×

Walled garden system for providing access to one or more websites that incorporate content from other websites and method thereof

  • US 8,448,231 B2
  • Filed: 10/05/2010
  • Issued: 05/21/2013
  • Est. Priority Date: 10/05/2010
  • Status: Active Grant
First Claim
Patent Images

1. A walled garden system for providing access from user devices to one or more websites specified on a cleared sites list, the cleared sites list having one or more hostname descriptors, the walled garden system comprising:

  • a firewall device having rules associated with a cleared internet protocol (IP) list including one or more cleared IP addresses corresponding to websites on the cleared sites list, wherein the cleared sites list contains a list of external websites accessible by a user and specified by either IP addresses or hostnames;

    the firewall device for permitting direct transfer of only cleared hypertext transfer protocol (HTTP) requests from a user device, wherein each of the cleared HTTP requests is to a cleared destination IP address that matches one of the cleared IP addresses; and

    a controller for examining non-cleared HTTP requests from the user device, wherein each of the non-cleared HTTP requests is to a non-cleared destination IP address that does not match one of the cleared IP addresses,the controller for acting as a transparent proxy between the user device and a non-cleared destination IP address of a non-cleared HTTP request when any of a destination host header and a referrer header of the non-cleared HTTP request matches a hostname descriptor of the cleared sites list, andthe controller for blocking the non-cleared HTTP request when neither of the destination host header nor the referrer header of the non-cleared HTTP request matches a hostname descriptor of the cleared sites list;

    wherein the controller is further configured to;

    add, with a first expiry setting, the destination IP address of the non-cleared HTTP request to the cleared IP addresses of the firewall device when the destination host header of the non-cleared HTTP request matches a hostname descriptor of the cleared sites list; and

    add, with a second expiry setting, the destination IP address of the non-cleared HTTP request to the cleared IP addresses of the firewall device when only the referrer header of the non-cleared HTTP request matches a hostname descriptor of the cleared sites list.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×