IP Library Granted Patent US 9,813,394
Granted Patent B2
US 9,813,394 · App. 15/382,392 · Granted Nov 7, 2017

Manage encrypted network traffic using DNS responses

Inventors: Paul Michael Martini (San Diego, CA); Peter Anthony Martini (San Diego, CA)
Assignee: iboss, Inc.
H04L63/0464H04L61/103H04L61/1511H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,813,394
App. No.
15/382,392
Granted
Nov 7, 2017
Kind
B2
Abstract

The present disclosure generally relates to managing encrypted network traffic using Domain Name System (DNS) responses. One example method includes requesting an address associated with the a domain name included in a predetermined set of domain names for which secure requests are to be identified; receiving a response from the resolution server including one or more addresses associated with the domain name; associating with the domain name a particular address selected from the received addresses; receiving a request to resolve the domain name; sending a response to the request to resolve the domain name including the particular address associated with the domain name; receiving a secure request for a resource, the secure request directed to the particular address associated with the domain name; and determining that the secure request is directed to the domain name based on the association between the particular address and the domain name.

Claims (91)

1. A computer-implemented method executed by one or more processors, the method comprising:

requesting an address associated with a domain name from a resolution server, the domain name included in a predetermined set of domain names for which secure requests are to be identified;

receiving a response from the resolution server including one or more addresses associated with the domain name;

associating with the domain name a particular address selected from the received one or more addresses;

receiving a request to resolve the domain name;

sending a response to the request to resolve the domain name, the sent response including the particular address associated with the domain name;

receiving a secure request for a resource, the secure request directed to the particular address associated with the domain name;

determining that the secure request is directed to the domain name based on the association between the particular address and the domain name;

selectively decrypting the secure request based at least in part on determining that the secure request is directed to the domain name, wherein selectively decrypting the secure request includes determining that the secure request should be decrypted based at least in part on one or more rules, and decrypting the secure request to generate decrypted information;

inspecting the decrypted information;

determining that the secure request should be forwarded based at least in part on inspecting the decrypted information and at least in part on the one or more rules;

modifying the decrypted information based at least in part on the one or more rules;

encrypting the decrypted information to produce a second secure request; and

forwarding the second secure request to an address associated with the domain name.

2. The method of claim 1 , wherein the domain name is a first domain name, the method further comprising:

requesting an address associated with a second domain name different than the first domain name from the resolution server;

receiving a second response from the resolution server including one or more addresses associated with the second domain name, wherein the one or more addresses associated with the second domain name includes the particular address; and

modifying the second response to remove the particular address.

3. The method of claim 1 , wherein:

the particular address includes an internet protocol (IP) address, requesting the address associated with the domain name from the resolution server includes sending a Domain Name System (DNS) request;

receiving the response from the resolution server includes receiving a DNS response;

receiving the request to resolve the domain name includes receiving a DNS request; and

sending the response to the request to resolve the domain name includes sending a DNS response.

4. The method of claim 1 , further comprising:

inspecting the decrypted information;

determining that the secure request should be forwarded based at least in part on inspecting the decrypted information and at least in part on the one or more rules; and

forwarding the secure request to an address associated with the domain name.

5. The method of claim 4 , wherein forwarding the secure request comprises:

re-encrypting the secure request; and

sending the secure request to the address associated with the domain name.

6. The method of claim 1 , further comprising:

inspecting the decrypted information;

determining that the secure request should be blocked based at least in part on inspecting the decrypted information and at least in part on the one or more rules; and

blocking the secure request.

7. The method of claim 6 , wherein blocking the secure request includes sending a redirect response to the secure request, the redirect response including an address associated with a block notification page.

8. The method of claim 1 , wherein receiving the secure request for the resource comprises:

establishing a first secure connection with a sender of the secure request; and

establishing a second secure connection with an address associated with the resource after establishing the first secure connection with the sender.

9. The method of claim 1 , wherein receiving the secure request for the resource comprises:

establishing a first secure connection with an address associated with the resource; and

establishing a second secure connection with a sender of the secure request after establishing the first secure connection with the address associated with the resource.

10. The method of claim 1 , wherein the domain name is a first domain name, the method further comprising:

receiving a request to resolve a second domain name different than the first domain name;

determining that the second domain name is not included in the predetermined set of domain names; and

sending a response to the request to resolve the second domain name, the response including an address corresponding to the second domain name.

