IP Library Patent Application 11532058
Patent Application
App. No. 11/532,058

SYSTEM AND METHOD OF PREVENTING WEB APPLICATIONS THREATS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/532,058
Abstract

A system and method for protection of Web based applications are described. An agent is included in a web server such that traffic is routed through the agent. A security module is also in communication with the agent. The agent receives information about the application profile, and patterns of acceptable traffic behavior, from the security module. The agent acts as a gatekeeper, holding up suspicious traffic that does not match the pattern of acceptable traffic behavior until the suspicious traffic has been analyzed by the security module. Using the agent, malicious traffic can dropped before it can reach the application, or the user can be logged out, or both.

Claims (74)

1 . A method of preventing an application attack, the method comprising:

verifying network traffic against a profile of acceptable behavior for a user of the application and identifying anomalous user traffic;

determining if the anomalous traffic is a threat; and

blocking the anomalous traffic at an application server.

2 . The method as defined in claim 1 , wherein the application is a Web application.

3 . The method as defined in claim 1 , wherein blocking is performed by an agent.

4 . The method as defined in claim 3 , wherein the agent is included in a web server.

5 . The method as defined in claim 3 , wherein the agent is included in a firewall.

6 . The method as defined in claim 1 , wherein the application server comprises an agent.

7 . The method as defined in claim 6 , wherein the agent determines if the anomalous traffic is a threat.

8 . The method as defined in claim 1 , wherein the profile of acceptable behavior is provided by a security module.

9 . The method as defined in claim 1 , wherein the profile of acceptable behavior is updated by an adaption module.

10 . The method as defined in claim 1 , wherein the profile of acceptable behavior is updated automatically.

11 . The method as defined in claim 1 , wherein the profile of acceptable behavior is updated in response to a change in the application.

12 . The method as defined in claim 1 , wherein identifying anomalous user traffic comprises matching predetermined patterns against data at specific locations in a request-reply pair.

13 . The method as defined in claim 1 , wherein identifying anomalous user traffic comprises validation of parameters in the user traffic.

14 . The method as defined in claim 1 , wherein identifying anomalous user traffic comprises analyzing outbound responses from the application to identify sensitive information.

15 . The method as defined in claim 1 , wherein verifying network traffic is performed out-of-line of network traffic flow.

16 . The method as defined in claim 1 , wherein blocking the anomalous traffic from an application server comprises a distributed detect and prevention architecture.

17 . The method as defined in claim 1 , wherein determining if the anomalous traffic is a threat comprises correlating events.

18 . The method as defined in claim 17 , wherein correlating events comprises an attack correlated event.

19 . The method as defined in claim 17 , wherein correlating events comprises a result correlated event.

20 . The method as defined in claim 1 , further comprising logging out the user.

21 . An application attack prevention system comprising:

a security module adapted to provide a profile of acceptable behavior for a user of the application; and

an agent adapted to receive the profile and identify anomalous user traffic, wherein if it is determined that the anomalous traffic is a threat, then blocking the anomalous traffic from an application server.

22 . The system as defined in claim 21 , wherein the application is a Web application.

23 . The system as defined in claim 21 , wherein the agent is included in a web server.

24 . The system as defined in claim 21 , wherein the agent is included in a firewall.

25 . The system as defined in claim 21 , wherein the profile of acceptable behavior is updated by an adaption module.

26 . The system as defined in claim 21 , wherein the profile of acceptable behavior is updated automatically.

27 . The system as defined in claim 21 , wherein the profile of acceptable behavior is updated in response to a change in the application.

28 . The system as defined in claim 21 , wherein identifying anomalous user traffic comprises matching predetermined patterns against data at specific locations in a request-reply pair.

29 . The method as defined in claim 21 , wherein identifying anomalous user traffic comprises analyzing outbound responses from the application to identify sensitive information.

30 . The system as defined in claim 21 , wherein identifying anomalous user traffic comprises validation of parameters in the user traffic.

31 . The system as defined in claim 21 , wherein determining if the anomalous traffic is a threat comprises correlating events.

32 . The system as defined in claim 31 , wherein correlating events comprises an attack correlated event.

33 . The system as defined in claim 31 , wherein correlating events comprises a result correlated event.

34 . The system as defined in claim 21 , further comprising logging out the user.

35 . An application attack prevention system comprising:

a security module adapted to provide a profile of acceptable behavior for a user of the application; and

an agent adapted to receive the profile and identify anomalous user traffic, wherein if it is determined that the anomalous traffic is a threat, logging out the user.

36 . The system as defined in claim 35 , wherein the application is a Web application.

37 . The system as defined in claim 35 , wherein the agent is included in a web server.

38 . The system as defined in claim 35 , further comprising blocking the anomalous traffic from an application server.

39 . The system as defined in claim 35 , wherein determining that the anomalous traffic is a threat comprises correlating events.

40 . The system as defined in claim 35 , wherein the security module is an out-of-line appliance.

41 . An application attack prevention system comprising:

a security module adapted to monitor user traffic and to provide a profile of acceptable behavior for a user of the application; and

an agent adapted to receive the profile and identify anomalous user traffic based upon the profile, wherein if it is determined that the anomalous traffic is a threat, logging out the user.

