US2023107418A1PendingUtilityA1

Security Mechanisms for Content Delivery Networks

Assignee: AT & T IP I LPPriority: Feb 26, 2021Filed: Dec 12, 2022Published: Apr 6, 2023
Est. expiryFeb 26, 2041(~14.6 yrs left)· nominal 20-yr term from priority
G06N 3/0464G06N 5/04H04L 2463/145H04L 67/10G06N 20/00H04L 67/568H04L 63/1466G06F 16/951H04L 9/50H04L 67/02H04L 63/1425G06N 3/08H04L 63/166G06F 16/955H04L 9/0643
71
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Security mechanisms for content delivery networks (“CDNs”) are disclosed herein. One security mechanism can be used to mitigate or prevent dynamic content attacks. A system can execute a CDN manager to perform operations. In particular, the CDN manager can receive a plurality of hypertext transfer protocol (“HTTP”) requests, and parse a plurality of headers from the plurality of HTTP requests to determine a plurality uniform resource locators (“URLs”). The CDN manager can generate a plurality of web page images associated with the plurality of URLs. The CDN manager can execute a machine learning algorithm, such as a convolution neural network, to perform an analysis of the plurality of web page images. Based upon the analysis of the plurality of web page images, the CDN manager can determine whether the plurality of HTTP requests are for the same web page, which can be indicative of a dynamic content attack.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 receiving, by a server of a content delivery network (“CDN”), a hash function and a hashed web page code associated with a web page, wherein the hashed web page code associated with the web page is generated by hashing a web page code associated with the web page using the hash function;   receiving, by the server of the CDN, a hypertext transfer protocol (“HTTP”) request for a requested web page, wherein the requested web page is associated with the web page code of the web page;   applying, by the server of the CDN, the hash function to a web page code of the requested web page identified in the HTTP request to generate a new hashed web page code associated with the requested web page;   comparing, by the server of the CDN, the hashed web page code with the new hashed web page code to determine if the hashed web page code and the new hashed web page code are equivalent; and   in response to determining that the hashed web page code and the new hashed web page code are not equivalent, determining, by the server of the CDN, that the HTTP request is malicious.   
     
     
         2 . The method of  claim 1 , wherein the hashed web page code associated with the web page is generated by a CDN manager executed by a processor of a server. 
     
     
         3 . The method of  claim 1 , wherein the hashed web page code associated with the web page is distributed to the server of the CDN via a distributed ledger. 
     
     
         4 . The method of  claim 1 , wherein determining that the HTTP request is malicious comprises detecting insertion of a malicious code into the web page code of the requested web page. 
     
     
         5 . The method of  claim 4 , wherein the malicious code comprises a tracking pixel. 
     
     
         6 . The method of  claim 1 , further comprising in response to determining that the HTTP request is malicious, refusing to serve the requested web page to a requesting user device. 
     
     
         7 . The method of  claim 6 , further comprising in response to determining that the hashed web page code and the new hashed web page code are equivalent, serving the requested web page to the requesting user device. 
     
     
         8 . A system comprising:
 a processor; and   a memory storing instructions that, when executed by the processor, cause the processor to perform operations comprising
 receiving a hash function and a hashed web page code associated with a web page, wherein the hashed web page code associated with the web page is generated by hashing a web page code associated with the web page using the hash function, 
 receiving a hypertext transfer protocol (“HTTP”) request for a requested web page, wherein the requested web page is associated with the web page code of the web page, 
 applying the hash function to a web page code of the requested web page identified in the HTTP request to generate a new hashed web page code associated with the requested web page, 
 comparing the hashed web page code with the new hashed web page code to determine if the hashed web page code and the new hashed web page code are equivalent, and 
 in response to determining that the hashed web page code and the new hashed web page code are not equivalent, determining that the HTTP request is malicious. 
   
     
     
         9 . The system of  claim 8 , wherein the hashed web page code associated with the web page is generated by a content delivery network (“CDN”) manager executed by a processor of a server. 
     
     
         10 . The system of  claim 8 , wherein the hashed web page code associated with the web page is distributed to the system via a distributed ledger. 
     
     
         11 . The system of  claim 8 , wherein determining that the HTTP request is malicious comprises detecting insertion of a malicious code into the web page code of the requested web page. 
     
     
         12 . The system of  claim 11 , wherein the malicious code comprises a tracking pixel. 
     
     
         13 . The system of  claim 8 , wherein the operations further comprise in response to determining that the HTTP request is malicious, refusing to serve the requested web page to a requesting user device. 
     
     
         14 . The system of  claim 13 , wherein the operations further comprise in response to determining that the hashed web page code and the new hashed web page code are equivalent, serving the requested web page to the requesting user device. 
     
     
         15 . A computer-readable storage medium comprising computer-executable instructions that, when executed by a processor of a system, cause the processor to perform operations comprising:
 receiving a hash function and a hashed web page code associated with a web page, wherein the hashed web page code associated with the web page is generated by hashing a web page code associated with the web page using the hash function;   receiving a hypertext transfer protocol (“HTTP”) request for a requested web page, wherein the requested web page is associated with the web page code of the web page;   applying the hash function to a web page code of the requested web page identified in the HTTP request to generate a new hashed web page code associated with the requested web page;   comparing the hashed web page code with the new hashed web page code to determine if the hashed web page code and the new hashed web page code are equivalent; and   in response to determining that the hashed web page code and the new hashed web page code are not equivalent, determining that the HTTP request is malicious.   
     
     
         16 . The computer-readable storage medium of  claim 15 , wherein the hashed web page code associated with the web page is generated by a content delivery network (“CDN”) manager executed by a processor of a server, and wherein the hashed web page code associated with the web page is distributed to the system via a distributed ledger. 
     
     
         17 . The computer-readable storage medium of  claim 15 , wherein determining that the HTTP request is malicious comprises detecting insertion of a malicious code into the web page code of the requested web page. 
     
     
         18 . The computer-readable storage medium of  claim 17 , wherein the malicious code comprises a tracking pixel. 
     
     
         19 . The computer-readable storage medium of  claim 15 , wherein the operations further comprise in response to determining that the HTTP request is malicious, refusing to serve the requested web page to a requesting user device. 
     
     
         20 . The computer-readable storage medium of  claim 19 , wherein the operations further comprise in response to determining that the hashed web page code and the new hashed web page code are equivalent, serving the requested web page to the requesting user device.

Join the waitlist — get patent alerts

Track US2023107418A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.