IP Library Granted Patent US 12,518,001
Granted Patent B2
US 12,518,001 · App. 18/676,304 · Granted Jan 6, 2026

Systems and methods for improving accuracy in recognizing and neutralizing injection attacks in computer services

Inventor: Kunal Anand (Marina Del Rey, CA)
Assignee: Imperva, Inc.
G06F21/54G06F21/554H04L63/1416H04L63/1466G06F2221/031
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,518,001
App. No.
18/676,304
Granted
Jan 6, 2026
Kind
B2
Abstract

A method for handing of injection attacks in requests for computer services is disclosed. The method includes receiving request data that represents a service to be provided by a server computer, parsing a data element from the request data wherein the data element includes a data key and a data value, determining whether the data key is one of one or more predetermined allowed data keys, and upon a condition in which the data key is not one of the predetermined allowed data keys, disabling any injection attacks in the request data before processing the request data by performing the service.

Claims (44)

1 . A method for handing of injection attacks in requests for computer services, the method comprising:

receiving request data that represents a service to be provided by a server computer;

parsing a data element from the request data wherein the data element includes a data key and a data value;

determining whether the data key is one of one or more predetermined allowed data keys;

upon a condition in which the data key is not one of the predetermined allowed data keys, disabling any injection attacks in the request data before processing the request data by performing the service;

processing, the one or more requests, each of which specifies a service to be performed by the server computer, wherein processing each request causes the server computer to perform each specified service and generate log data representative of each specified service;

parsing a second data element from the log data wherein the second data element includes a second data key and a second data value;

determining whether the second data key is one of one or more predetermined masked data keys; upon a condition in which the second data key is one of the predetermined masked data keys, replacing the second data value with obscured data within the log data; and

storing the log data resulting from the replacing.

2 . The method of claim 1 , further comprising:

receiving second request data that is distinct from the first-mentioned request data and that represents a second service to be provided by a server computer and that is distinct from the first-mentioned service;

parsing a second data element from the second request data wherein the second data element is distinct from the first-mentioned data element and includes a second data key and a second data value;

determining whether the second data key is one of the predetermined allowed data keys; and

upon a condition in which the second data key is one of the predetermined allowed data keys, processing the second request data by performing the second service without attempting to identify or disable any injection attacks in the second request data.

3 . The method of claim 1 , further comprising:

selecting, from a plurality of key specifications included in protective behavior settings for a query security engine, a key specification having a data path that matches a path associated with the request data, wherein the determining whether the data key is one of the one or more predetermined allowed data keys involves accessing a list of data keys included in the selected key specification.

4 . The method of claim 3 , wherein the plurality of key specifications is formatted in a JavaScript Object Notation (JSON) format.

5 . The method of claim 1 , wherein the request data includes structured data with a plurality of key-value pairs.

6 . A set of one or more non-transitory machine-readable storage media storing instructions which, when executed by one or more processors of a computer system, causes the computer system to perform operations for handling injection attacks in requests for computer services, the operations comprising:

receiving request data that represents a service to be provided by a server computer;

parsing a data element from the request data wherein the data element includes a data key and a data value;

determining whether the data key is one of one or more predetermined allowed data keys;

upon a condition in which the data key is not one of the predetermined allowed data keys, disabling any injection attacks in the request data before processing the request data by performing the service;

processing, the one or more requests, each of which specifies a service to be performed by the server computer, wherein processing each request causes the server computer to perform each specified service and generate log data representative of each specified service;

parsing a second data element from the log data wherein the second data element includes a second data key and a second data value;

determining whether the second data key is one of one or more predetermined masked data keys; upon a condition in which the second data key is one of the predetermined masked data keys, replacing the second data value with obscured data within the log data; and

storing the log data resulting from the replacing.

7 . The set of one or more non-transitory machine-readable storage media of claim 6 , wherein the operations further comprise:

receiving second request data that is distinct from the first-mentioned request data and that represents a second service to be provided by a server computer and that is distinct from the first-mentioned service;

parsing a second data element from the second request data wherein the second data element is distinct from the first-mentioned data element and includes a second data key and a second data value;

determining whether the second data key is one of the predetermined allowed data keys; and

upon a condition in which the second data key is one of the predetermined allowed data keys, processing the second request data by performing the second service without attempting to identify or disable any injection attacks in the second request data.

8 . The set of one or more non-transitory machine-readable storage media of claim 6 , wherein the operations further comprise:

selecting, from a plurality of key specifications included in protective behavior settings for a query security engine, a key specification having a data path that matches a path associated with the request data, wherein the determining whether the data key is one of the one or more predetermined allowed data keys involves accessing a list of data keys included in the selected key specification.

9 . The set of one or more non-transitory machine-readable storage media of claim 8 , wherein the plurality of key specifications is formatted in a JavaScript Object Notation (JSON) format.

10 . The set of one or more non-transitory machine-readable storage media of claim 6 , wherein the request data includes structured data with a plurality of key-value pairs.

11 . The set of one or more non-transitory machine-readable storage media of claim 6 , wherein the operations further comprise:

processing one or more requests, each of which specifies a service to be performed by the server computer, wherein processing each request causes the server computer to perform each specified service and generate log data representative of each specified service;

for each of one or more predetermined patterns:

identifying all matching data in the log data that matches the predetermined pattern;

replacing the matching data with obscured data within the log data; and

storing the log data resulting from the replacing.

12 . The set of one or more non-transitory machine-readable storage media of claim 11 , wherein the predetermined patterns are regular expressions.

