IP Library Granted Patent US 9,161,249
Granted Patent B1
US 9,161,249 · App. 13/177,891 · Granted Oct 13, 2015

Systems and methods for performing internet site security analyses

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,161,249
App. No.
13/177,891
Granted
Oct 13, 2015
Kind
B1
Abstract

A computer-implemented method for performing Internet site security analyzes may include (1) identifying a plurality of clients, each client within the plurality of clients connecting to the Internet from a different Internet Protocol address, (2) identifying a plurality of Internet sites targeted for a security assessment, and then, for each Internet site within the plurality of Internet sites, (3) selecting at least one client from the plurality of clients to use as a proxy for communicating with the Internet site, (4) communicating with the Internet site, using the client as a proxy, to gather information for a security analysis of the Internet site, and (5) performing the security analysis of the Internet site based at least in part on the gathered information. Various other methods, systems, and computer-readable media are also disclosed.

Claims (43)

1. A computer-implemented method for performing Internet site security analyses, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

identifying a plurality of clients, each client within the plurality of clients connecting to the Internet from a different public Internet Protocol address;

identifying a plurality of potentially malicious Internet sites targeted for a security assessment;

for each Internet site within the plurality of potentially malicious Internet sites:

selecting at least one client from the plurality of clients to use as a proxy for communicating with the Internet site on behalf of a security assessor;

communicating with the Internet site, using the client as a proxy, to gather information for a security analysis of the Internet site so that the Internet site is unable to block and/or tailor requests from the security assessor based on an Internet Protocol address of the client;

performing the security analysis of the Internet site based at least in part on the gathered information.

2. The computer-implemented method of claim 1 , wherein each client within the plurality of clients connects to the Internet from a different Internet Protocol address block.

3. The computer-implemented method of claim 1 , wherein using the client as a proxy comprises:

receiving a communication from the client to initiate a tunneling protocol;

communicating with the client via the tunneling protocol.

4. The computer-implemented method of claim 1 , wherein using the client as a proxy comprises communicating with a proxy agent installed on the client as part of an endpoint security software installation on the client.

5. The computer-implemented method of claim 1 , wherein using the client as a proxy comprises identifying a user-submitted agreement to allow a security vendor to use the client as a proxy for communications with Internet sites targeted for security assessments.

6. The computer-implemented method of claim 1 , wherein selecting the client from the plurality of clients comprises selecting the client based on the public Internet Protocol address of the client.

7. The computer-implemented method of claim 6 , wherein selecting the client based on the Internet Protocol address of the client comprises selecting the client to test the Internet site for a response differentiated by Internet Protocol addresses.

8. The computer-implemented method of claim 6 , wherein selecting the client based on the Internet Protocol address of the client comprises selecting the client to prevent detection as a security vendor by the Internet site.

9. The computer-implemented method of claim 6 , wherein selecting the client based on the Internet Protocol address of the client comprises selecting the client based on a geographical region of the client ascertainable by the Internet site.

10. A system for performing Internet site security analyses, the system comprising:

an identification module programmed to:

identify a plurality of clients, each client within the plurality of clients connecting to the Internet from a different public Internet Protocol address;

identify a plurality of potentially malicious Internet sites targeted for a security assessment;

a selection module programmed to, for each Internet site within the plurality of potentially malicious Internet sites, select at least one client from the plurality of clients to use as a proxy for communicating with the Internet site on behalf of a security assessor;

a gathering module programmed to communicate with the Internet site, using the client as a proxy, to gather information for a security analysis of the Internet site so that the Internet site is unable to block and/or tailor requests from the security assessor based on an Internet Protocol address of the client;

an analysis module programmed to perform the security analysis of the Internet site based at least in part on the gathered information;

at least one hardware processor configured to execute the identification module, the selection module, the gathering module, and the analysis module.

11. The system of claim 10 , wherein each client within the plurality of clients connects to the Internet from a different Internet Protocol address block.

12. The system of claim 10 , wherein the gathering module is programmed to use the client as a proxy by:

receiving a communication from the client to initiate a tunneling protocol;

communicating with the client via the tunneling protocol.

13. The system of claim 10 , wherein the gathering module is programmed to use the client as a proxy by communicating with a proxy agent installed on the client as part of an endpoint security software installation on the client.

14. The system of claim 10 , wherein the gathering module is programmed to use the client as a proxy by identifying a user-submitted agreement to allow a security vendor to use the client as a proxy for communications with Internet sites targeted for security assessments.

15. The system of claim 10 , wherein the selection module is programmed to select the client from the plurality of clients by selecting the client based on the public Internet Protocol address of the client.

16. The system of claim 15 , wherein the selection module is programmed to select the client based on the Internet Protocol address of the client by selecting the client to test the Internet site for a response differentiated by Internet Protocol addresses.

17. The system of claim 15 , wherein the selection module is programmed to select the client based on the Internet Protocol address of the client by selecting the client to prevent detection as a security vendor by the Internet site.

18. The system of claim 15 , wherein the selection module is programmed to select the client based on the Internet Protocol address of the client by selecting the client based on a geographical region of the client ascertainable by the Internet site.

19. A non-transitory computer-readable-storage medium comprising one or more computer-executable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

identify a plurality of clients, each client within the plurality of clients connecting to the Internet from a different public Internet Protocol address;

identify a plurality of potentially malicious Internet sites targeted for a security assessment;

for each Internet site within the plurality of potentially malicious Internet sites:

select at least one client from the plurality of clients to use as a proxy for communicating with the Internet site on behalf of a security assessor;

communicate with the Internet site, using the client as a proxy, to gather information for a security analysis of the Internet site so that the Internet site is unable to block and/or tailor requests from the security assessor based on an Internet Protocol address of the client;

perform the security analysis of the Internet site based at least in part on the gathered information.

20. The computer-readable-storage medium of claim 19 , wherein each client within the plurality of clients connects to the Internet from a different Internet Protocol address block.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Feb 14, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051935/0228 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 7, 2011
From: LEITA, CORRADO; DACIER, MARC
To: SYMANTEC CORPORATION
Reel/Frame 026555/0496 →