US2018270256A1PendingUtilityA1

Detecting the execution of alien content on a client computing device

Assignee: SHAPE SECURITY INCPriority: Mar 15, 2013Filed: May 14, 2018Published: Sep 20, 2018
Est. expiryMar 15, 2033(~6.6 yrs left)· nominal 20-yr term from priority
H04L 63/145H04L 63/1425H04L 63/1416H04L 67/02H04L 63/1466H04L 63/1483G06F 21/552G06F 21/54G06F 21/128
57
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques detecting the execution of alien content on a client computing device are provided. A set of web code is supplemented with a set of instrumentation code, which when executed at a client computing device, collects and reports information that describes execution of the set of web code at the client computing device, wherein the client computing device receives the set of web code and the set of instrumentation code. A set of information is received from the client computing device that is generated by the set of instrumentation code when the set of instrumentation code is executed at the client computing device. The presence of alien content interacting with the set of web code on the client computing device is determined based on the set of information.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer system comprising:
 one or more hardware processors;   memory coupled to the one or more hardware processors and storing one or more instructions, which when executed by the one or more hardware processors, cause the one or more hardware processors to:
 supplement a set of web code with a set of instrumentation code, which when executed at a client computing device, collects and reports information that describes execution of the set of web code at the client computing device, wherein the client computing device receives the set of web code and the set of instrumentation code; 
 receive, from the client computing device, a set of information generated by the set of instrumentation code when the set of instrumentation code is executed at the client computing device; and 
 determine the presence of alien content interacting with the set of web code on the client computing device based on the set of information. 
   
     
     
         2 . The computer system of  claim 1 , wherein the information that describes execution of the set of web code at the client computing device comprises a representation of at least a portion of a document object model generated at the client computing device. 
     
     
         3 . The computer system of  claim 2 , wherein the representation comprises one or more hashes of one or more objects in the document object model. 
     
     
         4 . The computer system of  claim 1 , wherein determining the presence of the alien content comprises comparing the set of information received from the client computing device with other data generated by execution of the set of web code at one or more other client computing devices. 
     
     
         5 . The computer system of  claim 4 , wherein comparing the set of information received from the client computing device comprises clustering data received from instrumentation code executing at a plurality of client computing devices. 
     
     
         6 . The computer system of  claim 1 , wherein determining the presence of the alien content comprises comparing the set of information received from the client computing device with data generated by clustering data received from instrumentation code executing on a plurality of client computing devices. 
     
     
         7 . The computer system of  claim 1 , wherein the one or more instructions, when executed, cause the one or more hardware processors to:
 determine that the alien content on the client computing device corresponds to benign content.   
     
     
         8 . The computer system of  claim 1 , wherein the benign content includes a known browser plug-in. 
     
     
         9 . The computer system of  claim 1 , wherein the one or more instructions, when executed, cause the one or more hardware processors to:
 determine, based on the set of information, that the alien content on the client computing device is malicious content.   
     
     
         10 . The computer system of  claim 9 , wherein the one or more instructions, when executed, cause the one or more hardware processors to:
 in response to determining that the alien content is malicious content, terminate one or more requests from the client computer.   
     
     
         11 . A method comprising:
 supplementing a set of web code with a set of instrumentation code, which when executed at a client computing device, collects and reports information that describes execution of the set of web code at the client computing device, wherein the client computing device receives the set of web code and the set of instrumentation code;   receiving, from the client computing device, a set of information generated by the set of instrumentation code when the set of instrumentation code is executed at the client computing device; and   determining, the presence of alien content interacting with the set of web code on the client computing device based on the set of information;   wherein the method is performed by one or more computing devices.   
     
     
         12 . The method of  claim 11 , wherein the information that describes execution of the set of web code at the client computing device comprises a representation of at least a portion of a document object model generated at the client computing device. 
     
     
         13 . The method of  claim 12 , wherein the representation comprises one or more hashes of one or more objects in the document object model. 
     
     
         14 . The method of  claim 11 , wherein determining the presence of the alien content comprises comparing the set of information received from the client computing device with other data generated by execution of the set of web code at one or more other client computing devices. 
     
     
         15 . The method of  claim 14 , wherein comparing the set of information received from the client computing device comprises clustering data received from instrumentation code executing at a plurality of client computing devices. 
     
     
         16 . The method of  claim 11 , wherein determining the presence of the alien content comprises comparing the set of information received from the client computing device with data generated by clustering data received from instrumentation code executing on a plurality of client computing devices. 
     
     
         17 . The method of  claim 11 , further comprising:
 determining that the alien content on the client computing device corresponds to benign content.   
     
     
         18 . The method of  claim 11 , wherein the benign content includes a known browser plug-in. 
     
     
         19 . The method of  claim 11 , further comprising:
 determining, based on the set of information, that the alien content on the client computing device is malicious content.   
     
     
         20 . The method of  claim 19 , further comprising:
 in response to determining that the alien content is malicious content, terminating one or more requests from the client computer.

Join the waitlist — get patent alerts

Track US2018270256A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.