IP Library › Granted Patent US 9,294,439
Granted Patent B2
US 9,294,439 · App. 13/943,662 · Granted Mar 22, 2016

Systems and methods for application-based interception of SSL/VPN traffic

Inventors: Charu Venkatraman (Bangalore, IN); Junxiao He (Saratoga, CA); Amarnath Mullick (Bangalore, IN); Shashi Nanjundaswamy (Bangalore, IN); James Harris (San Jose, CA); Ajay Soni (San Jose, CA)
Assignee: CITRIX SYSTEMS, INC.
H04L63/0227H04L63/0272H04L63/0876H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,294,439
App. No.
13/943,662
Granted
Mar 22, 2016
Kind
B2
Abstract

A method for intercepting, by an agent of a client, communications from the client to be transmitted via a virtual private network connection includes the step of intercepting communications based on identification of an application from which the communication originates. The agent receives information identifying a first application. The agent determines a network communication transmitted by the client originates from the first application and intercepts that communication. The agent transmits the intercepted communication via the virtual private network connection.

Claims (25)

1. A method for intercepting application communications for transmission via a virtual private network connection, the method comprising:

(a) receiving, by an agent of a client, an application routing table identifying one or more applications authorized for access via a virtual private network connection established with an device intermediary to the client and at least one server, each of the one or more applications identified via a name of an executable of the corresponding application;

(b) determining, by the agent, whether a first communication from the client is from a first application with a name of an executable identified by the received application routing table; and

(c) transmitting, by the agent based on the determination, the first communication via the virtual private network connection established with the device.

2. The method of claim 1 , comprising transmitting, by the device, the application routing table to the agent.

3. The method of claim 1 , comprising establishing, by the agent, the virtual private network connection with the device.

4. The method of claim 1 , comprising determining, by the agent, that a second communication is from a second application not identified in the application routing table, and allowing the second communication to pass via the client's network stack.

5. The method of claim 1 , comprising determining, by the agent, that a second communication is from a second application not identified in the application routing table, and not intercepting the network communication.

6. The method of claim 1 , comprising determining, by the agent, the name of the executable of the first application via a system level or kernel level call.

7. The method of claim 1 , comprising determining, by the agent, the name of the executable of the first application via an application programming interface.

8. The method of claim 1 , comprising comparing, by the agent, information from the first communication with information in the application routing table.

9. The method of claim 1 , comprising one of granting or denying, by the device, a level of access to the first application based on identification of the first application.

10. The method of claim 1 , comprising transmitting, by the agent, to the device an identification of the first application.

11. A system for intercepting application communications for transmission via a virtual private network connection, the system comprising:

an application routing table identifying one or more applications authorized for access via a virtual private network connection established with an device intermediary to a client and at least one server, each of the first one or more applications identified via a name of an executable of the corresponding application; and

an agent of a client, configured for receiving the application routing table, determining, based on the identification, whether a first communication from the client is from an application with a name of an executable identified by the received application routing table, and transmitting, based on the determination, the first communication via the virtual private network connection established with the device.

12. The system of claim 11 , wherein the application routing table is transmitted by the device to the agent.

13. The system of claim 11 , wherein the agent establishes the virtual private network connection with the device.

14. The system of claim 11 , wherein the agent determines that a second communication is from a second application not identified in the application routing table, and allows the second communication to pass via the client's network stack.

15. The system of claim 11 , wherein the agent determines that a second communication is from a second application not identified in the application routing table, and does not intercept the network communication.

16. The system of claim 11 , wherein the agent determines the name of the executable of the first application via a system level or kernel level call.

17. The system of claim 11 , wherein the agent determines the name of the executable of the first application via an application programming interface.

18. The system of claim 11 , wherein the agent compares information from the first communication with information in the application routing table.

19. The system of claim 11 , wherein the device grants or denies a level of access to the first application based on identification of the first application.

20. The system of claim 11 , wherein the agent transmits to the device an identification of the first application.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2013
From: VENKATRAMAN, CHARU; HE, JUNXIAO; MULLICK, AMARNATH; NANJUNDASWAMY, SHASHI; HARRIS, JAMES; SONI, AJAY
To: CITRIX SYSTEMS, INC.
Reel/Frame 031660/0812 →
Continuity (2)
Continuation 11462321 · Aug 3, 2006
Related Publication 20130304881A1 · Nov 14, 2013