Invention Grant
- Patent Title: Encrypted network traffic interception and inspection
-
Application No.: US12818605Application Date: 2010-06-18
-
Publication No.: US08578486B2Publication Date: 2013-11-05
- Inventor: Vladimir Lifliand , Avraham Michael Ben-Menahem
- Applicant: Vladimir Lifliand , Avraham Michael Ben-Menahem
- Applicant Address: US WA Redmond
- Assignee: Microsoft Corporation
- Current Assignee: Microsoft Corporation
- Current Assignee Address: US WA Redmond
- Main IPC: G06F7/04
- IPC: G06F7/04 ; G06F12/00 ; G06F12/14 ; G06F13/00 ; G06F17/30 ; G11C7/00

Abstract:
A method of operating a computing device that allows inspecting data that the device attempts to transmit over a network in an encrypted form for presence of malware, viruses or confidential information. The method includes intercepting a request from an application to an encryption component of an operating system to encrypt the data and acquiring encrypted data generated by the encryption component in response to the request. SSL or TLS protocol may be used for encryption. The request may be intercepted using API hooking. The data in an unencrypted form and an identifier of the encrypted data may be provided to a data inspection facility for establishing a correspondence between the unencrypted and encrypted data, using the identifier. The data inspection facility performs inspection of the unencrypted data to determine whether to allow transmission of the encrypted data over the network.
Public/Granted literature
- US20110314270A1 ENCRYPTED NETWORK TRAFFIC INTERCEPTION AND INSPECTION Public/Granted day:2011-12-22
Information query