CA2598227C - Mapping an encrypted https network packet to a specific url name and other data without decryption outside of a secure web server - Google Patents

Mapping an encrypted https network packet to a specific url name and other data without decryption outside of a secure web server Download PDF

Info

Publication number
CA2598227C
CA2598227C CA2598227A CA2598227A CA2598227C CA 2598227 C CA2598227 C CA 2598227C CA 2598227 A CA2598227 A CA 2598227A CA 2598227 A CA2598227 A CA 2598227A CA 2598227 C CA2598227 C CA 2598227C
Authority
CA
Canada
Prior art keywords
network
request packet
module
web server
plug
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Lifetime
Application number
CA2598227A
Other languages
English (en)
French (fr)
Other versions
CA2598227A1 (en
Inventor
Paul Fredric Klein
Jesse Nicholas Perez
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
International Business Machines Corp
Original Assignee
International Business Machines Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Family has litigation
First worldwide family litigation filed litigation Critical https://patents.darts-ip.com/?family=36273444&utm_source=google_patent&utm_medium=platform_link&utm_campaign=public_patent_search&patent=CA2598227(C) "Global patent litigation dataset” by Darts-ip is licensed under a Creative Commons Attribution 4.0 International License.
Application filed by International Business Machines Corp filed Critical International Business Machines Corp
Publication of CA2598227A1 publication Critical patent/CA2598227A1/en
Application granted granted Critical
Publication of CA2598227C publication Critical patent/CA2598227C/en
Anticipated expiration legal-status Critical
Expired - Lifetime legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425Traffic logging, e.g. anomaly detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/16Implementing security features at a particular protocol layer
    • H04L63/168Implementing security features at a particular protocol layer above the transport layer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/02Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Storage Device Security (AREA)
  • Computer And Data Communications (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Peptides Or Proteins (AREA)
  • Information Transfer Between Computers (AREA)
CA2598227A 2005-02-28 2006-02-20 Mapping an encrypted https network packet to a specific url name and other data without decryption outside of a secure web server Expired - Lifetime CA2598227C (en)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
US11/067,990 2005-02-28
US11/067,990 US7657737B2 (en) 2005-02-28 2005-02-28 Method for mapping an encrypted https network packet to a specific url name and other data without decryption outside of a secure web server
PCT/EP2006/060107 WO2006089879A1 (en) 2005-02-28 2006-02-20 Mapping an encrypted https network packet to a specific url name and other data without decryption outside of a secure web server

Publications (2)

Publication Number Publication Date
CA2598227A1 CA2598227A1 (en) 2006-08-31
CA2598227C true CA2598227C (en) 2014-10-07

Family

ID=36273444

Family Applications (1)

Application Number Title Priority Date Filing Date
CA2598227A Expired - Lifetime CA2598227C (en) 2005-02-28 2006-02-20 Mapping an encrypted https network packet to a specific url name and other data without decryption outside of a secure web server

Country Status (10)

Country Link
US (1) US7657737B2 (https=)
EP (1) EP1854243B1 (https=)
JP (1) JP4596554B2 (https=)
CN (1) CN100544289C (https=)
AT (1) ATE441264T1 (https=)
BR (1) BRPI0608276B1 (https=)
CA (1) CA2598227C (https=)
DE (1) DE602006008749D1 (https=)
TW (1) TWI362871B (https=)
WO (1) WO2006089879A1 (https=)

