IP Library Granted Patent US 12,437,079
Granted Patent B2
US 12,437,079 · App. 18/158,971 · Granted Oct 7, 2025

Browser session security system

Inventors: David Endler (Austin, TX); Jacob Wagh (Austin, TX); Nick Brands (Austin, TX)
Assignee: SpyCloud, Inc.
G06F21/577G06F16/9538G06F21/6263G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,437,079
App. No.
18/158,971
Granted
Oct 7, 2025
Kind
B2
Abstract

A process that includes receiving a session identity protection query that includes a target domain. The process further includes accessing a security database of compromised cookie data associated with a plurality of domains and determining the target domain is associated with first compromised cookie data of the compromised cookie data included in the security database. The process includes providing the first compromised cookie data in response the session identity protection query.

Claims (39)

1. A non-transitory, machine-readable medium storing instructions that, when executed by one or more processors, effectuate operations comprising:

receiving, by a computer system, a session identity protection query that includes a target domain;

accessing, by the computer system, a security database of compromised cookie data associated with a plurality of domains, wherein the compromised cookie data includes data to emulate a browser fingerprint of a user's web browser;

determining, by the computer system, the target domain is associated with first compromised cookie data of the compromised cookie data included in the security database; and

providing, by the computer system, the first compromised cookie data in response to the session identity protection query.

2. The medium of claim 1 , wherein the first compromised cookie data includes at least one of a source identifier, a cookie domain, a cookie name, a cookie value, a cookie expiration, a publish date of the first compromised cookie data, a machine identifier that is infected with a malicious program that caused a cookie to become compromised, an internet protocol address, a user hostname, or a user system registered owner from a malware log or a compromised cookie returned in a search query when determining that the target domain is associate with the first compromised cookie data.

3. The medium of claim 1 , wherein the session identity protection query includes a cookie domain.

4. The medium of claim 3 , wherein the session identity protection query includes at least one of a cookie name, a cookie expiration date, a source identifier, or a date range.

5. The medium of claim 1 , wherein the operations further comprise:

flagging user accounts associated with compromised devices determined from the first compromised cookie data.

6. The medium of claim 5 , wherein the operations further comprise:

performing a multi-factor authentication during login of a user of a user account that is included in the flagged user accounts even if the user account has a session cookie for bypassing the multi-factor authentication.

7. The medium of claim 1 , wherein the operations further comprise:

invalidating cookies that are identified in the first compromised cookie data.

8. The medium of claim 1 , wherein the operations further comprise:

deactivating a session at the target domain that is associated with a cookie identified in the first compromised cookie data.

9. The medium of claim 1 , wherein the operations further comprise:

notifying a user associated with the first compromised cookie data that a user device identified in the first compromised cookie data is infected with a malicious application.

10. The medium of claim 1 , wherein the operations further comprise:

updating, by the computer system, the security database with updated compromised information associated with the domain.

11. The medium of claim 10 , wherein the operations further comprise:

performing a search query based on the session identity protection query on only the updated compromised information to obtain second compromised cookie data from the updated compromised information;

determining the target domain is associated with the second compromised cookie data; and

providing the second compromised cookie data as an update to the session identity protection query.

12. The medium of claim 1 , wherein the session identity protection query originates from an application.

13. The medium of claim 1 , wherein the session identity protection query is an application programming interface (API) query.

14. The medium of claim 1 , wherein the security database includes over one billion user information assets that include the compromised cookie data.

15. The medium of claim 1 , wherein the first compromised cookie data of the compromised cookie data is retrieved within 500-900 msecs.

16. The medium of claim 1 , wherein the session identity protection query that includes a target domain is generated in response to an event occurring on an enterprise system.

17. The medium of claim 16 , wherein the event includes a user action that satisfies a suspected account takeover condition.

18. The medium of claim 1 , wherein the operations further comprise steps for:

identifying the first compromised cookie data.

19. The medium of claim 1 , wherein the operations further comprise steps for:

populating the security database.

20. A method, comprising:

receiving, by a computer system, a session identity protection query that includes a target domain;

accessing, by the computer system, a security database of compromised cookie data associated with a plurality of domains, wherein the compromised cookie data includes data to emulate a browser fingerprint of a user's web browser;

determining, by the computer system, the target domain is associated with first compromised cookie data of the compromised cookie data included in the security database; and

providing, by the computer system, the first compromised cookie data in response to the session identity protection query.

