IP Library Granted Patent US 9,137,260
Granted Patent B2
US 9,137,260 · App. 14/036,547 · Granted Sep 15, 2015

Detection of spoofing of remote client system information

Inventor: Alfred P. Gehrig, Jr. (Mission Viejo, CA)
Assignee: BLUECAVA, INC.
H04L63/1483G06F21/44H04L63/0876H04L63/1416H04L67/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,137,260
App. No.
14/036,547
Granted
Sep 15, 2015
Kind
B2
Abstract

Digital fingerprint generation logic executed by a client device includes quirk-exposing logic configured to expose behavioral differences between various system configurations of client devices. The digital fingerprint generation logic queries a remote client device for system configuration, and generates a digital fingerprint of the client device that includes a system configuration characteristic reported by the client device in response to the query. Results of execution of the quirk-exposing logic are compared to expected results that are specific to the reported system configuration. If the results of execution do not match the expected results, the digital fingerprint is determined to have been spoofed.

Claims (36)

1. A method for detecting spoofing of system information reported by a remote client device, the method comprising steps for:

querying the remote client device for system information identifying a system configuration of the remote client device;

receiving in response to the querying step a reported system configuration;

causing the remote client device to execute exposing logic configured to induce an expected result characteristic of the reported system configuration, wherein the expected result characteristic is based on processing of a common input by the exposing logic and will vary as a result of the system configuration of the remote client device;

identifying a result of execution of the exposing logic by the remote client device; and

determining that the system information is incorrect upon a condition in which the result of execution does not match the expected result.

2. The method of claim 1 wherein the system information includes a user agent that is reported by a browser executing in the remote client device.

3. The method of claim 1 wherein the exposing logic causes the remote client device to evaluate a mathematical expression and wherein the expected result includes a numerical value.

4. The method of claim 1 wherein the exposing logic is configured to cause execution of a function known to generate a particular error when executed within the reported system configuration.

5. The method of claim 1 wherein the expected result includes a regular expression.

6. The method of claim 1 wherein the reported system configuration is captured in a digital fingerprint.

7. A non-transitory computer readable medium useful in association with a computer which includes one or more processors and a memory, the computer readable medium including computer instructions which are configured to cause the computer, by execution of the computer instructions in the one or more processors from the memory, to detect incorrect system information about a remote client device by at least:

querying the remote client device for system information identifying a system configuration of the remote client device;

receiving in response to the querying step a reported system configuration;

causing the remote client device to execute exposing logic configured to induce an expected result characteristic of the reported system configuration, wherein the expected result characteristic is based on processing of a common input by the exposing logic and will vary as a result of the system configuration of the remote client device;

identifying a result of execution of the exposing logic by the remote client device; and

determining that the system information is incorrect upon a condition in which the result of execution does not match the expected result.

8. The computer readable medium of claim 7 wherein the system information includes a user agent that is reported by a browser executing in the remote client device.

9. The computer readable medium of claim 7 wherein the exposing logic causes the remote client device to evaluate a mathematical expression and wherein the expected result includes a numerical value.

10. The computer readable medium of claim 7 wherein the exposing logic is configured to cause execution of a function known to generate a particular error when executed within the reported system configuration.

11. The computer readable medium of claim 7 wherein the expected result includes a regular expression.

12. The computer readable medium of claim 7 wherein the reported system configuration is captured in a digital fingerprint.

13. A computer system comprising:

at least one microprocessor;

a computer readable medium that is operatively coupled to the microprocessor; and

a server logic that (i) executes in the microprocessor from the computer readable medium and (ii) when executed by the microprocessor, causes the computer to detect incorrect system information about a remote client device by at least:

querying the remote client device for system information identifying a system configuration of the remote client device;

receiving in response to the querying step a reported system configuration;

causing the remote client device to execute exposing logic configured to induce an expected result characteristic of the reported system configuration, wherein the expected result characteristic is based on processing of a common input by the exposing logic and will vary as a result of the system configuration of the remote client device;

identifying a result of execution of the exposing logic by the remote client device; and

determining that the system information is incorrect upon a condition in which the result of execution does not match the expected result.

14. The computer system of claim 13 wherein the system information includes a user agent that is reported by a browser executing in the remote client device.

15. The computer system of claim 13 wherein the exposing logic causes the remote client device to evaluate a mathematical expression and further wherein the result includes a numerical value.

16. The computer system of claim 13 wherein the exposing logic is configured to cause execution of a function known to generate a particular error when executed within the reported system configuration.

17. The computer system of claim 13 wherein the expected result includes a regular expression.

18. The computer system of claim 13 wherein the reported system configuration is captured in a digital fingerprint.

Assignments (6)
SECURITY INTEREST Recorded Oct 11, 2023
From: ADSTRA, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 065183/0685 →
CHANGE OF NAME Recorded Nov 2, 2022
From: ALC, INC.
To: ADSTRA, INC.
Reel/Frame 061875/0449 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2018
From: BLUECAVA, INC.
To: ALC, INC.
Reel/Frame 047315/0425 →
RELEASE OF SECURITY INTEREST Recorded Oct 23, 2018
From: COMERICA BANK
To: BLUECAVA, INC.
Reel/Frame 047270/0696 →
SECURITY INTEREST Recorded May 2, 2014
From: BLUECAVA, INC.
To: COMERICA BANK
Reel/Frame 032808/0459 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2013
From: GEHRIG, ALFRED P., JR.
To: BLUECAVA INC.
Reel/Frame 031306/0353 →
Continuity (3)
Continuation PCTUS2012033786 · Apr 16, 2012
Provisional Application 61476206 · Apr 15, 2011
Related Publication 20140026220A1 · Jan 23, 2014