IP Library Granted Patent US 7,752,336
Granted Patent B2
US 7,752,336 · App. 12/143,210 · Granted Jul 6, 2010

Method and apparatus for resource locator identifier rewrite

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,752,336
App. No.
12/143,210
Granted
Jul 6, 2010
Kind
B2
Abstract

A method and apparatus for resource locator identifier rewrite have been presented. A security device receives from a resource host over a non-secure hypertext transfer protocol (HTTP) session a response to a request received from a client over a secure HTTP session. The response includes a uniform resource locator (URL) that is supposed to be for a resource host, but the URL does not designate a secure resource access protocol and the resource host requires the secure resource access protocol. The URL is located in the response and modified to designate the secure resource access protocol. After modification, the response is transmitted via the secure resource access protocol session to the client.

Claims (51)

1. A method in a network security device comprising:

receiving from a resource host over a non-secure hypertext transfer protocol (HTTP) session a response to a request received from a client over a secure HTTP session, wherein the response includes a header, a body, and a uniform resource locator (URL) in the response body that is supposed to be for a resource host, but the URL does not designate a secure resource access protocol and the resource host requires the secure resource access protocol;

loading the response into a buffer of a ring buffer;

locating the URL in the response;

rewriting the URL to designate the secure resource access protocol;

parsing boundaries of the response;

transmitting the response via the secure resource access protocol session to the client; and

flushing the buffer up to a partial URL and load the buffer with the response to the partial URL.

2. The method of claim 1 wherein the URL is located and modified if the response includes a header Content-Encoding.

3. The method of claim 1 further comprising ensuring that the response and/or the request does not indicate support of persistent connection.

4. The method of claim 3 wherein ensuring that the response and/or the request does not indicate support of persistent connection comprises:

downgrading the version of HTTP indicated in the header; and

indicating in connection close by either modifying a connection field in the header or inserting a new field in the header.

5. The method of claim 1 wherein the URL is located and modified if the response has a content type of text and transmitting the response without locating and modifying the URL if the content type is not text.

6. The method of claim 1 further comprising ensuring that the response and/or the request does not indicate support of chunked transfer encoding.

7. The method of claim 6 wherein ensuring that the response and/or the request does not indicate support of chunked transfer encoding comprises downgrading the version of HTTP indicated in the header.

8. The method of claim 1 further comprising modifying the request to indicate that the requesting client does not support chunked transfer encoding while preserving persistent connection and chunked transfer encoding in the response if the client supports persistent connection and chunked transfer encoding.

9. The method of claim 1 further comprising modifying the response to prevent the client from using the content length indicated in the response.

10. A network security device comprising:

a set of one or more processors to perform security operations;

a set of one or more interfaces coupled with the set of processors;

a ring buffer to store message data; and

a resource access protocol module coupled with the set of processors, the resource access protocol module to,

load message data for individual resource access protocol sessions into different buffers of the ring buffer;

scan message data to locate resource locator identifiers (RLI) in a body of the message data,

for each located RLI, determine if the located RLI indicates a resource access protocol that should govern a request for a resource indicated by the located RLI,

for each located RLI that does not indicate the resource access protocol, rewrite the located RLI to indicate the resource access protocol,

parse boundaries of the message data

transmit via one of the set of interfaces the response with transport layer information that indicates a port corresponding to the resource access protocol, and

flush one of the buffers in the ring buffer up to a partial RLI and load the one buffer with message data in addition to the partial RLI.

11. The network security device of claim 10 , wherein the resource access protocol module includes a buffer daemon and a scan and parse daemon.

12. The network security device of claim 10 , further comprising a storage device to store a configuration file that indicates a set of one or more resource hosts and their corresponding appropriate request governing resource access protocol.

13. The network security device of claim 10 , further comprising the resource access protocol module to create a chunk with message data from one of the buffers in the ring buffer, wherein the message data includes a plurality of complete RLIs.

14. A non-transitory machine-readable storage medium that provides instructions, executable by a set of one or more processors in a network security device to cause said set of processors to perform operations comprising:

receiving from a resource host over a non-secure hypertext transfer protocol (HTTP) session a response to a request received from a client over a secure HTTP session, wherein the response includes a header, a body, and a uniform resource locator (URL) in the response body that is supposed to be for a resource host, but the URL does not designate a secure resource access protocol and the resource host requires the secure resource access protocol;

loading the response into a buffer of a ring buffer;

locating the URL in the response;

rewriting the URL to designate the secure resource access protocol;

parsing boundaries of the response;

transmitting the response via the secure resource access protocol session to the client; and

flushing the buffer up to a partial URL and load the buffer with the response to the partial URL.

15. The non-transitory machine-readable storage medium of claim 14 , wherein the URL is located and modified if the response includes a header “Content-Encoding”.

16. The non-transitory machine-readable storage medium of claim 14 , wherein the operations further comprise ensuring that the response and/or the request does not indicate support of persistent connection.

17. The non-transitory machine-readable storage medium of claim 16 , wherein ensuring that the response and/or the request does not indicate support of persistent connection comprises:

downgrading the version of HTTP indicated in the header; and

indicating in connection close by either modifying a connection field in the header or inserting a new field in the header.

18. The non-transitory machine-readable storage medium of claim 14 , wherein the URL is located and modified if the response has a content type of text and transmitting the response without locating and modifying the URL if the content type is not text.

19. The non-transitory machine-readable storage medium of claim 14 , wherein the operations further comprise ensuring that the response and/or the request does not indicate support of chunked transfer encoding.

20. The non-transitory machine-readable storage medium of claim 19 , wherein ensuring that the response and/or the request does not indicate support of chunked transfer encoding comprises downgrading the version of HTTP indicated in the header.

21. The non-transitory machine-readable storage medium of claim 14 , wherein the operations further comprise modifying the request to indicate that the requesting client does not support chunked transfer encoding while preserving persistent connection and chunked transfer encoding in the response if the client supports persistent connection and chunked transfer encoding.

22. The non-transitory machine-readable storage medium of claim 14 , wherein the operations further comprise modifying the response to prevent the client from using the content length indicated in the response.

Assignments (25)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Apr 2, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 045818/0566 →
CORRECTIVE ASSIGNMENT TO CORRECT THE INCORRECT PATENT NO. 7752386 PREVIOUSLY RECORDED AT REEL: 037281 FRAME: 0007. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Jan 11, 2018
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 045814/0740 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
MERGER Recorded Jan 5, 2016
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 037410/0631 →
MERGER Recorded Dec 14, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 037281/0007 →
CONVERSION AND NAME CHANGE Recorded Dec 14, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 037282/0382 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2012
From: GMUENDER, JOHN E.; NGUYEN, HUY MINH; LEVY, JOSEPH H.; MASSING, MICHAEL B.; CHEN, ZHONG; TELEHOWSKI, DAVID M.
To: SONICWALL, INC.
Reel/Frame 029387/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024823/0280 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0126 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024776/0337 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0115 →
PATENT SECURITY AGREEMENT (SECOND LIEN) Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024823/0280 →
SECURITY AGREEMENT Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024776/0337 →
MERGER Recorded Jul 28, 2010
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC.
Reel/Frame 024755/0083 →
CHANGE OF NAME Recorded Jul 28, 2010
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 024755/0091 →