Assignments (2)
SECURITY INTEREST Recorded Apr 9, 2024
From: SPYCLOUD, INC.
To: CANADIAN IMPERIAL BANK OF COMMERCE, AS ADMINISTRATIVE AGENT
Reel/Frame 067042/0751 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2023
From: ENDLER, DAVID; WAGH, JACOB; BRANDS, NICK
To: SPYCLOUD, INC.
Reel/Frame 064566/0642 →
Continuity (1)
Related Publication 20240248997A1 · Jul 25, 2024
References Cited (35)
US 11283832B2 · Endler · 2022 [cited by applicant]
US 11399021B2 · Endler et al. · 2022 [cited by applicant]
US 11438360B2 · Endler et al. · 2022 [cited by applicant]
US 11461458B2 · Endler et al. · 2022 [cited by applicant]
US 11503056B1 · Celiesius · 2022 [cited by examiner]
US 11558409B2 · Endler et al. · 2023 [cited by applicant]
US 11750645B2 · Endler et al. · 2023 [cited by applicant]
US 11888843B2 · Endler et al. · 2024 [cited by applicant]
US 20010045451A1 · Tan · 2001 [cited by examiner]
US 20090144806A1 · Gal · 2009 [cited by examiner]
US 20170262629A1 · Xu · 2017 [cited by examiner]
US 20200279041A1 · Endler · 2020 [cited by examiner]
US 20200279050A1 · Endler · 2020 [cited by applicant]
US 20210392132A1 · Olden · 2021 [cited by examiner]
US 20240007500A1 · Endler et al. · 2024 [cited by applicant]
US 20240037279A1 · Marudi · 2024 [cited by examiner]
Related U.S. Appl. No. 18/152,186, filed Jan. 10, 2023, 56 pages. [cited by applicant]
Related U.S. Appl. No. 18/543,916, filed Dec. 18, 2023, 84 pages. [cited by applicant]
Related International Patent Application PCT/US2024/012817, filed Jan. 24, 2024, 49 pages. [cited by applicant]
Related U.S. Appl. No. 62/753,812, filed Oct. 31, 2018, 76 pages. [cited by applicant]
Related U.S. Appl. No. 62/753,807, filed Oct. 31, 2018, 81 pages. [cited by applicant]
Related U.S. Appl. No. 62/753,800, filed Oct. 31, 2018, 77 pages. [cited by applicant]
Related U.S. Appl. No. 62/753,793, filed Oct. 31, 2018, 82 pages. [cited by applicant]
Related U.S. Appl. No. 62/812,205, filed Feb. 28, 2019, 90 pages. [cited by applicant]
Related U.S. Appl. No. 62/812,208, filed Feb. 28, 2019, 87 pages. [cited by applicant]
Web Archive of SpyCloud's Integrations Webpage, “SpyCloud Integrations,” https://web.archive.org/web/20211209033946/https://spycloud.com/products/integrations/, Dec. 9, 2021, 20 pages. [cited by applicant]
Web Archive of SpyCloud Products Webpage, “Take Action Before the Criminals Do,” https://web.archive.org/web/20220124200326/https://spycloud.com/products/, Oct. 23, 2021, 13 pages. [cited by applicant]
Web Archive of SpyCloud's Consumer ATO Prevention Product Webpage, “Protect Your Customers from Account Takeover Fraud,” https://web.archive.org/web/20211209032750/https://spycloud.com/products/consumer-ato-prevention/,… [cited by applicant]
Web Archive of SpyCloud's Employee ATO Prevention Product Webpage, “Reduce Your Risk of a Data Breach with Employee Account Takeover Prevention,” https://web.archive.org/web/20211209043359/https://spycloud.com/products/… [cited by applicant]
Web Archive of SpyCloud's Third Party Insight Product Webpage, “Reduce Your Risk of a Data Breach with SpyCloud Third Party Insight,” https://web.archive.org/web/20211209041042/https://spycloud.com/products/third-party-… [cited by applicant]
Web Archive of SpyCloud's Fraud Investigations Product Webpage, “Transform Your Online Fraud Investigations,” https://web.archive.org/web/20211209040150/https://spycloud.com/products/fraud-investigations/, Dec. 9, 2021,… [cited by applicant]
Web Archive of SpyCloud's API, “Data Delivered However You Need It,” https://web.archive.org/web/20211023004614/https://spycloud.com/products/spycloud-api/, Oct. 23, 2021, 5 pages. [cited by applicant]
Web Archive of SpyCloud's Active Directory Guardian Product Webpage, “Protect Your Enterprise from Account Takeover with Active Directory Guardian,” https://web.archive.org/web/20211209035439/https://spycloud.com/produc… [cited by applicant]
Web Archive of SpyCloud's VIP Guardian Product webpage, “Protect Your Highest-Risk Executives from Targeted Account Takeover,” https://web.archive.org/web/20211209043814/https://spycloud.com/products/vip-guardian/, Dec.… [cited by applicant]
Web Archive of SpyCLoud's Data Integration Product Webpage, “Data Partnerships with SpyCloud,” https://web.archive.org/web/20211209040506/https://spycloud.com/data-partnerships/, Dec. 9, 2021, 11 pages. [cited by applicant]