US2019373012A1PendingUtilityA1

Detecting and deploying countermeasures against an autonomous browser

Assignee: SHAPE SECURITY INCPriority: Feb 12, 2016Filed: Jun 18, 2019Published: Dec 5, 2019
Est. expiryFeb 12, 2036(~9.5 yrs left)· nominal 20-yr term from priority
G06F 2221/2103G06F 21/568G06F 2221/2133G06F 21/60H04L 2463/144H04L 63/1441G06F 21/554
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A computer system configured to improve security of server computers interacting with client computers, the system comprising: one or more processors executing instructions that cause the one or more processors to: select, from the plurality of detection tests, one or more first detection tests to be performed by a client computer; send, to the client computer, a first set of detection instructions that define the one or more first detection tests, and which when executed causes generating a first set of results that identifies a first set of characteristics of the client computer; receive the first set of results from the client computer; select one or more first countermeasures from a plurality of countermeasures based on the first set of characteristics identified in the first set of results; send, to the client computer, a first set of countermeasure instructions that define the one or more first countermeasures.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer system configured to improve security of one or more server computers interacting with one or more client computers, the system comprising:
 one or more processors;   a memory coupled to the one or more processors and storing a set of instructions that define a plurality of detection tests and which, when executed by the one or more processors, cause the one or more processors to:   select, from the plurality of detection tests, one or more first detection tests to be performed by a client computer;   send, to the client computer, a first set of detection instructions that define the one or more first detection tests, and which when executed causes generating a first set of results that identifies a first set of characteristics of the client computer;   receive the first set of results from the client computer;   select one or more first countermeasures from a plurality of countermeasures based on the first set of characteristics identified in the first set of results;   send, to the client computer, a first set of countermeasure instructions that define the one or more first countermeasures.   
     
     
         2 . The computer system of  claim 1 , wherein:
 the first set of characteristics indicates that the client computer is executing an instance of a particular browser;   the one or more first countermeasures are targeted toward the particular browser;   the one or more first countermeasures are associated with the particular browser; and   the one or more first countermeasures are selected based on determining that the one or more first countermeasures are associated with the particular browser.   
     
     
         3 . The computer system of  claim 1 , further comprising instructions which when executed cause the one or more processors to:
 select, from the plurality of detection tests, one or more second detection tests to be performed by the client computer, wherein the one or more second detection tests are different than the one or more first detection tests;   send, to the client computer, a second set of detection instructions that define the one or more second detection tests, and which when executed causes generating a second set of data that identifies a second set of characteristics of the client computer;   receive the second set of data from the client computer;   wherein selecting the one or more first countermeasures from the plurality of countermeasures is also based on the second set of data.   
     
     
         4 . The computer system of  claim 3 , wherein:
 a particular detection test among the one or more first detection tests is associated with the one or more second detection tests;   the first set of results indicates a particular result based on the particular detection test;   the one or more second detection tests are selected in response to determining that the first set of results included the particular result.   
     
     
         5 . The computer system of  claim 1 , wherein the first set of results indicates that the client computer is executing an instance of a particular browser that matches one or more characteristics of a first browser and a second browser;
 wherein the computer system further comprises instructions which when executed cause the one or more processors to:   select, from the plurality of detection tests, one or more second detection tests to be performed by the client computer, wherein the one or more second detection tests are associated with the first browser and the second browser, and the one or more second detection tests are different than the one or more first detection tests;   send, to the client computer, a second set of detection instructions that define the one or more second detection tests, and which when executed causes generating a second set of data that identifies a second set of characteristics of the client computer;   receive, from the client computer, the second set of data that identify the second set of characteristics;   determine, from the second set of characteristics, that the particular browser that is being executed by the client computer is the first browser and not the second browser;   determine that the one or more first countermeasures are associated with the first browser;   wherein selecting the one or more first countermeasures from the plurality of countermeasures is based on determining that the one or more first countermeasures are associated with the first browser.   
     
     
         6 . The computer system of  claim 1 , wherein a particular detection test, among the one or more first detection tests, detects whether a human user has provided input. 
     
