device and addressed to the resource.

11. The computer storage media of claim 8 , wherein the request to access the resource is a Hypertext Transfer Protocol (HTTP) or Hypertext Transfer Protocol Secure (HTTPS) GET or POST request.

12. The computer storage media of claim 8 , the operations further comprising:

removing the device from the network;

receiving, by the agent, a third request to access a third resource outside the network;

establishing, by the agent, a fourth encrypted connection between the device and the agent such that the agent is configured to act as a proxy of the resource to the device;

establishing, by the agent, a fifth encrypted connection between the agent and the third resource such that the agent is configured to act as a proxy of the device to the third resource;

sending, by the agent in response to receiving the third request to access the resource, a third policy request to the network appliance, the request specifying the third resource;

receiving, by the agent and from the network appliance, a third policy response indicating that the third resource is associated with one or more security policies of the network;

decrypting and selectively inspecting, by the agent, encrypted communication traffic from the device and addressed to the third resource, depending on the security policies; and

decrypting and selectively inspecting, by the agent, encrypted communication traffic from the third resource and address to the device, depending on the security policies.

13. The computer storage media of claim 8 , wherein the agent is a driver installed in a protocol stack of the device.

14. The computer storage media of claim 8 , wherein the agent is configured to receive requests to access resources from a plurality of applications of the device.

15. A system comprising:

one or more processors configured to execute computer program instructions; and

non-transitory computer storage media encoded with computer program instructions that, when executed by one or more processors, cause a computer device to perform operations comprising:

receiving, by an agent on a device within a network, a request to access a resource outside the network;

establishing, by the agent, a first encrypted connection between the device and the agent such that the agent is configured to act as a proxy of the resource to the device;

establishing, by the agent, a second encrypted connection between the agent and the resource such that the agent is configured to act as a proxy of the device to the resource;

sending, by the agent in response to receiving the request to access the resource, a policy request to a network appliance within the network, the request specifying the resource;

receiving, by the agent and from the network appliance, a policy response indicating that the resource is associated with one or more security policies of the network;

decrypting and selectively inspecting, by the agent, encrypted communication traffic from the device and addressed to the resource, depending on the security policies;

decrypting and selectively inspecting, by the agent, encrypted communication traffic from the resource and address to the device, depending on the security policies;

receiving, by the agent, a second request to access a second resource outside the network;

determining that the second resource is on a whitelist that lists resources for which man-in-the-middle analysis should not apply; and

causing the establishment, responsive to determining that the second resource is on the whitelist, a third encrypted connection between the device and the second resource to facilitate encrypted communication traffic between the device and the second resource; wherein the first, the second, and the third encrypted connections are separate and have different formats.

16. The system of claim 15 , wherein the device and the network appliance are subject to the same administrative control.

17. The system of claim 15 , wherein inspecting, by the agent, encrypted communication traffic from the device and addressed to the resource includes blocking encrypted communication traffic from the device and addressed to the resource.

18. The system of claim 15 , wherein the request to access the resource is a Hypertext Transfer Protocol (HTTP) or Hypertext Transfer Protocol Secure (HTTPS) GET or POST request.

19. The system of claim 15 , wherein the operations further comprising:

removing the device from the network;

receiving, by the agent, a third request to access a third resource outside the network;

establishing, by the agent, a fourth encrypted connection between the device and the agent such that the agent is configured to act as a proxy of the resource to the device;

establishing, by the agent, a fifth encrypted connection between the agent and the third resource such that the agent is configured to act as a proxy of the device to the third resource;

sending, by the agent in response to receiving the third request to access the resource, a third policy request to the network appliance, the request specifying the third resource;

receiving, by the agent and from the network appliance, a third policy response indicating that the third resource is associated with one or more security policies of the network;

decrypting and selectively inspecting, by the agent, encrypted communication traffic from the device and addressed to the third resource, depending on the security policies; and

decrypting and selectively inspecting, by the agent, encrypted communication traffic from the third resource and address to the device, depending on the security policies.

20. The system of claim 15 , wherein the agent is a driver installed in a protocol stack of the device.

21. The system of claim 15 , wherein the agent is configured to receive requests to access resources from a plurality of applications of the device.

Assignments (7)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0219 →
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
SECURITY INTEREST Recorded Dec 16, 2020
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 054789/0680 →
CHANGE OF NAME Recorded Jun 26, 2015
From: PHANTOM TECHNOLOGIES, INC.
To: IBOSS, INC.
Reel/Frame 036021/0064 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2015
From: MARTINI, PAUL MICHAEL
To: PHANTOM TECHNOLOGIES, INC.
Reel/Frame 035911/0190 →
Continuity (2)
Continuation 13890146 · May 8, 2013
Related Publication 20150215286A1 · Jul 30, 2015