US2017324772A1PendingUtilityA1

Systems and methods for identifying internet attacks

Assignee: CLEARFY S R LPriority: Nov 13, 2014Filed: Oct 28, 2015Published: Nov 9, 2017
Est. expiryNov 13, 2034(~8.3 yrs left)· nominal 20-yr term from priority
G06F 2221/2119H04L 43/08H04L 63/1466H04L 67/02H04L 41/0273G06F 21/554G06F 2221/032H04L 63/1416
35
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present disclosure relates to a system ( 1 ) and a method that employs such system ( 1 ) to detect and counteract Internet attacks of Man-in-the-Browser and/or Man-in-the-Middle type. The system ( 1 ) comprises a Traffic Inspector ( 2 ) in signal communication with a client computer ( 3 ) having a Web browser ( 4 ) residing therein for Internet browsing and with a Web server ( 5 ) having a Web application ( 6 ) residing therein. The Traffic Inspector ( 2 ) is configured to receive a request associated with the Web application ( 6 ) from the Web browser ( 4 ) and to send it to the Web browser ( 5 ), the Traffic Inspector ( 2 ) is configured to receive a DOM server code associated with the request from the Web server ( 5 ). The system is characterized in that it comprises a Traffic Analyzer ( 7 ) in signal communication with the Traffic Inspector ( 2 ) and having an algorithm application ( 8 ) residing therein, the Traffic Inspector ( 2 ) is configured to add a default code portion to the DOM server code to thereby generate a DOM client code to be sent to the Web browser ( 4 ) to receive a DOM rendered code associated with the DOM client code, the Traffic Inspector ( 2 ) is configured to send the DOM client code and the DOM rendered code to the Traffic Analyzer ( 7 ), the algorithm application ( 8 ) is configured to process the DOM rendered code to compare it with the DOM client code, to thereby identify at least one code difference.

Claims

exact text as granted — not AI-modified
1 . A system for identifying Internet attacks, characterized by comprising:
 a Traffic Inspector in signal communication with at least one client computer having a Web browser residing therein for Internet browsing and with a Web server having a Web application residing therein,   said Traffic Inspector being configured to receive at least one request associated with said Web application from said Web browser and to send said request to said Web browser when it is requested by a user of said client computer via said Web browser,   said Traffic Inspector being configured to receive a request-related DOM server code from said Web server,   a Traffic Analyzer having an algorithm application residing therein, said Traffic Analyzer being in signal communication with said Traffic Inspector,   said Traffic Inspector being configured to add an agent code portion to said DOM server code, to thereby generate a DOM client code and send said DOM client code to said Web browser,   said Traffic Inspector is configured to receive a DOM rendered code associated with said DOM client code from said Web browser,   said Traffic Inspector is configured to send at least said DOM client code and said DOM rendered code to said Traffic Analyzer,   said algorithm application is configured to process said DOM rendered code and compare it with said DOM client code to identify at least one code difference.   
     
     
         2 . The system as claimed in  claim 1 , wherein said Traffic Inspector is configured to receive at least said request associated with said Web application from said Web browser using the HTTP or HTTPS protocol and to send said request to said Web server. 
     
     
         3 . The system as claimed in  claim 1 , wherein said DOM server code is a HTML and/or Javascript code associated with said request, said agent code portion is a HTML and/or Javascript code, said DOM client code comprises at least said DOM server code and said agent code portion. 
     
     
         4 . The system as claimed in  claim 1 , wherein said agent code portion is configured to instruct said Web browser to send said DOM rendered code to said Traffic Inspector. 
     
     
         5 . The system as claimed in  claim 1 , comprising a Computer Administrator in signal communication with said Traffic Analyzer and configured to allow a user to program and monitor the operation of said Traffic Analyzer. 
     
     
         6 . The system as claimed in  claim 1 , wherein said Traffic Analyzer is configured to generate an attack-identification signal when said algorithm application identifies said at least one code difference and to send said attack-identification signal to said Traffic Inspector and/or to said Web browser and/or to said Computer Administrator and/or to an external unit, and/or to save said attack-identification signal in a database. 
     
     
         7 . The system as claimed in  claim 1 , wherein said algorithm application residing in said Traffic Analyzer is configured to process said DOM rendered code to compare it with said DOM client code using a comparison function to generate at least one attack-identification signal when said DOM client code is incompatible with said DOM rendered code. 
     
     
         8 . A method of identifying Man-in-the-Browser and/or Man-in-the-Middle Internet attacks using a system ( 1 ) as claimed in the preceding claims, characterized in that it comprises the steps of:
 generating a request for a Web application or Web resource via a Web browser using a URI or URL,   sending said request to a Web server using a Traffic Inspector,   receiving said server DOM code by said Traffic Inspector, which code has been automatically generated by said Web server according to said request,   adding an agent code portion to said DOM server code, by said Traffic Inspector, to thereby generate a DOM client code and send said DOM client code to said Web browser,   receiving and processing said DOM client code by said Web browser to automatically generate a DOM rendered code and send said DOM rendered code to said Traffic Inspector,   receiving said DOM rendered code by said Traffic Inspector and automatically send said DOM client code and said DOM rendered code to a Traffic Analyzer,   receiving, processing and comparing at least said DOM client code and said DOM rendered code, by an algorithm application residing in said Traffic Analyzer, to generate at least one attack-identification signal when said DOM client code is incompatible with said DOM rendered code.   
     
     
         9 . The method as claimed in  claim 8 , wherein said step of sending said request comprises the step of:
 sending said request using a HTTP or HTTPS protocol,   said agent code portion being a HTML and/or Javascript code, or another type of code and/or language that can be interpreted by a Web browser,   said DOM client code comprises at least said DOM server code and the default code portion.   
     
     
         10 . The method as claimed in  claim 9 , wherein said step of receiving and processing said DOM client code for automatic generation of said rendered DOM code comprises the steps of:
 receiving said DOM client code by said Web browser,   processing said DOM server code contained in said DOM client code by said Web browser ( 4 ) to automatically generate said DOM rendered code,   processing said agent code portion contained in said DOM client code by said Web browser ( 4 ) to send said DOM rendered code to said Traffic Inspector.   
     
     
         11 . The method as claimed in  claim 8 , wherein said step of receiving and comparing at least said DOM client code and said DOM rendered code, by said algorithm application residing in said Traffic Analyzer, to generate at least one attack-identification signal when said DOM client code is incompatible with said DOM rendered code comprises the step of:
 sending said attack-identification signal to said Traffic Inspector and/or said Web browser and/or a Computer Administrator and/or an external unit.   
     
     
         12 . The method as claimed in  claim 8 , wherein said step of receiving and comparing at least said DOM client code and said DOM rendered code, by said algorithm application residing in said Traffic Analyzer, to generate at least one attack-identification signal when said DOM client code is incompatible with said DOM rendered code comprises the step of:
 receiving and comparing at least said DOM client code and said DOM rendered code, by said algorithm application residing in said Traffic Analyzer by executing a comparison function to generate at least one attack-identification signal when said DOM client code is incompatible with said DOM rendered code.

Join the waitlist — get patent alerts

Track US2017324772A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.