IP Library Granted Patent US 9,390,290
Granted Patent B1
US 9,390,290 · App. 14/835,063 · Granted Jul 12, 2016

Applying group policies

Inventor: Paul Michael Martini (San Diego, CA)
Assignee: iboss, Inc.
G06F21/64H04L9/0825
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,390,290
App. No.
14/835,063
Granted
Jul 12, 2016
Kind
B1
Abstract

Information corresponding to a set of signatures is maintained, and for each signature in the set, an associated group policy of a network is maintained. A message from a device on the network is intercepted, and the message includes a header. At least a portion of the header matches a signature in the set of signatures. Responsive to determining that the portion of the header matches the signature, the matched signature's associated group policy of the network is applied to the device on the network.

Claims (81)

1. A method performed by data processing apparatus, the method comprising:

maintaining information corresponding to a set of signatures, and for each signature in the set, an associated group policy of a network, wherein each signature contains substrings designed to be matched against substrings of user agent strings;

at a first time:

intercepting a first message from a device on the network, the first message comprising a first Hypertext Transfer Protocol (HTTP) GET message and a first header;

determining that the first header does not match a signature in the set of signatures by determining that no substring of the signatures matches any substring of any user agent string of the first header;

responsive to determining that the first header does not match a signature in the set of signatures, routing the first message toward a destination of the first message;

at a second time after the first time:

receiving an update that includes a new signature;

updating the information to add the new signature to the set of signatures and to associate a group policy of the network to the new signature;

at a third time after the second time:

intercepting a second message from the device on the network, the second message comprising a second HTTP GET message and a second header;

determining that at least a portion of the second header matches the new signature in the updated set of signatures by matching a substring of the new signature to a substring of a second user agent string of the second header; and

responsive to determining that the portion of the second header matches the new signature, applying the new signature's associated group policy of the network to the device on the network.

2. The method of claim 1 , wherein applying the new signature's associated group policy of the network to the device on the network comprises:

looking up, in the information, one or more group policies of the network that are associated with the new signature.

3. The method of claim 1 , wherein the portion of the second header comprises one or more tokens.

4. The method of claim 1 , wherein at least some of the signatures in the set are product tokens.

5. The method of claim 1 , the method further comprising:

applying, before intercepting the first message at the first time, an initial group policy of the network to the device on the network; and

wherein applying the new signature's associated group policy of the network to the device on the network comprises removing the initial group policy of the network from the device on the network.

6. The method of claim 1 , wherein the intercepted second message has an intended destination, and wherein applying the new signature's associated group policy of the network to the device on the network causes the second message to be blocked from reaching the intended destination.

7. The method of claim 1 , wherein at least one of the signatures in the set represents deprecated software.

8. The method of claim 1 , wherein at least one of the signatures in the set represents software with a possible security vulnerability.

9. The method of claim 1 , wherein at least one of the signatures in the set represents a signature in a user agent string generated by malicious software.

10. The method of claim 1 , wherein each of the signatures in the set represents at least one selected from the group comprising deprecated software, software with a possible security vulnerability, and a signature in a user agent string generated by malicious software.

11. The method of claim 1 , wherein a user agent string of the first header is the same as a user agent string of the second header.

12. A non-transitory computer storage media encoded with computer program instructions that,

when executed by one or more processors, cause a computer device to perform operations comprising:

maintaining information corresponding to a set of signatures, and for each signature in the set, an associated group policy of a network, wherein each signature contains substrings designed to be matched against substrings of user agent strings;

at a first time:

intercepting a first message from a device on the network, the first message comprising a first Hypertext Transfer Protocol (HTTP) GET message and a first header;

determining that the first header does not match a signature in the set of signatures by determining that no substring of the signatures matches any substring of any user agent string of the first header;

responsive to determining that the first header does not match a signature in the set of signatures, routing the first message toward a destination of the first message;

at a second time after the first time:

receiving an update that includes a new signature;

updating the information to add the new signature to the set of signatures and to associate a group policy of the network to the new signature;

at a third time after the second time:

intercepting a second message from the device on the network, the second message comprising a second HTTP GET message and a second header;

determining that at least a portion of the second header matches the

new signature in the updated set of signatures by matching a substring of the new signature to a substring of a second user agent string of the second header; and

responsive to determining that the portion of the second header matches the new signature, applying the new signature's associated group policy of the network to the device on the network.

