IP Library Granted Patent US 11,924,180
Granted Patent B2
US 11,924,180 · App. 17/164,533 · Granted Mar 5, 2024

Manage encrypted network traffic using DNS responses

Inventors: Paul Michael Martini (San Diego, CA); Peter Anthony Martini (San Diego, CA)
Assignee: iboss, Inc.
H04L63/0464H04L41/00H04L61/10H04L61/103H04L61/4511H04L61/4552H04L61/5007H04L63/0428H04L67/02H04L61/58
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,924,180
App. No.
17/164,533
Granted
Mar 5, 2024
Kind
B2
Abstract

This present disclosure generally relates to managing encrypted network traffic using Domain Name System (DNS) responses. One example includes requesting an address; receiving a response from the resolution server including one or more addresses associated with the domain name; associating with the domain name a particular address selected from the received one or more addresses; receiving a request to resolve the domain name; sending a response to the request to resolve the domain name, the sent response including the particular address associated with the domain name; receiving a secure request for a resource, the secure request directed to the particular address associated with the domain name; and determining that the secure request is directed to the domain name based on the association between the particular address and the domain name.

Claims (65)

1. A computer-implemented method executed by one or more processors, the method comprising:

maintaining, before receiving a request to resolve a domain name, a predetermined set of domain names each associated with at least one particular address, each of the predetermined set of domain names identified as assigned to receive selectively-applied security actions, wherein the predetermined set of domain names are stored in a database that also contains monitoring rules that specify a particular security action to be applied to traffic, at least one of the domain names in the predetermined set of domain names based on a match of an address of the traffic and the at least one of the domain names in the predetermined set of domain names;

receiving from a particular client device, the request to resolve the domain name from a network that hosts a plurality of client devices including the particular client device;

sending a response to the request to resolve the domain name, the sent response including the particular address associated with the domain name;

receiving a secure request for a resource, the secure request directed to the particular address associated with the domain name;

determining that the secure request is directed to the domain name based on the association between the particular address and the domain name;

selectively decrypting the secure request based at least in part on determining that the secure request is directed to the domain name comprising:

determining that the secure request should be decrypted based at least in part on one or more rules; and

decrypting the secure request to generate decrypted information;

inspecting the decrypted information;

determining that the secure request should be blocked based at least in part on inspecting the decrypted information and at least in part on the one or more rules; and

blocking the secure request comprising sending a redirect response to the secure request, the redirect response including an address associated with a block notification page.

2. The method of claim 1 , wherein the domain name is a first domain name, the method further comprising:

requesting an address associated with a second domain name different than the first domain name;

receiving a second response including one or more addresses associated with the second domain name, wherein the one or more addresses associated with the second domain name includes the particular address; and

modifying the second response to remove the particular address.

3. The method of claim 1 , wherein:

the particular address includes an internet protocol (IP) address,

requesting the address associated with the domain name includes sending a Domain Name System (DNS) request;

receiving the response includes receiving a DNS response;

receiving the request to resolve the domain name includes receiving a DNS request; and

sending the response to the request to resolve the domain name includes sending a DNS response.

4. The method of claim 1 , further comprising:

inspecting the decrypted information;

determining that the secure request should be forwarded based at least in part on inspecting the decrypted information and at least in part on the one or more rules; and

forwarding the secure request to an address associated with the domain name.

5. The method of claim 4 , wherein forwarding the secure request comprises:

re-encrypting the secure request; and

sending the secure request to the address associated with the domain name.

6. The method of claim 1 , further comprising:

inspecting the decrypted information;

determining that the secure request should be forwarded based at least in part on inspecting the decrypted information and at least in part on the one or more rules;

modifying the decrypted information based at least in part on the one or more rules;

encrypting the decrypted information to produce a second secure request; and

forwarding the second secure request to an address associated with the domain name.

7. The method of claim 1 , wherein receiving the secure request for the resource comprises:

establishing a first secure connection with a sender of the secure request; establishing a second secure connection with an address associated with the resource after establishing the first secure connection with the sender.

8. The method of claim 1 , wherein receiving the secure request for the resource comprises:

establishing a first secure connection with an address associated with the resource;

establishing a second secure connection with a sender of the secure request after establishing the first secure connection with the address associated with the resource.

9. The method of claim 1 , wherein the domain name is a first domain name, the method further comprising:

receiving a request to resolve a second domain name different than the first domain name;

determining that the second domain name is not included in the predetermined set of domain names; and

sending a response to the request to resolve the second domain name, the response including an address corresponding to the second domain name.

10. The method of claim 1 , further comprising:

receiving a second request to resolve the domain name;

determining that the domain name is associated with the particular address; and

sending a response to the second request to resolve the domain name, the response including the particular address.

11. The method of claim 1 , wherein receiving the secure request for the resource includes receiving a request according to Hypertext Transfer Protocol Secure (HTTPS).

12. The method of claim 1 , further comprising selectively blocking the secure request based at least in part on determining that the secure request is directed to the domain name.

13. The method of claim 1 , wherein requesting the address for the domain name comprises receiving the response- and associating with the domain name the particular address are performed in response to receiving the request to resolve the domain name.

14. A system comprising:

one or more processors; and

computer memory storing instructions that, when executed by the processors, cause the processors to perform operations comprising:

maintaining, before receiving a request to resolve a domain name, a predetermined set of domain names each associated with at least one particular address, each of the predetermined set of domain names identified as assigned to receive selectively-applied security actions, wherein the predetermined set of domain names are stored in a database that also contains monitoring rules that specify a particular security action to be applied to traffic, at least one of the domain names in the predetermined set of domain names based on a match of an address of the traffic and the at least one of the domain names in the predetermined set of domain names;

receiving from a particular client device, the request to resolve the domain name from a network that hosts a plurality of client devices including the particular client device;

sending a response to the request to resolve the domain name, the sent response including the particular address associated with the domain name;

receiving a secure request for a resource, the secure request directed to the particular address associated with the domain name;

determining that the secure request is directed to the domain name based on the association between the particular address and the domain name;

selectively decrypting the secure request based at least in part on determining that the secure request is directed to the domain name comprising:

determining that the secure request should be decrypted based at least in part on one or more rules; and

decrypting the secure request to generate decrypted information;

inspecting the decrypted information;

determining that the secure request should be blocked based at least in part on inspecting the decrypted information and at least in part on the one or more rules; and

blocking the secure request comprising sending a redirect response to the secure request, the redirect response including an address associated with a block notification page.

Assignments (5)
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
FIRST AMENDMENT TO INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Sep 10, 2021
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 057566/0149 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2021
From: MARTINI, PAUL MICHAEL; MARTINI, PETER ANTHONY
To: IBOSS, INC.
Reel/Frame 056358/0315 →
Continuity (6)
Continuation 16513899 · Jul 17, 2019
Continuation 15803660 · Nov 3, 2017
Continuation 15382392 · Dec 16, 2016
Continuation 14848219 · Sep 8, 2015
Continuation 14280513 · May 16, 2014
Related Publication 20210234846A1 · Jul 29, 2021
Cited By (1)
US 12,513,009