IP Library Granted Patent US 12,452,292
Granted Patent B1
US 12,452,292 · App. 18/744,401 · Granted Oct 21, 2025

Inspecting requests and responses to identify application vulnerabilities

Inventor: Michiel Louis Appelman (Amersfoort, NL)
Assignee: CLOUDFLARE, INC.
H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,452,292
App. No.
18/744,401
Granted
Oct 21, 2025
Kind
B1
Abstract

An edge server of a cloud-based application vulnerability detection service receives a first request from a requesting device to access a resource hosted by an origin server. The edge server can determine that the first request has indications of including malicious content and block the first request. The edge server can then send a second request to a test environment of the origin server, where the second request is based on the first request. The edge server then receives a response from the origin server responsive to the second request. The cloud-based application vulnerability detection service can analyze the response to determine that the origin server has a vulnerability. The cloud-based application vulnerability detection service then provides information to a customer associated with the origin server indicating that the vulnerability has been blocked by the cloud-based application vulnerability detection service and that the origin server is subject to the vulnerability.

Claims (74)

1. A method, comprising:

receiving, at a cloud-based application vulnerability detection service, a first request from a first requesting device to access a first resource hosted by an origin server, the origin server belonging to a customer;

determining that the first request has indications of including malicious content based on a signature for the first request generated based on extracted attributes of the first request;

in response to determining that the first request has the indications of including the malicious content, blocking the first request;

sending a second request to a test environment of the origin server, wherein the second request is based on the first request;

receiving a first response from the origin server responsive to the second request;

determining that the first response indicates that the origin server has a vulnerability; and

providing information for the customer that indicates that the vulnerability has been blocked by the cloud-based application vulnerability detection service and the origin server is subject to the vulnerability.

2. The method of claim 1 , wherein sending the second request to the test environment of the origin server further comprises:

adding a header to the second request to indicate that the first request has the indications of including the malicious content.

3. The method of claim 1 , wherein blocking the first request further comprises:

transmitting a second response to the first requesting device indicating that the first request was blocked.

4. The method of claim 1 , wherein determining that the first response indicates that the origin server has the vulnerability further comprises:

determining that the first response includes sensitive information; and

encrypting the first response from the origin server using an encryption key of the customer associated with the origin server.

5. The method of claim 1 , wherein sending the second request to the test environment of the origin server includes applying a rate limiting rule for transmission of requests having indications of including malicious content to the origin server.

6. The method of claim 1 , further comprising:

receiving, at the cloud-based application vulnerability detection service, a third request from a second requesting device to access a second resource hosted by the origin server;

determining that the third request has indications of including malicious content;

in response to determining that the third request has the indications of including the malicious content, blocking the third request;

sending a fourth request to the test environment of the origin server, wherein the fourth request is based on the third request;

receiving a second response from the origin server responsive to the fourth request;

determining that the second response indicates that the origin server is not vulnerable; and

providing information to the customer that indicates that the vulnerability has been blocked by the cloud-based application vulnerability detection service and the origin server is not vulnerable.

7. A non-transitory machine-readable storage medium that provides instructions that, if executed by a processor, will cause said processor to perform operations comprising, comprising:

receiving, at a cloud-based application vulnerability detection service, a first request from a first requesting device to access a first resource hosted by an origin server, the origin server belonging to a customer;

determining that the first request has indications of including malicious content based on a signature for the first request generated based on extracted attributes of the first request;

in response to determining that the first request has the indications of including the malicious content, blocking the first request;

sending a second request to a test environment of the origin server, wherein the second request is based on the first request;

receiving a first response from the origin server responsive to the second request;

determining that the first response indicates that the origin server has a vulnerability; and

providing information for the customer that indicates that the vulnerability has been blocked by the cloud-based application vulnerability detection service and the origin server is subject to the vulnerability.

8. The non-transitory machine-readable storage medium of claim 7 , wherein sending the second request to the test environment of the origin server further comprises:

adding a header to the second request to indicate that the first request has the indications of including the malicious content.

