Mitigating scripted attacks using dynamic polymorphism
Abstract
In an embodiment, a data processing system comprises one or more processors; script analysis logic coupled to the one or more processors and configured to obtain a particular electronic document from a server computer; script injection logic coupled to the one or more processors and configured to insert a set of script code into source code of the electronic document to result in producing a modified electronic document prior to providing the modified electronic document to a client computer; wherein the script code is configured to run upon loading in the client computer and to cause transforming, when running in the client computer, one or more values of one or more elements of the source code of the electronic document into obfuscated values of the one or more elements.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer system configured to improve resistance of a client computer to attacks and comprising:
a memory comprising a set of processor logic; and one or more hardware processors coupled to the memory, wherein the set of processor logic, when executed by the one or more hardware processors, cause the one or more hardware processors to: generate a set of code that defines an element with a first value and one or more instructions, which when executed by the client computer causes the client computer to:
at a first time, transform the first value of the element to produce a second value based on the first value and a first transform operation, wherein the second value is different than the first value; and
at a second time that is subsequent to the first time, transform the second value of the element to a third value based on the second value and a second transform operation, wherein the third value is different than the first value and the second value;
send the set of code to the client computer.
2 . The computer system of claim 1 , wherein the set of code defines the first transform operation and the second transform operation.
3 . The computer system of claim 1 , wherein the element comprises an attribute and the first value is assigned to the attribute.
4 . The computer system of claim 1 , wherein the second value is a first combination of two or more segments of an obfuscated value, and the third value is a second combination of the two or more segments of the obfuscated value.
5 . The computer system of claim 4 , wherein the first combination and the second combination are randomly selected combinations.
6 . The computer system of claim 4 , wherein the first combination and the second combination are pseudo-randomly selected combinations.
7 . The computer system of claim 1 , wherein a first interval of time between the first time and the second time is selected randomly.
8 . The computer system of claim 7 , further comprising:
the set of code further causing the client computer, at a third time that is subsequent to the second time, to transform the third value of the element to a fourth value based on the third value, wherein the fourth value is different than the first value, the second value, and the third value; wherein a second interval of time between the second time and the third time is selected randomly and is different from the first interval of time.
9 . The computer system of claim 1 , wherein a first interval of time between the first time and the second time is selected pseudo-randomly.
10 . The computer system of claim 9 , further comprising:
the set of code further causing the client computer, at a third time that is subsequent to the second time, to transform the third value of the element to a fourth value based on the third value, wherein the fourth value is different than the first value, the second value, and the third value; wherein a second interval of time between the second time and the third time is selected pseudo-randomly and is different from the first interval of time.
11 . A method for improving resistance of a client computer to attacks, the method comprising:
at a client computer, receiving a set of code that defines an element with a first value and one or more instructions; using the client computer, at a first time, transforming the first value of the element to produce a second value based on the first value and a first transform operation, wherein the second value is different than the first value; and using the client computer, at a second time that is subsequent to the first time, transforming the second value of the element to a third value based on the second value and a second transform operation, wherein the third value is different than the first value and the second value.
12 . The method of claim 11 , wherein the set of code defines the first transform operation and the second transform operation.
13 . The method of claim 11 , wherein the element comprises an attribute, and the first value is assigned to the attribute.
14 . The method of claim 11 , wherein the second value is a first combination of two or more segments of an obfuscated value, and the third value is a second combination of the two or more segments of the obfuscated value.
15 . The method of claim 14 , wherein the first combination and the second combination are randomly selected combinations.
16 . The method of claim 14 , wherein the first combination and the second combination are pseudo-randomly selected combinations.
17 . The method of claim 11 , wherein a first interval of time between the first time and the second time is selected randomly.
18 . The method of claim 17 , the method further comprising:
at a third time that is subsequent to the second time, transform the third value of the element to a fourth value based on the third value, wherein the fourth value is different than the first value, the second value, and the third value; wherein a second interval of time between the second time and the third time is selected randomly and is different from the first interval of time.
19 . The method of claim 11 , wherein a first interval of time between the first time and the second time is selected pseudo-randomly.
20 . The method of claim 19 , the method further comprising:
at a third time that is subsequent to the second time, transform the third value of the element to a fourth value based on the third value, wherein the fourth value is different than the first value, the second value, and the third value; wherein a second interval of time between the second time and the third time is selected pseudo-randomly and is different from the first interval of time.Join the waitlist — get patent alerts
Track US2016359901A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.