IP Library Granted Patent US 12,432,245
Granted Patent B2
US 12,432,245 · App. 17/898,931 · Granted Sep 30, 2025

System and method for chaos testing in an edge network

Inventor: Kelly Shortridge (New York, NY)
Assignee: Fastly, Inc.
H04L63/1433H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,245
App. No.
17/898,931
Granted
Sep 30, 2025
Kind
B2
Abstract

Methods and apparatus are disclosed herein that enable an infrastructure service to implement security verification without significantly interrupting end user network traffic. The infrastructure service copies request messages and modifies a portion of the header information of the request message. Both the original message and the modified message are then sent for fulfillment. The infrastructure service compares the responses in order to create a security test report.

Claims (60)

1. A method of operating a server in an infrastructure service to verify security of a website, the method comprising:

receiving a request message that comprises a header portion and a content indicator that indicates at least a portion of a website that is requested, wherein the header portion comprises verification information;

determining that the request message will be tested;

removing the verification information from the header portion to create a modified header portion;

creating a second request message, wherein the second request message comprises the content indicator and the modified header portion;

forwarding, from the server, the request message and the second request message to a supply server;

receiving, at the server, a first response to the request message and a second response to the second request message;

returning, from the server, the first response in response to the request message;

comparing the first response and the second response; and

creating a security report based on the comparison, wherein the security report indicates if the server provided the requested portion of the website to the server in response to receiving the second request message with the modified header portion that did not include the verification information.

2. The method of claim 1 , wherein the supply server is an origin server.

3. The method of claim 1 , wherein the infrastructure service comprises an edge network, and the server is a server within the edge network.

4. The method of claim 3 , wherein the supply server is a server within the edge network.

5. The method of claim 1 , wherein removing the verification information from the header portion comprises removing the verification information and one or more cookies from the header portion to create the modified header portion.

6. The method of claim 1 , wherein removing the verification information from the header portion comprises removing the verification information from the header portion and inserting a cross-site origin into the header portion to create the modified header portion.

7. The method of claim 1 , further comprising transferring the security report for delivery to a manager associated with the website.

8. The method of claim 1 , further comprising:

receiving a further request message, wherein the further request message comprises a further header portion and a further content indicator that indicates at least a portion of a further website that is requested;

determining that the request message will not be tested;

forwarding the further request message to a supply server without creating a second further request message;

receiving a further response to the further request message; and

returning the further response in response to the further request message.

9. A server in an infrastructure service, the server configured to:

test security of a website, wherein testing the security of the website comprises:

receiving a request message that comprises a header portion and a content indicator that indicates at least a portion of the website that is requested, wherein the header portion comprises verification information;

determining that the request message will be tested;

removing the verification information from the header portion to create a modified header portion;

creating a second request message, wherein the second request message comprises the content indicator and the modified header portion;

forwarding, from the server, the request message and the second request message to a supply server;

receiving, at the server, a first response to the request message and a second response to the second request message;

returning, from the server, the first response in response to the request message;

comparing the first response and the second response; and

creating a security report based on the comparison, wherein the security report indicates if the server provided the requested portion of the website to the server in response to receiving the second request message with the modified header portion that did not include the verification information.

10. The server of claim 9 , wherein the supply server is an origin server.

11. The server of claim 9 , wherein the infrastructure service comprises an edge network, and the server is a server within the edge network.

12. The server of claim 11 , wherein the supply server is a server within the edge network.

13. The server of claim 9 , wherein removing the verification information from the header portion comprises removing the verification information from the header portion and one or more cookies from the header portion to create the modified header portion.

14. The server of claim 9 , wherein removing the verification information from the header portion comprises removing the verification information from the header portion and inserting a cross-site origin into the header portion to create the modified header portion.

15. The server of claim 9 , wherein testing the security of the website further comprises transferring the security report for delivery to a manager associated with the website.

