Firewall informed by web server security policy
Abstract
A user of a client device that is protected by a firewall may navigate to a website using a particular browser process (e.g., a window/tab of a browser) of the client device, sending a content request toward a web content server in the process. The firewall may intercept the content request, and may also receive information from the client device identifying which browser process initiated the content request. Before passing the content request to the appropriate web content server, the firewall may request and download a security policy from a security policy server. The security policy may notify the firewall which hosts are authorized/unauthorized for use with a particular domain, and which file types from each of these hosts are authorized/unauthorized for use with the particular domain. The firewall may then filter content related to the identified browser process based on the security policy.
Claims
exact text as granted — not AI-modified1 . A method for controlling access to digital content, the method comprising:
receiving a first policy dictating that only data of a type that matches an authorized type of data may be received from an authorized data source; receiving a request to access data at the authorized data source; identifying that the data request is for the authorized type of data from the authorized data source; and forwarding the data request to the authorized data source according the first policy, the forwarding based on the identification that the data request is for the authorized type of data from the authorized data source.
2 . The method of claim 1 , further comprising preventing a second type of data from being provided to a requesting computer based on the first policy dictating that only the data of the type that matches the authorized type of data may be received from the authorized data source.
3 . The method of claim 1 , further comprising blocking data associated with a second data request from being received from a host device based on a field of the first policy that indicates that requested data from host devices that require a reverse domain name service (DNS) mapping should be blocked.
4 . The method of claim 1 , further comprising:
receiving data associated with a second request for accessing data at a second authorized data source; identifying that the data associated with the second request includes an unauthorized type of data; and sending a reply without the second type of data to the requesting computer.
5 . The method of claim 1 , further comprising receiving a second policy that identifies a domain and a particular type of data, the second policy dictating that requests for the particular data type from the domain should be blocked.
6 . The method of claim 5 , further comprising blocking a request to retrieve the particular type of data from the domain according to the second policy.
7 . The method of claim 2 , further comprising:
identifying that the second type of data was requested from an unauthorized data source; and sending information to the requesting computer that identifies the unauthorized data source, wherein the information sent to the requesting computer results in the requesting computer blocking subsequent requests to access data from the unauthorized data source.
8 . A non-transitory computer-readable storage medium having embodied thereon a program executable by a processor for implementing a method for controlling access to digital content, the method comprising:
receiving a first policy dictating that only data of a type that matches an authorized type of data may be received from an authorized data source; receiving a request to access data at the authorized data source; identifying that the data request is for the authorized type of data from the authorized data source; and forwarding the data request to the authorized data source according the first policy, the forwarding based on the identification that the data request is for the authorized type of data from the authorized data source.
9 . The non-transitory computer-readable storage medium of claim 8 , the program further executable to prevent a second type of data from being provided to a requesting computer based on the first policy dictating that only the data of the type that matches the authorized type of data may be received from the authorized data source.
10 . The non-transitory computer-readable storage medium of claim 8 , the program further executable to block data associated with a second data request from being received from a host device based on a field of the first policy that indicates that requested data from host devices that require a reverse domain name service (DNS) mapping should be blocked.
11 . The non-transitory computer-readable storage medium of claim 1 , the program further executable to:
receive data associated with a second request for accessing data at a second authorized data source; identify that the data associated with the second request includes an unauthorized type of data; and send a reply without the second type of data to the requesting computer.
12 . The non-transitory computer-readable storage medium of claim 8 , the program further executable to receive a second policy that identifies a domain and a particular type of data, the second policy dictating that requests for the particular data type from the domain should be blocked.
13 . The non-transitory computer-readable storage medium of claim 12 , the program further executable to block a request to retrieve the particular type of data from the domain according to the second policy.
14 . The non-transitory computer-readable storage medium of claim 10 , the program further executable to:
identify that the second type of data was requested from an unauthorized data source; and send information to the requesting computer that identifies the unauthorized data source, wherein the information sent to the requesting computer results in the requesting computer blocking subsequent requests to access data from the unauthorized data source
15 . An apparatus for controlling access to digital content, the apparatus comprising:
a memory; a first policy stored in the memory that dictates that only data of a type that matches an authorized type of data may be received from an authorized data source; a processor that executes instructions out of the memory to:
compare a request to access data at the authorized data source with the first policy that dictates that only data of the type that matches the authorized type of data may be received from the authorized data source,
identify that the data request is for the authorized type of data from the authorized data source, and
prepare to forward the data request to the authorized data source according the first policy, wherein the data request is forwarding based on the identification that the data request is for the authorized type of data from the authorized data source.
16 . The apparatus of claim 15 , wherein the processor also executes instructions out of the memory to prevent a second type of data from being provided to a requesting computer based on the first policy dictating that only the data of the type that matches the authorized type of data may be received from the authorized data source.
17 . The apparatus of claim 15 , wherein the processor also executes instructions out of the memory to block data associated with a second data request from being received from a host device based on a field of the first policy that indicates that requested data from host devices that require a reverse domain name service (DNS) mapping should be blocked.
18 . The apparatus of claim 15 , wherein the processor also executes instructions out of the memory to:
receive data associated with a second request for accessing data at a second authorized data source, identify that the data associated with the second request includes an unauthorized type of data, and prepare to send a reply that does not include the second type of data to the requesting computer, wherein the reply is sent to the requesting computer without the second type of data.
19 . The apparatus of claim 15 , wherein the processor also executes instructions out of the memory to receive a second policy that identifies a domain and a particular type of data, the second policy dictating that requests for the particular data type from the domain should be blocked.
20 . The apparatus of claim 19 , wherein the processor also executes instructions out of the memory to block a request to retrieve the particular type of data from the domain according to the second policy.Join the waitlist — get patent alerts
Track US2020213278A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.