IP Library › Granted Patent US 11,445,003
Granted Patent B1
US 11,445,003 · App. 17/354,983 · Granted Sep 13, 2022

Systems and methods for autonomous program detection

Inventor: Rama Rao Katta (Fremont, CA)
Assignee: Citrix Systems, Inc.
H04L67/01H04L43/106H04L67/141H04L67/143
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,445,003
App. No.
17/354,983
Filed
Jun 22, 2021
Granted
Sep 13, 2022
Kind
B1
Examiner
DUONG, OANH
Art Unit
2441
USPC
709/224
Abstract

Systems and methods for autonomous program management include a device which receives a request from a client responsive to execution of a script on the client. The request may include a location corresponding to the script and an identifier. The device may determine that activity of the client is activity of an autonomous program based on a comparison of the location to a reference being generated by the device for the client and determined using the identifier from the request. The device may block a subsequent request from the client to a server responsive to the determination.

Claims (50)

1. A method comprising:

receiving, by a device, a request from a client responsive to execution of a script on the client, the request including a first uniform resource locator (URL) corresponding to the script and a session identifier;

determining, by the device, that activity of the client as activity of an autonomous program based on a comparison of the first URL to a reference URL, the reference URL being generated by the device for the client using the session identifier from the request; and

blocking, by the device, responsive to the determination, a subsequent request from the client to a server.

2. The method of claim 1 , wherein the reference URL is generated by the device for the client, and include data corresponding to at least one of the client, a session of the client, or the request.

3. The method of claim 2 , further comprising storing, by the device, the reference URL in a distributed hash table in association with the session identifier.

4. The method of claim 1 , further comprising identifying, by the device, the reference URL using the session identifier from the request.

5. The method of claim 1 , further comprising generating, by the device, the script for the client using the reference URL and data corresponding to at least one of the client, a session of the client, or the request.

6. The method of claim 1 , wherein the request is a second request, and wherein the reference URL comprises data corresponding to at least one of:

a domain name for a first request received prior to the first request from the client;

a cluster node identifier corresponding to the device;

a packet engine identifier corresponding to the device;

a transaction number for the first request;

a timestamp for the first request; or

a domain name URL for the first request.

7. The method of claim 6 , wherein the reference URL is a hashed value of the data.

8. The method of claim 1 , wherein the request is a second request, the method further comprising:

receiving, by the device from the client, a first request prior to the second request; and

transmitting, by the device to the client, a response including data to obtain the script from the device and the session identifier identifying a session between the client and a server, wherein the response to the first request causes the client to set the session identifier as a cookie.

9. The method of claim 8 , further comprising:

receiving, by the device from the client, a third request subsequent to receiving the first request and prior to receiving the second request, the third request requesting the script, the second request including the session identifier;

transmitting, by the device, the script to the client, the script generated by the device based on the client, the session, or the first request.

10. The method of claim 1 , wherein the device determines that the activity of the client is autonomous program activity responsive to the session identifier from the request not matching the session identifier generated for the session, or the first URL not matching the reference URL corresponding to the session identifier.

11. A device comprising:

one or more processors configured to:

receive a request from a client responsive to execution of a script on the client, the request including a first uniform resource locator (URL) corresponding to the script and a session identifier;

determine that activity of the client activity of an autonomous program based on a comparison of the first URL to a reference URL being generated by the device for the client and determined using the session identifier from the request; and

block, responsive to the determination, a subsequent request from the client to a server.

12. The device of claim 11 , wherein the reference URL is generated by the device for the client, and include data corresponding to at least one of the client, a session of the client, or the request.

13. The device of claim 12 , wherein the one or more processors are further configured to store the reference URL in a distributed hash table in association with the session identifier.

14. The device of claim 11 , wherein the one or more processors are further configured to identify the reference URL using the session identifier from the request.

15. The device of claim 11 , wherein the one or more processors are further configured to generate the script for the client using the reference URL and data corresponding to at least one of the client, a session of the client, or the request.

16. The device of claim 11 , wherein the request is a second request, and wherein the reference URL comprises a hashed value of data corresponding to at least one of:

a domain name for a first request received prior to the first request from the client;

a cluster node identifier corresponding to the device;

a packet engine identifier corresponding to the device;

a transaction number for the first request;

a timestamp for the first request; or

a domain name URL for the first request.

17. The device of claim 11 , wherein the request is a second request, and wherein the one or more processors are further configured to:

receive, from the client, a first request prior to the second request; and

transmit, to the client, a response including data to obtain a script from the device and the session identifier identifying a session between the client and a server, wherein the response to the first request causes the client to set the session identifier as a cookie.

18. The device of claim 17 , wherein the one or more processors are further configured to:

receive, from the client, a third request subsequent to receiving the first request and prior to receiving the second request, the third request requesting the script executable on the client, the second request including the session identifier;

transmit the script to the client, the script generated based on the client, the session, or the first request.

19. The device of claim 11 , wherein the one or more processors are configured to determine that the activity of the client is autonomous program activity responsive to the session identifier from the request not matching the session identifier generated for the session, or the first URL not matching the reference URL corresponding to the session identifier.

20. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to:

receive a request from a client responsive to execution of a script on the client, the request including a first uniform resource locator (URL) corresponding to the script and a session identifier;

determine that activity of the client is activity of an autonomous program based on a comparison of the first URL to a reference URL generated by the device for the client and determined using the session identifier from the request; and

block, responsive to the determination, a subsequent request from the client to a server.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 22, 2021
From: KATTA, RAMA RAO
To: CITRIX SYSTEMS, INC.
Reel/Frame 056626/0220 →
Cited By (5)
US 12,386,956 US 12,445,460 US 12,493,673 US 12,732,643 US 12,743,575