IP Library Granted Patent US 11,489,858
Granted Patent B2
US 11,489,858 · App. 17/828,678 · Granted Nov 1, 2022

Malware detection for proxy server networks

Inventor: Paul Michael Martini (San Diego, CA)
Assignee: iboss, Inc.
H04L63/1425G06F21/567H04L61/4511H04L61/59H04L63/0281H04L63/1416H04L63/1441H04L63/164H04L63/168H04L67/02H04L67/562H04L2101/35H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,489,858
App. No.
17/828,678
Granted
Nov 1, 2022
Kind
B2
Abstract

This specification generally relates to methods and systems for applying network policies to devices based on their current access network. One example method includes identifying a proxy connection request sent from a particular client device to a proxy server over a network, the proxy connection request including a hostname and configured to direct the proxy server to establish communication with the computer identified by the hostname on behalf of the client device; determining an identity of the client device based on the proxy connection request; identifying a domain name system (DNS) response to a DNS request including the hostname from the proxy connection request; and updating DNS usage information for the particular client based on the identified DNS response including the hostname from the proxy connection request.

Claims (49)

1. A system comprising:

computing hardware operating together to provide a proxy service and a client-monitoring service, the computing hardware comprising:

one or more network connections configured to communicate with a plurality of client devices and with a plurality of internet resources identified by universal resource locators (URLs);

one or more processors; and

computer-readable memory storing instructions that, when executed by the one or more processors, instantiate the proxy service and the client-monitoring service, wherein:

the proxy service is configured to receive a connection request from a particular client device to connect the particular client device with a particular internet resource identified by a particular URL;

the proxy service is further configured to, responsive to the proxy service receiving the connection request, send a first DNS request to a DNS service, the first DNS request comprising the particular URL and formed to cause the DNS service to send a first DNS response to the proxy service, the first DNS response comprising a particular Internet Protocol (IP) address for the particular URL;

the client-monitoring service is configured to, responsive to the proxy service receiving the connection request, send a second DNS request to the DNS service, the second DNS request formed to cause the DNS service to send a second DNS response to the proxy service, the second DNS request comprising the particular URL and formed to cause the DNS service to send the second DNS response to the client-monitoring service, the second DNS response comprising the particular IP address for the particular URL such that the computing hardware receives two DNS responses that both contain the same particular IP address;

the proxy service is further configured to establish a connection with the particular internet resource using the particular IP address;

the computing hardware is configured to receive an access request from the particular client device addressed to the proxy service, the access request comprising a request to access a second internet resource associated with the particular IP address;

the client-monitoring service is further configured to intercept the access request before the access request reaches the proxy service; and

the client-monitoring service is further configured to selectively forward the access request based on a classification of behavior of the particular client device.

2. The system of claim 1 , wherein the system is a multi-processor system in which the network connections, processors, and computer-readable memory are interconnected with at least one data bus.

3. The system of claim 1 , wherein to selectively forward the access request, the client-monitor service is further configured to forward the access request to an internet server at the particular IP address.

4. The system of claim 1 , wherein to selectively forward the access request, the client-monitor service is further configured to forward the access request to the proxy service.

5. The system of claim 1 , wherein to selectively forward the access request, the client-monitor service is further configured to perform a corrective action to the client device responsive to a classification of anomalous behavior for the client device.

6. The system of claim 1 , wherein the client-monitoring service is further configured to passively monitor network traffic received by the proxy service to determine that the proxy service receives the connection request.

7. The system of claim 1 , wherein the client-monitoring service is further configured to intercept and forward network traffic received by the proxy service to determine that the proxy service receives the connection request.

