IP Library Granted Patent US 9,584,543
Granted Patent B2
US 9,584,543 · App. 14/198,537 · Granted Feb 28, 2017

Method and system for web integrity validator

Inventor: Daniel Kaminsky (San Francisco, CA)
Assignee: WHITE OPS, INC.
H04L63/168H04L63/1408G06F21/31G06F21/566G06F2221/2133H04L63/08H04L63/105H04L63/145H04L63/1416H04L63/1425H04L63/1466H04L63/1483H04L67/02H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,584,543
App. No.
14/198,537
Granted
Feb 28, 2017
Kind
B2
Abstract

A computer-implemented method and system for the validation of a true browsing user on a website is disclosed. The invention allows for the collection of data regarding the evolving threat landscape created by online attackers. The system and method fingerprint user behavior to detect differences between a local user, a remote/foreign user, and an automated script. The system then covertly transmits that information back to a financial institution client without giving online attackers the opportunity to notice such transmittal. Certain embodiments of the invention also correspond with the browsing user to validate their identity. The claimed system and method proactively reveal attackers and attack ploys, additionally enabling institutions and security consultants to adapt to attacks in an automated fashion.

Claims (32)

1. A computer-implemented method for network security and integrity validation. comprising the steps of:

detecting, within a computer network, at least one codepath difference between a local user, a remote/foreign user, and an automated script, wherein said detecting is performed by a fingerprinter, said fingerprinter being configured to emit a source code to measure a manner in which a function is run within a browser,

transforming a source code emitted from said fingerprinter, wherein said transforming is performed by a mutator, said mutator being configured to send the same detection a plurality of times more in a mutated yet functionally equivalent form to require an attacker to emulate a same human action for each such transformation, said transformation being undetectable by a human user,

and employing defensive mechanisms for security-auditing,

wherein said detecting, transforming, and employing of defensive algorithms occurs concurrently and continuously,

thus enabling the collection of information regarding a browsing user.

2. The method of claim 1 , further comprising:

collecting said information regarding the browsing user in a central database,

processing said collected information via a maintainer application interface, and

corresponding, via a user interface façade, with a specific browsing user to validate said user's integrity if a security threat is detected.

3. The method of claim 2 , wherein said user interface façade comprises variable themes.

4. The method of claim 2 , wherein said security threat is a “Man-in-the-Browser” attack.

5. The method of claim 1 , further comprising randomizing defenses, which is performed by the mutator.

6. The method of claim 1 , wherein said defensive mechanisms further comprise defensive algorithms, encryption and obfuscating methodologies, attack tracing methodologies, and defensive design characteristics.

7. The method of claim 1 , wherein said transforming of source code is polymorphic.

8. The method of claim 1 , wherein said mutator additionally inserts anti-debugging, anti-tampering, and/or proof of work code in intertwined locations within the source code.

9. The method of claim 1 , wherein said at least one codepath difference is signified by the following: a mismatch between claimed and detected software versions, information about the visual environment being displayed to the user, information on the patterns of user input, timing, an availability of resources, and an ability to use functions normally not available.

10. The method of claim 1 , wherein said mutator is configured to reorder statements and functions without violating data flow constraints.

11. The method of claim 1 , wherein said imitator is configured to replace direct variable access with enumeration and computed hash comparisons.

12. The method of claim 1 , wherein said mutator is configured to replace single event listeners with code inside a personal global event dispatcher.

13. The method of claim 1 , wherein said imitator is configured to bind encryption routines to an expected environment.

14. The method of claim 1 , wherein said mutator is configured to convert constants into computations, wherein said computations are moved within the code.

15. The method of claim 1 , wherein said mutator is configured to convert variable access into a memory array.

16. The method of claim 1 , wherein said imitator is configured to convert source computations into a custom-written bytecode.

17. The method of claim 1 , wherein the mutator is configured to move computations out of scripting languages into computations performed by a rendering engine in the course of evaluating markup.

18. The method of claim 1 , wherein the mutator is configured to use a first encryption key for a first part of a code, and a second encryption key for a second part of the code, said first and second keys being requested at runtime from a backend server.

19. The method of claim 1 , wherein the defensive algorithms are configured to require a unique identifier with a cryptographic signature for each transformation.

20. A computer implemented system for validating a secure computer network, comprising a computing device including a processor that is coupled to a computer memory and a server, wherein the system performs the steps of:

detecting, within a computer network, at least one codepath difference between a local user, a remote/foreign user, and an automated script, wherein said detecting is performed by a fingerprinter, said fingerprinter being configured to emit a source code to measure a manner in which a function is run within a browser,

transforming a source code emitted from said fingerprinter, wherein said transforming is performed by a mutator, said mutator being configured to send the same detection a plurality of times more in a mutated yet functionally equivalent form to require an attacker to emulate a same human action for each such transformation, said transformation being undetectable by a human user,

and employing defensive mechanisms for security-auditing,

wherein said detecting, transforming, and employing of defensive algorithms occurs concurrently and continuously.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2025
From: ALTER DOMUS (US) LLC
To: HUMAN SECURITY, INC.; SINGULARITY BUYER LLC
Reel/Frame 071935/0384 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2025
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY
To: HUMAN SECURITY, INC.; SINGULARITY BUYER LLC; PERIMETERX, INC.
Reel/Frame 071935/0486 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 25, 2025
From: HUMAN SECURITY, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 072253/0310 →
SECURITY INTEREST Recorded Aug 9, 2022
From: HUMAN SECURITY, INC.; SINGULARITY BUYER LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 060758/0288 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 29, 2022
From: HUMAN SECURITY, INC.; SINGULARITY BUYER LLC; PERIMETERX, INC.
To: SILICON VALLEY BANK
Reel/Frame 061006/0055 →
TERMINATION AND RELEASE OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 24, 2021
From: COMERICA BANK
To: WHITE OPS, INC.
Reel/Frame 056676/0040 →
CHANGE OF NAME Recorded Mar 31, 2021
From: WHITE OPS, INC.
To: HUMAN SECURITY, INC.
Reel/Frame 057170/0011 →
SECURITY INTEREST Recorded Jun 29, 2015
From: WHITE OPS, INC.
To: COMERICA BANK
Reel/Frame 035998/0945 →
CHANGE OF NAME Recorded Jun 18, 2015
From: BOT OR NOT, LLC
To: WHITE OPS, INC
Reel/Frame 035948/0945 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 30, 2014
From: KAMINSKY, DANIEL
To: BOT OR NOT, LLC
Reel/Frame 033002/0620 →
Continuity (3)
Continuation In Part 14093964 · Dec 2, 2013
Provisional Application 61773106 · Mar 5, 2013
Related Publication 20150256556A1 · Sep 10, 2015