IP Library Granted Patent US 10,178,114
Granted Patent B2
US 10,178,114 · App. 14/855,101 · Granted Jan 8, 2019

Analyzing client application behavior to detect anomalies and prevent access

Inventors: Ido Safruti (San Francisco, CA); Omri Iluz (Sunnyvale, CA)
Assignee: PERIMETERX, INC.
H04L63/1425G06F21/552G06F21/577H04L63/0807H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,178,114
App. No.
14/855,101
Granted
Jan 8, 2019
Kind
B2
Abstract

A client device accesses content and performs actions at a remote application server via a user-agent application. The application server directs the user-agent application to a security verification system to retrieve and perform security tests. The security verification system receives information from the user-agent application describing characteristics of the user-agent application, and the security verification system selects a set of security tests to be performed by a security module executing in the user-agent application to verify that the user-agent application is accessing the application server consistent with the described user-agent application. The security verification system compares a set of test results with other user-agent applications and provides a token to the user-agent application to access the application server. The security module may also monitor and actions on the user-agent application to permit the security verification system to revise or revoke the token.

Claims (42)

1. A method comprising:

receiving, at a security verification system from a client device, a request to verify security of the client device that specifies characteristics of an application executing on the client device, the characteristics of the application identifying a type of the application and a version of the application;

identifying, at the security verification system, a set of tests based on the characteristics of the application by identifying the set of tests from a plurality of sets of tests associated with different applications and versions;

sending, by the security verification system, the set of tests to the client device for execution by the application at the client device;

receiving, at the security verification system from the client device, a set of test results from the client device reflecting execution of the set of security tests by the application of the client device accessing a service from an application server;

comparing, the set of test results to expected test results associated with characteristics matching the characteristics of the application executing on the client device to determine differences between the set of test results and the expected test results;

generating, by the security verification system, a security token for the application, the security token including a security score describing the differences between the set of test results and the expected test results; and

sending, by the security verification system, the security token to the client device for the application to provide the security token to the application server as verification of the application on the client device.

2. The method of claim 1 , wherein sending the set of tests to the application comprises sending executable code executed by the application to the client device.

3. The method of claim 2 , wherein the application is a web browser and the executable code is a script for execution by the web browser.

4. The method of claim 1 , wherein the tests executed by the application at the client device comprise at least one of: a test identifying a user's interactions with the application, a test identifying the application's display of the service accessed from the application server, a test identifying an application's interaction with the application server, and a test identifying an executing environment of the application.

5. The method of claim 1 , further comprises

providing an additional set of tests to the client device for execution by the application when the security score for the comparison is below a threshold, and

receiving an additional set of test results from the client device,

wherein generating the security token is further based on the additional set of test results.

6. The method of claim 1 , wherein generating the security token comprises adding an identification of the set of tests and the comparison of the test results to the set of expected test results to the token.

7. The method of claim 1 , wherein the tests are executed by a security module in the application, the method further comprising

receiving, after sending the security token to the client device, an application action identified by the security module;

updating the security token based on the application action; and

providing the updated security token to the application.

8. A system comprising:

a processor configured to execute instructions;

a non-transitory computer-readable medium storing instructions that when executed by the processor cause the processor to:

receive, from a client device, a request to verify security of the client device that specifies characteristics of an application executing on the client device, the characteristics of the application identifying a type of the application and a version of the application;

identify a set of tests based on the characteristics of the application by identifying the set of tests from a plurality of sets of tests associated with different applications and versions;

send the set of tests to the client device for execution by the application at the client device;

receive, from the client device, a set of test results from the client device reflecting execution of the set of security tests by an application of the client device accessing a service from an application server;

compare the set of test results to expected test results associated with characteristics matching the characteristics of the application executing on the client device to determine differences between the set of test results and the expected test results;

generate a security token for the application, the security token including a security score describing the differences between the set of test results and the expected test results; and

send the security token to the client device for the application to provide the security token to the application server as verification of the application on the client device.

9. The system of claim 8 , wherein sending the set of tests to the application comprises sending executable code executed by the application to the client device.

10. The system of claim 9 , wherein the application is a web browser and the executable code is a script for execution by the web browser.

11. The system of claim 8 , wherein the tests executed by the application at the client device comprise at least one of: a test identifying a user's interactions with the application, a test identifying the application's display of the service accessed from the application server, a test identifying an application's interaction with the application server, and a test identifying an executing environment of the application.

12. The system of claim 8 , wherein the instructions when executed by the processor further the processor to:

provide an additional set of tests to the client device for execution by the application when the security score for the comparison is below a threshold, and

receive an additional set of test results from the client device,

wherein generating the security token is further based on the additional set of test results.

13. The system of claim 8 , wherein generating the security token comprises adding an identification of the set of tests and the comparison of the test results to the set of expected test results to the token.

14. The system of claim 8 , wherein the tests are executed by a security module in the application, wherein the instructions when executed by the processor further the processor to:

receive, after sending the security token to the client device, an application action identified by the security module;

update the security token based on the application action; and

provide the updated security token to the application.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2025
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY
To: HUMAN SECURITY, INC.; SINGULARITY BUYER LLC; PERIMETERX, INC.
Reel/Frame 071935/0486 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2025
From: ALTER DOMUS (US) LLC
To: PERIMETERX, INC.
Reel/Frame 071935/0535 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 25, 2025
From: PERIMETERX, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 072253/0245 →
SECURITY INTEREST Recorded Aug 9, 2022
From: PERIMETERX, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 060761/0797 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT Recorded Jul 29, 2022
From: AB PRIVATE CREDIT INVESTORS LLC
To: PERIMTERX, INC.
Reel/Frame 061005/0906 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 29, 2022
From: HUMAN SECURITY, INC.; SINGULARITY BUYER LLC; PERIMETERX, INC.
To: SILICON VALLEY BANK
Reel/Frame 061006/0055 →
SECURITY INTEREST Recorded Nov 25, 2020
From: PERIMETERX, INC.
To: AB PRIVATE CREDIT INVESTORS LLC
Reel/Frame 054466/0093 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2016
From: SAFRUTI, IDO; ILUZ, OMRI
To: PERIMETERX, INC.
Reel/Frame 037521/0245 →
Continuity (2)
Provisional Application 62050449 · Sep 15, 2014
Related Publication 20160080345A1 · Mar 17, 2016
Cited By (1)
US 12,316,635