9. The non-transitory machine-readable storage medium of claim 7 , wherein blocking the first request further comprises:

transmitting a second response to the first requesting device indicating that the first request was blocked.

10. The non-transitory machine-readable storage medium of claim 7 , wherein determining that the first response indicates that the origin server has the vulnerability further comprises:

determining that the first response includes sensitive information; and

encrypting the first response from the origin server using an encryption key of the customer associated with the origin server.

11. The non-transitory machine-readable storage medium of claim 7 , wherein sending the second request to the test environment of the origin server includes applying a rate limiting rule for transmission of requests having indications of including the malicious content to the origin server.

12. The non-transitory machine-readable storage medium of claim 7 , wherein the operations further comprise:

receiving, at the cloud-based application vulnerability detection service, a third request from a second requesting device to access a second resource hosted by the origin server;

determining that the third request has indications of including malicious content;

in response to determining that the third request has the indications of including the malicious content, blocking the third request;

sending a fourth request to the test environment of the origin server, wherein the fourth request is based on the third request;

receiving a second response from the origin server responsive to the fourth request;

determining that the second response indicates that the origin server is not vulnerable; and

providing information to the customer that indicates that the vulnerability has been blocked by the cloud-based application vulnerability detection service and the origin server is not vulnerable.

13. A server, comprising:

a processor; and

a non-transitory machine-readable storage medium that provides instructions that, if executed by the processor, will cause the server to perform operations including:

receiving, at a cloud-based application vulnerability detection service, a first request from a first requesting device to access a first resource hosted by an origin server, the origin server belonging to a customer;

determining that the first request has indications of including malicious content based on a signature for the first request generated based on extracted attributes of the first request;

in response to determining that the first request has the indications of including the malicious content, blocking the first request;

sending a second request to a test environment of the origin server, wherein the second request is based on the first request;

receiving a first response from the origin server responsive to the second request;

determining that the first response indicates that the origin server has a vulnerability; and

providing information for the customer that indicates that the vulnerability has been blocked by the cloud-based application vulnerability detection service and the origin server is subject to the vulnerability.

14. The server of claim 13 , wherein sending the second request to the test environment of the origin server further comprises:

adding a header to the second request to indicate that the first request has the indications of including the malicious content.

15. The server of claim 13 , wherein blocking the first request further comprises:

transmitting a second response to the first requesting device indicating that the first request was blocked.

16. The server of claim 13 , wherein determining that the first response indicates that the origin server has the vulnerability further comprises:

determining that the first response includes sensitive information; and

encrypting the first response from the origin server using an encryption key of the customer associated with the origin server.

17. The server of claim 13 , wherein sending the second request to the test environment of the origin server includes applying a rate limiting rule for transmission of requests having indications of including the malicious content to the origin server.

18. The server of claim 13 , wherein the operations further comprise:

receiving, at the cloud-based application vulnerability detection service, a third request from a second requesting device to access a second resource hosted by the origin server;

determining that the third request has indications of including malicious content;

in response to determining that the third request has the indications of including the malicious content, blocking the third request;

sending a fourth request to the test environment of the origin server, wherein the fourth request is based on the third request;

receiving a second response from the origin server responsive to the fourth request;

determining that the second response indicates that the origin server is not vulnerable; and

providing information to the customer that indicates that the vulnerability has been blocked by the cloud-based application vulnerability detection service and the origin server is not vulnerable.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2024
From: APPELMAN, MICHIEL LOUIS
To: CLOUDFLARE, INC.
Reel/Frame 067736/0581 →
References Cited (5)
US 11374945B1 · Senecal · 2022 [cited by examiner]
US 11979373B2 · Grant · 2024 [cited by examiner]
US 20040010601A1 · Afergan · 2004 [cited by examiner]
US 20170237768A1 · Daniel · 2017 [cited by examiner]
US 20200159776A1 · Kitchen · 2020 [cited by examiner]