IP Library Patent Application 15956357
Patent Application
App. No. 15/956,357

DISTRIBUTED CLIENT PROTECTION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/956,357
Abstract

A method, system, and computer-usable medium are disclosed for, responsive to receipt of traffic from a server to a client, parsing content of the traffic, and injecting additional content into original content of the server response to override an action of the original content, such that when the client executes the content of the traffic the client determines whether the content includes additional content that overrides the action of the original content, and in response to determining that the content includes additional content that overrides the action of the original content, communicates parameters associated with execution of the action to an inspection service to determine if the action is malicious.

Claims (51)

1 . A computer-implementable method for managing network communication, comprising:

responsive to receipt of traffic from a server to a client:

parsing content of the traffic; and

injecting additional content into original content of the server response to override an action of the original content, such that when the client executes the content of the traffic the client:

determines whether the content includes additional content that overrides the action of the original content; and

in response to determining that the content includes additional content that overrides the action of the original content, communicates parameters associated with execution of the action to an inspection service to determine if the action is malicious.

2 . The method of claim 1 , wherein the inspection service executes locally on a security device that performs the steps of parsing content of the traffic and injecting additional content into original content of the server response.

3 . The method of claim 1 , wherein the inspection service executes remotely from a security device that performs the steps of parsing content of the traffic and injecting additional content into original content of the server response.

4 . The method of claim 1 , such that the client further, in response to determining that the content includes additional content that overrides the action of the original content, executes the action during inspection of the action by the inspection service.

5 . The method of claim 4 , such that the client further:

receives an indication from the inspection service regarding whether the action is malicious; and

if the indication from the inspection service indicates the action is malicious, communicates a warning to the user indicating that the action is malicious.

6 . The method of claim 1 , such that the client further, in response to determining that the content includes additional content that overrides the action of the original content, delays the action during inspection of the action by the inspection service.

7 . The method of claim 6 , such that the client further:

receives an indication from the inspection service regarding whether the action is malicious; and

if the indication from the inspection service indicates the action is malicious, blocks execution of the action.

8 . A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

responsive to receipt of traffic from a server to a client:

parsing content of the traffic; and

injecting additional content into original content of the server response to override an action of the original content, such that when the client executes the content of the traffic the client:

determines whether the content includes additional content that overrides the action of the original content; and

in response to determining that the content includes additional content that overrides the action of the original content, communicates parameters associated with execution of the action to an inspection service to determine if the action is malicious.

9 . The system of claim 8 , wherein the inspection service executes locally on a security device that performs the steps of parsing content of the traffic and injecting additional content into original content of the server response.

10 . The system of claim 8 , wherein the inspection service executes remotely from a security device that performs the steps of parsing content of the traffic and injecting additional content into original content of the server response.

11 . The system of claim 8 , such that the client further, in response to determining that the content includes additional content that overrides the action of the original content, executes the action during inspection of the action by the inspection service.

12 . The system of claim 11 , such that the client further:

receives an indication from the inspection service regarding whether the action is malicious; and

if the indication from the inspection service indicates the action is malicious, communicates a warning to the user indicating that the action is malicious.

13 . The system of claim 8 , such that the client further, in response to determining that the content includes additional content that overrides the action of the original content, delays the action during inspection of the action by the inspection service.

14 . The system of claim 13 , such that the client further:

receives an indication from the inspection service regarding whether the action is malicious; and

if the indication from the inspection service indicates the action is malicious, blocks execution of the action.

15 . A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

responsive to receipt of traffic from a server to a client:

parsing content of the traffic; and

injecting additional content into original content of the server response to override an action of the original content, such that when the client executes the content of the traffic the client:

determines whether the content includes additional content that overrides the action of the original content; and

in response to determining that the content includes additional content that overrides the action of the original content, communicates parameters associated with execution of the action to an inspection service to determine if the action is malicious.

16 . The storage medium of claim 15 , wherein the inspection service executes locally on a security device that performs the steps of parsing content of the traffic and injecting additional content into original content of the server response.

17 . The storage medium of claim 15 , wherein the inspection service executes remotely from a security device that performs the steps of parsing content of the traffic and injecting additional content into original content of the server response.

18 . The storage medium of claim 15 , such that the client further, in response to determining that the content includes additional content that overrides the action of the original content, executes the action during inspection of the action by the inspection service.

19 . The storage medium of claim 18 , such that the client further:

receives an indication from the inspection service regarding whether the action is malicious; and

if the indication from the inspection service indicates the action is malicious, communicates a warning to the user indicating that the action is malicious.

20 . The storage medium of claim 15 , such that the client further, in response to determining that the content includes additional content that overrides the action of the original content, delays the action during inspection of the action by the inspection service.

21 . The storage medium of claim 20 , such that the client further:

receives an indication from the inspection service regarding whether the action is malicious; and

if the indication from the inspection service indicates the action is malicious, blocks execution of the action.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0207 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055492/0266 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 27, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 052045/0482 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Jul 6, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 046495/0561 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2018
From: RAHKONEN, VALTTERI; LEVOMÄKI, ANTTI; JALIO, CHRISTIAN
To: FORCEPOINT LLC
Reel/Frame 045578/0482 →