US2019140835A1PendingUtilityA1

Blind Hash Compression

Assignee: SHAPE SECURITY INCPriority: Jan 21, 2014Filed: Dec 30, 2018Published: May 9, 2019
Est. expiryJan 21, 2034(~7.5 yrs left)· nominal 20-yr term from priority
H04L 9/3239G06F 21/577H04L 9/3236H04L 2209/30H04L 63/0876H04L 9/0643H04L 2209/16H04L 63/0428
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques are provided for blind hash compression, such as serving, from a computer server system and to a plurality of different computing devices remote from the computer server system, web code and code for reporting status of the computing devices; receiving from one or more of the computing devices, first data that indicates a parameter of the one or more computing devices, the first data in a compressed format; receiving from one or more others of the computing devices, second data that indicates the parameter of the one or more others of the computing devices, the second data in an uncompressed format; and compressing the second data and comparing the compressed second data to the first data to correlate the first data to the second data. The code for reporting status of the computing devices can include code for allowing the computing devices to determine whether to send the first or second data.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method, comprising:
 serving, from a computer server system and to a plurality of different computing devices remote from the computer server system, web code that has been recoded to obscure its operation from malware that may be operating on the different computing devices;   receiving from different ones of the computing devices, an obfuscated representation of a particular parameter for a first of the computing devices, and a nonobfuscated representation of the same parameter for a second of the computing devices;   obfuscating the unobfuscated representation of the particular parameter, and comparing the obfuscated representation for the second of the computing devices with the obfuscated representation for the first of the computing devices; and   based on a determination that the obfuscated representations correspond to each other, correlating the obfuscated representation to the unobfuscated representation on the computer server system,   wherein the code for reporting parameters of the computing devices includes code for allowing the computing devices to determine whether to send an obfuscated representation or an unobfuscated representation.   
     
     
         2 . The computer-implemented method of  claim 1 , wherein the code for allowing the computing devices to determine whether to send an obfuscated representation or an unobfuscated representation comprises biasing data that affects a frequency with which the computing devices select to send the plaintext representation or the hashed representation. 
     
     
         3 . The computer-implemented method of  claim 1 , further comprising:
 receiving from the computing devices, unobfusctaed representations and obfuscated representations of a plurality of different parameters of the computing devices;   obfuscating the received unobfuscated representations to created obfuscated values; and   using correlations between the obfuscated values and the received unobfuscated representations to identify parameters represented by the obfuscated representations.   
     
     
         4 . The computer-implemented method of  claim 1 , further comprising using the obfuscated representation and the unobfuscated representation to identify characteristics of malware executing on the computing devices. 
     
     
         5 . A computer-implemented method, comprising:
 serving, from a computer server system and to a plurality of different computing devices remote from the computer server system, web code and code for reporting status of the computing devices;   receiving from one or more of the computing devices, first data that indicates a parameter of the one or more computing devices, the first data in a compressed format;   receiving from one or more others of the computing devices, second data that indicates the parameter of the one or more others of the computing devices, the second data in an uncompressed format; and   compressing the second data and comparing the compressed second data to the first data to correlate the first data to the second data,   wherein the code for reporting status of the computing devices includes code for allowing the computing devices to determine whether to send the first data or the second data.   
     
     
         6 . The computer-implemented method of  claim 5 , wherein the code for allowing the computing devices to determine whether to send the first data or the second data comprises biasing data that affects a frequency with which the computing devices select to send the first data or the second data. 
     
     
         7 . The computer-implemented method of  claim 5 , wherein the first data is compressed on the computing devices using hashing. 
     
     
         8 . The computer-implemented method of  claim 7 , wherein the server system does not send hashing algorithm information to the computing devices. 
     
     
         9 . The computer-implemented method of  claim 5 , further comprising using the compressed format to represent the parameter in identifying aggregate activity by multiple of the computing devices. 
     
     
         10 . The computer-implemented method of  claim 9 , further comprising determining from the aggregate activity by multiple of the computer devices whether ones of the multiple computing devices is infected with malware. 
     
     
         11 . The computer-implemented method of  claim 5 , wherein the computer server system comprises an intermediary security server system that is separate from a web server system that generates and serves the web code. 
     
     
         12 . The computer-implemented method of  claim 5 , further comprising comparing information sent with the compressed second data to information derived from the received first data to determine whether the compressed second data was generated from data that matches the first data. 
     
     
         13 . One or more non-transitory storage devices storing instructions that, when executed by one or more computer processors, perform operations comprising:
 serving, from a computer server system and to a plurality of different computing devices remote from the computer server system, web code and code for reporting status of the computing devices;   receiving from one or more of the computing devices, first data that indicates a parameter of the one or more computing devices, the first data in a compressed format;   receiving from one or more others of the computing devices, second data that indicates the parameter of the one or more others of the computing devices, the second data in an uncompressed format; and   compressing the second data and comparing the compressed second data to the first data to correlate the first data to the second data,   wherein the code for reporting status of the computing devices includes code for allowing the computing devices to determine whether to send the first data or the second data.   
     
     
         14 . The one or more non-transitory storage devices of  claim 13 , wherein the code for allowing the computing devices to determine whether to send the first data or the second data comprises biasing data that affects a frequency with which the computing devices select to send the first data or the second data. 
     
     
         15 . The one or more non-transitory storage devices of  claim 13 , wherein the first data is compressed on the computing devices using hashing. 
     
     
         16 . The one or more non-transitory storage devices of  claim 13 , wherein the operations further comprise using the compressed format to represent the parameter in identifying aggregate activity by multiple of the computing devices. 
     
     
         17 . The one or more non-transitory storage devices of  claim 16 , wherein the operations further comprise determining from the aggregate activity by multiple of the computer devices whether ones of the multiple computing devices is infected with malware. 
     
     
         18 . The one or more non-transitory storage devices of  claim 13 , wherein the computer server system comprises an intermediary security server system that is separate from a web server system that generates and serves the web code. 
     
     
         19 . The one or more non-transitory storage devices of  claim 13 , wherein the operations further comprise comparing information sent with the compressed second data to information derived from the received first data to determine whether the compressed second data was generated from data that matches the first data.

Join the waitlist — get patent alerts

Track US2019140835A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.