IP Library Granted Patent US 9,705,902
Granted Patent B1
US 9,705,902 · App. 14/672,879 · Granted Jul 11, 2017

Detection of client-side malware activity

Inventors: Justin D. Call (Santa Clara, CA); Xinran Wang (San Ramon, CA); Yao Zhao (Fremont, CA); Timothy Dylan Peacock (San Francisco, CA)
Assignee: Shape Security, Inc.
H04L63/1416H04L43/04H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,705,902
App. No.
14/672,879
Granted
Jul 11, 2017
Kind
B1
Abstract

A computer-implemented method includes providing, for use by a third-party, injectable computer code that is capable of being served with other code provided by the third-party to client computing devices; receiving data from client computing devices that have been served the code by the third-party, the data including data that characterizes (a) the client computing devices and (b) user interaction with the client computing devices; classifying the client computing devices as controlled by actual users or instead by automated software based on analysis of the received data from the client computing devices; and providing to the third party one or more reports that characterize an overall level of automated software activity among client computing devices that have been served code by the third party.

Claims (60)

1. A computer-implemented method comprising:

providing, from a first server computer to a client computing device, and in response to a first request for a first set of code, a second set of code, which when executed on the client computing device, causes the client computing device to generate a set of data that characterizes the client computing device;

wherein the first set of code and the second set of code are different;

receiving the set of data from the client computing device that identifies a hardware configuration of the client computing device, the hardware configuration identifying an amount of memory;

classifying the client computing device as being controlled by automated software or not based on analysis of the hardware configuration is based on the identified amount of memory of the client computing device.

2. The computer-implemented method of claim 1 , wherein:

the hardware configuration further identifies a screen resolution;

classifying the client computing device as being controlled by automated software or not is further based on the screen resolution.

3. The computer-implemented method of claim 1 , wherein:

the hardware configuration further identifies one or more peripherals;

classifying the client computing device as being controlled by automated software or not is further based on the one or more peripherals.

4. The computer-implemented method of claim 1 wherein:

the set of data identifies a software configuration on the client computing device;

classifying the client computing device as being controlled by automated software or not is further based on the software configuration.

5. The computer-implemented method of claim 4 , wherein:

the software configuration further identifies a screen resolution;

classifying the client computing device as being controlled by automated software or not is further based on the screen resolution.

6. The computer-implemented method of claim 4 , wherein:

the software configuration identifies a browser and one or more properties of the browser;

classifying the client computing device as being controlled by automated software or not is further based on whether the one or more properties are consistent with the browser that is identified.

7. The computer-implemented method of claim 1 , wherein:

the set of data characterizes how a document object model defined in the first set of code is represented on the client computing device;

classifying the client computing device as being controlled by automated software or not is further based on how the document object model is represented on the client computing device.

8. The computer-implemented method of claim 1 comprising:

receiving, at the first server computer, a second request from a second server computer in response to the second server computer receiving the first request from the client computing device for the first set of code;

wherein providing the second set of code to the client computing device comprises sending the second set of code to the second server computer, which sends the first set of code and the second set of code to the client computing device.

9. The computer-implemented method of claim 1 comprising:

receiving, at the first server computer from a second server computer, the first set of code;

wherein providing the second set of code comprises sending the first set of code with the second set of code to the client computing device.

10. A computer system comprising:

a memory comprising a set of computer-executable instructions;

one or more computer processors coupled to the memory, wherein the set of computer-executable instructions, when executed by the one or more computer processors, cause the one or more computer processors to:

provide, from a first server computer to a client computing device, and in response to a first request for a first set of code, a second set of code, which when executed on the client computing device, causes the client computing device to generate a set of data that characterizes the client computing device;

wherein the first set of code and the second set of code are different;

receive the set of data from the client computing device that identifies a hardware configuration of the client computing device, the hardware configuration identifying an amount of memory;

classify the client computing device as being controlled by automated software or not based on analysis of the hardware configuration is based on the identified amount of memory of the client computing device.

11. The computer system of claim 10 , wherein:

the hardware configuration further identifies a screen resolution;

classifying the client computing device as being controlled by automated software or not is further based on the screen resolution.

12. The computer system of claim 10 , wherein:

the hardware configuration further identifies one or more peripherals;

classifying the client computing device as being controlled by automated software or not is further based on the one or more peripherals.

13. The computer system of claim 10 wherein:

the set of data identifies a software configuration on the client computing device;

classifying the client computing device as being controlled by automated software or not is further based on the software configuration.

14. The computer system of claim 13 , wherein:

the software configuration further identifies a screen resolution;

classifying the client computing device as being controlled by automated software or not is further based on the screen resolution.

15. The computer system of claim 13 , wherein:

the software configuration identifies a browser and one or more properties of the browser;

classifying the client computing device as being controlled by automated software or not is further based on whether the one or more properties are consistent with the browser that is identified.

16. The computer system of claim 10 , wherein:

the set of data characterizes how a document object model defined in the first set of code is represented on the client computing device;

classifying the client computing device as being controlled by automated software or not is further based on how the document object model is represented on the client computing device.

17. The computer system of claim 10 , wherein:

the set of computer-executable instructions, when executed by the one or more computer processors, cause the one or more computer processors to receive, at the first server computer, a second request from a second server computer in response to the second server computer receiving the first request from the client computing device for the first set of code;

wherein providing the second set of code to the client computing device comprises sending the second set of code to the second server computer, which sends the first set of code and the second set of code to the client computing device.

18. The computer system of claim 10 , wherein:

the set of computer-executable instructions, when executed by the one or more computer processors, cause the one or more computer processors to receive, at the first server computer from a second server computer, the first set of code;

wherein providing the second set of code comprises sending the first set of code with the second set of code to the client computing device.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Mar 5, 2019
From: SILICON VALLEY BANK
To: SHAPE SECURITY, INC.
Reel/Frame 048501/0115 →
SECURITY INTEREST Recorded May 25, 2018
From: SHAPE SECURITY, INC.
To: SILICON VALLEY BANK
Reel/Frame 046243/0254 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 2, 2015
From: CALL, JUSTIN D.; WANG, XINRAN; ZHAO, YAO; PEACOCK, TIMOTHY DYLAN
To: SHAPE SECURITY, INC.
Reel/Frame 036477/0498 →
Continuity (1)
Continuation 14255248 · Apr 17, 2014