13 . The set of one or more non-transitory machine-readable storage media of claim 6 , wherein the determining whether the second data key is one of the one or more predetermined masked data keys involves accessing a list of data keys included in a particular key specification of a plurality of key specifications included in protective behavior settings for a query security engine.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2025
From: ANAND, KUNAL
To: PREVOTY, INC.
Reel/Frame 072952/0803 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2025
From: PREVOTY, INC.
To: IMPERVA, INC.
Reel/Frame 072952/0837 →
CHANGE OF ASSIGNEE ADDRESS Recorded Nov 19, 2025
From: PREVOTY, INC.
To: PREVOTY, INC.
Reel/Frame 073588/0814 →
Continuity (7)
Continuation 17388001 · Jul 28, 2021
Division 16015980 · Jun 22, 2018
Continuation In Part 15268510 · Sep 16, 2016
Continuation In Part 14599978 · Jan 19, 2015
Provisional Application 62220903 · Sep 18, 2015
Provisional Application 61929474 · Jan 20, 2014
Related Publication 20240311470A1 · Sep 19, 2024
References Cited (51)
US 5742806A · Reiner et al. · 1998 [cited by applicant]
US 7437362B1 · Ben-Natan · 2008 [cited by examiner]
US 8225402B1 · Averbuch · 2012 [cited by examiner]
US 10002254B2 · Anand et al. · 2018 [cited by applicant]
US 11100218B2 · Anand · 2021 [cited by applicant]
US 20020078406A1 · Kondoh · 2002 [cited by examiner]
US 20040111642A1 · Peles · 2004 [cited by examiner]
US 20050149552A1 · Chan · 2005 [cited by examiner]
US 20050160101A1 · Gallagher · 2005 [cited by examiner]
US 20050203921A1 · Newman · 2005 [cited by examiner]
US 20060212438A1 · Ng · 2006 [cited by examiner]
US 20070208693A1 · Chang · 2007 [cited by examiner]
US 20090049547A1 · Fan · 2009 [cited by examiner]
US 20090150374A1 · Dewey · 2009 [cited by examiner]
US 20100005528A1 · Teller · 2010 [cited by examiner]
US 20100094765A1 · Nandy · 2010 [cited by examiner]
US 20100228693A1 · Dawson · 2010 [cited by examiner]
US 20110225647A1 · Dilley · 2011 [cited by examiner]
US 20110258704A1 · Ichnowski · 2011 [cited by examiner]
US 20120192280A1 · Venkatakrishnan · 2012 [cited by examiner]
US 20130312103A1 · Brumley · 2013 [cited by examiner]
US 20150205951A1 · Anand · 2015 [cited by examiner]
US 20160055026A1 · Fitzgerald · 2016 [cited by examiner]
US 20180084007A1 · Dinerstein · 2018 [cited by examiner]
US 20190081983A1 · Teal · 2019 [cited by examiner]
US 20190199730A1 · Nguyen-Tuong · 2019 [cited by examiner]
US 20210026951A1 · Woodworth, Jr. · 2021 [cited by examiner]
US 20220019658A1 · Anand · 2022 [cited by applicant]
“Thomas et al, On automated prepared statement generation to remove SOL injection vulnerabilities, 2009, Elsevier, Information and Software Technology 51, pp. 589-598” (Year: 2009). [cited by applicant]
Advisory Action U.S. Appl. No. 16/015,980, filed Jun. 4, 2020, 3 pages. [cited by applicant]
Buehrer et al., “Using Parse Tree Validation to Prevent SQL injection Attacks”, In: International Workshop on Software Engineering and Middleware, ACM, Sep. 2005, 8 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 16/015,980, filed Mar. 30, 2020, 9 pages. [cited by applicant]
Final office Action, U.S. Appl. No. 17/388,001, filed Oct. 17, 2023, 14 pages. [cited by applicant]
Halfond et al., “AMNESIA: Analysis and Monitoring for NEutralizing SQL-Injection Attacks”, ACM, ASE'05, Nov. 2005, 10 pages. [cited by applicant]
International Preliminary Report on Patentability, PCT App. No. PCT/US15/12082, Aug. 4, 2016, 8 pages. [cited by applicant]
International Preliminary Report on Patentability, PCT App. No. PCT/US16/52387, Mar. 29, 2018, 9 pages. [cited by applicant]
International Search Report and Written Opinion, PCT App. No. PCT/US15/12082, Apr. 24, 2015, 8 pages. [cited by applicant]
International Search Report and Written Opinion, PCT App. No. PCT/US16/52387, Dec. 28, 2016, 9 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 14/599,978, filed Feb. 25, 2016, 10 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 15/268,503, filed Jun. 27, 2017, 12 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 15/268,510, filed Jun. 27, 2017, 11 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/015,980, filed Dec. 2, 2019, 10 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/015,980, filed Sep. 30, 2020, 8 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/388,001, filed Apr. 19, 2023, 11 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 14/599,978, filed Aug. 9, 2016, 14 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 15/268,503, filed Feb. 23, 2018, 14 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 15/268,510, filed Mar. 23, 2018, 14 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/015,980, filed May 11, 2021, 10 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/388,001, filed Feb. 29, 2024, 14 pages. [cited by applicant]
Requirement for Restriction/Election U.S. Appl. No. 16/015,980, filed Oct. 4, 2019, 7 pages. [cited by applicant]
Requirement for Restriction/Election, U.S. Appl. No. 17/388,001, filed Feb. 10, 2023, 07 pages. [cited by applicant]