8. A system comprising:

a proxy server comprising a one or more first processors and first computer-readable memory, the proxy server running a proxy service; and

a client-monitoring server comprising one or more second processors and second computer-readable memory, the client-monitoring server running a client-monitoring service; wherein:

the proxy service is configured to receive a connection request from a particular client device to connect the particular client device with a particular internet resource identified by a particular URL;

the proxy service is further configured to, responsive to the proxy service receiving the connection request, send a first DNS request to a DNS service, the first DNS request comprising the particular URL and formed to cause the DNS service to send a first DNS response to the proxy service, the first DNS response comprising a particular Internet Protocol (IP) address for the particular URL;

the client-monitoring service is configured to, responsive to the proxy service receiving the connection request, send a second DNS request to the DNS service, the second DNS request formed to cause the DNS service to send the second DNS response to the proxy service, the second DNS request comprising the particular URL and formed to cause the DNS service to send a second DNS response to the client-monitoring service, the second DNS response comprising the particular IP address for the particular URL such that the computing hardware receives two DNS responses that both contain the same particular IP address;

the proxy service is further configured to establish a connection with the particular internet resource using the particular IP address;

the computing hardware is configured to receive an access request from the particular client device addressed to the proxy service, the access request comprising a request to access a second internet resource associated with the particular IP address;

the client-monitoring service is further configured to intercept the access request before the access request reaches the proxy service; and

the client-monitoring service is further configured to selectively forward the access request based on a classification of behavior of the particular client device.

9. The system of claim 8 , wherein to selectively forward the access request, the client-monitor service is further configured to forward the access request to an internet server at the particular IP address.

10. The system of claim 8 , wherein the proxy server is a first blade server in a server rack and the client-monitoring server is a second blade server in the server rack.

11. The system of claim 8 , wherein to selectively forward the access request, the client-monitor service is further configured to forward the access request to the proxy service.

12. The system of claim 8 , wherein to selectively forward the access request, the client-monitor service is further configured to perform a corrective action to the client device responsive to a classification of anomalous behavior for the client device.

13. The system of claim 8 , wherein the client-monitoring service is further configured to passively monitor network traffic received by the proxy service to determine that the proxy service receives the connection request.

14. The system of claim 8 , wherein the client-monitoring service is further configured to intercept and forward network traffic received by the proxy service to determine that the proxy service receives the connection request.

15. A method for providing network security services, the method comprising:

maintaining a proxy service; and

maintaining a client-monitoring service; wherein:

the proxy service is configured to receive a connection request from a particular client device to connect the particular client device with a particular internet resource identified by a particular URL;

the proxy service is further configured to, responsive to the proxy service receiving the connection request, send a first DNS request to a DNS service, the first DNS request comprising the particular URL and formed to cause the DNS service to send a first DNS response to the proxy service, the first DNS response comprising a particular Internet Protocol (IP) address for the particular URL;

the client-monitoring service is configured to, responsive to the proxy service receiving the connection request, send a second DNS request to the DNS service, the second DNS request formed to cause the DNS service to send a second DNS response to the proxy service, the second DNS request comprising the particular URL and formed to cause the DNS service to send the second DNS response to the client-monitoring service, the second DNS response comprising the particular IP address for the particular URL such that the computing hardware receives two DNS responses that both contain the same particular IP address;

the proxy service is further configured to establish a connection with the particular internet resource using the particular IP address;

the computing hardware is configured to receive an access request from the particular client device addressed to the proxy service, the access request comprising a request to access a second internet resource associated with the particular IP address;

the client-monitoring service is further configured to intercept the access request before the access request reaches the proxy service; and

the client-monitoring service is further configured to selectively forward the access request based on a classification of behavior of the particular client device.

16. The method of claim 15 , wherein to selectively forward the access request, the client-monitor service is further configured to forward the access request to an internet server at the particular IP address.

17. The method of claim 15 , wherein to selectively forward the access request, the client-monitor service is further configured to forward the access request to the proxy service.

18. The method of claim 15 , wherein to selectively forward the access request, the client-monitor service is further configured to perform a corrective action to the client device responsive to a classification of anomalous behavior for the client device.

19. The method of claim 15 , wherein the client-monitoring service is further configured to passively monitor network traffic received by the proxy service to determine that the proxy service receives the connection request.

20. The method of claim 15 , wherein the client-monitoring service is further configured to intercept and forward network traffic received by the proxy service to determine that the proxy service receives the connection request.

Assignments (4)
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2022
From: MARTINI, PAUL MICHAEL
To: IBOSS, INC.
Reel/Frame 060337/0861 →
Continuity (2)
Continuation 15256418 · Sep 2, 2016
Related Publication 20220294815A1 · Sep 15, 2022