IP Library Granted Patent US 11,736,516
Granted Patent B2
US 11,736,516 · App. 16/730,868 · Granted Aug 22, 2023

SSL/TLS spoofing using tags

Inventor: Gandhi Balasubramaniam (Shalimar, FL)
Assignee: Avast Software s.r.o.
H04L63/1466H04L9/3263H04L61/4511H04L63/0236H04L67/02H04L9/3268H04L61/2514H04L67/10H04L69/16H04L2101/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,736,516
App. No.
16/730,868
Granted
Aug 22, 2023
Kind
B2
Abstract

A network is secured by managing domain name requests such that client devices are restricted from visiting malicious or undesirable domains. An endpoint Domain Name Server (DNS) agent is installed on client devices on a local network, and the endpoint DNS agents intercept DNS requests from the client devices and process the received DNS request in the endpoint DNS agent based on a security policy set for the client device via the endpoint DNS agent. In a further example, the endpoint DNS agent receives an HTTP message from a client browser including a Server Name Identifier tag, and generates a signed certificate spoofing the domain identified in the Server Name Identifier tag to insert itself as a man-in-the-middle between the identified domain and the client browser.

Claims (33)

1. A method of managing Domain Name Server (DNS) requests, comprising:

receiving a DNS request from a browser on a client device in an endpoint DNS agent installed on a device on a local network, the DNS request comprising a requested domain name;

sending a DNS response from the endpoint DNS agent to the browser on the client device, the DNS response comprising the endpoint DNS agent's Internet Protocol (IP) address;

receiving from the browser on the client device a message with a Server Name Identification (SNI) tag identifying the requested domain name to a Hyper Text Transfer Protocol (HTTP) server in the endpoint DNS agent;

generating, by the endpoint DNS agent, a certificate for the requested domain name and sending it from the endpoint DNS agent to the browser on the client device;

retrieving information from a domain associated with the requested domain name in the endpoint DNS agent, and selectively forwarding the requested information from the endpoint DNS agent to the browser on the client device to provide security to the client device;

receiving a user election from the client device to override a DNS redirection returned in response to the DNS request; and

establishing a Secure Socket Layer/Transport Layer Security (SSL/TSL) connection between the HTTP server on the endpoint DNS agent and the browser on the client device.

2. The method of claim 1 , wherein the receiving a DNS request from a client device and sending a DNS response from the endpoint DNS agent are performed in a User Datagram Protocol (UDP) server of the endpoint DNS agent.

3. The method of claim 1 , wherein the device on the local network is the client device.

4. The method of claim 1 , wherein the device on the local network is a router, a gateway, or a security appliance.

5. The method of claim 1 , wherein processing the received DNS request in the endpoint DNS agent is based on a security policy set for the client device via the endpoint DNS agent to secure client devices.

6. A method of intercepting a Secure Socket Layer/Transport Layer Security (SSL/TSL) request to a remote server, comprising:

receiving, in a man-in-the-middle server in communication between a client device and a Hyper Text Transfer Protocol (HTTP) server, a message from the client device, the message comprising a Server Name Identification (SNI) tag identifying a requested domain name to the HTTP server;

generating, by an endpoint Domain Name Server (DNS) agent installed on a device on a local network, a certificate for the requested domain name and sending it from the man-in-the-middle server to the client device;

retrieving information from a domain associated with the requested domain name in the man-in-the-middle server, and selectively forwarding the requested information from the man-in-the-middle server to the client device to provide security to the client device;

receiving a user election from the client device to override a DNS redirection returned in response to a DNS request; and

establishing an SSL/TLS connection between the client device and the HTTP server on the man-in-the-middle server.

7. The method of claim 6 , wherein selectively forwarding the requested information from the man-in-the middle server to the client device comprises forwarding information selected based on a security policy for the client.

8. The method of claim 6 , wherein the man-in-the-middle server is a server on the client device.

9. The method of claim 6 , wherein the man-in-the-middle server is a router, a gateway, or a security appliance on a local network with the client device.

10. The method of claim 6 , wherein processing the received DNS request in the endpoint DNS agent is based on a security policy set for the client device via the endpoint DNS agent to secure client devices.

11. A method of managing Domain Name Server (DNS) requests, comprising:

receiving a DNS request from a browser on a client device in a User Datagram Protocol (UDP) server on an endpoint DNS agent installed on a device on a local network, the DNS request comprising a requested domain name;

sending a DNS response from the endpoint DNS agent to the client device comprising the endpoint DNS agent's Internet Protocol (IP) address;

forwarding from the endpoint DNS agent's UDP server to a Hyper Text Transfer Protocol (HTTP) server in the endpoint DNS agent a message with the requested domain name;

generating, by the endpoint DNS agent, a certificate for the requested domain name and sending it from the endpoint DNS agent to the browser on the client device;

retrieving information from a domain associated with the requested domain name in the endpoint DNS agent, and selectively forwarding the requested information from the endpoint DNS agent to the client device to provide security to the client device;

receiving a user election from the client device to override a DNS redirection returned in response to the DNS request; and

establishing a Secure Socket Layer/Transport Layer Security (SSL/TSL) connection between the HTTP server on the endpoint DNS agent and the browser on the client device.

12. The method of claim 11 , wherein the device on the local network is the client device.

13. The method of claim 11 , wherein the device on the local network is a router, a gateway, or a security appliance.

14. The method of claim 11 , wherein processing the received DNS request in the endpoint DNS agent is based on a security policy set for the client device via the endpoint DNS agent to secure client devices.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: GEN DIGITAL AMERICAS S.R.O.
To: GEN DIGITAL INC.
Reel/Frame 071771/0767 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: AVAST SOFTWARE S.R.O.
To: GEN DIGITAL AMERICAS S.R.O.
Reel/Frame 071777/0341 →
RELEASE OF SECURITY INTEREST Recorded Mar 26, 2021
From: CREDIT SUISSE INTERNATIONAL, AS COLLATERAL AGENT
To: AVAST SOFTWARE, S.R.O.
Reel/Frame 055726/0435 →
SECURITY INTEREST Recorded May 6, 2020
From: AVAST SOFTWARE S.R.O.
To: CREDIT SUISSE INTERNATIONAL, AS COLLATERAL AGENT
Reel/Frame 052582/0285 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2019
From: BALASUBRAMANIAM, GANDHI
To: AVAST SOFTWARE S.R.O.
Reel/Frame 051389/0785 →