US2019243971A1PendingUtilityA1

Using instrumentation code to detect bots or malware

Assignee: SHAPE SECURITY INCPriority: Mar 15, 2013Filed: Dec 27, 2018Published: Aug 8, 2019
Est. expiryMar 15, 2033(~6.6 yrs left)· nominal 20-yr term from priority
G06F 21/566H04L 63/0428G06F 11/3644H04L 63/1441H04L 63/1483H04L 63/145G06F 21/563G06F 11/3065G06F 21/54G06F 21/51H04L 63/1416G06F 2201/865G06F 21/14G06F 21/128H04L 63/1425G06F 11/3409G06F 2221/033H04L 63/123H04L 63/0471H04L 67/01
64
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques are provided for using instrumentation code to detect bots or malware. Data corresponding to requests from a plurality of client devices for a web resource comprising web code is obtained. The web resource is hosted by a first web server system. For a first client device of the plurality of client devices, instrumentation code is served. The instrumentation code is configured to execute on the first client device to monitor execution of the web code of the web resource at the first client device. One or more responses generated by the instrumentation code at the first client device are received from the first client device. The one or more responses are based one or more interactions with the web code at the first client device.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 obtaining data corresponding to requests from a plurality of client devices for a web resource comprising web code, wherein the web resource is hosted by a first web server system;   for a first client device of the plurality of client devices, serving instrumentation code that is configured to execute on the first client device to monitor execution of the web code of the web resource at the first client device;   receiving, from the first client device, one or more responses generated by the instrumentation code at the first client device based one or more interactions with the web code at the first client device;   wherein the method is performed by one or more computing devices.   
     
     
         2 . The method of  claim 1 , wherein the one or more responses comprises a report indicating that the instrumentation code, when executing at the first client device, detected abnormal behavior at the first client device. 
     
     
         3 . The method of  claim 1 ,
 wherein the instrumentation code is configured to report execution of a particular operation with respect to the web resource;   wherein the instrumentation code, when executing at the first client device, detects performance of the particular operation at the first client device and transmits a report in response to detecting the performance of the particular operation.   
     
     
         4 . The method of  claim 1 ,
 wherein the instrumentation code is configured to report a call to a particular method with respect to the web resource;   wherein the instrumentation code, when executing at the first client device, detects the call to the particular method at the first client device and transmits a report in response to detecting the call to the particular method.   
     
     
         5 . The method of  claim 1 ,
 wherein the instrumentation code is configured to detect a change to a Document Object Model (DOM) corresponding to the web resource;   wherein the instrumentation code, when executing at the first client device, detects the change to the DOM and transmits a response in response to detecting the change to the DOM.   
     
     
         6 . The method of  claim 1 ,
 wherein the instrumentation code, when executing at the first client device, collects information that characterizes interactions with the web code;   wherein the one or more responses comprises at least a portion of the information collected at the first client device.   
     
     
         7 . The method of  claim 6 , wherein the information that characterizes interactions with the web code comprises at least one of key strokes and mouse movements. 
     
     
         8 . The method of  claim 6 , wherein the interactions with the web code comprises changes in focus between particular elements of the web code. 
     
     
         9 . The method of  claim 6 , wherein the information that characterizes interactions with the web code comprises timing information of interactions with the web code. 
     
     
         10 . The method of  claim 1 , wherein serving the web code comprises serving modified web code comprising the instrumentation code. 
     
     
         11 . The method of  claim 1 , further comprising:
 receiving a plurality of security reports generated by instrumentation code executing on the plurality of computing devices that requested the web resource hosted by the first web server system, the plurality of security reports including the one or more responses generated by the instrumentation code at the first client device;   analyzing the plurality of security reports to determine abstracted information about security threats from the plurality of security reports;   generating one or more updated security measures for the first web server system that hosts the web resource based on analyzing the plurality of security reports.   
     
     
         12 . The method of  claim 1 , further comprising:
 receiving a plurality of security reports generated by instrumentation code executing on the plurality of computing devices that requested the web resource from a first web server system and a second plurality of computing devices that requested one or more other web resources other from one or more other web server systems different from the first web server system;   wherein the plurality of security reports includes the one or more responses generated by the instrumentation code at the first client device;   analyzing the plurality of security reports to determine abstracted information about security threats from the plurality of security reports;   generating one or more updated security measures for a plurality of web server systems based on analyzing the plurality of security reports.   
     
     
         13 . A computer system comprising:
 one or more hardware processors;   a memory coupled to the one or more hardware processors and storing one or more instructions which, when executed by the one or more hardware processors, cause the one or more hardware processors to:   obtain data corresponding to requests from a plurality of client devices for a web resource comprising web code, wherein the web resource is hosted by a first web server system;   for a first client device of the plurality of client devices, serve instrumentation code that is configured to execute on the first client device to monitor execution of the web code of the web resource at the first client device;   receive, from the first client device, one or more responses generated by the instrumentation code at the first client device based one or more interactions with the web code at the first client device.   
     
     
         14 . The computer system of  claim 13 ,
 wherein the instrumentation code is configured to report execution of a particular operation with respect to the web resource;   wherein the instrumentation code, when executing at the first client device, detects performance of the particular operation at the first client device and transmits a report in response to detecting the performance of the particular operation.   
     
     
         15 . The computer system of  claim 13 ,
 wherein the instrumentation code is configured to report a call to a particular method with respect to the web resource;   wherein the instrumentation code, when executing at the first client device, detects the call to the particular method at the first client device and transmits a report in response to detecting the call to the particular method.   
     
     
         16 . The computer system of  claim 13 ,
 wherein the instrumentation code is configured to detect a change to a Document Object Model (DOM) corresponding to the web resource;   wherein the instrumentation code, when executing at the first client device, detects the change to the DOM and transmits a response in response to detecting the change to the DOM.   
     
     
         17 . The computer system of  claim 13 ,
 wherein the instrumentation code, when executing at the first client device, collects information that characterizes interactions with the web code;   wherein the one or more responses comprises at least a portion of the information collected at the first client device.   
     
     
         18 . The computer system of  claim 17 , wherein the information that characterizes interactions with the web code comprises at least one of key strokes, mouse movements, changes in focus between particular elements of the web code, and timing information of interactions with the web code. 
     
     
         19 . The computer system of  claim 13 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to:
 receive a plurality of security reports generated by instrumentation code executing on the plurality of computing devices that requested the web resource hosted by the first web server system, the plurality of security reports including the one or more responses generated by the instrumentation code at the first client device;   analyze the plurality of security reports to determine abstracted information about security threats from the plurality of security reports;   generate one or more updated security measures for the first web server system that hosts the web resource based on analyzing the plurality of security reports.   
     
     
         20 . The computer system of  claim 13 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to:
 receive a plurality of security reports generated by instrumentation code executing on the plurality of computing devices that requested the web resource from a first web server system and a second plurality of computing devices that requested one or more other web resources other from one or more other web server systems different from the first web server system;   wherein the plurality of security reports includes the one or more responses generated by the instrumentation code at the first client device;   analyze the plurality of security reports to determine abstracted information about security threats from the plurality of security reports;   generate one or more updated security measures for a plurality of web server systems based on analyzing the plurality of security reports.

Join the waitlist — get patent alerts

Track US2019243971A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.