US2016359901A1PendingUtilityA1

Mitigating scripted attacks using dynamic polymorphism

Assignee: SHAPE SECURITY INCPriority: Sep 9, 2014Filed: Aug 19, 2016Published: Dec 8, 2016
Est. expirySep 9, 2034(~8.1 yrs left)· nominal 20-yr term from priority
Inventors:Siying Yang
G06F 21/54H04L 63/1491H04L 63/1441H04L 63/168H04L 67/02H04L 2209/16H04L 63/062
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In an embodiment, a data processing system comprises one or more processors; script analysis logic coupled to the one or more processors and configured to obtain a particular electronic document from a server computer; script injection logic coupled to the one or more processors and configured to insert a set of script code into source code of the electronic document to result in producing a modified electronic document prior to providing the modified electronic document to a client computer; wherein the script code is configured to run upon loading in the client computer and to cause transforming, when running in the client computer, one or more values of one or more elements of the source code of the electronic document into obfuscated values of the one or more elements.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer system configured to improve resistance of a client computer to attacks and comprising:
 a memory comprising a set of processor logic; and   one or more hardware processors coupled to the memory, wherein the set of processor logic, when executed by the one or more hardware processors, cause the one or more hardware processors to:   generate a set of code that defines an element with a first value and one or more instructions, which when executed by the client computer causes the client computer to:
 at a first time, transform the first value of the element to produce a second value based on the first value and a first transform operation, wherein the second value is different than the first value; and 
 at a second time that is subsequent to the first time, transform the second value of the element to a third value based on the second value and a second transform operation, wherein the third value is different than the first value and the second value; 
   send the set of code to the client computer.   
     
     
         2 . The computer system of  claim 1 , wherein the set of code defines the first transform operation and the second transform operation. 
     
     
         3 . The computer system of  claim 1 , wherein the element comprises an attribute and the first value is assigned to the attribute. 
     
     
         4 . The computer system of  claim 1 , wherein the second value is a first combination of two or more segments of an obfuscated value, and the third value is a second combination of the two or more segments of the obfuscated value. 
     
     
         5 . The computer system of  claim 4 , wherein the first combination and the second combination are randomly selected combinations. 
     
     
         6 . The computer system of  claim 4 , wherein the first combination and the second combination are pseudo-randomly selected combinations. 
     
     
         7 . The computer system of  claim 1 , wherein a first interval of time between the first time and the second time is selected randomly. 
     
     
         8 . The computer system of  claim 7 , further comprising:
 the set of code further causing the client computer, at a third time that is subsequent to the second time, to transform the third value of the element to a fourth value based on the third value, wherein the fourth value is different than the first value, the second value, and the third value;   wherein a second interval of time between the second time and the third time is selected randomly and is different from the first interval of time.   
     
     
         9 . The computer system of  claim 1 , wherein a first interval of time between the first time and the second time is selected pseudo-randomly. 
     
     
         10 . The computer system of  claim 9 , further comprising:
 the set of code further causing the client computer, at a third time that is subsequent to the second time, to transform the third value of the element to a fourth value based on the third value, wherein the fourth value is different than the first value, the second value, and the third value;   wherein a second interval of time between the second time and the third time is selected pseudo-randomly and is different from the first interval of time.   
     
     
         11 . A method for improving resistance of a client computer to attacks, the method comprising:
 at a client computer, receiving a set of code that defines an element with a first value and one or more instructions;   using the client computer, at a first time, transforming the first value of the element to produce a second value based on the first value and a first transform operation, wherein the second value is different than the first value; and   using the client computer, at a second time that is subsequent to the first time, transforming the second value of the element to a third value based on the second value and a second transform operation, wherein the third value is different than the first value and the second value.   
     
     
         12 . The method of  claim 11 , wherein the set of code defines the first transform operation and the second transform operation. 
     
     
         13 . The method of  claim 11 , wherein the element comprises an attribute, and the first value is assigned to the attribute. 
     
     
         14 . The method of  claim 11 , wherein the second value is a first combination of two or more segments of an obfuscated value, and the third value is a second combination of the two or more segments of the obfuscated value. 
     
     
         15 . The method of  claim 14 , wherein the first combination and the second combination are randomly selected combinations. 
     
     
         16 . The method of  claim 14 , wherein the first combination and the second combination are pseudo-randomly selected combinations. 
     
     
         17 . The method of  claim 11 , wherein a first interval of time between the first time and the second time is selected randomly. 
     
     
         18 . The method of  claim 17 , the method further comprising:
 at a third time that is subsequent to the second time, transform the third value of the element to a fourth value based on the third value, wherein the fourth value is different than the first value, the second value, and the third value;   wherein a second interval of time between the second time and the third time is selected randomly and is different from the first interval of time.   
     
     
         19 . The method of  claim 11 , wherein a first interval of time between the first time and the second time is selected pseudo-randomly. 
     
     
         20 . The method of  claim 19 , the method further comprising:
 at a third time that is subsequent to the second time, transform the third value of the element to a fourth value based on the third value, wherein the fourth value is different than the first value, the second value, and the third value;   wherein a second interval of time between the second time and the third time is selected pseudo-randomly and is different from the first interval of time.

Join the waitlist — get patent alerts

Track US2016359901A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.