IP Library Granted Patent US 12,348,487
Granted Patent B2
US 12,348,487 · App. 18/464,758 · Granted Jul 1, 2025

Web application firewall for an online service

Inventors: Artur Bergman (Denver, CO); Sean Leach (Castle Pines, CO); Tyler McMullen (San Francisco, CA); Christian Peron (San Francisco, CA); Federico Schwindt (San Francisco, CA); Eric Hodel (San Francisco, CA)
Assignee: Fastly, Inc.
H04L63/0263H04L63/0245H04L63/1466H04L67/02H04L67/1065H04L67/563H04L67/568H04L67/63
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,348,487
App. No.
18/464,758
Granted
Jul 1, 2025
Kind
B2
Abstract

Disclosed herein are enhancements for operating a web application firewall to reduce load. In one implementation, a method of operating a content server for a web application comprising running a web accelerator with a plurality of threads on the content server. The method further provides receiving a request for content which will be provided to a web application, filtering the request and determining that the content will be requested from a second server. After determining that the content will be requested from a second server, reviewing the request with a web application firewall operating at a network layer 7, forwarding the request, receiving the content, and providing the content. Further, the web application firewall is controlled by a plurality of sets of rules, which can be updated without restarting the web accelerator.

Claims (56)

1. A method of operating a content server within an online service, the method comprising:

receiving, at the content server, a request for content wherein the content comprises data to be provide to a web application;

filtering the request for the content;

identifying a source of the content;

determining that the content will be requested from a second server;

after determining that the content will be requested from the second server, identifying a first set of rules for a Web Application Firewall (WAF) from among a selection of sets of rules and reviewing the request for the content with the WAF according to the first set of rules, wherein the first set of rules corresponds to the source of the content;

forwarding the request for the content to the second server;

receiving the content from the second server; and

providing the content.

2. The method of claim 1 , wherein:

the second server is configured to provide data from a selection of sources; and

the selection of sources comprises the source of the content.

3. The method of claim 1 , wherein the second server comprises an origin server.

4. The method of claim 1 , wherein the data to be provided to the web application comprises dynamic data.

5. The method of claim 1 , wherein the data to be provided to the web application comprises uncacheable data.

6. The method of claim 1 , wherein filtering the request for the content comprises comparing an address of a sender of the request for the content to a list of addresses.

7. The method of claim 1 , wherein determining that the content will be requested from the second server comprises determining that the content is not available within the content server.

8. The method of claim 1 , wherein the first set of rules comprises:

a set of operating system rules;

a set of standard rules; and

a set of custom rules.

9. A content server within an online service, the content server comprising:

a processor; and

memory with instructions stored thereon, which, when executed by the processor, cause the content server to:

receive, at the content server, a request for content wherein the content comprises data to be provided to a web application;

filter the request for the content;

identify a source of the content;

determine that the content will be requested from a second server;

after determining that the content will be requested from the second server, identify a first set of rules for a Web Application Firewall (WAF) from among a selection of sets of rules and review the request for the content with the WAF according to the first set of rules, wherein the first set of rules corresponds to the source of the content;

forward the request for the content to the second server;

receive the content from the second server; and

provide the content.

10. The content server of claim 9 , wherein:

the second server is configured to provide data from a selection of sources; and

the selection of sources comprises the source of the content.

11. The content server of claim 9 , wherein the second server comprises an origin server.

12. The content server of claim 9 , wherein the data to be provided to the web application comprises dynamic data.

13. The content server of claim 9 , wherein the data to be provided to the web application comprises uncacheable data.

14. The content server of claim 9 , wherein the instructions, when executed by the processor, cause the content server to compare an address of a sender of the request for the content to a list of addresses to filter the content.

15. The content server of claim 9 , wherein the instructions, when executed by the processor, cause the content server to determine that the content is not available within the content server to determine that the content will be request from the second server.

16. The content server of claim 9 , wherein the first set of rules comprises:

a set of operating system rules;

a set of standard rules; and

a set of custom rules.

