IP Library Granted Patent US 12,483,567
Granted Patent B2
US 12,483,567 · App. 18/389,475 · Granted Nov 25, 2025

Malicious request detection

Inventors: Marina Grechuhin (New York, NY); Moshe Ingber (New York, NY); Ori Gold (New York, NY)
Assignee: HUMAN SECURITY, INC.
H04L63/1416G06N20/00H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,483,567
App. No.
18/389,475
Granted
Nov 25, 2025
Kind
B2
Abstract

Systems, methods, apparatuses, and computer program products for analyzing malware traffic with direct malware detonation. The method may include, collecting page data of a website, and information of a user request. The method may also include generating an algorithm and a baseline of authorized activity with the collected page data and the information of the user request. In addition, the method may include establishing legitimacy of the user request based on the algorithm and the baseline. Further, the method may include controlling access to a web application based on the legitimacy of the user request.

Claims (63)

1 . A method, comprising:

collecting page data of a website, and information of a user request;

generating an algorithm and a baseline of authorized activity with the collected page data and the information of the user request, wherein the baseline is generated by determining a query depth, a number of queries sent in the user request, variable keys and if they are used, and a category of the user request;

establishing legitimacy of the user request based on the baseline, wherein the user request is established as legitimate when the information of the user request is within the baseline, and wherein the user request is established as illegitimate when the information of the user request lie outside of the baseline; and

controlling access to a web application based on the legitimacy of the user request by

granting access to the web application when the user request is established as legitimate; and

denying access to the web application when the request is established as illegitimate.

2 . The method according to claim 1 , wherein the page data comprises at least one of the following:

uniform resource locator parts comprising a scheme, a path, or a query string,

hypertext markup language input elements data comprising an identifier, a name, a type, or a label, or

hypertext markup language format element data comprising x, y, width, or height.

3 . The method according to claim 1 , wherein the user request comprises at least one of the following:

a body,

metadata, or

a request structure and order of elements.

4 . The method according to claim 1 , further comprising:

implementing the algorithm and the baseline in a machine learning model; and

dynamically training the machine learning model based on the collected page data of the website.

5 . The method according to claim 4 , further comprising:

determining, via the machine learning model, a web page type based on the collected page data.

6 . An apparatus, comprising:

at least one processor; and

at least one memory comprising computer program code,

the at least one memory and the computer program code configured to, when executed by the at least one processor, cause the apparatus at least to:

collect page data of a website, and information of a user request;

generate an algorithm and a baseline of authorized activity with the collected page data and the information of the user request, wherein the baseline is generated by determining a query depth, a number of queries sent in the user request, variable keys and if they are used, and a category of the user request;

establish legitimacy of the user request based on the baseline, wherein the user request is established as legitimate when the information of the user request is within the baseline, and wherein the user request is established as illegitimate when the information of the user request lie outside of the baseline; and

control access to a web application based on the legitimacy of the user request by

granting access to the web application when the user request is established as legitimate; and

denying access to the web application when the request is established as illegitimate.

7 . The apparatus according to claim 6 , wherein the page data comprises at least one of the following:

uniform resource locator parts comprising a scheme, a path, or a query string,

hypertext markup language input elements data comprising an identifier, a name, a type, or a label, or

hypertext markup language format element data comprising x, y, width, or height.

8 . The apparatus according to claim 6 , wherein the user request comprises at least one of the following:

a body,

metadata, or

a request structure and order of elements.

9 . The apparatus according to claim 6 , wherein the at least one memory and the computer program code are further configured to, when executed by the at least one processor, cause the apparatus at least to:

implement the algorithm and the baseline in a machine learning model; and

dynamically train the machine learning model based on the collected page data of the website.

10 . The apparatus according to claim 9 , wherein the at least one memory and the computer program code are further configured to, when executed by the at least one processor, cause the apparatus at least to:

determine, via the machine learning model, a web page type based on the collected page data.

11 . A computer program, embodied on a non-transitory computer readable medium, the computer program comprising computer executable code, which, when executed by a processor, causes the processor to:

collect page data of a website, and information of a user request;

generate an algorithm and a baseline of authorized activity with the collected page data and the information of the user request, wherein the baseline is generated by determining a query depth, a number of queries sent in the user request, variable keys and if they are used, and a category of the user request;

establish legitimacy of the user request based on the baseline, wherein the user request is established as legitimate when the information of the user request is within the baseline, and wherein the user request is established as illegitimate when the information of the user request lie outside of the baseline; and

control access to a web application based on the legitimacy of the user request by

granting access to the web application when the user request is established as legitimate; and

denying access to the web application when the request is established as illegitimate.

12 . The computer program according to claim 11 , wherein the page data comprises at least one of the following:

uniform resource locator parts comprising a scheme, a path, or a query string,

hypertext markup language input elements data comprising an identifier, a name, a type, or a label, or

hypertext markup language format element data comprising x, y, width, or height.

13 . The computer program according to claim 11 , wherein the user request comprises at least one of the following:

a body,

metadata, or

a request structure and order of elements.

14 . The computer program according to claim 11 , wherein the processor is further caused to:

implement the algorithm and the baseline in a machine learning model; and

dynamically train the machine learning model based on the collected page data of the website.

15 . The computer program according to claim 14 , wherein the processor is further caused to:

determine, via the machine learning model, a web page type based on the collected page data.

Assignments (2)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 25, 2025
From: HUMAN SECURITY, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 072253/0310 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2023
From: GRECHUHIN, MARINA; INGBER, MOSHE; GOLD, ORI
To: HUMAN SECURITY, INC.
Reel/Frame 065563/0012 →
Continuity (1)
Related Publication 20250159000A1 · May 15, 2025
References Cited (12)
US 20110185421A1 · Wittenstein · 2011 [cited by examiner]
US 20150106870A1 · Li · 2015 [cited by examiner]
US 20190173900A1 · Safruti · 2019 [cited by examiner]
US 20190190946A1 · Nagaraja · 2019 [cited by examiner]
US 20200151617A1 · Chauhan · 2020 [cited by examiner]
US 20210344661A1 · Krylov · 2021 [cited by examiner]
US 20210377303A1 · Bui · 2021 [cited by examiner]
US 20230018387A1 · Kuksta · 2023 [cited by examiner]
US 20230254330A1 · Singh · 2023 [cited by examiner]
US 20240106846A1 · Kapoor · 2024 [cited by examiner]
CN 109241383A · 2019 [cited by examiner]
Kaul et al., AI to Detect and Mitigate Security Vulnerabilities in APIs: Encryption, Authentication, and Anomaly Detection in Enterprise-Level Distributed Systems, Eigenpub Review of Science and Technology, 2021, 29 tot… [cited by examiner]