IP Library Granted Patent US 9,705,898
Granted Patent B2
US 9,705,898 · App. 15/206,802 · Granted Jul 11, 2017

Applying group policies

Inventor: Paul Michael Martini (San Diego, CA)
Assignee: iboss, Inc.
H04L63/1408G06F21/64H04L9/0825H04L63/104H04L63/12H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,705,898
App. No.
15/206,802
Granted
Jul 11, 2017
Kind
B2
Abstract

Information corresponding to a set of signatures is maintained, and for each signature in the set, an associated group policy of a network is maintained. A message from a device on the network is intercepted, and the message includes a header. At least a portion of the header matches a signature in the set of signatures. Responsive to determining that the portion of the header matches the signature, the matched signature's associated group policy of the network is applied to the device on the network.

Claims (44)

1. A method performed by data processing apparatus, the method comprising:

intercepting, by a network gateway on a network, a message from a client device on the network, the message comprising a Hypertext Transfer Protocol (HTTP) GET message and further comprising a header having a user agent string;

determining that at least a portion of the header matches a particular signature in a set of signatures by matching a substring of the user agent string to the particular signature, wherein the particular signature includes a wildcard character that can be matched to one or more of a plurality of characters in the user agent string; and

responsive to determining that the portion of the header matches the particular signature, applying a group policy associated with the matched signature to the client device on the network.

2. The method of claim 1 , wherein the portion of the header comprises one or more tokens.

3. The method of claim 1 , wherein at least some of the signatures in the set are product tokens.

4. The method of claim 1 , the method further comprising:

applying, before intercepting the message, an initial group policy of the network to the client device on the network; and

wherein applying the signature's associated group policy of the network to the client device on the network comprises removing the initial group policy of the network from the client device on the network.

5. The method of claim 1 , wherein the intercepted message has an intended destination, and wherein applying the signature's associated group policy of the network to the client device on the network causes the message to be blocked from reaching the intended destination.

6. The method of claim 1 , wherein at least one of the signatures in the set represents deprecated software.

7. The method of claim 1 , wherein at least one of the signatures in the set represents software with a possible security vulnerability.

8. The method of claim 1 , wherein at least one of the signatures in the set represents a signature in a user agent string generated by malicious software.

9. The method of claim 1 , wherein each of the signatures in the set represents at least one selected from the group comprising deprecated software, software with a possible security vulnerability, and a signature in a user agent string generated by malicious software.

10. A non-transitory computer storage media encoded with computer program instructions that, when executed by one or more processors, cause a computer device to perform operations comprising:

intercepting, by a network gateway on a network, a message from a client device on the network, the message comprising a Hypertext Transfer Protocol (HTTP) GET message and further comprising a header having a user agent string;

determining that at least a portion of the header matches a particular signature in a set of signatures by matching a substring of the user agent string to the particular signature, wherein the particular signature includes a wildcard character that can be matched to one or more of a plurality of characters in the user agent string; and

responsive to determining that the portion of the header matches the particular signature, applying a group policy associated with the matched signature to the client device on the network.

11. The non-transitory computer storage media of claim 10 , wherein the portion of the header comprises one or more tokens.

12. The non-transitory computer storage media of claim 10 , wherein at least some of the signatures in the set are product tokens.

13. The non-transitory computer storage media of claim 10 , the operations further comprising:

applying, before intercepting the message, an initial group policy of the network to the client device on the network; and

wherein applying the signature's associated group policy of the network to the client device on the network comprises removing the initial group policy of the network from the client device on the network.

14. The non-transitory computer storage media of claim 10 , wherein the intercepted message has an intended destination, and wherein applying the signature's associated group policy of the network to the client device on the network causes the message to be blocked from reaching the intended destination.

15. The non-transitory computer storage media of claim 10 , wherein at least one of the signatures in the set represents deprecated software.

16. The non-transitory computer storage media of claim 10 , wherein at least one of the signatures in the set represents software with a possible security vulnerability.

17. The non-transitory computer storage media of claim 10 , wherein at least one of the signatures in the set represents a signature in a user agent string generated by malicious software.

18. The non-transitory computer storage media of claim 10 , wherein each of the signatures in the set represents at least one selected from the group comprising deprecated software, software with a possible security vulnerability, and a signature in a user agent string generated by malicious software.

19. A system comprising:

one or more processors configured to execute computer program instructions; and

computer storage media encoded with computer program instructions that, when executed by one or more processors, cause a computer device to perform operations comprising:

intercepting, by a network gateway on a network, a message from a client device on the network, the message comprising a Hypertext Transfer Protocol (HTTP) GET message and further comprising a header having a user agent string;

determining that at least a portion of the header matches a particular signature in a set of signatures by matching a substring of the user agent string to the particular signature, wherein the particular signature includes a wildcard character that can be matched to one or more of a plurality of characters in the user agent string; and

responsive to determining that the portion of the header matches the particular signature, applying a group policy associated with the matched signature to the client device on the network.

20. The system of claim 19 , wherein the portion of the header comprises one or more tokens.

21. The system of claim 19 , wherein at least some of the signatures in the set are product tokens.

22. The system of claim 19 , the operations further comprising:

applying, before intercepting the message, an initial group policy of the network to the client device on the network; and

wherein applying the signature's associated group policy of the network to the client device on the network comprises removing the initial group policy of the network from the client device on the network.

23. The system of claim 19 , wherein the intercepted message has an intended destination, and wherein applying the signature's associated group policy of the network to the client device on the network causes the message to be blocked from reaching the intended destination.

24. The system of claim 19 , wherein at least one of the signatures in the set represents deprecated software.

25. The system of claim 19 , wherein at least one of the signatures in the set represents software with a possible security vulnerability.

26. The system of claim 19 , wherein at least one of the signatures in the set represents a signature in a user agent string generated by malicious software.

27. The system of claim 19 , wherein each of the signatures in the set represents at least one selected from the group comprising deprecated software, software with a possible security vulnerability, and a signature in a user agent string generated by malicious software.

Assignments (6)
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0219 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
SECURITY INTEREST Recorded Dec 16, 2020
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 054789/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2017
From: MARTINI, PAUL MICHAEL
To: IBOSS, INC.
Reel/Frame 040939/0506 →
Continuity (3)
Continuation 14835063 · Aug 25, 2015
Continuation 14472302 · Aug 28, 2014
Related Publication 20160323298A1 · Nov 3, 2016