17. A method of operating a server within an online service, the method comprising:

receiving, at the content server, a request for content wherein the content comprises data to be provided to a web application;

filtering the request for the content;

identifying a source of the content;

determining that the content will be requested from a second server;

after determining that the content will be requested from the second server, identifying a first rule for a Web Application Firewall (WAF) from among a set of rules and reviewing the request for the content with the WAF according to the first rule, wherein the first rule corresponds to the source of the content;

creating a new request for the content to send to the second server;

receiving the content from the second server; and

providing the content.

18. The method of claim 17 , wherein filtering the request for the content comprises comparing an address of a sender of the request for the content to a list of addresses.

19. The method of claim 17 , wherein determining that the content will be requested from the second server comprises determining that the content is not available within the content server.

20. The method of claim 17 , wherein the data to be provided to the web application comprises dynamic data.

Assignments (2)
SECURITY INTEREST Recorded May 1, 2024
From: FASTLY, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY, AS ADMINISTRATIVE AGENT
Reel/Frame 067281/0500 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2023
From: BERGMAN, ARTUR; LEACH, SEAN; MCMULLEN, TYLER; PERON, CHRISTIAN; SCHWINDT, FEDERICO; HODEL, ERIC
To: FASTLY, INC.
Reel/Frame 064862/0937 →
Continuity (5)
Continuation 17372941 · Jul 12, 2021
Continuation 16050673 · Jul 31, 2018
Provisional Application 62556012 · Sep 8, 2017
Provisional Application 62539130 · Jul 31, 2017
Related Publication 20240007439A1 · Jan 4, 2024
References Cited (25)
US 6813690B1 · Lango · 2004 [cited by examiner]
US 8996614B2 · Choudhary · 2015 [cited by examiner]
US 10630758B2 · Alstad · 2020 [cited by examiner]
US 20040064351A1 · Mikurak · 2004 [cited by applicant]
US 20060294223A1 · Glasgow · 2006 [cited by examiner]
US 20080228772A1 · Plamondon · 2008 [cited by examiner]
US 20130097600A1 · Cardona · 2013 [cited by examiner]
US 20130152187A1 · Strebe · 2013 [cited by examiner]
US 20130254343A1 · Stevens · 2013 [cited by examiner]
US 20150205643A1 · Miyamoto · 2015 [cited by examiner]
US 20160048868A1 · Mirisola · 2016 [cited by examiner]
US 20160057163A1 · Boffa et al. · 2016 [cited by applicant]
US 20160182454A1 · Phonsa et al. · 2016 [cited by applicant]
US 20160323143A1 · Kim · 2016 [cited by examiner]
US 20170180322A1 · Agarwal et al. · 2017 [cited by applicant]
US 20170332421A1 · Sternberg · 2017 [cited by examiner]
US 20180013792A1 · Glenn · 2018 [cited by examiner]
US 20200228561A1 · Petry · 2020 [cited by examiner]
US 20210211868A1 · Rodriguez Bravo · 2021 [cited by examiner]
US 20210288942A1 · Preda · 2021 [cited by examiner]
GB 2529655A · 2016 [cited by examiner]
Auxilia et al., “Anomaly detection using negative security model in web application”, 2010 International Conference on Computer Information Systems and Industrial Management Applications (CISIM), Date of Conference: Oct… [cited by examiner]
Ho-Yu Lam et al., “A traffic-aware top-N firewall ruleset approximation algorithm”, ANCS '10: Proceedings of the 6th ACM/IEEE Symposium on Architectures for Networking and Communications Systems, Article No. 9, pp. 1-2,… [cited by applicant]
Takahashi et al., “Application for Autonomous Decentralized Multi Layer Cache System to Web Application Firewall”, Tenth International Symposium on Autonomous Decentralized Systems, Date of Conference: Mar. 23-27 (Year:… [cited by applicant]
Stringhini et al., “Shady Paths: Leveraging Surfing Crowds to Detect Malicious Web Pages”, CCS '13: Proceedings of the 2013 ACM SIGSAC conference on Computer & Communications Security, Nov. 2013, 12 pages. [cited by applicant]