13. The storage media of claim 12 , wherein the portion of the second header comprises one or more tokens; and

wherein at least some of the signatures in the set are product tokens.

14. The storage media of claim 12 , the operations further comprising:

applying, before intercepting the first message at the first time, an initial group policy of the network to the device on the network; and

wherein applying the new signature's associated group policy of the network to the device on the network comprises removing the initial group policy of the network from the device on the network.

15. The storage media of claim 12 , wherein the intercepted second message has an intended destination, and wherein applying the new signature's associated group policy of the network to the device on the network causes the second message to be blocked from reaching the intended destination.

16. The storage media of claim 12 , wherein at least one of the signatures in the set represents deprecated software.

17. The storage media of claim 12 , wherein at least one of the signatures in the set represents software with a possible security vulnerability.

18. The storage media of claim 12 , wherein at least one of the signatures in the set represents a signature in a user agent string generated by malicious software.

19. The storage media of claim 12 , wherein each of the signatures in the set represents at least one selected from the group comprising deprecated software, software with a possible security vulnerability, and a signature in a user agent string generated by malicious software.

20. The storage media of claim 12 , wherein applying the new signature's associated group policy of the network to the device on the network comprises:

looking up, in the information, one or more group policies of the network that are associated with the new signature.

21. A system comprising:

one or more processors configured to execute computer program instructions; and

a non-transitory computer storage media encoded with computer program instructions that, when executed by one or more processors, cause a computer device to perform operations comprising:

maintaining information corresponding to a set of signatures, and for each signature in the set, an associated group policy of a network, wherein each signature contains substrings designed to be matched against substrings of user agent strings;

at a first time:

intercepting a first message from a device on the network, the first message comprising a first Hypertext Transfer Protocol (HTTP) GET message and a first header;

determining that the first header does not match a signature in the set of signatures by determining that no substring of the signatures matches any substring of any user agent string of the first header;

responsive to determining that the first header does not match a signature in the set of signatures, routing the first message toward a destination of the first message;

at a second time after the first time:

receiving an update that includes a new signature;

updating the information to add the new signature to the set of signatures and to associate a group policy of the network to the new signature;

at a third time after the second time:

intercepting a second message from the device on the network, the second message comprising a second HTTP GET message and a second header;

determining that at least a portion of the second header matches the new signature in the updated set of signatures by matching a substring of the new signature to a substring of a second user agent string of the second header; and

responsive to determining that the portion of the second header matches the new signature, applying the new signature's associated group policy of the network to the device on the network.

22. The system of claim 21 , wherein applying the new signature's associated group policy of the network to the device on the network comprises:

looking up, in the information, one or more group policies of the network that are associated with the new signature.

23. The system of claim 21 , wherein the portion of the second header comprises one or more tokens; and

wherein at least some of the signatures in the set are product tokens.

24. The system of claim 21 , the operations further comprising:

applying, before intercepting the first message at the first time, an initial group policy of the network to the device on the network; and

wherein applying the new signature's associated group policy of the network to the device on the network comprises removing the initial group policy of the network from the device on the network.

25. The system of claim 21 , wherein the intercepted second message has an intended destination, and wherein applying the new signature's associated group policy of the network to the device on the network causes the second message to be blocked from reaching the intended destination.

26. The system of claim 21 , wherein at least one of the signatures in the set represents deprecated software.

27. The system of claim 21 , wherein at least one of the signatures in the set represents software with a possible security vulnerability.

28. The system of claim 21 , wherein at least one of the signatures in the set represents a signature in a user agent string generated by malicious software.

29. The system of claim 21 , wherein each of the signatures in the set represents at least one selected from the group comprising deprecated software, software with a possible security vulnerability, and a signature in a user agent string generated by malicious software.

30. The system of claim 21 , wherein a user agent string of the first header is the same as a user agent string of the second header.

Assignments (6)
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0219 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
SECURITY INTEREST Recorded Dec 16, 2020
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 054789/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 28, 2015
From: MARTINI, PAUL MICHAEL
To: IBOSS, INC.
Reel/Frame 036452/0852 →
Continuity (1)
Continuation 14472302 · Aug 28, 2014