     
         7 . The computer system of  claim 1 , wherein a particular detection test of the one or more first detection tests detects whether the client computer was physically moved. 
     
     
         8 . The computer system of  claim 1 , further comprising instructions which when executed cause the one or more processors to:
 receive, from a server computer among the one or more server computers, one or more original instructions to be sent to a browser being executed on the client computer;   send, to the client computer, the one or more original instructions with the first set of detection instructions;   select, from the plurality of detection tests, one or more second detection tests to be performed by the client computer;   send, to the client computer, the first set of detection instructions that define the one or more first detection tests, and which when executed causes generating a first set of data that identifies the first set of characteristics of the client computer.   
     
     
         9 . A method to improve security of one or more server computers interacting with one or more client computers, the method comprising:
 selecting, from a plurality of detection tests, one or more first detection tests to be performed by a client computer;   send, to the client computer, a first set of detection instructions that define the one or more first detection tests, and which when executed causes generating a first set of results that identifies a first set of characteristics of the client computer;   receiving the first set of results from the client computer;   selecting one or more first countermeasures from a plurality of countermeasures based on the first set of characteristics identified in the first set of results;   sending, to the client computer, a first set of countermeasure instructions that define the one or more first countermeasures;   wherein the method is performed by one or more computer processors.   
     
     
         10 . The method of  claim 9 , wherein:
 the first set of characteristics indicates that the client computer is executing an instance of a particular browser;   the one or more first countermeasures are targeted toward the particular browser;   the one or more first countermeasures are associated with the particular browser; and   the one or more first countermeasures are selected based on determining that the one or more first countermeasures are associated with the particular browser.   
     
     
         11 . The method of  claim 9 , further comprising:
 selecting, from the plurality of detection tests, one or more second detection tests to be performed by the client computer, wherein the one or more second detection tests are different than the one or more first detection tests;   sending, to the client computer, a second set of detection instructions that define the one or more second detection tests, and which when executed causes generating a second set of data that identifies a second set of characteristics of the client computer;   receiving the second set of data from the client computer;   wherein selecting the one or more first countermeasures from the plurality of countermeasures is also based on the second set of data.   
     
     
         12 . The method of  claim 11 , wherein:
 a particular detection test among the one or more first detection tests is associated with the one or more second detection tests;   the first set of results indicates a particular result based on the particular detection test;   the one or more second detection tests are selected in response to determining that the first set of results included the particular result.   
     
     
         13 . The method of  claim 9 , wherein the first set of results indicates that the client computer is executing an instance of a particular browser that matches one or more characteristics of a first browser and a second browser, and the method further comprising:
 selecting, from the plurality of detection tests, one or more second detection tests to be performed by the client computer, wherein the one or more second detection tests are associated with the first browser and the second browser, and the one or more second detection tests are different than the one or more first detection tests;   sending, to the client computer, a second set of detection instructions that define the one or more second detection tests, and which when executed causes generating a second set of data that identifies a second set of characteristics of the client computer;   receiving, from the client computer, the second set of data that identify the second set of characteristics;   determining, from the second set of characteristics, that the particular browser that is being executed by the client computer is the first browser and not the second browser;   determining that the one or more first countermeasures are associated with the first browser;   wherein selecting the one or more first countermeasures from the plurality of countermeasures is based on determining that the one or more first countermeasures are associated with the first browser.   
     
     
         14 . The method of  claim 9 , wherein a particular detection test, of the one or more first detection tests, detects whether a human user has provided input. 
     
     
         15 . The method of  claim 9 , wherein a particular detection test, of the one or more first detection tests, detects whether the client computer was physically moved. 
     
     
         16 . The method of  claim 9 , further comprising:
 receiving, from a server computer among the one or more server computers, one or more original instructions to be sent to a browser being executed on the client computer;   sending, to the client computer, the one or more original instructions with the first set of detection instructions;   selecting, from the plurality of detection tests, one or more second detection tests to be performed by the client computer;   sending, to the client computer, the first set of detection instructions that define the one or more first detection tests, and which when executed causes generating a first set of data that identifies the first set of characteristics of the client computer.

Join the waitlist — get patent alerts

Track US2019373012A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.