IP Library Granted Patent US 11,411,965
Granted Patent B2
US 11,411,965 · App. 15/294,728 · Granted Aug 9, 2022

Method and system of attack detection and protection in computer systems

Inventors: Jeffrey Williams (Ashton, MD); Arshan Dabirsiaghi (Parkville, CA)
H04L63/1416G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,411,965
App. No.
15/294,728
Filed
Oct 15, 2016
Granted
Aug 9, 2022
Kind
B2
Art Unit
2498
USPC
726/1
Abstract

In one example aspect, a computerized method of automatically detecting and blocking at least one attack on an application includes the step of modifying instructions of the application to include at least one sensor. The at least one sensor generates a set of events related to detecting an attack on the application or a computing system implementing the application. The method includes the step of reviewing, from within the application, the set of events generated by the at least one sensor. The method includes the step of detecting a presence of at least one attack on the application based on the review of the set of events. The method includes the step of invoking an attack response action.

Claims (45)

1. A computerized method of automatically detecting and blocking at least one attack on an application comprising:

wherein the at least one attack is on the application;

modifying, from within the application, instructions of the application to include at least one sensor, wherein the sensor generates a set of events related to detecting an attack on the application, when executed by one or more processors, or a computing system implementing the application, wherein the at least one sensor is configured to create an event based on a configuration information for the application, and wherein the sensor comprises a passive sensor that generates an event that is collected and analyzed whenever an instrumented method is invoked;

reviewing, from within the application, the set of events generated by the at least one sensor;

detecting, from within the application, a presence of the at least one attack on the application based on the review of the set of events; and

invoking, from within the application, an attack response action, wherein the step of invoking an attack response action further comprises:

enabling a custom set of rules and responses to be enforced as a virtual patch,

modifying a set of instructions of the application snapshot to include at least one sensor adapted to generate an action selected by testing and analyzing a runtime behavior of a run-time library or run time component, and

dynamically patching a code segment at a run-time of the application, and

wherein the sensors and the attack response actions are controlled by a set of custom rules created by a user, and

wherein the set of custom rules are used to implement the virtual patch to the application.

2. The computerized method of claim 1 , wherein the set of events are related to detecting both the attack on the application or the computing system implementing the application and a vulnerability detection related to an attack vulnerability of the application or in the computing system implementing the application.

3. The computerized method of claim 1 , wherein the detected attack comprises a bot attack.

4. The computerized method of claim 1 , wherein the detected attack comprises an attempt to exploit a specific known vulnerability in a library the application or in the computing system implementing the application.

5. The computerized method of claim 1 further comprising:

implementing a lazy-attack evaluation.

6. The computerized method of claim 1 , wherein the attack response action comprises a logging action that records a set of events related to the attack.

7. The computerized method of claim 1 , wherein the attack response action comprises throwing an exception.

8. The computerized method of claim 1 , wherein the attack response action comprises redirecting the user's web browser to another web page.

9. The computerized method of claim 1 , wherein the attack response action comprises sending the user's web browser to a honeypot mechanism.

10. The computerized method of claim 1 , wherein the attack response action comprising adding or enabling a specified security feature or reconfiguring the application.

11. The computerized method of claim 1 , wherein the sensor is configured to create an action snapshot based on the data in HTTP requests and a response that is either received or transmitted by the application.

12. The computerized method of claim 1 , wherein the code segment to be patched is a software component or library that is a part of the application.

13. A server system of automatically detecting and blocking at least one attack on an application comprising:

a processor configured to execute instructions;

a memory containing instructions when executed on the processor, causes the processor to perform operations that:

modify, from within the application, instructions of the application to include at least one sensor, wherein the sensor generates a set of events related to detecting an attack on the application or a computing system implementing the application, wherein the at least one sensor is configured to create an event based on a configuration information for the application, and wherein the sensor comprises a passive sensor that generates an event that is collected and analyzed whenever an instrumented method is invoked;

review, from within the application, the set of events generated by the at least one sensor;

detect, from within the application, a presence of at least one attack on the application based on the review of the set of events; and

invoke, from within the application, an attack response action by:

enabling a custom set of rules and responses to be enforced as a virtual patch,

modifying a set of instructions of the application snapshot to include at least one sensor adapted to generate an action selected by testing and analyzing a runtime behavior of a run-time library or run time component, and

dynamically patching a code segment at a run-time of the application, and

wherein the sensors and the attack response actions are controlled by a set of custom rules created by a user, and

wherein the set of custom rules are used to implement the virtual patch to the application.

14. A computerized method of automatically detecting and blocking at least one attack on an application comprising:

modifying, from within the application, instructions of the application to include at least one sensor, wherein the sensor generates a set of events related to detecting an attack on the application, when executed by one or more processors, or a computing system implementing the application, wherein the sensor is configured to create an event based on a configuration information for the application, and wherein the sensor comprises an active sensor or a passive sensor that generates an event that is collected and analyzed whenever an instrumented method is invoked;

reviewing, from within the application, the set of events generated by the at least one sensor;

detecting, from within the application, a presence of at least one attack on the application based on the review of the set of events; and

invoking, from within the application, an attack response action, wherein the step of invoking an attack response action further comprises:

enabling a custom set of rules and responses to be enforced as a virtual patch,

modifying a set of instructions of the application snapshot to include at least one sensor adapted to generate an action selected by testing and analyzing a runtime behavior of a run-time library or run time component, and

dynamically patching a code segment at a run-time of the application, and

wherein the sensors and the attack response actions are controlled by a set of custom rules created by a user, and

wherein the set of custom rules are used to implement the virtual patch to the application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2017
From: WILLIAMS, JEFFREY; DABIRSIAGHI, ARSHAN
To: CONTRAST SECURITY, INC.
Reel/Frame 043659/0718 →
Continuity (8)
Continuation In Part 15000030 · Jan 18, 2016
Continuation In Part 14177628 · Feb 11, 2014
Continuation In Part 13466527 · May 8, 2012
Continuation 12870367 · Aug 27, 2010
Provisional Application 62241897 · Oct 15, 2015
Provisional Application 62408775 · Oct 15, 2016
Provisional Application 61315666 · Mar 19, 2010
Related Publication 20170142138A1 · May 18, 2017
Cited By (18)
US 12,355,787 US 12,363,148 US 12,368,746 US 12,375,573 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,576 US 12,489,770 US 12,500,911 US 12,513,221 US 12,537,837 US 12,537,839 US 12,556,548 US 12,587,553 US 12,659,326 US 12,689,638 US 12,706,932