IP Library Patent Application 15256418
Patent Application
App. No. 15/256,418

MALWARE DETECTION FOR PROXY SERVER NETWORKS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/256,418
Abstract

This specification generally relates to methods and systems for applying network policies to devices based on their current access network. One example method includes identifying a proxy connection request sent from a particular client device to a proxy server over a network, the proxy connection request including a hostname and configured to direct the proxy server to establish communication with the computer identified by the hostname on behalf of the client device; determining an identity of the client device based on the proxy connection request; identifying a domain name system (DNS) response to a DNS request including the hostname from the proxy connection request; and updating DNS usage information for the particular client based on the identified DNS response including the hostname from the proxy connection request.

Claims (44)

1 . A computer-implemented method executed by one or more processors, the method comprising:

identifying, by a monitoring device, a proxy connection request sent from a particular client device to a proxy server over a network, the proxy connection request including a hostname and configured to direct the proxy server to establish communication with a computer identified by the hostname on behalf of the client device, wherein the monitoring device is separate from the client device and the proxy server, and wherein the monitoring device receives the proxy connection request from the network;

identifying, by the monitoring device, a domain name system (DNS) response to a DNS request including the hostname from the proxy connection request, wherein the DNS request is sent by the proxy server in response to the proxy connection request from the particular client device, and wherein the monitoring device receives the DNS response from the network;

determining, by the monitoring device, that the DNS response is associated with the particular client device based on the DNS response including the hostname from the proxy connection request; and

in response to determining that the DNS response is associated with the particular client device, updating, by the monitoring device, DNS usage information for the particular client device based on the identified DNS response.

2 . The method of claim 1 , wherein identifying the DNS response including the hostname includes:

sending the DNS request including the hostname from the proxy connection request; and

receiving the DNS response.

3 . The method of claim 1 , wherein the DNS usage information includes a DNS request rate for the particular client device, a DNS request failure rate for the particular client device, and hostnames included in DNS requests associated with the particular client device.

4 . The method of claim 1 , wherein the hostname is included in a Uniform Resource Locator (URL).

5 . The method of claim 1 , wherein the DNS request is sent by the proxy server on behalf of the client device and in response to the proxy connection request.

6 . The method of claim 1 , further comprising:

determining that the particular client device is exhibiting anomalous behavior based on the updated DNS usage information; and

performing a corrective action to the particular client device based on the determination.

7 . The method of claim 6 , wherein the anomalous behavior is associated with a malicious software program, and the corrective action includes removing the particular client device from the network.

8 . A non-transitory, computer-readable medium storing instructions operable when executed to cause at least one processor to perform operations comprising:

identifying, by a monitoring device, a proxy connection request sent from a particular client device to a proxy server over a network, the proxy connection request including a hostname and configured to direct the proxy server to establish communication with a computer identified by the hostname on behalf of the client device, wherein the monitoring device is separate from the client device and the proxy server, and wherein the monitoring device receives the proxy connection request from the network;

identifying, by the monitoring device, a domain name system (DNS) response to a DNS request including the hostname from the proxy connection request, wherein the DNS request is sent by the proxy server in response to the proxy connection request from the particular client device, and wherein the monitoring device receives the DNS response from the network;

determining, by the monitoring device, that the DNS response is associated with the particular client device based on the DNS response including the hostname from the proxy connection request; and

in response to determining that the DNS response is associated with the particular client device, updating, by the monitoring device, DNS usage information for the particular client device based on the identified DNS response.

9 . The non-transitory, computer-readable medium of claim 8 , the operations further comprising:

determining that the particular client device is exhibiting anomalous behavior based on the updated DNS usage information; and

performing a corrective action to the particular client device based on the determination.

10 . The non-transitory, computer-readable medium of claim 9 , wherein the anomalous behavior is associated with a malicious software program, and the corrective action includes removing the particular client device from the network.

11 . The non-transitory, computer-readable medium of claim 8 , wherein the DNS usage information includes a DNS request rate for the particular client device, a DNS request failure rate for the particular client device, and hostnames included in DNS requests associated with the particular client device.

12 . The non-transitory, computer-readable medium of claim 8 , wherein the hostname is included in a Uniform Resource Locator (URL).

13 . The non-transitory, computer-readable medium of claim 8 , wherein the DNS request is sent by the proxy server on behalf of the client device and in response to the proxy connection request.

14 . The non-transitory, computer-readable medium of claim 8 , wherein identifying the DNS response including the hostname includes:

sending the DNS request including the hostname from the proxy connection request; and

receiving the DNS response.

15 . A system comprising:

memory for storing data; and

one or more processors operable to perform operations comprising:

identifying, by a monitoring device, a proxy connection request sent from a particular client device to a proxy server over a network, the proxy connection request including a hostname and configured to direct the proxy server to establish communication with a computer identified by the hostname on behalf of the client device, wherein the monitoring device is separate from the client device and the proxy server, and wherein the monitoring device receives the proxy connection request from the network;

identifying, by the monitoring device, a domain name system (DNS) response to a DNS request including the hostname from the proxy connection request, wherein the DNS request is sent by the proxy server in response to the proxy connection request from the particular client device, and wherein the monitoring device receives the DNS response from the network;

determining, by the monitoring device, that the DNS response is associated with the particular client device based on the DNS response including the hostname from the proxy connection request; and

in response to determining that the DNS response is associated with the particular client device, updating, by the monitoring device, DNS usage information for the particular client device based on the identified DNS response.

16 . The system of claim 15 , the operations further comprising:

determining that the particular client device is exhibiting anomalous behavior based on the updated DNS usage information; and

performing a corrective action to the particular client device based on the determination.

17 . The system of claim 16 , wherein the anomalous behavior is associated with a malicious software program, and the corrective action includes removing the particular client device from the network.

18 . The system of claim 15 , wherein the DNS usage information includes a DNS request rate for the particular client device, a DNS request failure rate for the particular client device, and hostnames included in DNS requests associated with the particular client device.

19 . The system of claim 15 , wherein the hostname is included in a Uniform Resource Locator (URL).

20 . The system of claim 15 , wherein the DNS request is sent by the proxy server on behalf of the client device and in response to the proxy connection request.

Assignments (3)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0219 →
SECURITY INTEREST Recorded Dec 16, 2020
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 054789/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: MARTINI, PAUL MICHAEL
To: IBOSS, INC.
Reel/Frame 042664/0430 →