IP Library Granted Patent US 9,485,275
Granted Patent B2
US 9,485,275 · App. 14/824,287 · Granted Nov 1, 2016

Detection of spoofing of remote client system information

Inventor: Alfred P. Gehrig, Jr. (Mission Viejo, CA)
Assignee: BLUECAVA, INC.
H04L63/1483G06F21/44H04L63/0876H04L63/1416H04L67/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,485,275
App. No.
14/824,287
Granted
Nov 1, 2016
Kind
B2
Abstract

Digital fingerprint generation logic executed by a client device includes quirk-exposing logic configured to expose behavioral differences between various system configurations of client devices. The digital fingerprint generation logic queries a remote client device for system configuration, and generates a digital fingerprint of the client device that includes a system configuration characteristic reported by the client device in response to the query. Results of execution of the quirk-exposing logic are compared to expected results that are specific to the reported system configuration. If the results of execution do not match the expected results, the digital fingerprint is determined to have been spoofed.

Claims (36)

1. A method for detecting spoofing of system information reported by a remote client device, the method comprising steps for:

querying the remote client device for system information identifying a system configuration of the remote client device;

receiving in response to the querying step a reported system configuration;

causing the remote client device to execute exposing logic configured to induce an expected result characteristic of the reported system configuration, wherein the expected result characteristic is based on processing a common input and will vary as a result of the browser type installed on the remote client device;

identifying a result of execution of the exposing logic by the remote client device; and

determining that the system information is incorrect upon a condition in which the result of execution does not match the expected result for the browser type installed on the remove device.

2. The method of claim 1 wherein the system information includes data from one or more plug-ins installed on a browser on the remote client device.

3. The method of claim 1 wherein the exposing logic causes the remote client device to evaluate a mathematical expression and wherein the expected result includes a numerical value.

4. The method of claim 1 wherein the exposing logic is configured to cause execution of a function known to generate a particular error when executed within the reported system configuration.

5. The method of claim 1 wherein the exposing logic involves browser quirk data.

6. The method of claim 1 wherein the reported system configuration is captured in a digital fingerprint.

7. A non-transitory computer readable medium useful in association with a computer which includes one or more processors and a memory, the computer readable medium including computer instructions which are configured to cause the computer, by execution of the computer instructions in the one or more processors from the memory, to detect incorrect system information about a remote client device by at least:

querying the remote client device for system information identifying a system configuration of the remote client device;

receiving in response to the querying step a reported system configuration;

causing the remote client device to execute exposing logic configured to induce an expected result characteristic of the reported system configuration, wherein the expected result characteristic is based on processing a common input and will vary as a result of the browser type installed on the remote client device;

identifying a result of execution of the exposing logic by the remote client device; and

determining that the system information is incorrect upon a condition in which the result of execution does not match the expected result for the browser type installed on the remote client device.

8. The computer readable medium of claim 7 wherein the system information includes data from one or more plug-ins installed on a browser on the remote client device.

9. The computer readable medium of claim 7 wherein the exposing logic causes the remote client device to evaluate a mathematical expression and wherein the expected result includes a numerical value.

10. The computer readable medium of claim 7 wherein the exposing logic is configured to cause execution of a function known to generate a particular error when executed within the reported system configuration.

11. The computer readable medium of claim 7 wherein the exposing logic involves browser quirk data.

12. The computer readable medium of claim 7 wherein the reported system configuration is captured in a digital fingerprint.

13. A computer system comprising:

at least one microprocessor;

a computer readable medium that is operatively coupled to the processor; and

a server logic that (i) executes in the microprocessor from the computer readable medium and (ii) when executed by the microprocessor, causes the computer to detect incorrect system information about a remote client device by at least:

querying the remote client device for system information identifying a system configuration of the remote client device;

receiving in response to the querying step a reported system configuration;

causing the remote client device to execute exposing logic configured to induce an expected result characteristic of the reported system configuration, wherein the expected result characteristic is based on processing a common input and will vary as a result of the browser type installed on the remote client device;

identifying a result of execution of the exposing logic by the remote client device; and

determining that the system information is incorrect upon a condition in which the result of execution does not match the expected result for the browser type installed on the remote device.

14. The computer system of claim 13 wherein the system information includes data from one or more plug-ins installed on a browser on the remote client device.

15. The computer system of claim 13 wherein the exposing logic causes the remote client device to evaluate a mathematical expression and further wherein the result includes a numerical value.

16. The computer system of claim 13 wherein the exposing logic is configured to cause execution of a function known to generate a particular error when executed within the reported system configuration.

17. The computer system of claim 13 wherein the exposing logic involves browser quirk data.

18. The computer system of claim 13 wherein the reported system configuration is captured in a digital fingerprint.

Assignments (4)
CHANGE OF NAME Recorded Nov 2, 2022
From: ALC, INC.
To: ADSTRA, INC.
Reel/Frame 061875/0449 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2018
From: BLUECAVA, INC.
To: ALC, INC.
Reel/Frame 047315/0425 →
RELEASE OF SECURITY INTEREST Recorded Oct 23, 2018
From: COMERICA BANK
To: BLUECAVA, INC.
Reel/Frame 047270/0689 →
SECURITY INTEREST Recorded Jan 13, 2016
From: BLUECAVA, INC.
To: COMERICA BANK
Reel/Frame 037477/0408 →
Continuity (4)
Continuation 14036547 · Sep 25, 2013
Continuation PCTUS2012033786 · Apr 16, 2012
Provisional Application 61476206 · Apr 15, 2011
Related Publication 20150350244A1 · Dec 3, 2015