IP Library Granted Patent US 9,838,419
Granted Patent B1
US 9,838,419 · App. 14/954,043 · Granted Dec 5, 2017

Detection and remediation of watering hole attacks directed against an enterprise

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,838,419
App. No.
14/954,043
Granted
Dec 5, 2017
Kind
B1
Abstract

A method comprises obtaining data characterizing web browsing activity of a group of users of an enterprise, processing the data characterizing the web browsing activity to identify one or more patterns of web browsing activity of the group of users, selecting, based on the patterns of web browsing activity, at least one website to check for evidence of a watering hole attack threat to the enterprise, analyzing elements of said at least one website to identify executable code evidencing the watering hole attack threat to the enterprise, and modifying access by one or more client devices of the enterprise to said at least one website responsive to identifying executable code of said at least one website evidencing the watering hole attack threat to the enterprise.

Claims (66)

1. A method comprising:

obtaining data characterizing web browsing activity of a group of users of an enterprise;

processing the data characterizing the web browsing activity to identify one or more patterns of web browsing activity of the group of users;

selecting, based on the patterns of web browsing activity, at least one website to check for evidence of a watering hole attack threat to the enterprise;

analyzing elements of said at least one website to identify executable code evidencing the watering hole attack threat to the enterprise; and

modifying access by one or more client devices of the enterprise to said at least one website responsive to identifying executable code of said at least one website evidencing the watering hole attack threat to the enterprise;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory; and

wherein analyzing the elements of said at least one website comprises:

generating an updated snapshot of said at least one website;

comparing the updated snapshot to one or more previous snapshots of said at least one website;

identifying one or more new elements of said at least one website based on comparing the updated snapshot to the one or more previous snapshots; and

analyzing executable code of the one or more new elements to determine evidence of the watering hole attack threat to the enterprise.

2. The method of claim 1 wherein selecting said at least one website comprises intercepting an attempted access to said at least one website by a given one of the client devices.

3. The method of claim 2 further comprising transmitting a notification indicating the watering hole attack posed by said at least one website over at least one network to the given client device.

4. The method of claim 2 further comprising transmitting a notification indicating the watering hole attack posed by said at least one website over at least one network to at least one of the client devices other than the given client device.

5. The method of claim 1 further comprising generating a set of websites identified as potential targets for the watering hole attack threat to the enterprise based on the patterns of web browsing activity, wherein selecting said at least one website comprises periodically selecting respective ones of the set of websites identified as potential targets for the watering hole attack threated to the enterprise.

6. The method of claim 1 wherein said at least one website is selected by crawling said at least one network to search for websites susceptible to watering hole attacks.

7. The method of claim 1 wherein modifying access by the one or more client devices of the enterprise to said at least one website comprises at least one of blocking and filtering elements of said at least one website comprising malicious executable code.

8. The method of claim 1 wherein modifying access by the one or more client devices of the enterprise to said at least one website comprises adding said at least one website to a blacklist of websites blocked by the enterprise, the blacklist being implemented by at least one of a domain name system operated by the enterprise and a firewall operated by the enterprise.

9. The method of claim 1 wherein analyzing the elements of said at least one website further comprises:

identifying one or more clusters of elements of said at least one website;

detecting elements of said at least one website that do not match the identified clusters; and

classifying the detected elements as anomalies.

10. The method of claim 9 further comprising analyzing executable code of the elements classified as anomalies to determine evidence of the watering hole attack threat to the enterprise.

11. The method of claim 9 wherein the elements of said at least one website are clustered based on the geographic distances between sources of each of the elements.

12. The method of claim 9 wherein the elements of said at least one website are clustered based on coding language.

13. The method of claim 9 wherein the elements of said at least one website are clustered based on textual analysis.

14. The method of claim 1 wherein at least one of the one or more previous snapshots and the updated snapshot comprises a smart snapshot that ignores elements of said at least one website that cannot execute code.

