IP Library › Granted Patent US 11,997,135
Granted Patent B2
US 11,997,135 · App. 17/136,518 · Granted May 28, 2024

Systems and methods for protection against theft of user credentials

Inventors: Daniel G. Wing (Truckee, CA); Manbinder Pal Singh (Coral Springs, FL)
Assignee: Citrix Systems, Inc.
H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,997,135
App. No.
17/136,518
Filed
Dec 29, 2020
Granted
May 28, 2024
Kind
B2
Art Unit
2433
USPC
726/23
Abstract

A computer system is provided. The computer system includes a memory and at least one processor coupled to the memory and configured to protect against theft of user credentials. The at least one processor is further configured to recognize a uniform resource locator (URL) to which a web browser is navigating, as a URL for which protection is to be provided. The recognition is based on an absence of the URL from a history of visited URLs for which a password has been entered. The at least one processor is further configured to extract a character sequence of selected length that is entered into a field of a website associated with the recognized URL; compare an encryption of the character sequence to entries in a list of encrypted partial passwords of the same selected length; and perform a security action in response to a match resulting from the comparison.

Claims (38)

1. A computer system comprising:

a memory; and

at least one processor coupled to the memory and configured to:

recognize a uniform resource locator (URL) to which a web browser is navigating as a URL for which protection is to be provided, the recognition based on an absence of the URL from a history of visited URLs for which a password has been entered;

extract a sequence of characters entered into a website associated with the URL, the extraction performed in response to the recognition;

monitor a rate at which the sequence of characters is entered;

compare an encryption of the extracted sequence of characters to one or more entries in a list of encrypted partial passwords, wherein a character length of the encryption of the extracted sequence of characters is chosen to match a character length of the encrypted partial passwords, wherein the character length of the encrypted partial passwords is less than a full password length;

perform a security action in response to a match resulting from the comparison; and

in response to the monitored rate exceeding a threshold keystroke rate, disable the security action and provide a warning that a malicious agent may be hosted on the computer system.

2. The computer system of claim 1 , wherein the list of encrypted partial passwords is generated by detection of passwords provided to visited websites over a selected period of time and encrypting the detected passwords.

3. The computer system of claim 1 , wherein the list of encrypted partial passwords is generated by obtaining a list of passwords from a web browser database of saved passwords and encrypting the passwords in the obtained list of passwords.

4. The computer system of claim 1 , wherein the recognition is further based on a match of the URL to an entry in a list of suspect URLs, the list of suspect URLs generated by a URL reputation manager.

5. The computer system of claim 1 , wherein the at least one processor is further configured to suppress the security action if an input field of the website is associated with a label that indicates a password entry is requested.

6. The computer system of claim 1 , wherein the at least one processor is further configured to provide the security action if an input field of the website is associated with a label that does not indicate a password entry is requested.

7. A method for protection of user credentials comprising:

recognizing, by a computer system, a uniform resource locator (URL) to which a web browser is navigating, as a URL for which protection is to be provided, the recognition based on an absence of the URL from a history of visited URLs for which a password has been entered;

extracting, by the computer system, a sequence of characters entered into a website associated with the URL, the extraction performed in response to the recognition;

monitoring, by the computer system, a rate at which the sequence of characters is entered;

comparing, by the computer system, an encryption of the extracted sequence of characters to one or more entries in a list of encrypted partial passwords, wherein a character length of the encryption of the extracted sequence of characters is chosen to match a character length of the encrypted partial passwords, wherein the character length of the encrypted partial passwords is less than a full password length;

performing, by the computer system, a security action in response to a match resulting from the comparison; and

in response to the monitored rate exceeding a threshold keystroke rate, disable the security action and provide a warning that a malicious agent may be hosted on the computer system.

8. The method of claim 7 , wherein the list of encrypted partial passwords is generated by detection of passwords provided to visited websites over a selected period of time and encrypting the detected passwords.

9. The method of claim 7 , wherein the list of encrypted partial passwords is generated by obtaining a list of passwords from a web browser database of saved passwords and encrypting the passwords in the obtained list of passwords.

10. The method of claim 7 , wherein the recognition is further based on a match of the URL to an entry in a list of suspect URLs, the list of suspect URLs generated by a URL reputation manager.

11. The method of claim 7 , further comprising suppressing the security action if an input field of the website is associated with a label that indicates a password entry is requested.

12. The method of claim 7 , further comprising providing the security action if an input field of the website is associated with a label that does not indicate a password entry is requested.

13. A non-transitory computer readable medium storing executable sequences of instructions to provide protection of user credentials, the sequences of instructions comprising instructions to:

recognize a uniform resource locator (URL) to which a web browser is navigating as a URL for which protection is to be provided, the recognition based on an absence of the URL from a history of visited URLs for which a password has been entered;

extract a sequence of characters entered into a website associated with the URL, the extraction performed in response to the recognition;

compare an encryption of the extracted sequence of characters to one or more entries in a list of encrypted partial passwords, wherein a character length of the encryption of the extracted sequence of characters is chosen to match a character length of the encrypted partial passwords, wherein the character length of the encrypted partial passwords is less than a full password length;

perform a security action in response to a match resulting from the comparison; and

monitor a rate at which the sequence of characters is entered and, in response to the monitored rate exceeding a threshold keystroke rate, disable the security action and provide a warning that a malicious agent may be hosted on the computer system.

14. The computer readable medium of claim 13 , wherein the list of encrypted partial passwords is generated by detection of passwords provided to visited websites over a selected period of time and encrypting the detected passwords.

15. The computer readable medium of claim 13 , wherein the list of encrypted partial passwords is generated by obtaining a list of passwords from a web browser database of saved passwords and encrypting the passwords in the obtained list of passwords.

16. The computer readable medium of claim 13 , wherein the recognition is further based on a match of the URL to an entry in a list of suspect URLs, the list of suspect URLs generated by a URL reputation manager.

17. The computer readable medium of claim 13 , wherein the sequences of instructions further include instructions to detect an operation to paste a character string and use the character string as the extracted sequence of characters.

18. The computer readable medium of claim 13 , wherein the sequences of instructions further include instructions to suppress the security action if an input field of the website is associated with a label that indicates a password entry is requested.

19. The computer readable medium of claim 13 , wherein the sequences of instructions further include instructions to provide the security action if an input field of the website is associated with a label that does not indicate a password entry is requested.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2020
From: WING, DANIEL G.; SINGH, MANBINDER PAL
To: CITRIX SYSTEMS, INC.
Reel/Frame 054783/0199 →
Continuity (1)
Related Publication 20220210187A1 · Jun 30, 2022
Cited By (1)
US 12,192,233