IP Library Granted Patent US 11,641,355
Granted Patent B2
US 11,641,355 · App. 17/405,238 · Granted May 2, 2023

Security service for an unmanaged device

Inventors: Martin Stecher (Paderborn, DE); Andre Sabban (Paderborn, DE)
Assignee: Skyhigh Security LLC
H04L63/10H04L43/50H04L63/102H04W12/37G06F8/65H04L63/0281H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,641,355
App. No.
17/405,238
Granted
May 2, 2023
Kind
B2
Abstract

Particular embodiments described herein provide for a network element that can be configured to receive, from an electronic device, a request to access a network service. In response to the request, the network element can send data related to the network service to the electronic device and add a test link to the data related to the network service. The network element can also be configured to determine if the test link was successfully executed and classify the electronic device as untrusted if the test link was not successfully executed.

Claims (45)

1. A non-transitory, machine-readable medium including instructions that, when executed by at least one processor of a network element, cause the at least one processor to perform operations comprising:

receiving, from an electronic device, a request to access a network service;

in response to the request, sending to the electronic device (i) data related to the network service and (ii) a test link to redirect network traffic through to a predefined network element;

preventing access to the network service, at least in part based on a determination that a request for the test link was not routed through the network element; and

communicating a remedial action instruction to the electronic device to route a communication for the network service through the network element, at least in part based on the determination.

2. The medium of claim 1 , wherein the network element includes a reverse proxy that receives the request to access the network service.

3. The medium of claim 1 , the operations further comprising:

obtaining credentials from an identity provider; and

allowing the electronic device to access the requested network service, at least in part based on the credentials.

4. The medium of claim 1 , wherein the determination is at least in part based on a time out for a reception of the test link by the network element.

5. The medium of claim 1 , the operations further comprising:

storing a cookie in a reputation database for the electronic device, at least in part based on the determination.

6. The medium of claim 1 , the operations further comprising:

allowing access to the network service, at least in part based on a determination that the request for the test link was routed through the network element.

7. The medium of claim 1 , wherein the test link includes a page redirect.

8. A method implemented by a network element, the method comprising:

receiving, from an electronic device, a request to access a network service;

in response to the request, sending to the electronic device (i) data related to the network service and (ii) a test link to redirect network traffic through to a predefined network element;

preventing access to the network service, at least in part based on a determination that a request for the test link was not routed through the network element; and

communicating a remedial action instruction to the electronic device to route a communication for the network service through the network element, at least in part based on the determination.

9. The method of claim 8 , further comprising:

receiving, by a reverse proxy included in the network element, the request to access the network service.

10. The method of claim 8 , further comprising:

obtaining credentials from an identity provider; and

allowing the electronic device to access the requested network service, at least in part based on the credentials.

11. The method of claim 8 , wherein the determination is at least in part based on a time out for a reception of the test link by the network element.

12. The method of claim 8 , further comprising:

storing a cookie in a reputation database for the electronic device, at least in part based on the determination.

13. The method of claim 8 , wherein the test link includes a page redirect.

14. A network element, comprising:

a memory element that stores instructions; and

a processing unit that executes the instructions to

receive, from an electronic device, a request to access a network service,

in response to the request, send to the electronic device (i) data related to the network service and (ii) a test link to redirect network traffic through to a predefined network element,

prevent access to the network service, at least in part based on a determination that a request for the test link was not routed through the network element, and

communicate a remedial action instruction to the electronic device to route a communication for the network service through the network element, at least in part based on the determination.

15. The network element of claim 14 , further comprising:

a reverse proxy that receives the request to access the network service.

16. The network element of claim 14 , wherein the processing unit executes the instructions to

obtain credentials from an identity provider; and

allow the electronic device to access the requested network service, at least in part based on the credentials.

17. The network element of claim 14 , wherein the determination is at least in part based on a time out for a reception of the test link by the network element.

18. The network element of claim 14 , wherein the processing unit executes the instructions to store a cookie in a reputation database for the electronic device, at least in part based on the determination.

19. The network element of claim 14 , wherein the processing unit executes the instructions to allow access to the network service, at least in part based on a determination that the request for the test link was routed through the network element.

20. The network element of claim 14 , wherein the test link includes a page redirect.

Assignments (7)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2022
From: MUSARUBRA US LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 061032/0678 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 059855/0807 →