42 . The system as defined in claim 41 , further comprising blocking the anomalous traffic from an application server.

43 . The system as defined in claim 41 , wherein the application is a Web application.

44 . The system as defined in claim 41 , wherein the user traffic is monitored out-of-line.

45 . An application server comprising:

an input adapted to receive a profile of acceptable behavior for a user of an application; and

an agent adapted to receive the profile of acceptable behavior for the user, wherein the agent monitors the user traffic to the server and identifies anomalous user traffic based upon the profile, and logs out the user if it is determined that the anomalous traffic is a threat.

46 . The server as defined in claim 45 , wherein the profile of acceptable behavior is provided by a security module adapted to monitor Web traffic.

47 . The server as defined in claim 45 , further comprising updating the profile by an adaption module.

48 . The server as defined in claim 46 , wherein updating the profile is automatic.

49 . The server as defined in claim 46 , wherein updating is in response to a change in the application.

50 . The server as defined in claim 45 , wherein the application is a Web application.

51 . The server as defined in claim 45 , wherein the security module monitors Web traffic out-of-line.

52 . The server as defined in claim 45 , further comprising blocking the anomalous traffic from the server.

53 . The server as defined in claim 45 , wherein determining that the anomalous traffic is a threat comprises correlating events.

54 . An application server comprising:

an input adapted to receive a profile of acceptable behavior for a user of an application; and

an agent adapted to receive the profile of acceptable behavior for the user, wherein the agent monitors user traffic to the server and identifies anomalous user traffic based upon the profile, and then blocks the anomalous traffic from the server if it is determined that the anomalous traffic is a threat.

55 . The server as defined in claim 54 , wherein the profile of acceptable behavior is provided by a security module adapted to monitor user traffic.

56 . The server as defined in claim 54 , further comprising updating the profile by an adaption module.

57 . The server as defined in claim 56 , wherein updating the profile is automatic.

58 . The server as defined in claim 56 , wherein updating the profile is in response to an a change in the application.

59 . The server as defined in claim 56 , wherein the security module monitors user traffic out-of-line.

60 . The server as defined in claim 56 , further comprising logging the user out.

61 . The server as defined in claim 56 , wherein the application is a Web application.

Assignments (12)
RELEASE OF SECURITY INTEREST Recorded Jul 11, 2012
From: SILICON VALLEY BANK
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 028526/0001 →
RELEASE OF SECURITY INTEREST Recorded Jul 10, 2012
From: SILICON VALLEY BANK
To: TW BREACH SECURITY, INC.
Reel/Frame 028519/0348 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDRESS OF THE RECEIVING PARTY PREVIOUSLY RECORDED ON REEL 027867 FRAME 0199. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT. Recorded Mar 19, 2012
From: TRUSTWAVE HOLDINGS, INC.
To: SILICON VALLEY BANK
Reel/Frame 027886/0058 →
SECURITY AGREEMENT Recorded Mar 15, 2012
From: TRUSTWAVE HOLDINGS, INC.
To: SILICON VALLEY BANK
Reel/Frame 027867/0199 →
SECURITY AGREEMENT Recorded Mar 8, 2011
From: TW BREACH SECURITY, INC.
To: SILICON VALLEY BANK
Reel/Frame 025914/0284 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2011
From: TW BREACH SECURITY, INC.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 025590/0351 →
MERGER Recorded Oct 21, 2010
From: BREACH SECURITY, INC.
To: TW BREACH SECURITY, INC.
Reel/Frame 025169/0652 →
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2010
From: SRBA #5, L.P. (SUCCESSOR IN INTEREST TO ENTERPRISE PARTNERS V, L.P. AND ENTERPRISE PARTNERS VI, L.P.); EVERGREEN PARTNERS US DIRECT FUND III, L.P.; EVERGREEN PARTNERS DIRECT FUND III (ISRAEL) L.P.; EVERGREEN PARTNERS DIRECT FUND III (ISRAEL 1) L.P.
To: BREACH SECURITY, INC.
Reel/Frame 024869/0883 →
RELEASE OF SECURITY INTEREST Recorded Jun 28, 2010
From: COMERICA BANK
To: BREACH SECURITY, INC.
Reel/Frame 024599/0435 →
SECURITY AGREEMENT Recorded Feb 17, 2009
From: BREACH SECURITY, INC.
To: COMERICA BANK
Reel/Frame 022266/0646 →
SECURITY AGREEMENT Recorded Jan 23, 2009
From: BREACH SECURITY, INC.
To: ENTERPRISE PARTNERS V, L.P.; SRBA # 5, L.P.; ENTERPRISE PARTNERS VI, L.P.
Reel/Frame 022151/0041 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 3, 2007
From: OVERCASH, KEVIN; DELIKAT, KATE; MIZRAHI, RAMI; EFRON, GALIT; KOLTON, DORON; WEXLER, ASAF; GAVRIELI, NETTA; ZAHAVI, YORAM
To: BREACH SECURITY, INC.
Reel/Frame 018703/0253 →