US2015052607A1PendingUtilityA1

Method and system for protecting web applications against web attacks

Assignee: IMMUN IO INCPriority: Aug 15, 2013Filed: Aug 15, 2014Published: Feb 19, 2015
Est. expiryAug 15, 2033(~7.1 yrs left)· nominal 20-yr term from priority
G06F 21/554H04L 63/20G06F 21/53G06F 21/54G06F 8/65H04L 67/02G06F 21/552H04L 67/34H04L 63/1466H04L 67/1001
36
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present disclosure provided a method and system for protecting web applications against web attacks comprising a cloud service for generating rules and receiving reports, an agent manager in communication with the cloud service receiving rules from the cloud service and passing reports thereto, and an in-application agent in communication with the agent manager for receiving rules therefrom and passing reports thereto for protecting an application in which the in-application agent is embedded.

Claims

exact text as granted — not AI-modified
1 . A system for protecting a web application against a web attack, the system comprising:
 an in-application agent for applying rules for protecting the web application in which the in-application agent is embedded and for generating reports of suspicious activity;   a cloud service for providing rules, receiving the reports and generating new rules in response to the reports received without user intervention in the in-application agent; and   an agent manager in communication with the cloud service for receiving the rules from the cloud service and passing the rules received to the in-application agent and for receiving the reports from the in-application agent and passing the reports received to the cloud service.   
     
     
         2 . The system of  claim 1  wherein the cloud service dynamically updates the rules based upon new threat information received from an external source. 
     
     
         3 . The system of  claim 1  wherein the in-application agent includes a link manager for communications with the agent manager. 
     
     
         4 . The system of  claim 1  wherein the in-application agent includes hooks into the web application. 
     
     
         5 . The system of  claim 1  wherein the cloud service generates and updates rules in response to both application-level and external data sources. 
     
     
         6 . The system of  claim 1  wherein, upon receiving the new rules, the in-application agent updates a web protection configuration to use the new rules. 
     
     
         7 . The system of  claim 1  wherein the in-application agent processes the rules locally to detect and respond to a threat. 
     
     
         8 . A method of protecting a web application against a web attack, the method comprising:
 embedding an in-application agent into the web application to be protected;   generating rules in a cloud service;   providing the rules generated to the in-application agent;   applying, by the in-application agent, the rules to protect the web application in which the in-application agent is embedded.   
     
     
         9 . The method of  claim 8  further comprising:
 detecting suspicious activity by the in-application agent; 
 generating a report; and 
 sending the report to the cloud service. 
 
     
     
         10 . The method of  claim 9  further comprising, upon receiving the report at the cloud service:
 generating a new rule; and 
 sending the new rule to the in-application agent. 
 
     
     
         11 . The method of  claim 8  further comprising:
 receiving new threat information at the cloud service from an external source; 
 generating new rules; and 
 sending the new rules to the in-application agent; and 
 the in-application agent using the new rules to protect against a new threat. 
 
     
     
         12 . A non-transitory computer readable medium comprising instructions in code which when stored in a memory of a computing device and executed by a processor of the computing device cause the computing device to:
 execute an in-application agent embedded in a web application, the in-application agent including:   an in-app library for storing rules;   a rules processor for applying the rules and for generating one or more reports;   a link manager for receiving new rules from a cloud service generated in response to the one or more reports;   one or more hooks in the web application enabling the rules processor to inject the new rules into the web application.   
     
     
         13 . The computer readable medium of  claim 12  wherein the link manager communicates with the cloud service by communicating via an encrypted link with an agent manager. 
     
     
         14 . The computer readable medium of  claim 12  wherein the rules processor disables input/output operations to sandbox the new rules injected into the web application.

Join the waitlist — get patent alerts

Track US2015052607A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.