US2019312859A1PendingUtilityA1

Authenticated bypass of default security countermeasures

Assignee: SHAPE SECURITY INCPriority: Jul 1, 2014Filed: Jun 25, 2019Published: Oct 10, 2019
Est. expiryJul 1, 2034(~7.9 yrs left)· nominal 20-yr term from priority
Inventors:Siying Yang
G06F 21/55H04L 63/168H04L 63/1441H04L 63/083H04L 63/20H04L 63/105G06F 21/14H04L 63/145H04L 63/1416H04L 67/02
66
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques for authenticated bypass of default security countermeasures are described. A request for an electronic resource, generated at a client computing device, is received. A security token generated at the client computing device, generated using a shared secret comprising a token recipe, is received. The security token received from the client computing device is validated. Validating the security token includes verifying an identity of the client computing device. Based on validating the security token, a level of trust for the client computing device is determined. Based on the level of trust for the client computing device, a modified set of security countermeasures is selected based on a default set of one or more security countermeasures that interfere with an ability of malware to interact with the electronic resource on the client computing device. The modified set of countermeasures is applied to the request for the electronic resource.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer system comprising:
 one or more hardware processors;   a memory coupled to the one or more hardware processors and storing one or more instructions which, when executed by the one or more hardware processors, cause the one or more hardware processors to:   receive a request for an electronic resource generated at a client computing device;   receive a security token generated at the client computing device using a shared secret comprising a token recipe;   validate the security token received from the client computing device, wherein validating the security token includes verifying an identity of the client computing device;   determine, based on validating the security token, a level of trust for the client computing device;   select, based on the level of trust for the client computing device, a modified set of security countermeasures based on a default set of one or more security countermeasures that interfere with an ability of malware to interact with the electronic resource on the client computing device;   apply the modified set of countermeasures to the request for the electronic resource.   
     
     
         2 . The system of  claim 1 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to provide, to the client computing device, one or more updates that cause the client computing device to generate the security token using the token recipe and the one or more updates. 
     
     
         3 . The system of  claim 1 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to provide, at a prior time, the token recipe via at least one secure channel to the client computing device. 
     
     
         4 . The system of  claim 1 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to:
 register the client computing device at the prior time;   provide the token recipe to the client computing device via a secure channel when the client computing device is registered.   
     
     
         5 . The system of  claim 1 , wherein the determining the level of trust for the client computing device comprises determining that the client computing device is whitelisted based on validating the security token. 
     
     
         6 . The system of  claim 5 , wherein selecting the modified set of security countermeasures comprises selecting no security countermeasures based on determining that the client computing device is whitelisted. 
     
     
         7 . The system of  claim 1 , wherein the security token is included in the request generated at the client computing device. 
     
     
         8 . The system of  claim 1 , wherein at least one security measure of the one or more security countermeasures causes the one or more processors to:
 insert, into the electronic resource, to produce a modified electronic resource, instrumentation code that is programmed to execute on the client computing device and to monitor one or more interactions by other resources on the client computing device with the modified electronic resource; and   send the modified electronic resource to the client computing device.   
     
     
         9 . The system of  claim 1 , wherein at least one security measure of the one or more security countermeasures causes the one or more processors to send the electronic resource, without any alterations, to the client computing device. 
     
     
         10 . The system of  claim 1 , wherein the one or more processors are further configured to:
 receive a second request from a second client computing device for the electronic resource;   determine that a second security token received from the second client computing device is invalid;   in response to determining that the second security token is invalid, select a default set of security countermeasures to be applied to the request for the electronic resource.   
     
     
         11 . A method comprising:
 receiving a request for an electronic resource generated at a client computing device;   receiving a security token generated at the client computing device using a shared secret comprising a token recipe;   validating the security token received from the client computing device, wherein validating the security token includes verifying an identity of the client computing device;   determining, based on validating the security token, a level of trust for the client computing device;   selecting, based on the level of trust for the client computing device, a modified set of security countermeasures based on a default set of one or more security countermeasures that interfere with an ability of malware to interact with the electronic resource on the client computing device;   applying the modified set of countermeasures to the request for the electronic resource;   wherein the method is performed by one or more computing devices.   
     
     
         12 . The method of  claim 11 , further comprising providing, to the client computing device, one or more updates that cause the client computing device to generate the security token using the token recipe and the one or more updates. 
     
     
         13 . The method of  claim 11 , further comprising providing, at a prior time, the token recipe via at least one secure channel to the client computing device. 
     
     
         14 . The method of  claim 11 , wherein further comprising:
 registering the client computing device at the prior time;   providing the token recipe to the client computing device via a secure channel when the client computing device is registered.   
     
     
         15 . The method of  claim 11 , wherein the determining the level of trust for the client computing device comprises determining that the client computing device is whitelisted based on validating the security token. 
     
     
         16 . The method of  claim 15 , wherein selecting the modified set of security countermeasures comprises selecting no security countermeasures based on determining that the client computing device is whitelisted. 
     
     
         17 . The method of  claim 11 , wherein the security token is included in the request generated at the client computing device. 
     
     
         18 . The method of  claim 11 , further comprising:
 inserting, into the electronic resource, to produce a modified electronic resource, instrumentation code that is programmed to execute on the client computing device and to monitor one or more interactions by other resources on the client computing device with the modified electronic resource; and   sending the modified electronic resource to the client computing device.   
     
     
         19 . The method of  claim 11 , wherein at least one security measure of the one or more security countermeasures causes the one or more processors to send the electronic resource, without any alterations, to the client computing device. 
     
     
         20 . The method of  claim 11 , further comprising:
 receiving a second request from a second client computing device for the electronic resource;   determining that a second security token received from the second client computing device is invalid;   in response to determining that the second security token is invalid, selecting a default set of security countermeasures to be applied to the request for the electronic resource.

Join the waitlist — get patent alerts

Track US2019312859A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.