16. The server of claim 9 , wherein testing the security of the website further comprises:

receiving a further request message, wherein the further request message comprises a further header portion and a further content indicator that indicates at least a portion of a further website that is requested;

determining that the request message will not be tested;

forwarding the further request message to a supply server without creating a second further request message;

receiving a further response to the further request message; and

returning the further response in response to the further request message.

17. A server in an infrastructure service, the server comprising:

a processor and tangible memory;

the tangible memory storing instructions, which, when executed by the processor, instruct the processor to test security of a website, wherein testing the security of the website comprises:

receiving a request message that comprises a header portion and a content indicator that indicates at least a portion of the website that is requested, wherein the header portion comprises verification information;

determining that the request message will be tested;

removing the verification information from the header portion to create a modified header portion;

creating a second request message, wherein the second request message comprises the content indicator and the modified header portion;

forwarding, from the server, the request message and the second request message to a supply server;

receiving, at the server, a first response to the request message and a second response to the second request message;

returning, from the server, the first response in response to the request message;

comparing the first response and the second response; and

creating a security report based on the comparison, wherein the security report indicates if the server provided the requested portion of the website to the server in response to receiving the second request message with the modified header portion that did not include the verification information.

18. The server of claim 17 , wherein removing the verification information from the header portion comprises removing the verification information from the header portion and one or more cookies from the header portion to create the modified header portion.

19. The server of claim 17 , wherein removing the verification information from the header portion comprises removing the verification information from the header portion and inserting a cross-site origin into the header portion to create the modified header portion.

20. The server of claim 17 , wherein testing the security of the website further comprises transferring the security report for delivery to a manager associated with the website.

Assignments (2)
SECURITY INTEREST Recorded May 1, 2024
From: FASTLY, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY, AS ADMINISTRATIVE AGENT
Reel/Frame 067281/0500 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2022
From: SHORTRIDGE, KELLY
To: FASTLY, INC.
Reel/Frame 061168/0850 →
Continuity (1)
Related Publication 20240073235A1 · Feb 29, 2024
References Cited (27)
US 8826443B1 · Raman · 2014 [cited by examiner]
US 8914406B1 · Haugsnes · 2014 [cited by examiner]
US 9075990B1 · Yang · 2015 [cited by examiner]
US 9350757B1 · Falkowitz · 2016 [cited by examiner]
US 10200384B1 · Mushtaq · 2019 [cited by examiner]
US 10880322B1 · Jakobsson · 2020 [cited by examiner]
US 11909764B1 · Curran · 2024 [cited by examiner]
US 20020143933A1 · Hind · 2002 [cited by examiner]
US 20020156836A1 · Janosik, Jr. · 2002 [cited by examiner]
US 20030018707A1 · Flocken · 2003 [cited by examiner]
US 20030195861A1 · McClure · 2003 [cited by examiner]
US 20110099467A1 · Kapur · 2011 [cited by examiner]
US 20110283359A1 · Prince · 2011 [cited by examiner]
US 20120117222A1 · Holloway · 2012 [cited by examiner]
US 20140215560A1 · Roberson · 2014 [cited by examiner]
US 20140259147A1 · L'Heureux · 2014 [cited by examiner]
US 20150222656A1 · Haugsnes · 2015 [cited by examiner]
US 20150347751A1 · Card · 2015 [cited by examiner]
US 20160182537A1 · Tatourian · 2016 [cited by examiner]
US 20170118241A1 · Call · 2017 [cited by examiner]
US 20180152471A1 · Jakobsson · 2018 [cited by examiner]
US 20180351986A1 · Johns · 2018 [cited by examiner]
US 20200167478A1 · Tammachi · 2020 [cited by examiner]
US 20200351306A1 · Nedbal · 2020 [cited by examiner]
US 20210021612A1 · Higbee · 2021 [cited by examiner]
US 20210281584A1 · Levine · 2021 [cited by examiner]
US 20230367833A1 · Kol · 2023 [cited by examiner]