US2020213278A1PendingUtilityA1

Firewall informed by web server security policy

Assignee: SONICWALL US HOLDINGS INCPriority: Nov 10, 2015Filed: Nov 26, 2019Published: Jul 2, 2020
Est. expiryNov 10, 2035(~9.3 yrs left)· nominal 20-yr term from priority
H04L 61/5007H04L 61/4511H04L 63/1416H04L 67/02H04L 63/145H04L 63/20H04L 63/0245H04L 63/0263H04L 63/101G06F 16/951H04L 63/0227H04L 61/2007H04L 61/1511
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A user of a client device that is protected by a firewall may navigate to a website using a particular browser process (e.g., a window/tab of a browser) of the client device, sending a content request toward a web content server in the process. The firewall may intercept the content request, and may also receive information from the client device identifying which browser process initiated the content request. Before passing the content request to the appropriate web content server, the firewall may request and download a security policy from a security policy server. The security policy may notify the firewall which hosts are authorized/unauthorized for use with a particular domain, and which file types from each of these hosts are authorized/unauthorized for use with the particular domain. The firewall may then filter content related to the identified browser process based on the security policy.

Claims

exact text as granted — not AI-modified
1 . A method for controlling access to digital content, the method comprising:
 receiving a first policy dictating that only data of a type that matches an authorized type of data may be received from an authorized data source;   receiving a request to access data at the authorized data source;   identifying that the data request is for the authorized type of data from the authorized data source; and   forwarding the data request to the authorized data source according the first policy, the forwarding based on the identification that the data request is for the authorized type of data from the authorized data source.   
     
     
         2 . The method of  claim 1 , further comprising preventing a second type of data from being provided to a requesting computer based on the first policy dictating that only the data of the type that matches the authorized type of data may be received from the authorized data source. 
     
     
         3 . The method of  claim 1 , further comprising blocking data associated with a second data request from being received from a host device based on a field of the first policy that indicates that requested data from host devices that require a reverse domain name service (DNS) mapping should be blocked. 
     
     
         4 . The method of  claim 1 , further comprising:
 receiving data associated with a second request for accessing data at a second authorized data source;   identifying that the data associated with the second request includes an unauthorized type of data; and   sending a reply without the second type of data to the requesting computer.   
     
     
         5 . The method of  claim 1 , further comprising receiving a second policy that identifies a domain and a particular type of data, the second policy dictating that requests for the particular data type from the domain should be blocked. 
     
     
         6 . The method of  claim 5 , further comprising blocking a request to retrieve the particular type of data from the domain according to the second policy. 
     
     
         7 . The method of  claim 2 , further comprising:
 identifying that the second type of data was requested from an unauthorized data source; and   sending information to the requesting computer that identifies the unauthorized data source, wherein the information sent to the requesting computer results in the requesting computer blocking subsequent requests to access data from the unauthorized data source.   
     
     
         8 . A non-transitory computer-readable storage medium having embodied thereon a program executable by a processor for implementing a method for controlling access to digital content, the method comprising:
 receiving a first policy dictating that only data of a type that matches an authorized type of data may be received from an authorized data source;   receiving a request to access data at the authorized data source;   identifying that the data request is for the authorized type of data from the authorized data source; and   forwarding the data request to the authorized data source according the first policy, the forwarding based on the identification that the data request is for the authorized type of data from the authorized data source.   
     
     
         9 . The non-transitory computer-readable storage medium of  claim 8 , the program further executable to prevent a second type of data from being provided to a requesting computer based on the first policy dictating that only the data of the type that matches the authorized type of data may be received from the authorized data source. 
     
     
         10 . The non-transitory computer-readable storage medium of  claim 8 , the program further executable to block data associated with a second data request from being received from a host device based on a field of the first policy that indicates that requested data from host devices that require a reverse domain name service (DNS) mapping should be blocked. 
     
     
         11 . The non-transitory computer-readable storage medium of  claim 1 , the program further executable to:
 receive data associated with a second request for accessing data at a second authorized data source;   identify that the data associated with the second request includes an unauthorized type of data; and   send a reply without the second type of data to the requesting computer.   
     
     
         12 . The non-transitory computer-readable storage medium of  claim 8 , the program further executable to receive a second policy that identifies a domain and a particular type of data, the second policy dictating that requests for the particular data type from the domain should be blocked. 
     
     
         13 . The non-transitory computer-readable storage medium of  claim 12 , the program further executable to block a request to retrieve the particular type of data from the domain according to the second policy. 
     
     
         14 . The non-transitory computer-readable storage medium of  claim 10 , the program further executable to:
 identify that the second type of data was requested from an unauthorized data source; and   send information to the requesting computer that identifies the unauthorized data source, wherein the information sent to the requesting computer results in the requesting computer blocking subsequent requests to access data from the unauthorized data source   
     
     
         15 . An apparatus for controlling access to digital content, the apparatus comprising:
 a memory;   a first policy stored in the memory that dictates that only data of a type that matches an authorized type of data may be received from an authorized data source;   a processor that executes instructions out of the memory to:
 compare a request to access data at the authorized data source with the first policy that dictates that only data of the type that matches the authorized type of data may be received from the authorized data source, 
 identify that the data request is for the authorized type of data from the authorized data source, and 
 prepare to forward the data request to the authorized data source according the first policy, wherein the data request is forwarding based on the identification that the data request is for the authorized type of data from the authorized data source. 
   
     
     
         16 . The apparatus of  claim 15 , wherein the processor also executes instructions out of the memory to prevent a second type of data from being provided to a requesting computer based on the first policy dictating that only the data of the type that matches the authorized type of data may be received from the authorized data source. 
     
     
         17 . The apparatus of  claim 15 , wherein the processor also executes instructions out of the memory to block data associated with a second data request from being received from a host device based on a field of the first policy that indicates that requested data from host devices that require a reverse domain name service (DNS) mapping should be blocked. 
     
     
         18 . The apparatus of  claim 15 , wherein the processor also executes instructions out of the memory to:
 receive data associated with a second request for accessing data at a second authorized data source,   identify that the data associated with the second request includes an unauthorized type of data, and   prepare to send a reply that does not include the second type of data to the requesting computer, wherein the reply is sent to the requesting computer without the second type of data.   
     
     
         19 . The apparatus of  claim 15 , wherein the processor also executes instructions out of the memory to receive a second policy that identifies a domain and a particular type of data, the second policy dictating that requests for the particular data type from the domain should be blocked. 
     
     
         20 . The apparatus of  claim 19 , wherein the processor also executes instructions out of the memory to block a request to retrieve the particular type of data from the domain according to the second policy.

Join the waitlist — get patent alerts

Track US2020213278A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.