Web-based Security and Filtering System for Inbound/outbound Communications with Proxy Chaining
Abstract
A customizable system for filtering web-based HTTP requests for outbound and inbound access to web sites. An administrative module in a user computer configures a range of access levels for inbound and outbound communications and has list maintenance functions. Users attempting to access an unfriendly site are anonymously forwarded to a friendly site or the request is terminated. A first proxy server in each user computer of a LAN has access to the WWW, has a customizable friendly and unfriendly outbound list, one of which is active and a customizable friendly and unfriendly inbound list, one of which is active. A second HTTP proxy server without an administrative module or friendly or unfriendly lists is between the first proxy server and the Internet as a LAN gateway or at an ISP domain, the second proxy being capable of communicating to a proxy of a destination or directly to a destination.
Claims
exact text as granted — not AI-modifiedThe invention claimed is:
1 . A versatile customizable combination system for providing filtering of outbound requests for access to web sites on the Internet or for controlling inbound requests from the Internet for access to web resources protected by the system, or for filtering both outbound requests for access to web sites on the Internet and controlling inbound requests from the Internet for access to web resources protected by said system, the system having at least one user account, said system comprising:
one or more user computers, wherein each of the said one or more user computers comprises either a dynamically allocated Internet protocol address or a static Internet protocol address; the one or more user computers comprising one or more hardware processors and comprising memory, wherein the memory stores executable instructions, the executable instructions comprising: an administrative module, wherein said administrative module is located in one of the one or more user computers; a first proxy server in at least one of the said one or more user computers; wherein the first proxy server has access to the world wide web, wherein said first proxy server is configured by the administrative module; wherein said first proxy server is programmed to:
receive a request from said requesting client,
and
either approve said request from said requesting client, terminate said request from said requesting client, or re-route said request from said requesting client;
wherein said requesting client is at least an HTTP (Hypertext Transfer Protocol) application or a web browser, a second proxy server in at least one of the one or more computers; wherein said second proxy server does not comprise said administrative module, wherein said second proxy server is placed between said first proxy server and either a resource or the Internet; wherein said second proxy server communicates either with a proxy of a destination or directly to said destination; wherein said second proxy server further comprises an Internet Protocol address used for proxy forwarding, wherein said Internet Protocol address used for proxy forwarding is set during configuration of said first proxy server, wherein said first proxy server forwards said request to said second proxy server if said first proxy server approves said request; and wherein said first proxy server and said second proxy server are in communication with one another through a network communication link.
2 . The system of claim 1 , wherein the executable instructions comprising:
wherein said administrative module is configured to create one or more different types of user accounts, wherein each of the said one or more different types of user accounts requires one or more unique authentication credentials; wherein said administrative module configures one or more different access levels per user account.
3 . The system of claim 2 , wherein when a user logs into said first proxy server and presents said one or more unique authentication credentials, said first proxy server checks an identity of said user.
4 . The system of claim 3 , wherein upon a successful authentication of said user's identity by said first proxy, said user logs into the system.
5 . The system of claim 3 , wherein said first proxy server, upon a failed authentication of said user, will either offer said user an opportunity to login again, deny said request from said requesting client, or re-route said request from said requesting client to replacement resources.
6 . The system of claim 2 , wherein the executable instructions comprising:
wherein said first proxy server further comprises at least one of a friendly inbound list and an unfriendly inbound list; wherein said administrative module configures at least one of a friendly inbound list and an unfriendly inbound list of said first proxy per user account.
7 . The system of claim 6 , wherein when a user logs into said first proxy server and presents said one or more unique authentication credentials, said first proxy server checks an identity of said user.
8 . The system of claim 7 , wherein upon a successful authentication of said user's identity by said first proxy server, said first proxy server either checks said one or more identity attributes of said requesting client against at least one of said friendly inbound list of the particular user account or said unfriendly inbound list of the particular user account.
9 . The system of claim 2 , wherein the executable instructions comprising:
wherein said first proxy server further comprises at least one of a friendly outbound list and an unfriendly outbound list; and wherein said administrative module configures at least one of a friendly outbound list and an unfriendly outbound list of said first proxy per user account.
10 . The system of claim 9 , wherein when a user logs into said first proxy server and presents said one or more unique authentication credentials, said first proxy server checks an identity of said user.
11 . The system of claim 10 , wherein upon a successful authentication of said user's identity by said first proxy server, said first proxy server either checks said text of said client's requested web resource(s) or URL against at least one of said friendly outbound list of the particular user account or said unfriendly outbound list of the particular user account.
12 . The system of claim 2 , wherein one or more different types of user accounts further includes a type of user account without administrative privileges or the ability to view information on additional user accounts.
