IP Library Granted Patent US 12,381,913
Granted Patent B1
US 12,381,913 · App. 17/932,187 · Granted Aug 5, 2025

Systems and methods for utilizing contextual digital fingerprints to protect against browser-based malicious attacks

Inventor: Iskander Sanchez Rola (Antibes, FR)
Assignee: Gen Digital Inc.
H04L63/1483H04L63/029H04L63/067H04L63/0281
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,381,913
App. No.
17/932,187
Granted
Aug 5, 2025
Kind
B1
Abstract

The disclosed computer-implemented method for utilizing contextual digital fingerprints to protect against browser-based malicious attacks may include (i) detecting an execution of one or more fingerprinting application programming interface (API) calls utilized by a target website for providing access to a user, (ii) generating identity data comprising specific values for each of the fingerprinting API calls to create a contextual digital fingerprint, (iii) storing the contextual digital fingerprint for consecutive accesses to the target website, and (iv) performing a security action that, based on the identity data in the contextual digital fingerprint, protects against browser-based malicious attacks attempting to access the target website. Various other methods, systems, and computer-readable media are also disclosed.

Claims (44)

1. A computer-implemented method for utilizing contextual digital fingerprints to protect against browser-based malicious attacks, at least a portion of the method being performed by one or more computing devices comprising at least one processor, the method comprising:

detecting, by the one or more computing devices, an execution of one or more fingerprinting application programming interface (API) calls utilized by a target website for providing access to a user;

generating, by the one or more computing devices, a contextual digital fingerprint that is specific to the target website by generating new values specific to the target website for each of the fingerprinting API calls;

storing, by the one or more computing devices, the contextual digital fingerprint for consecutive accesses to the target website using the contextual digital fingerprint; and

performing, by the one or more computing devices, a security action that, based on the contextual digital fingerprint, protects against browser-based malicious attacks attempting to access the target website.

2. The computer-implemented method of claim 1 , wherein detecting the execution of the fingerprinting API calls utilized by the target website for providing access to the user comprises:

monitoring, by at least one of a web browser and a browser extension and in real-time, the execution of the fingerprinting API calls; and

identifying one or more programming code functions returned in response to the fingerprinting API calls.

3. The computer-implemented method of claim 1 , wherein generating the contextual digital fingerprint further comprises linking the contextual digital fingerprint with a predetermined location.

4. The computer-implemented method of claim 3 , wherein linking the contextual digital fingerprint with the predetermined location comprises utilizing a virtual private network (VPN) tunnel to link the contextual digital fingerprint with a geographic location associated with a user accessing the target website.

5. The computer-implemented method of claim 3 , wherein linking the contextual digital fingerprint with the predetermined location comprises utilizing a proxy to link the contextual digital fingerprint with a geographic location associated with a user accessing the target website.

6. The computer-implemented method of claim 1 , wherein generating the contextual digital fingerprint further comprises:

receiving data identifying one or more new fingerprinting API calls utilized by the target website;

generating new identity data for each of the new fingerprinting API calls based on the target website; and

updating the contextual digital fingerprint based on the new identity data.

7. The computer-implemented method of claim 1 , wherein generating the contextual digital fingerprint comprises generating the specific values for each of a plurality of calls to a programming code function.

8. The computer-implemented method of claim 1 , wherein storing the contextual digital fingerprint for the consecutive accesses to the target website comprises saving the contextual digital fingerprint as encrypted data to at least one of a local client storage device and a password manager service.

9. The computer-implemented method of claim 1 , wherein performing the security action comprises preventing a phishing website utilized in the browser-based malicious attacks from accessing the identity data generated for the contextual digital fingerprint.

10. The computer-implemented method of claim 1 , wherein the contextual digital fingerprint is created utilizing at least one of a web browser or a web browser extension.

11. A system for utilizing contextual digital fingerprints to protect against browser-based malicious attacks, the system comprising:

at least one physical processor;

physical memory comprising computer-executable instructions and one or more modules that, when executed by the physical processor, cause the physical processor to:

detect, by a detection module, an execution of one or more fingerprinting application programming interface (API) calls utilized by a target website for providing access to a user;

generate, by an identity module, a contextual digital fingerprint that is specific to the target website by generating new values specific to the target website for each of the fingerprinting API calls;

store, by a storage module, the contextual digital fingerprint for consecutive accesses to the target website using the contextual digital fingerprint; and

perform, by a security module, a security action that, based on the contextual digital fingerprint, protects against browser-based malicious attacks attempting to access the target website.

12. The system of claim 11 , wherein the detection module detects the execution of the fingerprinting API calls utilized by the target website for providing access to the user by:

monitoring, by at least one of a web browser and a browser extension and in real-time, the execution of the fingerprinting API calls; and

identifying one or more programming code functions returned in response to the fingerprinting API calls.

13. The system of claim 11 , wherein the identity module further links the contextual digital fingerprint with a predetermined location.

14. The system of claim 13 , wherein the identity module links the contextual digital fingerprint with the predetermined location by utilizing a virtual private network (VPN) tunnel to link the contextual digital fingerprint with a geographic location associated with a user accessing the target website.

15. The system of claim 13 , wherein the identity module links the contextual digital fingerprint with the predetermined location by utilizing a proxy to link the contextual digital fingerprint with a geographic location associated with a user accessing the target website.

16. The system of claim 11 , wherein the identity module further:

receives data identifying one or more new fingerprinting API calls utilized by the target website;

generates new identity data for each of the new fingerprinting API calls; and

updates the contextual digital fingerprint based on the new identity data.

17. The system of claim 11 , wherein the identity module generates the contextual digital fingerprint by generating the specific values for each of a plurality of calls to a programming code function.

18. The system of claim 11 , wherein the storage module stores the contextual digital fingerprint for the consecutive accesses to the target website by saving the contextual digital fingerprint as encrypted data to at least one of a local client storage device and a password manager service.

19. The system of claim 11 , wherein the security module performs the security action by preventing a phishing website utilized in the browser-based malicious attacks from accessing the identity data generated for the contextual digital fingerprint.

20. A non-transitory computer-readable medium comprising one or more computer-executable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

detect an execution of one or more fingerprinting application programming interface (API) calls utilized by a target website for providing access to a user;

generate a contextual digital fingerprint that is specific to the target website by generating new values specific to the target website for each of the fingerprinting API calls;

store the contextual digital fingerprint for consecutive accesses to the target website using the contextual digital fingerprint; and

perform a security action that, based on the contextual digital fingerprint, protects against browser-based malicious attacks attempting to access the target website.

Assignments (2)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 20, 2022
From: SANCHEZ ROLA, ISKANDER
To: NORTONLIFELOCK INC.
Reel/Frame 061145/0864 →
References Cited (6)
US 10419431B2 · Long · 2019 [cited by examiner]
US 10474559B2 · Moorthi · 2019 [cited by examiner]
US 11017075B1 · Hatem · 2021 [cited by examiner]
US 11455641B1 · Shahidzadeh · 2022 [cited by examiner]
US 20150163311A1 · Heath · 2015 [cited by examiner]
US 20200082413A1 · Tseng · 2020 [cited by examiner]