Method and apparatus for content filtering on spdy connections

US2016119288A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016119288-A1
Application numberUS-201414522251-A
CountryUS
Kind codeA1
Filing dateOct 23, 2014
Priority dateOct 23, 2014
Publication dateApr 28, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The present disclosure discloses a method and a network device for performing content filtering on SPDY connections. Specifically, a network device receives, from a client device, a first control frame identifying a first maximum number of unsolicited unacknowledged messages related to a web resource that can be transmitted by a web server. The network device transmits to the web server a second control frame identifying a second and different maximum number of unsolicited unacknowledged messages related to the web resource that can be transmitted by the web server. In some embodiments, the network device establishes a first connection with the client device without forwarding the request to the web server, and a second connection with the web server. Further, the network device inspects data in the unsolicited unacknowledged messages and forwards at least portion of the data to the client device using the first connection.

First claim

Opening claim text (preview).

What is claimed is: 1 . A non-transitory computer readable comprising instructions which, when executed by one or more hardware processors, causes performance of operations comprising: receiving, from a client device by a network device, a first control frame identifying a first maximum number of unsolicited unacknowledged messages related to a web resource that can be transmitted by a web server; transmitting, by the network device to the web server, a second control frame identifying a second maximum number of unsolicited unacknowledged messages related to the web resource that can be transmitted by the web server, wherein the second maximum number of unsolicited unacknowledged messages is different than the first maximum number of unsolicited unacknowledged messages. 2 . The medium of claim 1 , wherein the operations further comprise: based on the second control frame: receiving, by the network device from the web server, a plurality of unsolicited unacknowledged messages related to the web resource; forwarding, by the network device to the client device, data in the unsolicited unacknowledged messages related to the web resource. 3 . The medium of claim 1 , wherein the second maximum number of unsolicited unacknowledged messages related to the web resource is less than the first maximum number of unsolicited unacknowledged messages related to the web resource. 4 . The medium of claim 1 , wherein the second maximum number of unsolicited unacknowledged messages related to the web resource that can be transmitted by a web server is zero. 5 . The medium of claim 1 , wherein the second maximum number of unsolicited unacknowledged messages related to a web resource that can be transmitted by a web server is selected based on a reputation and/or category associated with the web resource. 6 . The medium of claim 1 , wherein the second maximum number of unsolicited unacknowledged messages related to a web resource that can be transmitted by a web server is dynamically selected based on data associated with the web server that was previously cached by the network device. 7 . The medium of claim 1 , wherein the second maximum number of unsolicited unacknowledged messages related to a web resource that can be transmitted by a web server is selected based on an application associated with the web resource. 8 . The medium of claim 1 , wherein the second maximum number of unsolicited unacknowledged messages related to a web resource that can be transmitted by a web server is selected based on characteristics associated with the client device. 9 . The medium of claim 1 , wherein the second maximum number of unsolicited unacknowledged messages related to a web resource that can be transmitted by a web server is selected based on prior behavior by the client device. 10 . A non-transitory computer readable comprising instructions which, when executed by one or more hardware processors, causes performance of operations comprising: receiving, from a client device by a network device, a request for a first connection with a web server to obtain a web resource; establishing, by the network device, the first connection between the network device and the client device without forwarding the request to the web server, wherein the network device functions as a proxy for the web server; establishing, by the network device, a second connection between the network device and the web server; receiving, by the network device, one or more unsolicited unacknowledged messages corresponding to the web resource from the web server via the second connection; inspecting, by the network device, data in the one or more unsolicited unacknowledged messages and forwarding at least portion of the data to the client device using the first connection. 11 . The medium of claim 10 , wherein the operations further comprise: receiving, by the network device from the client device, a first maximum number of unsolicited unacknowledged messages related to the web resource that can be transmitted by the web server; transmitting, by the network device to the web server, a second maximum number of unsolicited unacknowledged messages related to the web resource that can be transmitted by the web server, wherein the first maximum number is different than the second maximum number. 12 . The medium of claim 10 , wherein forwarding at least a portion of the data comprises filtering the data based on a reputation, category, and/or application associated with the web resource. 13 . A system comprising: at least one device including a hardware processor; the system configured to perform operations comprising: receiving, from a client device by a network device, a first control frame identifying a first maximum number of unsolicited unacknowledged messages related to a web resource that can be transmitted by a web server; transmitting, by the network device to the web server, a second control frame identifying a second maximum number of unsolicited unacknowledged messages related to the web resource that can be transmitted by the web server, wherein the second maximum number of unsolicited unacknowledged messages is different than the first maximum number of unsolicited unacknowledged messages. 14 . The system of claim 13 , wherein the operations further comprise: based on the second control frame: receiving, by the network device from the web server, a plurality of unsolicited unacknowledged messages related to the web resource; forwarding, by the network device to the client device, data in the unsolicited unacknowledged messages related to the web resource. 15 . The system of claim 13 , wherein the second maximum number of unsolicited unacknowledged messages related to the web resource is one of: (a) less than the first maximum number of unsolicited unacknowledged messages related to the web resource; and (b) zero. 16 . The system of claim 13 , wherein the second maximum number of unsolicited unacknowledged messages related to a web resource that can be transmitted by a web server is selected based on a reputation and/or category associated with the web resource. 17 . The system of claim 13 , wherein the second maximum number of unsolicited unacknowledged messages related to a web resource that can be transmitted by a web server is dynamically selected based on data associated with the web server that was previously cached by the network device. 18 . The system of claim 13 , wherein the second maximum number of unsolicited unacknowledged messages related to a web resource that can be transmitted by a web server is selected based on an application associated with the web resource. 19 . The system of claim 13 , wherein the second maximum number of unsolicited unacknowledged messages related to a web resource that can be transmitted by a web server is selected based on characteristics associated with the client device. 20 . The system of claim 13 , wherein the second maximum number of unsolicited unacknowledged messages related to a web resource that can be transmitted by a web server is selected based on prior behavior by the client device.

Assignees

Inventors

Classifications

  • Proxies · CPC title

  • based on web technology, e.g. hypertext transfer protocol [HTTP] · CPC title

  • Filtering policies (mail message filtering H04L51/212) · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016119288A1 cover?
The present disclosure discloses a method and a network device for performing content filtering on SPDY connections. Specifically, a network device receives, from a client device, a first control frame identifying a first maximum number of unsolicited unacknowledged messages related to a web resource that can be transmitted by a web server. The network device transmits to the web server a secon…
Who is the assignee on this patent?
Aruba Networks Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/0281. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Apr 28 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).