Dynamically analyzing third-party application website certificates across users to detect malicious activity
Abstract
A verification server provides certificate verification services to users of third-party application sites. In some embodiments, a verifier component of a user's client device provides the verification server with a certificate of a third-party application site, and the verification server indicates whether the certificate is successfully verified. In response to successful verification, the verifier component of the user's client device takes an action such as permitting the user's credentials to be provided to the third-party application site. In some embodiments, verifier components of numerous client devices provide certificates to the verification server, based on which the verification server learns which certificates are valid for a given third-party application site.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method performed on a client device, the computer-implemented method comprising:
requesting, by a web browser for a user, a web page of a third-party application web site; receiving the web page and a corresponding certificate from the third-party application web site; computing, by a plugin of the web browser of the client device, a fingerprint of the certificate; sending, by the plugin to a server, the fingerprint of the certificate and an identifier of the third-party application; receiving, by the plugin from the server, an indication that the fingerprint of the certificate matches a known fingerprint of a certificate of the third-party application that was reported to the server by client devices other than the client device, the reporting being performed by plugins of web browsers of the client devices other than the client device; and responsive to receiving the indication, automatically sending, by the plugin without express user confirmation, credentials of the user to the third-party application.
2 . A non-transitory computer-readable storage medium storing executable instructions that when executed by a processor of a client device perform actions comprising:
requesting, for a user, a web page of a third-party application web site; receiving the web page and a corresponding certificate from the third-party application web site; sending, to a server by a verifier component of the client device, a representation of the certificate and an identifier of the third-party application; receiving an indication from the server that the representation matches a stored certificate representation of the third-party application; and responsive to receiving the indication, permitting, by the verifier component, credentials of the user to be provided to the third-party application.
3 . The non-transitory computer-readable storage medium of claim 2 , the actions further comprising computing a fingerprint of the certificate as the certificate representation.
4 . The non-transitory computer-readable storage medium of claim 2 , wherein the verifier component is a web browser plugin.
5 . The non-transitory computer-readable storage medium of claim 2 , wherein the client device is a smartphone, and the verifier component is a security application installed on the smartphone.
6 . The non-transitory computer-readable storage medium of claim 2 , further comprising:
requesting, for a user, a web page of a second third-party application web site; receiving the web page and a corresponding second certificate; sending, to the server by the verifier component of the client device, a second representation of the second certificate and an identifier of the second third-party application; receiving a second indication from the server that the second representation fails to match a stored certificate representation of the second third-party application.
7 . The non-transitory computer-readable storage medium of claim 6 , further comprising:
responsive to receiving the second indication:
initiating a virtual private network (VPN) connection with a trusted server,
using the VPN connection to communicate with the second third-party application,
receiving a third certificate from the second third-party application website,
sending, to the server by the verifier component of the client device, a third representation of the third certificate and an identifier of the second third-party application,
receiving a third indication from the server that the third representation matches a stored certificate representation of the second third-party application, and
responsive to receiving the third indication, ceasing to use the VPN connection for communication with the second third-party application site.
8 . A computer-implemented method performed on a client device, the computer-implemented method comprising:
requesting, for a user, a web page of a third-party application web site; receiving the web page and a corresponding certificate from the third-party application web site; sending, to a server by a verifier component of the client device, a representation of the certificate and an identifier of the third-party application; receiving an indication from the server that the representation matches a stored certificate representation of the third-party application; and responsive to receiving the indication, permitting, by the verifier component, credentials of the user to be provided to the third-party application.
9 . The computer-implemented method of claim 8 , further comprising computing a fingerprint of the certificate as the certificate representation.
10 . The computer-implemented method of claim 8 , wherein the verifier component is a web browser plugin.
11 . The computer-implemented method of claim 8 , wherein the client device is a smartphone, and the verifier component is a security application installed on the smartphone.
12 . The computer-implemented method of claim 8 , further comprising:
requesting, for a user, a web page of a second third-party application website; receiving the web page and a corresponding second certificate; sending, to the server by the verifier component of the client device, a second representation of the second certificate and an identifier of the second third-party application; receiving a second indication from the server that the second representation fails to match a stored certificate representation of the second third-party application.
13 . The computer-implemented method of claim 12 , further comprising:
responsive to receiving the second indication:
initiating a virtual private network (VPN) connection with a trusted server,
using the VPN connection to communicate with the second third-party application,
receiving a third certificate from the second third-party application website,
sending, to the server by the verifier component of the client device, a third representation of the third certificate and an identifier of the second third-party application,
receiving a third indication from the server that the third representation matches a stored certificate representation of the second third-party application, and
responsive to receiving the third indication, ceasing to use the VPN connection for communication with the second third-party application site.Join the waitlist — get patent alerts
Track US2021083881A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.