IP Library Granted Patent US 9,246,932
Granted Patent B2
US 9,246,932 · App. 13/186,426 · Granted Jan 26, 2016

Selective website vulnerability and infection testing

Inventors: Tomas Gorny (Paradise Valley, AZ); Tracy Conrad (Scottsdale, AZ); Scott Lovell (Lynnfield, MA); Neill E. Feather (Phoenix, AZ)
Assignee: SiteLock, LLC
H04L63/1433H04L43/0876G06F2221/2119
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,246,932
App. No.
13/186,426
Granted
Jan 26, 2016
Kind
B2
Abstract

In embodiments of the present invention improved capabilities are described for selective website vulnerability and infection testing and intelligently paced rigorous direct website testing. By providing robust website content integrity checking while only lightly loading the website hosting server, visitor bandwidth availability is maintained through selective testing and intelligently paced external website exercising. A modular pod-based computing architecture of interconnected severs configured with a sharded database facilitates selective website testing and intelligent direct website test pacing while providing scalability to support large numbers of website testing subscribers.

Claims (17)

1. A method for moderating bandwidth consumption of a hosting system for a set of commonly hosted websites on which vulnerability and infection testing is to be performed, the method comprising:

determining, with a computer remotely connected to the set of commonly hosted websites over a network, an expected bandwidth consumption by users due to non-testing access to at least a portion of the set of commonly hosted websites of the hosting system at a time when the vulnerability and infection testing of the commonly hosted websites is to commence;

comparing, with the computer remotely connected to the set of commonly hosted websites, the determined expected bandwidth consumption by users of the hosting system to a predetermined threshold value;

selecting, with the computer remotely connected to the set of commonly hosted websites, at least one of lower bandwidth consuming procedures and higher bandwidth consuming procedures of the vulnerability and infection testing to be performed at the time when infection testing is to commence, wherein the higher bandwidth consuming procedures are selected if the determined expected bandwidth consumption by users of the hosting system is lower than the predetermined threshold value;

selecting, by the computer remotely connected to the set of commonly hosted websites, a website from the set of commonly hosted websites; and

scanning, by the computer remotely connected to the set of commonly hosted websites, the content of the selected website at a pace determined by the selected higher or lower bandwidth consuming procedures.

2. The method of claim 1 , further comprising determining the pacing of the selected procedures based upon the determined bandwidth consumption by users of the hosting system.

3. The method of claim 1 , wherein the vulnerability and infection testing is performed by a plurality of website security services.

4. The method of claim 1 , wherein the vulnerability and infection testing for at least one of the commonly hosted websites includes accessing one or more pages of the at least one of the commonly hosted websites.

5. The method of claim 4 , further comprising capturing links from one or more pages of the at least one of the commonly hosted websites and comparing the captured links to a link analysis dataset comprising at least one of whitelisted links and black-listed links.

6. The method of claim 1 , further comprising a step of selecting for vulnerability and infection testing at least one page of one of the commonly hosted websites based on the at least one page having been found to have contained a vulnerability or an infection during a prior vulnerability and infection test.

7. The method of claim 1 , further comprising a step of selecting for vulnerability and infection testing a first page of one of the commonly hosted websites before a second page of that website wherein the first page contains a link that was identified as infected by previous vulnerability and infection testing and the second page does not contain a link that was not previously identified as infected by previous vulnerability and infection testing.

8. The method of claim 1 , wherein the vulnerability and infection testing includes scanning a subset of link string page generation variables.

9. The method of claim 1 , further comprising a step of comparing a Uniform Resource Locator (URL) length of a first page of one of the commonly hosted websites with a URL length of a second page of that commonly hosted website, and a step of performing the vulnerability and infection testing on whichever of the first and second pages has the shortest length before performing the vulnerability and infection testing of the other of the first and second pages.

10. The method of claim 1 , wherein the selecting step includes a determination of which pages of the commonly hosted websites to test.

11. The method of claim 1 , wherein the first set of lower consuming bandwidth procedures is selected over the second set of higher consuming bandwidth procedures if the determined loading level is greater than a predetermined threshold.

12. The method of claim 1 , further including performing the selected procedures prior to a subsequent testing invocation.

Assignments (5)
SECURITY INTEREST Recorded May 21, 2021
From: SITELOCK, LLC
To: CRESCENT AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 056309/0630 →
RELEASE OF SECURITY INTEREST Recorded Feb 22, 2021
From: CARLYLE GLOBAL INVESTMENT MANAGEMENT, L.L.C.
To: SITELOCK, LLC
Reel/Frame 055359/0621 →
SECURITY INTEREST Recorded Apr 5, 2018
From: SITELOCK, LLC
To: CARLYLE GLOBAL INVESTMENT MANAGEMENT, L.L.C.
Reel/Frame 045449/0207 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2015
From: LOVELL, SCOTT; FEATHER, NEILL E.
To: SITELOCK, LLC
Reel/Frame 037052/0218 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2011
From: GORNY, THOMAS; RAVICHANDRAN, HARI; CONRAD, TRACY
To: SITELOCK, LLC
Reel/Frame 027143/0250 →
Continuity (2)
Provisional Application 61365402 · Jul 19, 2010
Related Publication 20120036580A1 · Feb 9, 2012