Families Citing this family (19)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7865511B2 (en) 2004-06-25 2011-01-04 Apple Inc. News feed browser
US8612844B1 (en) * 2005-09-09 2013-12-17 Apple Inc. Sniffing hypertext content to determine type
US7882091B2 (en) * 2008-01-09 2011-02-01 Stephen Schneider Record tagging, storage and filtering system and method
US20100132007A1 (en) * 2008-11-25 2010-05-27 Cisco Technology, Inc. Accelerating channel change time with external picture property markings
US8850013B2 (en) * 2010-05-10 2014-09-30 Jaron Waldman Server load balancing using geodata
KR20120132013A (ko) * 2011-05-27 2012-12-05 주식회사 팬택 휴대용 단말, 휴대용 단말의 하드웨어 모듈간에 전송되는 데이터의 보안 방법
CN102811426A (zh) * 2011-05-30 2012-12-05 网秦无限(北京)科技有限公司 移动设备的消息的加密发送和接收的方法和系统
TWI581124B (zh) * 2012-01-13 2017-05-01 精品科技股份有限公司 網際網路之資料封包防護系統與方法
US9176838B2 (en) 2012-10-19 2015-11-03 Intel Corporation Encrypted data inspection in a network environment
US9043593B2 (en) * 2013-03-11 2015-05-26 International Business Machines Corporation Session attribute propagation through secure database server tiers
GB2516050A (en) * 2013-07-09 2015-01-14 Ibm A Network Security System
CN103701819B (zh) * 2013-12-30 2017-04-05 北京网康科技有限公司 超文本传输协议解密的处理方法及装置
CN105812345B (zh) * 2014-12-31 2019-08-23 广州市动景计算机科技有限公司 一种实现网页到客户端通信的方法及装置
US9774572B2 (en) * 2015-05-11 2017-09-26 Salesforce.Com, Inc. Obfuscation of references to network resources
JP6700894B2 (ja) * 2016-03-25 2020-05-27 キヤノン株式会社 画像処理装置、制御方法、プログラム
CN109165511B (zh) * 2018-08-08 2022-07-15 深圳前海微众银行股份有限公司 Web安全漏洞处理方法、系统及计算机可读存储介质
EP4611313A3 (en) 2020-05-04 2025-09-10 Juniper Networks, Inc. Efficient encryption and decryption of duplicate packets communicated via a virtual private network
US11575653B2 (en) * 2020-05-04 2023-02-07 Juniper Networks, Inc. Efficient encryption and decryption of duplicate packets communicated via a virtual private network
EP4009602B1 (en) * 2020-12-07 2022-11-09 Siemens Healthcare GmbH Providing a first digital certificate and a dns response

Family Cites Families (30)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP3263878B2 (ja) * 1993-10-06 2002-03-11 日本電信電話株式会社 暗号通信システム
WO1998011702A1 (en) 1996-09-10 1998-03-19 Accrue Software, Inc. Apparatus and methods for capturing, analyzing and viewing live network information
GB2319705B (en) * 1996-11-21 2001-01-24 Motorola Ltd Arrangement for encryption/decryption of data and data carrier incorporating same
US6065046A (en) * 1997-07-29 2000-05-16 Catharon Productions, Inc. Computerized system and associated method of optimally controlled storage and transfer of computer programs on a computer network
US6092196A (en) * 1997-11-25 2000-07-18 Nortel Networks Limited HTTP distributed remote user authentication system
US6148336A (en) * 1998-03-13 2000-11-14 Deterministic Networks, Inc. Ordering of multiple plugin applications using extensible layered service provider with network traffic filtering
US6363477B1 (en) * 1998-08-28 2002-03-26 3Com Corporation Method for analyzing network application flows in an encrypted environment
US6324648B1 (en) * 1999-12-14 2001-11-27 Gte Service Corporation Secure gateway having user identification and password authentication
US6510464B1 (en) * 1999-12-14 2003-01-21 Verizon Corporate Services Group Inc. Secure gateway having routing feature
US7325127B2 (en) * 2000-04-25 2008-01-29 Secure Data In Motion, Inc. Security server system
US7673329B2 (en) * 2000-05-26 2010-03-02 Symantec Corporation Method and apparatus for encrypted communications to a secure server
US20020035559A1 (en) * 2000-06-26 2002-03-21 Crowe William L. System and method for a decision engine and architecture for providing high-performance data querying operations
US20020035681A1 (en) * 2000-07-31 2002-03-21 Guillermo Maturana Strategy for handling long SSL messages
US8364798B2 (en) * 2001-01-23 2013-01-29 Verizon Business Global Llc Method and system for providing software integration for a telecommunications services on-line procurement system
US9219708B2 (en) * 2001-03-22 2015-12-22 DialwareInc. Method and system for remotely authenticating identification devices
US7409714B2 (en) 2001-06-13 2008-08-05 Mcafee, Inc. Virtual intrusion detection system and method of using same
US7149892B2 (en) * 2001-07-06 2006-12-12 Juniper Networks, Inc. Secure sockets layer proxy architecture
GB0119488D0 (en) * 2001-08-10 2001-10-03 Cellectivity Ltd E-commerce method for mobile telephones
US20030065941A1 (en) * 2001-09-05 2003-04-03 Ballard Clinton L. Message handling with format translation and key management
US6970918B2 (en) * 2001-09-24 2005-11-29 International Business Machines Corporation System and method for transcoding support of web content over secure connections
US7010608B2 (en) * 2001-09-28 2006-03-07 Intel Corporation System and method for remotely accessing a home server while preserving end-to-end security
US7181141B1 (en) * 2001-11-02 2007-02-20 Ciena Corporation Method and system for collecting network topology in an optical communications network
US7093121B2 (en) * 2002-01-10 2006-08-15 Mcafee, Inc. Transferring data via a secure network connection
JP2003209570A (ja) * 2002-01-11 2003-07-25 Fujitsu Ltd 中継方法そのクライアント、サーバ、中継装置
US20030163608A1 (en) * 2002-02-21 2003-08-28 Ashutosh Tiwary Instrumentation and workload recording for a system for performance testing of N-tiered computer systems using recording and playback of workloads
US7260623B2 (en) * 2002-06-27 2007-08-21 Sun Microsystems, Inc. Remote services system communication module
JP3794491B2 (ja) * 2002-08-20 2006-07-05 日本電気株式会社 攻撃防御システムおよび攻撃防御方法
US7386723B2 (en) * 2002-11-22 2008-06-10 Intel Corporation Method, apparatus and system for compressing IPSec-protected IP packets
US7412539B2 (en) * 2002-12-18 2008-08-12 Sonicwall, Inc. Method and apparatus for resource locator identifier rewrite
US7627669B2 (en) * 2003-05-21 2009-12-01 Ixia Automated capturing and characterization of network traffic using feedback