15. A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by a processing device cause the processing device:

to obtain data characterizing web browsing activity of a group of users of an enterprise;

to process the data characterizing the web browsing activity to identify one or more patterns of web browsing activity of the group of users;

to select, based on the patterns of web browsing activity, at least one website to check for evidence of a watering hole attack threat to the enterprise;

to analyze elements of said at least one web site to identify executable code evidencing the watering hole attack threat to the enterprise; and

to modify access by one or more client devices of the enterprise to said at least one website responsive to identifying executable code of said at least one website evidencing the watering hole attack threat to the enterprise;

wherein analyzing the elements of said at least one website comprises:

generating an updated snapshot of said at least one website;

comparing the updated snapshot to one or more previous snapshots of said at least one website;

identifying one or more new elements of said at least one website based on comparing the updated snapshot to the one or more previous snapshots; and

analyzing executable code of the one or more new elements to determine evidence of the watering hole attack threat to the enterprise.

16. The computer program product of claim 15 wherein analyzing the elements of said at least one website further comprises:

identifying one or more clusters of elements of said at least one website based on geographic distances between sources of each of the elements of said at least one website;

detecting elements of said at least one website that do not match the identified clusters;

classifying the detected elements as anomalies; and

analyzing executable code of the elements classified as anomalies to determine evidence of the watering hole attack threat to the enterprise.

17. The computer program product of claim 15

wherein at least one of the one or more previous snapshots and the updated snapshot comprises a smart snapshot that ignores elements of said at least one website that cannot execute code.

18. An apparatus comprising:

a processing device comprising a processor coupled to a memory;

the processing device being configured:

to obtain data characterizing web browsing activity of a group of users of an enterprise;

to process the data characterizing the web browsing activity to identify one or more patterns of web browsing activity of the group of users;

to select, based on the patterns of web browsing activity, at least one website to check for evidence of a watering hole attack threat to the enterprise;

to analyze elements of said at least one website to identify executable code evidencing the watering hole attack threat to the enterprise; and

to modify access by one or more client devices of the enterprise to said at least one website responsive to identifying executable code of said at least one website evidencing the watering hole attack threat to the enterprise;

wherein analyzing the elements of said at least one website comprises:

generating an updated snapshot of said at least one website;

comparing the updated snapshot to one or more previous snapshots of said at least one website;

identifying one or more new elements of said at least one website based on comparing the updated snapshot to the one or more previous snapshots; and

analyzing executable code of the one or more new elements to determine evidence of the watering hole attack threat to the enterprise.

19. The apparatus of claim 18 wherein analyzing the elements of said at least one website further comprises:

identifying one or more clusters of elements of said at least one website based on geographic distances between sources of each of the elements of said at least one website;

detecting elements of said at least one website that do not match the identified clusters;

classifying the detected elements as anomalies; and

analyzing executable code of the elements classified as anomalies to determine evidence of the watering hole attack threat to the enterprise.

20. The apparatus of claim 18

wherein at least one of the one or more previous snapshots and the updated snapshot comprises a smart snapshot that ignores elements of said at least one website that cannot execute code.

Assignments (22)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
NOTICE OF PARTIAL TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN TRADEMARK RIGHTS AND PATENT RIGHTS RECORDED AT REEL/FRAME: 056098/0534 Recorded Jun 3, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 071484/0819 →
NOTICE OF PARTIAL TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN TRADEMARK RIGHTS AND PATENT RIGHTS RECORDED AT REEL/FRAME: 056096/0525 Recorded Jun 3, 2025
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC
Reel/Frame 071482/0733 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2025
From: RSA SECURITY LLC
To: NETWITNESS SECURITY LLC
Reel/Frame 071495/0168 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2015
From: FLEYDER, URI; KERNER, ROTEM; RABINOVICH, ZEEV; SALINAS, ROTEM; FRANK, DANIEL; BEN-PORAT, LIOR
To: EMC CORPORATION
Reel/Frame 037167/0720 →