11. The method of claim 1 , further comprising:

receiving a second request to resolve the domain name;

determining that the domain name is associated with the particular address; and

sending a response to the second request to resolve the domain name, the response including the particular address.

12. The method of claim 1 , wherein receiving the secure request for the resource includes receiving a request according to Hypertext Transfer Protocol Secure (HTTPS).

13. The method of claim 1 , further comprising selectively blocking the secure request based at least in part on determining that the secure request is directed to the domain name.

14. The method of claim 1 , wherein requesting the address for the domain name from the resolution server, receiving the response from the resolution server, and associating with the domain name the particular address are performed in response to receiving the request to resolve the domain name.

15. A system comprising:

memory for storing data; and

one or more processors operable to perform operations comprising:

requesting an address associated with a domain name from a resolution server, the domain name included in a predetermined set of domain names for which secure requests are to be identified;

receiving a response from the resolution server including one or more addresses associated with the domain name;

associating with the domain name a particular address selected from the received one or more addresses;

receiving a request to resolve the domain name;

sending a response to the request to resolve the domain name, the sent response including the particular address associated with the domain name;

receiving a secure request for a resource, the secure request directed to the particular address associated with the domain name;

determining that the secure request is directed to the domain name based on the association between the particular address and the domain name;

selectively decrypting the secure request based at least in part on determining that the secure request is directed to the domain name, wherein selectively decrypting the secure request includes determining that the secure request should be decrypted based at least in part on one or more rules, and decrypting the secure request to generate decrypted information;

inspecting the decrypted information;

determining that the secure request should be forwarded based at least in part on inspecting the decrypted information and at least in part on the one or more rules;

modifying the decrypted information based at least in part on the one or more rules;

encrypting the decrypted information to produce a second secure request; and

forwarding the second secure request to an address associated with the domain name.

16. The system of claim 15 , wherein the domain name is a first domain name, the operations further comprising:

requesting an address associated with a second domain name different than the first domain name from the resolution server;

receiving a second response from the resolution server including one or more addresses associated with the second domain name, wherein the one or more addresses includes the particular address; and

modifying the second response to remove the particular address.

17. The system of claim 15 , the operations further comprising:

the particular address includes an internet protocol (IP) address, requesting the address associated with the domain name from the resolution server includes sending a Domain Name System (DNS) request;

receiving the response from the resolution server includes receiving a DNS response;

receiving the request to resolve the domain name includes receiving a DNS request; and

sending the response to the request to resolve the domain name includes sending a DNS response.

18. A non-transitory, computer-readable medium storing instructions operable when executed to cause at least one processor to perform operations comprising:

requesting an address associated with a domain name from a resolution server, the domain name included in a predetermined set of domain names for which secure requests are to be identified;

receiving a response from the resolution server including one or more addresses associated with the domain name;

associating with the domain name a particular address selected from the received one or more addresses;

receiving a request to resolve the domain name;

sending a response to the request to resolve the domain name, the sent response including the particular address associated with the domain name;

receiving a secure request for a resource, the secure request directed to the particular address associated with the domain name;

determining that the secure request is directed to the domain name based on the association between the particular address and the domain name;

selectively decrypting the secure request based at least in part on determining that the secure request is directed to the domain name, wherein selectively decrypting the secure request includes determining that the secure request should be decrypted based at least in part on one or more rules, and decrypting the secure request to generate decrypted information;

inspecting the decrypted information;

determining that the secure request should be forwarded based at least in part on inspecting the decrypted information and at least in part on the one or more rules;

modifying the decrypted information based at least in part on the one or more rules;

encrypting the decrypted information to produce a second secure request; and

forwarding the second secure request to an address associated with the domain name.

Assignments (6)
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0219 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
SECURITY INTEREST Recorded Dec 16, 2020
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 054789/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2017
From: MARTINI, PAUL MICHAEL; MARTINI, PETER ANTHONY
To: IBOSS, INC.
Reel/Frame 042510/0869 →
Continuity (3)
Continuation 14848219 · Sep 8, 2015
Continuation 14280513 · May 16, 2014
Related Publication 20170099271A1 · Apr 6, 2017