IP Library Granted Patent US 10,931,690
Granted Patent B1
US 10,931,690 · App. 16/127,164 · Granted Feb 23, 2021

Thwarting potentially malicious online activity

Inventor: Venkadesan Marimuthu (Chennai, IN)
Assignee: NORTONLIFELOCK, INC.
H04L63/1416H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,931,690
App. No.
16/127,164
Granted
Feb 23, 2021
Kind
B1
Abstract

Thwarting potentially malicious online activity. In one embodiment, a method may include logging legitimate online user activities performed at a browser. The method may also include receiving a suspicious online activity that was performed at a website. The method may further include comparing the suspicious online activity to the logged legitimate online user activities to determine whether the suspicious online activity matches any of the logged legitimate online user activities. The method may also include, in response to determining that the suspicious online activity does not match any of the logged legitimate online user activities, determining that the suspicious online activity is a potentially malicious online activity, and thwarting the potentially malicious online activity by performing a remedial action at the website to protect the website from the potentially malicious online activity.

Claims (40)

1. A computer-implemented method for thwarting potentially malicious online activity, at least a portion of the method being performed by a network device comprising at least one processor, the method comprising:

logging legitimate online user activities that were performed at, and detected at, a browser;

receiving a report of a suspicious online activity that was performed at, and detected at, a web server hosting a website;

comparing the reported suspicious online activity to the logged legitimate online user activities to determine whether the reported suspicious online activity matches any of the logged legitimate online user activities; and

in response to determining that the reported suspicious online activity does not match any of the logged legitimate online user activities:

determining that the reported suspicious online activity is a potentially malicious online activity; and

thwarting the potentially malicious online activity by performing a remedial action at the website to protect the website from the potentially malicious online activity.

2. The method of claim 1 , wherein the legitimate online user activities performed at the browser are captured by a password manager.

3. The method of claim 2 , wherein the password manager is a browser extension of the browser.

4. The method of claim 2 , wherein the report of the suspicious online activity is received by the password manager.

5. The method of claim 2 , wherein, prior to the logging, the user is authenticated by the password manager at the browser in order to confirm that any activities performed at the browser by the user are legitimate.

6. The method of claim 1 , wherein the performing of the remedial action at the website comprises blocking one or more network devices from accessing the website.

7. The method of claim 1 , wherein the performing of the remedial action at the website comprises rolling back one or more changes at the website that were made in response to the potentially malicious online activity.

8. One or more non-transitory computer-readable media comprising one or more computer-readable instructions that, when executed by one or more processors of a network device, cause the network device to perform a method for thwarting potentially malicious online activity, the method comprising:

logging legitimate online user activities that were performed at, and detected at, a browser;

receiving a report of a suspicious online activity that was performed at, and detected at, a web server hosting a website;

comparing the reported suspicious online activity to the logged legitimate online user activities to determine whether the reported suspicious online activity matches any of the logged legitimate online user activities; and

in response to determining that the reported suspicious online activity does not match any of the logged legitimate online user activities:

determining that the reported suspicious online activity is a potentially malicious online activity; and

thwarting the potentially malicious online activity by performing a remedial action at the website to protect the website from the potentially malicious online activity.

9. The one or more non-transitory computer-readable media of claim 8 , wherein the legitimate online user activities performed at the browser of the network device are captured by a password manager.

10. The one or more non-transitory computer-readable media of claim 9 , wherein the password manager is a browser extension of the browser.

11. The one or more non-transitory computer-readable media of claim 9 , wherein the report of the suspicious online activity is received by the password manager.

12. The one or more non-transitory computer-readable media of claim 9 , wherein, prior to the logging, the user is authenticated by the password manager at the browser in order to confirm that any activities performed at the browser by the user are legitimate.

13. The one or more non-transitory computer-readable media of claim 8 , wherein the performing of the remedial action at the website comprises blocking one or more network devices from accessing the website.

14. The one or more non-transitory computer-readable media of claim 8 , wherein the performing of the remedial action at the web site comprises rolling back one or more changes at the website that were made in response to the potentially malicious online activity.

15. A network device for thwarting potentially malicious online activity, the network device comprising:

one or more processors; and

one or more non-transitory computer-readable media comprising one or more computer-readable instructions that, when executed by the one or more processors, cause the network device to perform a method comprising:

logging legitimate online user activities that were performed at, and detected at, a browser;

receiving a report of a suspicious online activity that was performed at, and detected at, a web server hosting a website;

comparing the reported suspicious online activity to the logged legitimate online user activities to determine whether the reported suspicious online activity matches any of the logged legitimate online user activities; and

in response to determining that the reported suspicious online activity does not match any of the logged legitimate online user activities:

determining that the reported suspicious online activity is a potentially malicious online activity; and

thwarting the potentially malicious online activity by performing a remedial action at the website to protect the website from the potentially malicious online activity.

16. The network device of claim 15 , wherein the legitimate online user activities performed at the browser of the network device are captured by a password manager that is a browser extension of the browser.

17. The network device of claim 16 , wherein the report of the suspicious online activity is received by the password manager.

18. The network device of claim 16 , wherein, prior to the logging, the user is authenticated by the password manager at the browser in order to confirm that any activities performed at the browser by the user are legitimate.

19. The network device of claim 15 , wherein the performing of the remedial action at the website comprises blocking one or more network devices from accessing the website.

20. The network device of claim 15 , wherein the performing of the remedial action at the website comprises rolling back one or more changes at the website that were made in response to the potentially malicious online activity.

Assignments (6)
CHANGE OF NAME Recorded May 18, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 063697/0493 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Mar 5, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 052109/0186 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2018
From: MARIMUTHU, VENKADESAN
To: SYMANTEC CORPORATION
Reel/Frame 046836/0314 →