Polymorphic Treatment of Data Entered At Clients
Abstract
A computer-implemented method includes identifying, in web code to be served to a client, presence of code for generating a form; generating additional, executable code to be run on the client device, the additional, executable code being arranged to identify user input on the client device and modify the form so that data from the user input is received into one or more alternative fields of the form other than a first field to which a user performing the input directed the input; receiving a request from the client device based on completion of input into the form; and converting data from the received request so that data for the one or more alternative fields of the form is directed to the first field of the form for processing by a web server system that initially generated the web code.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method, comprising:
identifying, in web code to be served to a client, presence of code for generating a form; generating additional, executable code to be run on the client device, the additional, executable code being arranged to identify user input on the client device and modify the form so that data from the user input is received into one or more alternative fields of the form other than a first field to which a user performing the input directed the input; receiving a request from the client device based on completion of input into the form; and converting data from the received request so that data for the one or more alternative fields of the form is directed to the first field of the form for processing by a web server system that initially generated the web code.
2 . The computer-implemented method of claim 1 , wherein the additional, executable code is generated by an intermediary security server system located between the web server system and the Internet, and that intercepts data served from and requests provided to the web server system.
3 . The computer-implemented method of claim 1 , wherein identifying the presence of code for generating a form comprises parsing HTML code generated by the web server system.
4 . The computer-implemented method of claim 1 , wherein identifying the presence of code for generating a form comprises at least partially rendering a web page represented by the web code, and analyzing a DOM generated by the at least partially rendering of the web page.
5 . The computer-implemented method of claim 1 , wherein the one or more alternative fields are hidden fields that are not visible to a user of the client device.
6 . The computer-implemented method of claim 5 , wherein the additional, executable code is further arranged to encrypt characters entered into the form by the user before transmitting the request.
7 . The computer-implemented method of claim 1 , wherein the additional, executable code is further arranged to insert dummy characters in the first field.
8 . The computer-implemented method of claim 1 , wherein converting the data from the received request comprises identifying data for performing a reverse transformation on data in the received request, wherein the reverse transformation corresponds to a transformation that was dictated by the additional, executable code.
9 . The computer-implemented method of claim 1 , further comprising serving code for generating the form and additional, executable code to a second client device, wherein the additional executable code is arranged to modify the form in a different manner than was the additional, executable code provided to the client device.
10 . A computer-implemented system, comprising:
one or more computer processors; and one or more tangible storage devices accessible by the one or more processors and storing instructions that, when executed, perform operations that include:
identifying, in web code to be served to a client, presence of code for generating a form;
generating additional, executable code to be run on the client device, the additional, executable code being arranged to identify user input on the client device and modify the form so that data from the user input is received into one or more alternative fields of the form other than a first field to which a user provider the user input directed the user input;
receiving a request from the client device based on completion of input into the form; and
converting data from the received request so that data for the one or more alternative fields of the form is directed to the first field of the form for processing by a web server system that initially generated the web code.
11 . The computer-implemented system of claim 10 , wherein the additional, executable code is generated by an intermediary security server system located between the web server system and the Internet, and that intercepts data served from and requests provided to the web server system.
12 . The computer-implemented system of claim 10 , wherein the one or more alternative fields are hidden fields that are not visible to a user of the client device.
13 . The computer-implemented system of claim 12 , wherein the additional, executable code is further arranged to encrypt characters entered into the form by the user before transmitting the request.
14 . The computer-implemented system of claim 10 , wherein converting the data form the received request comprises identifying data for performing a reverse transformation on data in the received request, wherein the reverse transformation corresponds to a transformation that was dictated by the additional, executable code.
15 . The computer-implemented system of claim 10 , wherein the operations further comprise serving code for generating the form and additional, executable code to a second client device, wherein the additional executable code is arranged to modify the form in a different manner than was the additional, executable code provided to the client device.
16 . A computer-implemented system, comprising:
a plurality of client devices; a web server system; and a security server system having one or more tangible, non-transient storage devices and arranged to respond to requests from the plurality of client devices by obtaining code from the web server system and modifying the code from the web server system so as to add additional, executable code to cause data input at the plurality of client devices that is entered into fields of the form that the code identifies, to be stored instead in fields that are created by supplemental code generated by the security server system.
17 . The computer-implemented system of claim 16 , wherein the security server system is further arranged to convert data from requests received from particular ones of the plurality of client devices so that data stored in the fields that are created by the supplemental code is directed to fields from an original version of the form served by the web server system.
18 . The computer-implemented system of claim 16 , wherein the fields created by the supplemental code comprise hidden fields that are not visible to a user of the client device.
19 . The computer-implemented system of claim 16 , wherein the supplemental code is arranged to insert dummy characters in the fields that the data is entered into by users.Join the waitlist — get patent alerts
Track US2017041341A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.