US2021089644A1PendingUtilityA1

Method, means, system, processor, and memory for intercepting malicious websites

Assignee: ALIBABA GROUP HOLDING LTDPriority: Apr 14, 2017Filed: Oct 14, 2020Published: Mar 25, 2021
Est. expiryApr 14, 2037(~10.7 yrs left)· nominal 20-yr term from priority
H04L 61/4511G06F 2221/2119G06F 21/53H04L 67/02H04L 69/40H04L 63/0281H04L 63/1441H04L 63/0236H04L 63/0272H04L 61/1511
43
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Embodiments of the present application relate to a method, device, and system for intercepting traffic to malicious websites. The method includes obtaining, by one or more processors, a network request from a terminal, obtaining, by one or more processors, domain information from the network request, determining, by one or more processors, whether the domain information corresponds to an access-prohibited website domain, and communicating, by one or more processors, a web page response to terminal, wherein the web page response is based at least in part on the determining whether the domain information corresponds to an access-prohibited website domain.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method, comprising:
 obtaining, by one or more processors of a terminal, information pertaining to a web page from a Domain Name Server (DNS server);   determining, by the one or more processors of the terminal, that the web page corresponds to an access-prohibited website domain based at least in part on the information pertaining to the web page;   invoking, by the one or more processors of the terminal, a command to communicate in a virtual private network connect-on-demand mode with at least the web page; and   obtaining, by the one or more processors of the terminal, the web page via a virtual private network established based at least in part on the virtual private network connect-on-demand mode.   
     
     
         2 . The method of  claim 1 , further comprising:
 communicating, by the one or more processors of the terminal, a network request to the is DNS server, wherein the network request comprises domain information.   
     
     
         3 . The method of  claim 2 , wherein the information pertaining to the web page is communicated to the terminal in response to the terminal communicating the network request to the DNS server. 
     
     
         4 . The method of  claim 2 , wherein the communicating the network request comprises:
 obtaining an application program-to-network layer network request; and   sending the network request to the DNS server, wherein the domain information comprises a domain name.   
     
     
         5 . The method of  claim 2 , wherein the obtaining the information pertaining to the web page comprises:
 in response to the DNS server determining that the domain information comprised in the network request is consistent with information stored in a mapping of domain information to access-prohibited website domains, receiving, from the DNS server, the IP address of the warning page; and   in response to the DNS server determining that the domain information comprised in the network request is not consistent with information stored in the mapping of domain information to access-prohibited website domains, receiving, from the DNS server, the IP address corresponding to the domain information comprised in the network request.   
     
     
         6 . The method of  claim 1 , further comprising:
 configuring, by the one or more processors of the terminal, one or more conditions for invoking the private network connect-on-demand mode; and   determining, by the one or more processors of the terminal, whether at least one of the one or more conditions for invoking the virtual private network connect-on-demand mode is satisfied;   wherein:
 the virtual private network is invoked in response to a determination that the at least one of the one or more conditions for invoking the virtual private network connect-on-demand mode is satisfied; and 
 the at least one of the one or more conditions comprises receiving an indication that the domain information corresponds to the access-prohibited website domain. 
   
     
     
         7 . The method of  claim 6 , wherein the one or more conditions for invoking the virtual private network connect-on-demand mode comprises one or more of:
 access of at least one preset domain name;   a network to which a terminal is connected switches to a preset WiFi network;   failure of a preset network request; and   an indication with respect to a preset domain, the indication being communicated from a designated server, and the designated server communicating the designation in response to at least one preset domain name being accessed.   
     
     
         8 . The method of  claim 1 , further comprising:
 configuring, by the one or more processors of the terminal, one or more conditions for invoking the virtual private network connect-on-demand mode, wherein the one or more conditions comprise one or more of:
 access of at least one preset domain name; 
 a network to which a terminal is connected switches to a preset WiFi network; 
 failure of a preset network request; and 
 an indication with respect to a preset domain, the indication being communicated from a designated server, and the designated server communicating the designation in response to at least one preset domain name being accessed. 
   
     
     
         9 . A device, comprising:
 one or more processors configured to:
 obtain a terminal, information pertaining to a web page from a Domain Name Server (DNS server); 
 determine that the web page corresponding to the domain information corresponds to an access-prohibited website domain based at least in part on the information pertaining to the web page; 
 invoke a command to communicate in a virtual private network connect-on-demand mode with at least the web page; and 
 obtain the web page via a virtual private network established based at least in part on the virtual private network connect-on-demand mode; and 
   one or more memories coupled to the one or more processors, configured to provide the one or more processors with instructions.   
     
