IP Library Granted Patent US 12,261,869
Granted Patent B2
US 12,261,869 · App. 18/339,738 · Granted Mar 25, 2025

Malware detection for proxy server networks

Inventor: Paul Michael Martini (Boston, MA)
Assignee: iboss, Inc.
H04L63/1425G06F21/567H04L61/4511H04L61/59H04L63/0281H04L63/1416H04L63/1441H04L63/164H04L63/168H04L67/02H04L67/562H04L2101/35H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,261,869
App. No.
18/339,738
Granted
Mar 25, 2025
Kind
B2
Abstract

This specification generally relates to methods and systems for applying network policies to devices based on their current access network. One example method includes identifying a proxy connection request sent from a particular client device to a proxy server over a network, the proxy connection request including a hostname and configured to direct the proxy server to establish communication with the computer identified by the hostname on behalf of the client device; determining an identity of the client device based on the proxy connection request; identifying a domain name system (DNS) response to a DNS request including the hostname from the proxy connection request; and updating DNS usage information for the particular client based on the identified DNS response including the hostname from the proxy connection request.

Claims (58)

1. A computer-implemented method executed by one or more processors, the method comprising:

receiving, by a proxy in data communication with a local area network (LAN), proxy connection requests from client devices on the LAN, the proxy connection requests including a hostname and configured to direct the proxy to establish communication with a computer identified by the hostname on behalf of the client devices;

actively monitoring, by an anti-malware system in data communication with the LAN, the proxy connection requests, the active monitoring being after the proxy connection requests have been transmitted out of the LAN and before the proxy connection requests are received by the proxy;

determining, by the anti-malware system, identities of the client devices based on the proxy connection requests;

sending, by the proxy, first domain name system (DNS) requests in response to receiving the proxy connection requests;

receiving, by the proxy, first DNS responses from one or more DNS server in response to the first DNS requests;

sending, by the anti-malware system, second DNS requests in response to determining identities of the client devices;

receiving, by the anti-malware system, second DNS responses from the one or more DNS servers in response to the second DNS requests;

determining, by the anti-malware system, that the one of the second DNS responses is associated with a particular client device out of a plurality of client devices;

updating, by the anti-malware system, DNS usage information for the particular client device based on the identified DNS responses including the hostname from the proxy connection request; and

determining, by the anti-malware system, that the particular client is exhibiting anomalous behavior based on the updated DNS usage information.

2. The method of claim 1 , wherein the DNS usage information includes a DNS request rate for the particular client device, a DNS request failure rate for the particular client device, and hostnames included in DNS requests associated with the particular client device.

3. The method of claim 1 , wherein the hostname is included in a Uniform Resource Locator (URL).

4. The method of claim 1 , further comprising:

performing a corrective action to the particular client device based on the determination.

5. The method of claim 4 , wherein the anomalous behavior is associated with a malicious software program, and the corrective action includes removing the particular client device from the network.

6. A system comprising:

one or more processors; and

computer memory storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving, by a proxy in data communication with a local area network (LAN), proxy connection requests from client devices on the LAN, the proxy connection requests including a hostname and configured to direct the proxy to establish communication with a computer identified by the hostname on behalf of the client devices;

actively monitoring, by an anti-malware system in data communication with the LAN, the proxy connection requests, the active monitoring being after the proxy connection requests have been transmitted out of the LAN and before the proxy connection requests are received by the proxy;

determining, by the anti-malware system, identities of the client devices based on the proxy connection requests;

sending, by the proxy, first domain name system (DNS) requests in response to receiving the proxy connection requests;

receiving, by the proxy, first DNS responses from one or more DNS server in response to the first DNS requests;

sending, by the anti-malware system, second DNS requests in response to determining identities of the client devices;

receiving, by the anti-malware system, second DNS responses from the one or more DNS servers in response to the second DNS requests;

determining, by the anti-malware system, that the one of the second DNS responses is associated with a particular client device out of a plurality of client devices;

updating, by the anti-malware system, DNS usage information for the particular client device based on the identified DNS responses including the hostname from the proxy connection request; and

determining, by the anti-malware system, that the particular client is exhibiting anomalous behavior based on the updated DNS usage information.

7. The system of claim 6 , wherein identifying the DNS responses including the hostname includes:

sending the DNS requests including the hostname from the proxy connection request; and

receiving the DNS response.

8. The system of claim 6 , wherein the DNS usage information includes a DNS request rate for the particular client device, a DNS request failure rate for the particular client device, and hostnames included in DNS requests associated with the particular client device.

9. The system of claim 6 , wherein the hostname is included in a Uniform Resource Locator (URL).

10. The system of claim 6 , wherein the operations further comprise:

performing a corrective action to the particular client device based on the determination.

11. The system of claim 10 , wherein the anomalous behavior is associated with a malicious software program, and the corrective action includes removing the particular client device from the network.

