Systems and Methods for Detecting man-in-the-middle cybersecurity threats
Systems, methods, and non-transitory computer readable media including instructions for implementing a runtime virtual barrier for fine grained execution control are disclose. Implementing the runtime virtual barrier for fine grained execution control includes receiving, by an application capable of JavaScript execution, an executable code including an API invocation; intercepting, by a virtual barrier, the API invocation; determining that the API invocation is an invocation for a native API configured for subsequent execution in response to a trigger event; based on the determination that the API invocation is an invocation for a native API configured for subsequent execution, recording an invocation source identifier; and upon occurrence of the trigger event: retrieving the invocation source identifier; and influencing execution of the native API based on the invocation source identifier.
1 - 60 . (canceled)
61 . A non-transitory computer readable medium containing instructions that when executed by at least one processor cause the at least one processor to perform cybersecurity operations for detecting a communication discrepancy, the operations comprising:
transmitting at least one first request to an endpoint device;
determining a first response time based on the transmitted at least one first request;
transmitting at least one second request to the endpoint device;
determining a second response time based on the transmitted at least one second request;
determining a difference between the first response time and the second response time; and
based on the determination of the difference between the first response time and the second response time, determining whether to implement a remedial action.
62 . The non-transitory computer readable medium of claim 61 , wherein the endpoint device is an intended destination of an electronic communication sent by a client device associated with transmitting at least one of the at least one first request or the at least one second request.
63 . The non-transitory computer readable medium of claim 61 , wherein at least one of the first response time or the second response time is a Time to First Byte (TTFB).
64 . The non-transitory computer readable medium of claim 61 , wherein:
the at least one first request is a plurality of first requests;
the at least one second request is a plurality of second requests;
the first response time is a first metric of response times associated with the plurality of first requests; and
the second response time is a second metric of response times associated with the plurality of second requests.
65 . The non-transitory computer readable medium of claim 64 , wherein the first metric is an average of the response times associated with the plurality of first requests, and the second metric is an average of the response times associated with the plurality of second requests.
66 . The non-transitory computer readable medium of claim 61 , wherein the at least one first request includes a first payload and the at least one second request includes a second payload larger than the first payload.
67 . The non-transitory computer readable medium of claim 61 , wherein determining whether to implement a remedial action includes determining to implement a remedial action when the difference between the first response time and the second response time exceeds a predetermined threshold.
68 . The non-transitory computer readable medium of claim 67 , wherein the predetermined threshold is uncorrelated with a payload size associated with at least one of the at least one first request or the at least one second request.
69 . The non-transitory computer readable medium of claim 61 , wherein the transmission of at least one of the at least one first request or the at least one second request is caused by a cybersecurity web agent.
70 . The non-transitory computer readable medium of claim 69 , wherein the remedial action is implemented at a client device hosting the cybersecurity web agent.
71 . The non-transitory computer readable medium of claim 61 , wherein the remedial action includes issuing a prompt indicating that a connection associated with the at least one first request and the at least one second request is compromised.
72 . The non-transitory computer readable medium of claim 61 , wherein the remedial action includes logging digital information associated with an execution environment associated with a connection to the endpoint device.
73 . The non-transitory computer readable medium of claim 61 , wherein the remedial action includes influencing an execution environment associated with a web browser.
74 . A cybersecurity method for detecting a communication discrepancy, the method comprising:
transmitting at least one first request to an endpoint device;
determining a first response time based on the transmitted at least one first request;
transmitting at least one second request to the endpoint device;
determining a second response time based on the transmitted at least one second request;
determining a difference between the first response time and the second response time; and
based on the determination of the difference between the first response time and the second response time, determining whether to implement a remedial action.
75 . The method of claim 74 , wherein at least one of the first response time or the second response time is a Time to First Byte (TTFB).
76 . The method of claim 74 , wherein:
the at least one first request is a plurality of first requests;
the at least one second request is a plurality of second requests;
the first response time is a first metric of response times associated with the plurality of first requests; and
the second response time is a second metric of response times associated with the plurality of second requests.
77 . The method of claim 74 , wherein the at least one first request includes a first payload and the at least one second request includes a second payload larger than the first payload.
78 . The method of claim 74 , wherein determining whether to implement a remedial action includes determining to implement a remedial action when the difference between the first response time and the second response time exceeds a predetermined threshold.
79 . The method of claim 78 , wherein the predetermined threshold is uncorrelated with a payload size associated with at least one of the at least one first request or the at least one second request.
80 . A cybersecurity system for detecting a communication discrepancy between two communication parties, the system comprising:
at least one processor configured to:
transmit at least one first request to an endpoint device;
determine a first response time based on the transmitted at least one first request;
transmit at least one second request to the endpoint device;
determine a second response time based on the transmitted at least one second request;
determine a difference between the first response time and the second response time; and
based on the determination of the difference between the first response time and the second response time, determine whether to implement a remedial action.
81 - 159 . (canceled)