     
         10 . The method of  claim 1 , further comprising:
 communicating a web page request to a remote application server based at least in part on the obtaining the information pertaining to the web page from the DNS server, wherein:
 the information pertaining to the web page comprises one of an Internet Protocol (IP) address corresponding to a warning page or an IP address corresponding to the domain information according to the determination of whether the web page corresponds to the access-prohibited website domain; 
 the web page request comprises IP address information obtained from the web page response; and 
 in response to a determination that the web page is determined to correspond to the access-prohibited website domain, the information pertaining to the web page includes information pertaining to a warning page. 
   
     
     
         11 . A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:
 obtaining, by one or more processors of a terminal, information pertaining to a web page from a Domain Name Server (DNS server);   determining, by the one or more processors of the terminal, that the web page corresponding to the domain information corresponds to an access-prohibited website domain based at least in part on the information pertaining to the web page;   invoking, by the one or more processors of the terminal, a command to communicate in a virtual private network connect-on-demand mode with at least the web page; and   obtaining, by the one or more processors of the terminal, the web page via a virtual private network established based at least in part on the virtual private network connect-on-demand mode.   
     
     
         12 . A system for intercepting malicious websites, comprising:
 a terminal, comprising:
 one or more terminal processors configured to:
 obtain information pertaining to a web page from a Domain Name Server (DNS server); 
 determine that the web page corresponding to the domain information corresponds to an access-prohibited website domain based at least in part on the information pertaining to the web page; 
 invoke a command to communicate in a virtual private network connect-on-demand mode with at least the web page; and 
 obtain the web page via a virtual private network established based at least in part on the virtual private network connect-on-demand mode; and 
 
 one or more terminal memories coupled to the one or more terminal processors, configured to provide the one or more terminal processors with instructions; and 
   the DNS server, comprising:
 one or more server processors, configured to:
 receive a network request; 
 obtain domain name information from the network request; 
 determine the information pertaining to the web page based at least in part on the domain name information; and 
 communicate the information pertaining to the web page to the terminal; and 
 
 one or more server memories coupled to the one or more server processors, configured to provide the one or more server processors with instructions. 
   
     
     
         13 . The system of  claim 12 , wherein the one or more server processors are further configured to:
 determine whether the domain name information is matches pre-saved access-prohibited website domain name information;   in response to determining that the domain name information matches the pre-saved access-prohibited website domain name information, sending an Internet Protocol (IP) address corresponding to a warning page to the terminal, the indication that the domain information corresponds to the access-prohibited website domain, or both; and   in response to determining that the domain name information is different from the pre-saved access-prohibited website domain name information, sending the an IP address corresponding to the domain information to the terminal.   
     
     
         14 . The system of  claim 12 , wherein the one or more terminal processors are further configured to:
 communicate the network request to the DNS server, wherein the network request comprises domain information.   
     
     
         15 . The system of  claim 14 , wherein the information pertaining to the web page is communicated to the terminal in response to the terminal communicating the network request to the DNS server. 
     
     
         16 . The system of  claim 12 , wherein the terminal is configured to store one or more start conditions associated with invoking the virtual private network connect-on-demand mode, the one or more start conditions comprising one or more of:
 starting the virtual private network in response to determining that at least one preset domain name is accessed;   starting the virtual private network in response to determining that the network to which the terminal is connected switches to a preset WiFi network;   starting the virtual private network in response to determining that the network to which the terminal is connected switches to a mobile network;   starting the virtual private network in response to determining that a preset network request fails; and   starting the virtual private network in response to determining, upon at least one preset domain name being accessed, that a designated server is used to perform analysis and the analysis fails.   
     
     
         17 . The system of  claim 12 , wherein the domain name information comprises a domain name. 
     
     
         18 . The system of  claim 12 , further comprising:
 a remote application server, comprising:
 one or more remote application server processors, configured to:
 receive a web page request sent by the terminal, the web page request comprising a web page address; and 
 determining a web page result based at least in part on the web page request; and 
 communicating the web page result to the terminal; and 
 
 one or more remote application server memories coupled to the one or more remote application server processors, and configured to provide the one or more remote application server processors with instructions. 
   
     
     
         19 . The system of  claim 12 , wherein the information pertaining to the web page comprises an IP address.

Join the waitlist — get patent alerts

Track US2021089644A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.