12. A system comprising:

computing hardware operating together to provide an anti-malware system, the computing hardware comprising:

one or more network connections configured to communicate with a local area network (LAN);

one or more processors; and

computer-readable memory storing instructions that, when executed by the one or more processors, cause the one or more processors to operate the anti-malware system, comprising:

receiving, by a proxy in data communication with a local area network (LAN), proxy connection requests from client devices on the LAN, the proxy connection requests including a hostname and configured to direct the proxy to establish communication with a computer identified by the hostname on behalf of the client devices;

actively monitoring, by an anti-malware system in data communication with the LAN, the proxy connection requests, the active monitoring being after the proxy connection requests have been transmitted out of the LAN and before the proxy connection requests are received by the proxy;

determining, by the anti-malware system, identities of the client devices based on the proxy connection requests;

sending, by the proxy, first domain name system (DNS) requests in response to receiving the proxy connection requests;

receiving, by the proxy, first DNS responses from one or more DNS server in response to the first DNS request;

sending, by the anti-malware system, second DNS requests in response to determining identities of the client devices;

receiving, by the anti-malware system, second DNS responses from the one or more DNS servers in response to the second DNS requests;

determining, by the anti-malware system, that the one of the second DNS responses is associated with a particular client device out of a plurality of client devices;

updating, by the anti-malware system, DNS usage information for the particular client device based on the identified DNS responses including the hostname from the proxy connection request; and

determining, by the anti-malware system, that the particular client is exhibiting anomalous behavior based on the updated DNS usage information.

13. The system of claim 12 , wherein identifying the DNS responses including the hostname includes:

sending the DNS requests including the hostname from the proxy connection request; and

receiving the DNS response.

14. The system of claim 12 , wherein the DNS usage information includes a DNS request rate for the particular client device, a DNS request failure rate for the particular client device, and hostnames included in DNS requests associated with the particular client device.

15. The system of claim 12 , wherein the hostname is included in a Uniform Resource Locator (URL).

16. The system of claim 12 , wherein the anomalous behavior is associated with a malicious software program.

Assignments (2)
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2023
From: MARTINI, PAUL MICHAEL
To: IBOSS, INC.
Reel/Frame 065410/0972 →
Continuity (4)
Continuation 17945892 · Sep 15, 2022
Continuation 17828678 · May 31, 2022
Continuation 15256418 · Sep 2, 2016
Related Publication 20230336577A1 · Oct 19, 2023
References Cited (28)
US 9003526B2 · El-Moussa · 2015 [cited by examiner]
US 9705922B2 · Foxhoven · 2017 [cited by examiner]
US 20070039053A1 · Dvir · 2007 [cited by applicant]
US 20080082662A1 · Dandliker · 2008 [cited by applicant]
US 20100118869A1 · Li · 2010 [cited by examiner]
US 20110302656A1 · El-Moussa · 2011 [cited by examiner]
US 20120303808A1 · Xie · 2012 [cited by applicant]
US 20140283062A1 · Kamthe · 2014 [cited by examiner]
US 20160021056A1 · Chesla · 2016 [cited by examiner]
US 20160050224A1 · Ricafort · 2016 [cited by examiner]
US 20160277435A1 · Salajegheh · 2016 [cited by examiner]
US 20160323409A1 · Kölhi · 2016 [cited by examiner]
US 20160344606A1 · Baccarani · 2016 [cited by examiner]
US 20170244713A1 · Sun · 2017 [cited by examiner]
US 20170374017A1 · Gautam · 2017 [cited by examiner]
US 20180069878A1 · Martini · 2018 [cited by applicant]
Luo et al., “Leveraging client-side DNS failure patterns to identify malicious behaviors,” 2015 IEEE Conference on Communications and Network Security (CNS) Year: 2015 | Conference Paper | Publisher: IEEE. [cited by examiner]
Cai et al., “A Behavior-Based Method for Detecting DNS Amplification Attacks,” 2016 10th International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing (IMIS) Year: 2016 | Conference Paper |… [cited by examiner]
Al-Batanieh et al., “Analysis and detection of malicious data exfiltration in web traffic,” 2012 7th International Conference on Malicious and Unwanted Software Year: 2012 1 Conference Paper 1 Publisher: IEEE. [cited by applicant]
Apple.com Blog “DNS Server Logs to Monitor Traffic”, Mar. 29, 2016, downloaded from the internet at: http://discussions.apple.com/thread/7513584?start=0&tstart=0 on Sep. 1, 2016, 5 pages. [cited by applicant]
Bro.org, “Monitoring HTTP Traffic with Bro”, Sep. 1, 2016, downloaded from the internet at: https://www.bro.org/sphinx-git/httpmonitor/index.html on Sep. 1, 2016, 10 pages. [cited by applicant]
Cai et al., “A Behavior-Based Method for Detecting DNS Amplification Attacks,” 2016 10th International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing (IMIS) Year: 2016 1 Conference Paper 1… [cited by applicant]
Extended European Search Report in European Appln No. 17847650, dated May 31, 2019, 6 pages. [cited by applicant]
International Preliminary Report on Patentability in International Appln. No. PCT/US2017/49949, dated Mar. 5, 2019, 6 pages. [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/US2017/49949, dated Sep. 27, 2017, 11 pages. [cited by applicant]
Luo et al., “Leveraging client-side DNS failure patterns to identify malicious behaviors,” 2015 IEEE Conference on Communications and Network Security (CNS) Year: 2015 1 Conference Paper 1 Publisher: IEEE. [cited by applicant]
Newton, “Domain Name System—How DNS Lookups Work When Using an HTTP Proxy (or not) in IE”, Aug. 8, 2011, downloaded from the internet at: http://serverfault.com/questions/169816/how-dns-lookups-work-when-using-an-http-p… [cited by applicant]
Zhirayr, “How to Monitor Squid Proxy Server”, Aug. 10, 2012, downloaded from the internet at: http://www.monitis.com/blog/how-to-monitor-squid-proxy-server/ on Sep. 1, 2016, 12 pages. [cited by applicant]