13 . The system of claim 2 , wherein said one or more different types of user accounts is configured with access levels ranging from no access to all access.
14 . A versatile customizable combination system for providing filtering of outbound requests for access to web sites on the Internet or for controlling inbound requests for access to web resources protected by said system, or for filtering both outbound requests for access to web sites on the Internet and controlling inbound requests from the Internet for access to web resources protected by said system, said system having at least one user account, said system comprising:
one or more user computers, wherein each of the said one or more user computers comprises either a dynamically allocated Internet protocol address or a static Internet protocol address; the one or more user computers comprising one or more hardware processors and comprising memory, wherein the memory stores executable instructions, the executable instructions comprising: an administrative module; wherein said administrative module is located in one of the one or more user computers, a first proxy server in at least one of the said one or more user computers; wherein the first proxy server has access to the world wide web; wherein said first proxy server is configured by the administrative module; wherein said first proxy server further comprises at least one of a friendly inbound list and an unfriendly inbound list; wherein said first proxy server is programmed to:
receive a request from said requesting client,
check one or more identity attributes of said requesting client against one or more of the friendly inbound list and the unfriendly inbound list;
either approve said request from said requesting client, terminate said request from said requesting client, or re-route said request from said requesting client; and
wherein said requesting client is at least an HTTP (Hypertext Transfer Protocol) application or a web browser.
15 . The system of claim 14 , wherein the executable instructions comprising:
wherein said administrative module configures one or more different access levels, and wherein said administrative module is configured to create one or more different types of user accounts, wherein each of the said one or more different types of user accounts requires one or more unique authentication credentials; wherein said administrative module configures at least one of a friendly inbound list and an unfriendly inbound list of said first proxy per user account.
16 . The system of claim 15 , wherein when a user logs into said first proxy server and presents said one or more unique authentication credentials, said first proxy server checks an identity of said user.
17 . The system of claim 16 , wherein upon a successful authentication of said user's identity by said first proxy, the said user logs into the system.
18 . The system of claim 16 , wherein said first proxy server, upon a failed authentication of said user, will either offer said user an opportunity to login again, deny said request from said requesting client, or re-route said request from said requesting client to replacement resources.
19 . The system of claim 15 , wherein upon a successful authentication of said user's identity by said first proxy server, said first proxy server either checks said one or more identity attributes of said requesting client against at least one of said friendly inbound list of the particular user account or said unfriendly inbound list of the particular user account.
20 . A versatile customizable combination system for providing filtering of outbound requests for access to web sites on the Internet or for filtering both outbound requests and inbound requests from the providing for access to web resources protected by said system, said system having at least one user account, said system comprising:
one or more user computers, wherein each of the said one or more user computers comprises either a dynamically allocated Internet protocol address or a static Internet protocol address; the one or more user computers comprising one or more hardware processors and comprising memory, wherein the memory stores executable instructions, the executable instructions comprising: an administrative module; wherein said administrative module is located in one of the one or more user computers, wherein said administrative module configures one or more different access levels, and wherein said first proxy server further comprises at least one of a friendly outbound list and an unfriendly outbound list; a first proxy server in at least one of the said one or more user computers; wherein the first proxy server has access to the world wide web; wherein said first proxy server is configured by the administrative module; wherein said first proxy server is programmed to:
receive a request from said requesting client,
either approve said request from said requesting client, terminate said request from said requesting client, or re-route said request from said requesting client;
wherein said requesting client is at least an HTTP (Hypertext Transfer Protocol) application or a web browser.
21 . The system of claim 20 , wherein the executable instructions comprising:
wherein said administrative module is configured to create one or more different types of user accounts, wherein each of the said one or more different types of user accounts requires one or more unique authentication credentials; wherein said administrative module configures one or more different access levels per user account; and wherein said administrative module configures at least one of a friendly outbound list and an unfriendly outbound list per user account.
22 . The system of claim 21 , wherein when as user logs into said first proxy server and presents said one or more unique authentication credentials, said first proxy server checks an identity of said user.
23 . The system of claim 22 , wherein upon a successful authentication of said user's identity by said first proxy, the said user logs into the system.
24 . The system of claim 22 , wherein upon a successful authentication of said user's identity by said first proxy server, said first proxy server either checks said text of said client's requested web resource(s) or URL-against at least one of said friendly outbound list of the particular user account or said unfriendly outbound list of the particular user account.
25 . The system of claim 22 , wherein said first proxy server, upon a failed authentication of said user, will either offer said user an opportunity to login again, deny said request from said requesting client, or re-route said request from said requesting client to replacement resources.Join the waitlist — get patent alerts
Track US2015281182A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.