IP Library Granted Patent US 9,380,064
Granted Patent B2
US 9,380,064 · App. 13/940,448 · Granted Jun 28, 2016

System and method for improving the resiliency of websites and web services

Inventors: Ronald Mraz (South Salem, NY); Gabriel Silberman (Hastings on Hudson, NY)
Assignee: Owl Computing Technologies, Inc.
H04L63/1408H04L63/0209H04L63/0227H04L69/40
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,380,064
App. No.
13/940,448
Granted
Jun 28, 2016
Kind
B2
Abstract

A system is disclosed for monitoring the status of a website operating on a host and for remedying any identified problems. A first platform is coupled to the host for monitoring the website and periodically transmits status information about the website. A second platform is coupled to the first platform for periodically receiving the status information about the at least one feature. The second platform is configured to compare the received status information with a copy of the website and based thereon determine if the website has been compromised. The second platform is further configured to output an alert signal after determining that the website has been compromised. A third platform is coupled to the second platform and separately coupled to the host computer. The third platform is configured to receive the alert signal from the second platform and to forward the alert signal to the host computer.

Claims (23)

1. A system for monitoring status of a particular website operating on a host hardware platform, the website formed from one or more files stored on the host hardware platform, and for remedying any problems identified by such monitoring, comprising:

a first hardware platform having a first connection coupled to the host hardware platform, for monitoring at least one feature of the website by periodically reading at least one of the files forming the website and configured to periodically transmit status information about the at least one feature on a second connection, the second connection separate from the first connection;

a second hardware platform having a first connection coupled to the second connection of the first hardware platform for periodically receiving the status information about the at least one feature and a second connection, the second hardware platform configured to compare the received status information with a copy of the website files stored on the second hardware platform and based thereon determine if the website has been compromised, the second hardware platform further configured to output an alert signal on the second connection after determining that the website has been compromised;

a third hardware platform having a first connection coupled to the second connection of the second hardware platform and a second connection coupled to the host hardware platform via a separate dedicated connection and configured to receive the alert signal from the second hardware platform and forward the alert signal to the host hardware platform via the separate dedicated connection; and

wherein the second connection of the second hardware platform is coupled to the first connection of the third hardware platform only via a manifest transfer engine configured to receive a manifest from the second hardware platform, to receive information from the second connection of the second hardware platform and to pass the received information to the first connection of the third hardware platform only if the received information is identified in the manifest, and wherein the manifest defines which information is allowed to pass from the second hardware platform to the third hardware platform.

2. The system of claim 1 , wherein the second connection of the first hardware platform is coupled to the first connection of the second hardware platform only via a one-way data link.

3. The system of claim 1 , wherein the second connection of the second hardware platform is coupled to the first connection of the third hardware platform only via a one-way data link.

4. The system of claim 1 , wherein the second hardware platform is further configured to output the copy of the website files on the second connection after determining that the website has been compromised and wherein the third hardware platform is further configured to receive the copy of the website files from the second server and forward the copy of the website to the host hardware platform along with the alert signal.

5. The system of claim 1 , wherein the status information comprises one or more complete files constituting the website.

6. The system of claim 1 , wherein the status information comprises a list of one or more filenames for files constituting the website.

7. The system of claim 1 , wherein the status information comprises portions of one or more complete files constituting the website.

8. The system of claim 1 , wherein the status information comprises signature information for one or more complete files constituting the website.

9. The system of claim 1 , wherein the status information comprises file creation information for one or more complete files constituting the website.

10. The system of claim 1 , wherein the status information comprises credential information for one or more complete files constituting the website.

11. The system of claim 1 , wherein the status information comprises metadata for one or more complete files constituting the website.

12. The system of claim 1 , wherein the host hardware platform is coupled to a first network for public access by one or more users and wherein the second hardware platform is coupled to a second network for private access by an administrator.

13. The system of claim 1 , wherein the first connection of the first hardware platform is coupled to the host hardware platform via a dedicated connection.

14. The system of claim 1 , wherein the first connection of the first hardware platform is coupled to the host hardware platform via a public network.

15. A system for monitoring status of a particular website operating on a host hardware platform, the website formed from one or more files stored on the host hardware platform, and for remedying any problems identified by such monitoring, comprising:

a first hardware platform having a first connection coupled to the host hardware platform for monitoring at least one feature of the website by periodically reading at least one of the files forming the website and configured to periodically transmit status information about the at least one feature on a second connection, the second connection separate from the first connection;

a second hardware platform having a first connection coupled to the second connection of the first hardware platform for periodically receiving the status information about the at least one feature and a second connection, the second hardware platform configured to compare the received status information with a copy of the website files stored on the second hardware platform and based thereon determine if the website has been compromised, the second hardware platform further configured to output an alert signal on the second connection after determining that the website has been compromised;

a third hardware platform having a first connection coupled to the second connection of the second hardware platform and a second connection coupled to the host hardware platform via a separate dedicated connection and configured to receive the alert signal from the second hardware platform and forward the alert signal to the host hardware platform via the separate dedicated connection; and

wherein the second connection of the first hardware platform is coupled to the first connection of the second hardware platform only via a manifest transfer engine configured to receive a manifest from the second hardware platform, to receive information from the second connection of the first hardware platform and to pass the received information to the first connection of the second hardware platform only if the received information is identified in the manifest, and wherein the manifest defines which information is allowed to pass from the first hardware platform to the second hardware platform.

Assignments (8)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL 041136, FRAME 0223 Recorded Sep 11, 2024
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: OWL CYBER DEFENSE SOLUTIONS, LLC
Reel/Frame 068945/0922 →
SECURITY INTEREST Recorded Sep 11, 2024
From: OWL CYBER DEFENSE SOLUTIONS, LLC
To: RGA REINSURANCE COMPANY
Reel/Frame 068938/0313 →
MERGER AND CHANGE OF NAME Recorded Sep 2, 2022
From: OWL CYBER DEFENSE SOLUTIONS, LLC; TRESYS TECHNOLOGY, LLC
To: OWL CYBER DEFENSE SOLUTIONS, LLC
Reel/Frame 060978/0964 →
CHANGE OF NAME Recorded Jun 20, 2017
From: OWL COMPUTING TECHNOLOGIES, LLC
To: OWL CYBER DEFENSE SOLUTIONS, LLC
Reel/Frame 042902/0582 →
CORRECTIVE ASSIGNMENT TO CORRECT TO REMOVE THIS DOCUMENT SERVES AS AN OATH/DECLARATION (37 CFR 1.63) FROM THE COVER SHEET PREVIOUSLY RECORDED AT REEL: 041765 FRAME: 0034. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER EFFECTIVE DATE 02/03/2017. Recorded Apr 21, 2017
From: OWL COMPUTING TECHNOLOGIES, INC.
To: OWL COMPUTING TECHNOLOGIES, LLC
Reel/Frame 042344/0033 →
MERGER Recorded Mar 28, 2017
From: OWL COMPUTING TECHNOLOGIES, INC.
To: OWL COMPUTING TECHNOLOGIES, LLC
Reel/Frame 041765/0034 →
SECURITY INTEREST Recorded Jan 31, 2017
From: OWL COMPUTING TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 041136/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2013
From: MRAZ, RONALD; SILBERMAN, GABRIEL
To: OWL COMPUTING TECHNOLOGIES, INC.
Reel/Frame 030793/0352 →
Continuity (1)
Related Publication 20150020194A1 · Jan 15, 2015