IP Library Granted Patent US 8,286,248
Granted Patent B1
US 8,286,248 · App. 12/024,972 · Granted Oct 9, 2012

System and method of web application discovery via capture and analysis of HTTP requests for external resources

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,286,248
App. No.
12/024,972
Granted
Oct 9, 2012
Kind
B1
Abstract

A method for discovering the structure, state transitions, and patterns of behavior of users of a web application includes a method for causing the web application to make HTTP requests for resources from an external supplier; capture of the requests for the external resources; extraction of meaningful data from the captured requests; and analysis to draw conclusions based on the extracted data. A system of invention provides a reference implementation of the method.

Claims (50)

1. A web application topology discovery method comprising:

providing access to a trust mark from a server not under control of an owner of a web application, wherein references to the trust mark are embedded in content of the web application by the owner of the web application;

receiving at the server one or more requests for the trust mark from one or more users of the web application, the requests being generated by the users' web browsers upon encountering the embedded references to the trust mark in the content of the web application; and

inspecting the received requests to obtain information about the web application to be used as an input for a security scan.

2. The method of claim 1 wherein references to the trust mark embedded in the content of the web application include uniform resource locators (URLs) that can be used by a web browser to construct requests to retrieve the trust mark from the server and wherein each constructed request includes a referrer header containing the URL and auxiliary request information.

3. The method of claim 1 further comprising recording the received requests by maintaining the trust mark requests in a relational database.

4. The method of claim 1 wherein inspecting the received requests comprises parsing the request according to the HTTP protocol.

5. The method of claim 1 wherein inspecting the received requests to identify a part of the web application to serve as an input for a security scan comprises determining a frequency of a given location within the application where the application is referencing the trust mark, such that more frequently accessed content may be prioritized in the security scan.

6. The method of claim 1 wherein inspecting the received requests to identify a part of the web application to serve as an input for a security scan comprises:

extracting session identifiers from the received requests;

grouping the requests according to their session;

extracting information regarding a sequence of a received request within a session;

ordering the requests in the sequence in which they were made; and

determining from such session and sequence information a traffic pattern through the web application.

7. The method of claim 6 wherein determining a traffic pattern through the web application comprises determining a business process associated with the web application.

8. The method of claim 1 wherein inspecting the received requests to identify a part of the web application to serve as an input for a security scan comprises:

determining a frequency of a given location within the application where the application is referencing the trust mark;

extracting session and sequence information from the received requests and determining a traffic pattern through the web application from such session and sequence information;

combining the frequency and traffic pattern to identify one or more critical nodes for prioritization in the security scan.

9. A system for discovering topology of a web application, the system comprising:

a store containing one or more trust marks;

a server adapted to provide access to the one or more trust marks upon receiving requests from a user of the web application, each request being generated upon a user's encountering a reference to the trust mark embedded in the content of the web application by an owner of the web application;

a request log adapted to store the received requests; and

an analysis module adapted to inspect the received requests to obtain information about the web application to be used as an input for a security scan;

wherein the system is not under control of an owner of the web application.

10. The system of claim 9 wherein the system is part of a network of distributed scanning servers.

11. The system of claim 9 wherein the system further comprises a local scan appliance controlled by a central vulnerability management system.

12. The system of claim 9 wherein the reference to the trust mark embedded in the content of the web application includes a uniform resource locator (URL) and wherein each request includes a referrer header containing the URL and auxiliary request information.

13. The system of claim 9 wherein the server is an HTTP server.

14. The system of claim 9 wherein the request log adapted to store the received requests comprises a relational database.

15. The system of claim 9 wherein the analysis module is adapted to inspect the received requests to obtain information about the web application to be used as an input for a security scan by determining a frequency of a given location within the application where the application is referencing the trust mark, such that more frequently accessed content may be prioritized in the security scan.

16. The system of claim 9 wherein the analysis module is adapted to inspect the received requests to obtain information about the web application to be used as an input for a security scan by:

extracting session identifiers from the received requests;

grouping the requests according to their session;

extracting information regarding a sequence of a received request within a session;

ordering the requests in the sequence in which they were made; and

determining from such session and sequence information a traffic pattern through the web application.

17. The system of claim 16 wherein the analysis module is further adapted to determine a business process associated with the web application.

18. The system of claim 9 wherein the analysis module is adapted to inspect the received requests to obtain information about the web application to be used as an input for a security scan by:

determining a frequency of a given location within the application where the application is referencing the trust mark;

extracting session and sequence information from the received requests and determining a traffic pattern through the web application from such session and sequence information;

combining the frequency and traffic pattern to identify one or more critical nodes for prioritization in the security scan.

19. A web application topology discovery method comprising:

providing access to a trust mark from a server not under control of an owner of a web application, wherein references to the trust mark, each reference including a uniform resource locator (URL), are embedded in content of the web application by the owner of the web application;

receiving at the server one or more requests for the trust mark from one or more users of the web application, the requests being generated by the users' web browsers upon encountering the embedded references to the trust mark in the content of the web application, wherein each constructed request includes a referrer header containing the URL; and

inspecting the received requests to obtain information about the web application to be used as an input for a security scan.

20. The method of claim 19 wherein inspecting the received requests to identify a part of the web application to serve as an input for a security scan comprises:

determining a frequency of a given location within the application where the application is referencing the trust mark;

extracting session and sequence information from the received requests and determining a traffic pattern through the web application from such session and sequence information;

combining the frequency and traffic pattern to identify one or more critical nodes for prioritization in the security scan.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2008
From: OLIPHANT, BRETT; TYLER, BEN; PACK, GABRIEL; HARDIN, BRETT
To: MCAFEE, INC.
Reel/Frame 020457/0450 →