IP Library Granted Patent US 8,429,751
Granted Patent B2
US 8,429,751 · App. 12/722,778 · Granted Apr 23, 2013

Method and apparatus for phishing and leeching vulnerability detection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,429,751
App. No.
12/722,778
Granted
Apr 23, 2013
Kind
B2
Abstract

A system and method for protection of Web based applications are described. Anomalous traffic can be identified by comparing the traffic to a profile of acceptable user traffic when interacting with the application. Phishing and leeching are one type of anomalous traffic that is detected. The anomalous traffic, or security events, identified at the individual computer networks are communicated to a central security manager. Various responsive actions may be taken in response to detection of phishing or leeching.

Claims (18)

1. A method for securing a web server, the method comprising:

tokenizing, with a processor, a referrer domain name from an HTTP header of a received HTTP request to form a set of referrer tokens, each token of the set of referrer tokens representing a portion of the referrer domain name;

tokenizing, with the processor, a host domain name from the HTTP header to form a set of host tokens, each token of the set of host tokens representing a portion of the host domain name;

comparing at least two referrer tokens of the set of referrer tokens to at least two host tokens of the set of host tokens, the at least two referrer tokens including a first top level domain token, the at least two host tokens including a second top level domain token;

determining whether the received request is a result of an instruction from an external source based on whether the at least two referrer tokens match the at least two host tokens; and

performing a responsive action if the request is the result of the instruction from the external source.

2. The method of claim 1 , wherein the responsive action includes blocking the HTTP request.

3. The method of claim 1 , wherein the comparison is performed using matching criteria.

4. The method of claim 3 , wherein the matching criteria comprise one or more site aliases.

5. A tangible computer-readable storage disc or storage device comprising computer-readable instructions which, when executed, cause a machine to at least:

tokenize a referrer domain name from an HTTP header of a received HTTP request to form a set of referrer tokens, each token of the set of referrer tokens representing a portion of the referrer domain name;

tokenize a host domain name from the HTTP header to form a set of host tokens, each token of the set of host tokens representing a portion of the host domain name;

compare at least two referrer tokens of the set of referrer tokens to at least two host tokens of the set of host tokens, the at least two referrer tokens including a first top level domain token, the at least two host tokens including a second top level domain token;

determine whether the received request is a result of an instruction from an external source based on whether the at least two referrer tokens match the at least two host tokens; and

perform a responsive action if the request is the result of the instruction from the external source.

6. The computer-readable storage disc or storage device of claim 5 , wherein the responsive action includes blocking the HTTP request.

7. The computer-readable storage disc or storage device of claim 5 , wherein the comparison is performed using matching criteria.

8. The computer-readable storage disc or storage device of claim 7 , wherein the matching criteria comprise one or more site aliases.

Assignments (17)
SECURITY INTEREST Recorded Feb 18, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 073824/0146 →
SECURITY INTEREST Recorded Jan 30, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 073649/0743 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 071508/0540 Recorded Aug 18, 2025
From: LEVELBLUE, LLC
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 072510/0679 →
SECURITY INTEREST Recorded Jun 24, 2025
From: TRUSTWAVE HOLDINGS, INC.
To: LEVELBLUE, LLC
Reel/Frame 071508/0540 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 070952/0452 Recorded Jun 24, 2025
From: STG V, L.P.; STG VI, L.P.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 071723/0263 →
SECURITY INTEREST Recorded Apr 25, 2025
From: TRUSTWAVE HOLDINGS, INC.
To: STG V, L.P.; STG VI, L.P.
Reel/Frame 070952/0452 →
SECURITY INTEREST Recorded Oct 22, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: CYBEREASON INC.
Reel/Frame 068974/0691 →
SECURITY INTEREST Recorded Sep 12, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: CYBEREASON INC.
Reel/Frame 068572/0937 →
SECURITY INTEREST Recorded Jan 8, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: SINGTEL ENTERPRISE SECURITY (US), INC.
Reel/Frame 066050/0947 →
RELEASE OF SECURITY INTEREST Recorded Jul 11, 2012
From: SILICON VALLEY BANK
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 028526/0001 →
SECURITY AGREEMENT Recorded Jul 10, 2012
From: TRUSTWAVE HOLDINGS, INC.; TW SECURITY CORP.
To: WELLS FARGO CAPITAL FINANCE, LLC, AS AGENT
Reel/Frame 028518/0700 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2012
From: TW BREACH SECURITY INC.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 028159/0866 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDRESS OF THE RECEIVING PARTY PREVIOUSLY RECORDED ON REEL 027867 FRAME 0199. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT. Recorded Mar 19, 2012
From: TRUSTWAVE HOLDINGS, INC.
To: SILICON VALLEY BANK
Reel/Frame 027886/0058 →
SECURITY AGREEMENT Recorded Mar 15, 2012
From: TRUSTWAVE HOLDINGS, INC.
To: SILICON VALLEY BANK
Reel/Frame 027867/0199 →
MERGER Recorded Jan 5, 2011
From: BREACH SECURITY, INC.
To: TW BREACH SECURITY, INC.
Reel/Frame 025590/0247 →
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2010
From: SRBA #5, L.P. (SUCCESSOR IN INTEREST TO ENTERPRISE PARTNERS V, L.P. AND ENTERPRISE PARTNERS VI, L.P.); EVERGREEN PARTNERS US DIRECT FUND III, L.P.; EVERGREEN PARTNERS DIRECT FUND III (ISRAEL) L.P.; EVERGREEN PARTNERS DIRECT FUND III (ISRAEL 1) L.P.
To: BREACH SECURITY, INC.
Reel/Frame 024869/0883 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2010
From: MIZRAHI, RAMI; EFRON-NITZAN, GALIT; KATZ, OR
To: BREACH SECURITY, INC.
Reel/Frame 024267/0791 →