×

Enhanced server to client session inspection

  • US 8,037,528 B2
  • Filed: 09/17/2007
  • Issued: 10/11/2011
  • Est. Priority Date: 09/17/2007
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • receiving, by an inspection device positioned in a network between a client and a server, a request from the client for response data from the server, the request including a specification of one or more forms of transforming the response data sent by the server in response to the request, wherein the one or more forms of transforming comprise at least one of encrypting the response data or compressing the response data;

    modifying, by the inspection device, the request in a manner designed to prevent the server from transforming the response data in accordance with the specification;

    sending, by the inspection device, the modified request to the server;

    receiving, by the inspection device, the response data from the server;

    determining, by the inspection device, if the response data is transformed in accordance with the specification despite the modification of the request;

    if the response data is not transformed in accordance with the specification, inspecting, by the inspection device, the response data for malicious content; and

    if the response data is transformed in accordance with the specification, concluding, by the inspection device, the server is untrustworthy and taking one or more predetermined actions.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×