Filter Appliance Remapping Ambiguous Domains to Unique IPs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current web filters cannot uniquely identify and block access to domains that share IP addresses and SSL certificates with other domains, leading to ambiguity in filtering policies.

Innovation Solution

A method and apparatus that remap ambiguous network domains to unique IP addresses, intercept DNS queries, and manage access by replacing destination IP addresses in HTTP requests, allowing for effective filtering of nonsecure and secure traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If web filters use standard DNS mapping to domains, then domains can be accessed using their public IP addresses, but domains that share IP addresses and SSL certificates cannot be uniquely identified for filtering

Engineering Contradiction:
Improvefiltering accuracyVSAvoiddomain identification precision
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces a filter appliance as an intermediary component between the client device and the domain. This appliance intercepts DNS queries, performs remapping to unique IP addresses for domains that share public IPs, and manages HTTP requests by replacing destination IP addresses. The intermediary resolves the identification ambiguity by creating a one-to-one mapping between ambiguous domains and unique internal IP addresses, enabling precise filtering without modifying the public DNS infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If domains share public IP addresses to reduce hosting costs, then resource utilization improves, but web filtering capability deteriorates due to inability to uniquely identify domains

Engineering Contradiction:
ImproveIP address sharing capabilityVSAvoidfiltering policy enforcement
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the IP address space into public shared IP addresses and private unique IP addresses. The filter appliance creates a virtual segmentation where each ambiguous domain is mapped to a distinct internal IP address, allowing filtering policies to be applied individually to each domain despite their shared public IP. This segmentation enables the filtering system to treat each domain independently while preserving the cost benefits of shared public IP addressing.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If the filter appliance remaps ambiguous domains to unique IP addresses, then domain identification precision improves, but network infrastructure complexity increases

Engineering Contradiction:
Improvedomain identification precisionVSAvoidfilter appliance complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The filter appliance is designed to perform multiple functions: DNS query interception and remapping, HTTP request management with IP address replacement, SSL certificate verification, and filtering policy enforcement. By consolidating these diverse functions into a single multi-functional device, the patent reduces the need for multiple separate components, thereby managing complexity while achieving precise domain identification and filtering.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10257157B2Restricting communication over an encrypted network connection to internet domains that share common IP addresses and shared SSL certificates
Publication Date: 2019.04.09 IBOSS INC
  • US10257157B2 patent drawing
  • US10257157B2 patent drawing
  • US10257157B2 patent drawing

AI summary

An apparatus prevents communication by a client device to a domain that cannot be uniquely identified by relocating the DNS mapping of the domain to a destination IP Address that is uniquely identifiable and that represents a location of an apparatus that provides a data path to the domain.