Also Published As

Publication number Publication date
EP1854243A1 (en) 2007-11-14
EP1854243B1 (en) 2009-08-26
BRPI0608276A2 (pt) 2009-12-15
JP4596554B2 (ja) 2010-12-08
ATE441264T1 (de) 2009-09-15
JP2008532398A (ja) 2008-08-14
US7657737B2 (en) 2010-02-02
TW200640217A (en) 2006-11-16
BRPI0608276B1 (pt) 2019-02-05
CA2598227A1 (en) 2006-08-31
US20060195687A1 (en) 2006-08-31
CN100544289C (zh) 2009-09-23
TWI362871B (en) 2012-04-21
CN101107812A (zh) 2008-01-16
WO2006089879A1 (en) 2006-08-31
DE602006008749D1 (de) 2009-10-08

Similar Documents

Publication Publication Date Title
CA2598227C (en) Mapping an encrypted https network packet to a specific url name and other data without decryption outside of a secure web server
US6351810B2 (en) Self-contained and secured access to remote servers
US6442687B1 (en) System and method for secure and anonymous communications
US8539224B2 (en) Obscuring form data through obfuscation
US8145898B2 (en) Encryption/decryption pay per use web service
US6874084B1 (en) Method and apparatus for establishing a secure communication connection between a java application and secure server
US7441116B2 (en) Secure resource distribution through encrypted pointers
US6836795B2 (en) Mapping connections and protocol-specific resource identifiers
US20090276835A1 (en) Secure cross-domain communication for web mashups
US20020174340A1 (en) System, method and computer program product for auditing XML messages in a network-based message stream
EP2371096B1 (en) Electronic file sending method
US8201238B1 (en) Remote directory browsing through a secure gateway of a virtual private network
KR20060100920A (ko) 웹 서비스를 위한 신뢰되는 제3자 인증
JP2004513453A (ja) 信頼性のある分散型ピアツーピアネットワークを確立する方法及びシステム
CN107959660A (zh) 一种基于Nginx的静态文件访问方法和装置
US20070260747A1 (en) Protecting Electronic File Transfer from Unauthorized Access or Copying
US7421576B1 (en) Interception and modification of network authentication packets with the purpose of allowing alternative authentication modes
US7765310B2 (en) Opaque cryptographic web application data protection
US8520840B2 (en) System, method and computer product for PKI (public key infrastructure) enabled data transactions in wireless devices connected to the internet
CN113645193B (zh) 网络安全防护方法、业务管理系统及计算机可读存储介质
Bhandari et al. Review Paper on Web Service Security
Kurumatani et al. Hosting a Server on a Browser Using Wemu Architecture: Secure File Sharing Service Implementation
JP2002007288A (ja) 否認防止情報管理方法、その装置及びプログラム記録媒体
Llamas Covert channel analysis and data hiding in tcp/ip
WO2002045335A1 (en) System and method for secure and anonymous communications

Legal Events

Date Code Title Description
EEER Examination request
MPN Maintenance fee for patent paid

Free format text: FEE DESCRIPTION TEXT: MF (PATENT, 19TH ANNIV.) - STANDARD

Year of fee payment: 19

U00 Fee paid

Free format text: ST27 STATUS EVENT CODE: A-4-4-U10-U00-U101 (AS PROVIDED BY THE NATIONAL OFFICE); EVENT TEXT: MAINTENANCE REQUEST RECEIVED

Effective date: 20250123

U11 Full renewal or maintenance fee paid

Free format text: ST27 STATUS EVENT CODE: A-4-4-U10-U11-U102 (AS PROVIDED BY THE NATIONAL OFFICE); EVENT TEXT: MAINTENANCE FEE PAYMENT DETERMINED COMPLIANT

Effective date: 20250123