IP Library Granted Patent US 9,680,801
Granted Patent B1
US 9,680,801 · App. 15/145,672 · Granted Jun 13, 2017

Selectively altering references within encrypted pages using man in the middle

Inventor: Paul Michael Martini (San Diego, CA)
Assignee: iboss, Inc.
H04L63/0428H04L67/02H04L67/141H04L67/2814H04L67/2871H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,680,801
App. No.
15/145,672
Granted
Jun 13, 2017
Kind
B1
Abstract

A request addressed to a particular resource is received and a determination is made that the request should be redirected to a man-in-the-middle gateway within the network. A first encrypted connection is established between the client device and the man-in-the-middle gateway, and a second encrypted connection between the man-in-the-middle gateway and the server. The resource is modified into a modified resource by changing pointers within the particular resource to point to a location in a domain associated with the man-in-the-middle gateway within the network. The modified resource is served.

Claims (70)

1. A computer-implemented method executed by one or more processors, the method comprising:

receiving, from a client device within a network, a request addressed to a particular resource on a server outside the network;

determining that the request should be redirected to a man-in-the-middle gateway within the network;

redirecting the request to a man-in-the-middle gateway within the network responsive to determining that the request should be redirected;

establishing a first encrypted connection between the client device and the man-in-the-middle gateway, and a second encrypted connection between the man-in-the-middle gateway and the server;

retrieving, by the man-in-the-middle-gateway, the particular resource from the server;

modifying the particular resource into a modified resource by changing pointers within the particular resource to point to a location in a domain associated with the man-in-the-middle gateway within the network; and

serving, by the man-in-the-middle-gateway to the client device, the modified resource.

2. The method of claim 1 , wherein the request is a first request and the client device is a first client device, the method further comprising:

receiving, from a second client device within the network, a second request addressed to the particular resource;

determining that the second request should not be redirected to the man-in-the-middle gateway within the network;

responsive to determining that the second request should not be redirected to the man-in-the-middle gateway, redirecting the second request to a proxy service outside of the network configured to:

establish a third encrypted connection between the second client device and the proxy service, and a fourth encrypted connection between the proxy service and the server;

retrieve the particular resource from the server;

modify the particular resource into a second modified resource by changing pointers within the particular resource; and

serve the second modified resource to the second client device.

3. The method of claim 2 , the method further comprising:

receiving, from a third client device within the network, a third request addressed to an address of a second resource on a second server outside the network; and

routing the request to the address of the second resource.

4. The method of claim 1 , wherein modifying the particular resource into the modified resource comprises modifying the particular resource based on a security policy.

5. The method of claim 1 , wherein modifying the particular resource into the modified resource comprises replacing the resource with a different resource.

6. The method of claim 1 , wherein modifying the particular resource into the modified resource comprises replacing Hypertext Transfer Protocol (HTTP) links in the particular resource with different HTTP links.

7. The method of claim 1 , wherein modifying the particular resource into the modified resource comprises replacing the resource with an HTTP status code object.

8. The method of claim 1 , the method further comprising determining that a security policy of the network identifies the particular resource for inspection upon entry to the network.

9. A system comprising:

a processor configured to execute computer program instructions; and

a tangible, non-transitory computer storage medium encoded with computer program instructions that, when executed by the processor, cause the system to perform operations comprising:

receiving, from a client device within a network, a request addressed to a particular resource on a server outside the network;

determining that the request should be redirected to a man-in-the-middle gateway within the network;

redirecting the request to a man-in-the-middle gateway within the network responsive to determining that the request should be redirected;

establishing a first encrypted connection between the client device and the man-in-the-middle gateway, and a second encrypted connection between the man-in-the-middle gateway and the server;

retrieving, by the man-in-the-middle-gateway, the particular resource from the server;

modifying the particular resource into a modified resource by changing pointers within the particular resource to point to a location in a domain associated with the man-in-the-middle gateway within the network; and

serving, by the man-in-the-middle-gateway to the client device, the modified resource.

