IP Library Granted Patent US 8,756,697
Granted Patent B2
US 8,756,697 · App. 13/436,818 · Granted Jun 17, 2014

Systems and methods for determining vulnerability to session stealing

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,756,697
App. No.
13/436,818
Granted
Jun 17, 2014
Kind
B2
Abstract

Systems and methods for determining vulnerability to session stealing are disclosed. An example method includes intercepting, at a first computing device, an intercepted packet sent from a client to a second computing device different than the first computing device, the intercepted packet including a first instruction in a first portion of the intercepted packet, determining, using a template, a second portion of the intercepted packet that is a value that is changed by a calculated amount each time that the client sends a packet, changing the value by the calculated amount to determine a next value for a next packet, replacing the second portion of the intercepted packet with the next value to generate a modified packet, replacing the first portion of the modified packet with a second instruction, and transmitting the modified packet to the second computing device.

Claims (44)

1. A method comprising:

intercepting, at a first computing device, an packet sent from a client to a second computing device different than the first computing device, the packet including a first instruction in a first portion of the packet;

determining, using a template, a second portion of the packet that is a value that is changed by a calculated amount each time that the client sends a packet;

changing the value by the calculated amount to determine a next value for a next packet;

replacing the second portion of the packet with the next value to generate a modified packet;

replacing the first portion of the modified packet with a second instruction; and

transmitting the modified packet to the second computing device.

2. A method as defined in claim 1 , further comprising determining if the second computing device accepts the modified packet.

3. A method as defined in claim 1 , further comprising determining if the second computing device executes the second instruction.

4. A method as defined in claim 3 , further comprising notifying an entity associated with the second computing device in response to determining that the second computing device executed the second instruction.

5. A method as defined in claim 3 , further comprising generating a report indicating whether or not the second computing device executes the second instruction.

6. A method as defined in claim 1 , wherein the calculated amount is identified in the template.

7. A method as defined in claim 1 , wherein the calculated amount is an integer by which the value is incremented.

8. A method as defined in claim 1 , further comprising determining, using the template, that the first portion of the packet includes the first instruction.

9. A method as defined in claim 1 , wherein the template identifies a byte offset of at least one of the first portion or the second portion.

10. A method as defined in claim 1 , wherein the first packet is associated with an existing communication session between the client and the second computing device.

11. A method as defined in claim 10 , further comprising instructing the client to terminate the session after receiving the packet at the first computing device.

12. A method as defined in claim 10 , wherein the modified packet is associated with the session.

13. A method as defined in claim 1 , further comprising at least one of:

instructing an address resolution protocol system to replace an address of the second computing device with an address of the first computing device;

instructing a domain name system to replace an address of the second computing device with an address of the first computing device; and

changing a network address of the second computing device from a first address to a second address and changing a network address of the first computing device to the first address.

14. A method as defined in claim 1 , further comprising:

receiving a plurality of packets including the packet at the first computing device from the client;

determining a number of times that the first instruction is included in the plurality of packets; and

selecting the packet for modification when the number of times meets a threshold.

15. A method as defined in claim 1 , further comprising:

determining a number of parameters in the first instruction; and

selecting the packet for modification when the number of parameters meets a threshold.

16. A method as defined in claim 1 , further comprising storing the next value to be used in determining a value for a second modified packet.

17. A method as defined in claim 1 , wherein the second portion is a packet sequence number.

18. A tangible computer readable storage medium storing instructions that, when executed, cause a machine to at least:

intercept, at a first computing device, an packet sent from a client to a second computing device different than the first computing device, the packet including a first instruction in a first portion of the packet;

determine, using a template, a second portion of the packet that is a value that is changed by a calculated amount each time that the client sends a packet;

change the value by the calculated amount to determine a next value for a next packet;

replace the second portion of the packet with the next value to generate a modified packet;

replace the first portion of the modified packet with a second instruction; and

transmit the modified packet to the second computing device.

19. A tangible computer readable storage medium as defined in claim 18 , wherein the instructions, when executed further cause the machine to determine if the second computing device accepts the modified packet.

20. A tangible computer readable storage medium as defined in claim 18 , wherein the instructions, when executed further cause the machine to determine if the second computing device executes the second instruction.

21. An apparatus comprising:

a session tracking module to intercept, at a first computing device, an packet sent from a client to a second computing device different than the first computing device, the packet including a first instruction in a first portion of the packet and to determine, using a template, a second portion of the packet that is a value that is changed by a calculated amount each time that the client sends a packet;

a data modification module to change the value by the calculated amount to determine a next value for a next packet and to replace the second portion of the packet with the next value to generate a modified packet, and to replace the first portion of the modified packet with a second instruction; and

a finalization module to transmit the modified packet to the second computing device.

Assignments (11)
SECURITY INTEREST Recorded Feb 18, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 073824/0146 →
SECURITY INTEREST Recorded Jan 30, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 073649/0743 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 071508/0540 Recorded Aug 18, 2025
From: LEVELBLUE, LLC
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 072510/0679 →
SECURITY INTEREST Recorded Jun 24, 2025
From: TRUSTWAVE HOLDINGS, INC.
To: LEVELBLUE, LLC
Reel/Frame 071508/0540 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 070952/0452 Recorded Jun 24, 2025
From: STG V, L.P.; STG VI, L.P.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 071723/0263 →
SECURITY INTEREST Recorded Apr 25, 2025
From: TRUSTWAVE HOLDINGS, INC.
To: STG V, L.P.; STG VI, L.P.
Reel/Frame 070952/0452 →
SECURITY INTEREST Recorded Oct 22, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: CYBEREASON INC.
Reel/Frame 068974/0691 →
SECURITY INTEREST Recorded Sep 12, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: CYBEREASON INC.
Reel/Frame 068572/0937 →
SECURITY INTEREST Recorded Jan 8, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: SINGTEL ENTERPRISE SECURITY (US), INC.
Reel/Frame 066050/0947 →
SECURITY AGREEMENT Recorded May 23, 2013
From: TRUSTWAVE HOLDINGS, INC.
To: WELLS FARGO CAPITAL FINANCE, LLC, AS AGENT
Reel/Frame 030486/0550 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2012
From: OCEPEK, STEVEN R.; HENDRIQUE, WENDEL GUGLIELMETTI
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 028970/0287 →