CA3023218C

Selectively altering references within encrypted pages using man in the middle

Abstract

A request addressed to a particular resource is received and a determination is made that the request should be redirected to a man-in-the-middle gateway within the network. A first encrypted connection is established between the client device and the man-in-the-middle gateway, and a second encrypted connection between the man-in-the-middle gateway and the server. The resource is modified into a modified resource by changing pointers within the particular resource to point to a location in a domain associated with the man-in-the-middle gateway within the network. The modified resource is served.

CA3023218C, drawing sheet 1
Sheet 1 of 8

Term

10.6 yearsleft in the term

Expires 2 May 2037.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

21 claims: 3 independent, 18 dependent

  1. 1
    A computer-implemented method, the method comprising:receiving, by a network gateway from a first client device within a network, a first request addressed to a particular resource on a server outside the network;determining, by the network gateway, that the first request should be redirected to a man-in-the-middle gateway within the network;redirecting, by the network gateway, the request to the man-in-the-middle gateway within the network responsive to determining that the first request should be redirected;establishing a first encrypted connection between the first client device and the man-in-the-middle gateway, and a second encrypted connection between the manin-the-middle gateway and the server;retrieving, by the man-in-the-middle-gateway, the particular resource from the server;modifying, by the man-in-the-middle gateway, the particular resource into a modified resource by changing pointers within the particular resource to point to a location in a domain associated with the man-in-the-middle gateway within the network;serving, by the man-in-the-middle-gateway to the first client device, the modified resource;Date Reçue/Date Received 2021-08-27 receiving, by the network gateway from a second client device within the network, a second request addressed to the particular resource on the server;determining, by the network gateway, that the second request should not be redirected to the man-in-the-middle gateway within the network;and responsive to determining that the second request should not be redirected to the man-in-the-middle gateway, redirecting, by the network gateway, the second request to a cloud proxy service outside of the network, the cloud proxy service configured to: establish a third encrypted connection between the second client device and the cloud proxy service, and a fourth encrypted connection between the cloud proxy service and the server;retrieve the particular resource from the server;modify the particular resource into a second modified resource by changing pointers within the particular resource;and serve the second modified resource to the second client device.
  2. 8
    A system comprising:at least one processor configured to execute computer program instructions;and a tangible, non-transitory computer storage medium encoded with computer program instructions that, when executed by the at least one processor, cause the system to perform operations comprising: receiving, by a network gateway from a first client device within a network, a first request addressed to a particular resource on a server outside the network;determining, by the network gateway that the first request should be redirected to a man-in-the-middle gateway within the network;Date Reçue/Date Received 2021-08-27 redirecting, by the network gateway, the first request to the man-in-themiddle gateway within the network responsive to determining that the first request should be redirected;establishing a first encrypted connection between the first client device and the man-in-the-middle gateway, and a second encrypted connection between the man-in-the-middle gateway and the server;retrieving, by the man-in-the-middle-gateway, the particular resource from the server;modifying, by the man-in-the-middle-gateway, the particular resource into a modified resource by changing pointers within the particular resource to point to a location in a domain associated with the man-in-the-middle gateway within the network;serving, by the man-in-the-middle-gateway to the first client device, the modified resource;receiving, by the network gateway from a second client device within the network, a second request addressed to the particular resource on the server;determining, by the network gateway that the second request should not be redirected to the man-in-the-middle gateway within the network;and responsive to determining that the second request should not be redirected to the man-in-the-middle gateway, redirecting, by the network gateway, the second request to a cloud proxy service outside of the network, the cloud proxy service configured to: Date Reçue/Date Received 2021-08-27 establish a third encrypted connection between the second client device and the cloud proxy service, and a fourth encrypted connection between the cloud proxy service and the server;retrieve the particular resource from the server;modify the particular resource into a second modified resource by changing pointers within the particular resource;and serve the second modified resource to the second client device.
  3. 15
    A non-transitory, computer-readable medium storing instructions operable when executed to cause at least one processor to perform operations comprising:receiving, by a network gateway from a first client device within a network, a first request addressed to a particular resource on a server outside the network;determining, by the network gateway, that the first request should be redirected to a man-in-the-middle gateway within the network;redirecting, by the network gateway, the first request to the man-in-the-middle gateway within the network responsive to determining that the first request should be redirected;establishing a first encrypted connection between the first client device and the man-in-the-middle gateway, and a second encrypted connection between the manin-the-middle gateway and the server;retrieving, by the man-in-the-middle-gateway, the particular resource from the server;modifying, by the man-in-the-middle gateway, the particular resource into a modified resource by changing pointers within the particular resource to point to a location in a domain associated with the man-in-the-middle gateway within the network;Date Reçue/Date Received 2021-08-27 serving, by the man-in-the-middle-gateway to the first client device, the modified resource;receiving, by the network gateway from a second client device within the network, a second request addressed to the particular resource on the server;determining, by the network gateway that the second request should not be redirected to the man-in-the-middle gateway within the network;and responsive to determining that the second request should not be redirected to the man-in-the-middle gateway, redirecting, by the network gateway, the second request to a cloud proxy service outside of the network, the cloud proxy service configured to: establish a third encrypted connection between the second client device and the cloud proxy service, and a fourth encrypted connection between the cloud proxy service and the server;retrieve the particular resource from the server;modify the particular resource into a second modified resource by changing pointers within the particular resource;and serve the second modified resource to the second client device.