10. The system of claim 9 , wherein the request is a first request and the client device is a first client device, the operations further comprising:

receiving, from a second client device within the network, a second request addressed to the particular resource;

determining that the second request should not be redirected to the man-in-the-middle gateway within the network;

responsive to determining that the second request should not be redirected to the man-in-the-middle gateway, redirecting the second request to a proxy service outside of the network.

11. The system of claim 10 , the operations further comprising:

receiving, from a third client device within the network, a third request addressed to an address of a second resource on a second server outside the network; and

routing the request to the address of the second resource.

12. The system of claim 9 , wherein modifying the particular resource into the modified resource comprises modifying the particular resource based on a security policy.

13. The system of claim 9 , wherein modifying the particular resource into the modified resource comprises replacing the resource with a different resource.

14. The system of claim 9 , wherein modifying the particular resource into the modified resource comprises replacing Hypertext Transfer Protocol (HTTP) links in the particular resource with different HTTP links.

15. The system of claim 9 , wherein modifying the particular resource into the modified resource comprises replacing the resource with an HTTP status code object.

16. The system of claim 9 , the operations further comprising determining that a security policy of the network identifies the particular resource for inspection upon entry to the network.

17. A non-transitory computer-readable medium storing instructions operable when executed to cause at least one processor to perform operations comprising:

receiving, from a client device within a network, a request addressed to a particular resource on a server outside the network;

determining that the request should be redirected to a man-in-the-middle gateway within the network;

redirecting the request to a man-in-the-middle gateway within the network responsive to determining that the request should be redirected;

establishing a first encrypted connection between the client device and the man-in-the-middle gateway, and a second encrypted connection between the man-in-the-middle gateway and the server;

retrieving, by the man-in-the-middle-gateway, the particular resource from the server;

modifying the particular resource into a modified resource by changing pointers within the particular resource to point to a location in a domain associated with the man-in-the-middle gateway within the network; and

serving, by the man-in-the-middle-gateway to the client device, the modified resource.

18. The non-transitory computer-readable medium of claim 17 , wherein the request is a first request and the client device is a first client device, the operations further comprising:

receiving, from a second client device within the network, a second request addressed to the particular resource;

determining that the second request should not be redirected to the man-in-the-middle gateway within the network;

responsive to determining that the second request should not be redirected to the man-in-the-middle gateway, redirecting the second request to a proxy service outside of the network configured to:

establish a third encrypted connection between the second client device and the proxy service, and a fourth encrypted connection between the proxy service and the server;

retrieve the particular resource from the server;

modify the particular resource into a second modified resource by changing pointers within the particular resource; and

serve the second modified resource to the second client device.

19. The non-transitory computer-readable medium of claim 18 , the operations further comprising:

receiving, from a third client device within the network, a third request addressed to an address of a second resource on a second server outside the network; and

routing the request to the address of the second resource.

20. The non-transitory computer-readable medium of claim 17 , wherein modifying the particular resource into the modified resource comprises modifying the particular resource based on a security policy.

21. The non-transitory computer-readable medium of claim 17 , wherein modifying the particular resource into the modified resource comprises replacing the resource with a different resource.

22. The non-transitory computer-readable medium of claim 17 , wherein modifying the particular resource into the modified resource comprises replacing Hypertext Transfer Protocol (HTTP) links in the particular resource with different HTTP links.

23. The non-transitory computer-readable medium of claim 17 , wherein modifying the particular resource into the modified resource comprises replacing the resource with an HTTP status code object.

24. The non-transitory computer-readable medium of claim 17 , the operations further comprising determining that a security policy of the network identifies the particular resource for inspection upon entry to the network.

Assignments (6)
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0219 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
SECURITY INTEREST Recorded Dec 16, 2020
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 054789/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 23, 2016
From: MARTINI, PAUL MICHAEL
To: IBOSS, INC.
Reel/Frame 040408/0619 →