US2017111312A1PendingUtilityA1

Restricting Communication Over an Encrypted Network Connection to Internet Domains that Share Common IP Addresses and Shared SSL Certificates

Assignee: IBOSS INCPriority: Apr 24, 2012Filed: Dec 29, 2016Published: Apr 20, 2017
Est. expiryApr 24, 2032(~5.7 yrs left)· nominal 20-yr term from priority
H04L 61/2007H04L 63/0823H04L 63/0227H04L 61/1511H04L 67/02H04L 63/101H04L 63/0236H04L 61/5007H04L 63/0209H04L 61/4511H04L 63/10H04L 63/166
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An apparatus prevents communication by a client device to a domain that cannot be uniquely identified by relocating the DNS mapping of the domain to a destination IP Address that is uniquely identifiable and that represents a location of an apparatus that provides a data path to the domain.

Claims

exact text as granted — not AI-modified
1 . A method of a filter appliance comprising:
 receiving a communication from an electronic device, the communication including a reference to a network domain that cannot be uniquely identified; and   remapping the network domain to an IP address having a unique identity of the network domain, wherein the IP address is not a publicly known IP address of the network domain.   
     
     
         2 . The method of  claim 1 , wherein the method comprises:
 receiving a second communication from the electronic device, the second communication including the IP address that has the unique identity of the network domain; and   forwarding the second communication.   
     
     
         3 . The method of  claim 1 , wherein the IP address of the communication further comprises:
 a destination IP address.   
     
     
         4 . The method of  claim 1 , wherein the network domain that cannot be uniquely identified further comprises:
 the network domain is associated with an IP address that is shared with another network domain; and   the network domain is associated with a SSL certificate that is shared with another network domain.   
     
     
         5 . The method of  claim 4 , wherein the IP address that is shared with another network domain further comprises:
 the IP address being identical to at least one IP address of the other network domain.   
     
     
         6 . The method of  claim 4 , wherein the network domain shares the SSL certificate with the other network domain further comprises:
 the SSL certificate of the network domain includes a wildcard character in a specification of a name of the network domain.   
     
     
         6 . The method of  claim 4 , wherein the network domain shares the SSL certificate with the other network domain further comprises:
 the SSL certificate of the network domain includes a wildcard character in a specification of a name of the network domain.   
     
     
         8 . The method of  claim 1 , wherein the IP address having the unique identity of the network domain further comprises:
 an IP address of a Relay Server.   
     
     
         9 . A method of an apparatus comprising:
 receiving from a client device a DNS Query for an Internet domain name that cannot be uniquely identified;   determining whether or not Internet domain name is designated as a remapped domain name;   sending to the client device a spoofed destination IP address in response to the DNS Query;   receiving from the client device a nonsecure HTTP request transaction using the spoofed destination IP address;   determining whether or not the nonsecure HTTP request is blocked for access by the client device;   managing access to the Internet domain name that cannot be uniquely identified by replacing the destination IP address of the nonsecure HTTP request with an IP address than can be uniquely identified, when the nonsecure HTTP request for access to the Internet domain name is not blocked;   sending a blocked access message to the client device, when the nonsecure HTTP request for access to the Internet domain name is blocked.   
     
     
         10 . The method of  claim 9 , wherein the Internet domain name that cannot be uniquely identified further comprises:
 the Internet domain name having ambiguity.   
     
     
         11 . The method of  claim 9 , wherein the Internet domain name that cannot be uniquely identified further comprises:
 the Internet domain name being mapped by an external DNS server to at least one IP address that is shared with another Internet domain the external DNS server; and   the Internet domain name having a SSL certificate that is shared with another domain.   
     
     
         12 . The method of  claim 9 , wherein the spoofed destination IP address further comprises:
 the IP address being associated with a Relay Server.   
     
     
         13 . The method of  claim 9 , wherein managing access to the Internet domain name further comprises:
 forwarding the nonsecure HTTP request to the spoofed destination IP address.   
     
     
         14 . The method of  claim 9 , wherein the determining whether or not the nonsecure HTTP request is blocked for access by the client device further comprises:
 searching a list of blocked domains for an indication that the Internet domain name is blocked for access by the client device.   
     
     
         15 . A method of managing access to an Internet domain name that cannot be uniquely identified by an apparatus, the method comprising:
 receiving a nonsecure HTTP request of a client device, the HTTP request having a spoofed destination IP address and a source IP address;   creating a session that associates the client device to the HTTP request;   changing the destination address in the HTTP request to a DNS mapped IP address of the Internet domain name, for each packet in the HTTP request, yielding a changed HTTP request;   changing the source IP address in the HTTP request from a client IP address to an IP address of a Relay Server, for each packet in the HTTP request, yielding the changed HTTP request;   sending to a domain server that is associated with the Internet domain name, each packet in the changed HTTP request;   receiving from the domain server a response to the changed HTTP request;   associating the response to client device in reference to the session, the response having a destination IP address and source IP address;   changing the destination IP address in the response to the spoofed destination IP address, yielding a changed response;   changing the source IP address in the response to the client IP address, yielding the changed response; and   forwarding the changed response to the client device.   
     
     
         16 . The method of  claim 15 , wherein HTTP request further comprises:
 a nonsecure HTTP request.   
     
     
         17 . The method of  claim 15 , wherein HTTP request further comprises:
 a secure HTTPS request.   
     
     
         18 . A hardware-based web filter appliance that prevents communication by a client device to a domain that cannot be uniquely identified, the hardware-based web filter appliance comprising:
 a first component that is operable to relocate a DNS mapping of the domain of a packet to a destination IP Address; and   a second component that is operable to forward the packet,   wherein the destination IP address is uniquely identifiable,   wherein the destination IP address represents a location of another apparatus that provides a data path to the domain.

Join the waitlist — get patent alerts

Track US2017111312A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.