IP Library Granted Patent US 9,021,583
Granted Patent B2
US 9,021,583 · App. 13/014,668 · Granted Apr 28, 2015

System and method for network security including detection of man-in-the-browser attacks

Inventors: Andreas Wittenstein (Woodacre, CA); Michael Eynon (Mountain View, CA); James Lioyd (San Francisco, CA); Laura Mather (Mountain View, CA)
Assignee: EMC Corporation
H04L63/1425G06F21/552H04L63/1416G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,021,583
App. No.
13/014,668
Filed
Jan 26, 2011
Granted
Apr 28, 2015
Kind
B2
Art Unit
2491
USPC
726/22
Abstract

A method is performed in a network security system implemented in a computer or electronic device that is coupled to secured online resources for detecting unauthorized accesses of those secured online resources. The method includes monitoring a user activity session. It is determined whether the user activity session is indicative of a hidden session by an attacker, where the determination includes comparing the user activity session to an average user activity session.

Claims (45)

1. In a network security system implemented in an electronic device, coupled to secured online resources for detecting unauthorized accesses of those secured online resources, a method comprising:

monitoring, by the electronic device, a current user activity session in which a client device sends a series of access requests to a server device which is constructed and arranged to provide access to the secured online resources,

from the series of access requests sent by the client device, providing a set of current frequency measurements, each of the set of current frequency measurements indicating a number of times the client device (i) receives a first webpage from the server device and (ii) sends a request to the server device for a second webpage within a predefined range of time after receiving the first webpage from the server device, and

comparing the set of current frequency measurements to a set of average frequency measurements from an average user activity session model to produce an anomaly score which indicates whether the current user activity session is indicative of a hidden session by an attacker;

wherein providing the set of current frequency measurements includes:

providing a first frequency value indicating a number of times the client device (i) receives the first webpage from the server device and (ii) sends a request to the server device for the second webpage within a first range of time after receiving the first webpage from the server device, and

providing a second frequency value indicating a number of times the client device (i) receives the first webpage from the server device and (ii) sends a request to the server device for the second webpage within a second range of time after receiving the first webpage from the server device, the first range of time and the second range of time being nonoverlapping and finite; and

wherein comparing the set of current frequency measurements to the set of average frequency measurements includes:

outputting the anomaly score based on the first frequency value and the second frequency value.

2. The method of claim 1 further comprising collecting average parameter values during a data collection period.

3. The method of claim 2 wherein the average parameter values include an average time between clicks for an average user activity session, wherein determining whether the current user activity session is indicative of a hidden session by an attacker includes comparing user time between clicks for the current user activity session to the average time between clicks for the average user activity session.

4. The method of claim 2 wherein the average parameter values include a website page view order in an average user activity session, wherein determining whether the current user activity session is indicative of a hidden session by an attacker includes comparing website page view order for the current user activity session with the website page view order in the average user activity session.

5. The method of claim 2 wherein the average parameter values include an average time between clicks for a specified page, wherein determining whether the current user activity session is indicative of a hidden session by an attacker includes comparing the time between clicks for the specified page during the current user activity session to the average time between clicks for the specified page.

6. The method of claim 1 further comprising synchronizing transaction records.

7. The method of claim 6 wherein synchronizing transaction records includes correcting for errant clock settings among all active clients using a website during a data collection period.

8. The method of claim 6 wherein synchronizing transaction records includes adjusting for transmission time between clients and servers.

9. The method of claim 6 wherein synchronizing transaction records includes adjusting for client service load time.

10. The method of claim 6 wherein synchronizing transaction records includes estimating service timing characteristics for each service provided by a website during a data collection period.

11. The method of claim 10 wherein synchronizing transaction records includes estimating server delay statistics for each service provided by a server during the data collection period.

12. The method of claim 10 wherein synchronizing transaction records includes measuring and modeling echo delay statistics.

13. The method of claim 6 wherein synchronizing transaction records includes forming a server timing model with an affine function of service duration.

14. The method of claim 13 wherein the server timing model includes a multiplicative rate parameter selected from receive rate, send rate and sent rate.

15. The method of claim 13 wherein the server timing model includes an additive bias parameter selected from a receive bias, send bias and sent bias.

16. The method of claim 1 , further comprising:

adding anomaly scores to produce an overall threat score.

17. A network security system coupled to secured online resources, the network security system being constructed and arranged to detect unauthorized accesses of those secured online resources, the network security system comprising:

memory; and

a controller including controlling circuitry constructed and arranged to:

monitor a current user activity session in which a client device sends a series of access requests to a server device which is constructed and arranged to provide access to the secured online resources,

from the series of access requests sent by the client device, provide a set of current frequency measurements, each of the set of current frequency measurements indicating a number of times the client device (i) receives a first webpage from the server device and (ii) sends a request to the server device for a second webpage within a predefined range of time after receiving the first webpage from the server device, and

compare the set of current frequency measurements to a set of average frequency measurements from an average user activity session model to produce an anomaly score which indicates whether the current user activity session is indicative of a hidden session by an attacker;

wherein the controlling circuitry constructed and arranged to provide the set of current frequency measurements is further constructed and arranged to:

provide a first frequency value indicating a number of times the client device (i) receives the first webpage from the server device and (ii) sends a request to the server device for the second webpage within a first range of time after receiving the first webpage from the server device, and

provide a second frequency value indicating a number of times the client device (i) receives the first webpage from the server device and (ii) sends a request to the server device for the second webpage within a second range of time after receiving the first webpage from the server device, the first range of time and the second range of time being nonoverlapping and finite; and

wherein the controlling circuitry constructed and arranged to compare the set of current frequency measurements to the set of average frequency measurements is further constructed and arranged to:

output the anomaly score based on the first frequency value and the second frequency value.

18. A computer program product having a non-transitory, computer-readable storage medium which stores instructions which, when executed by a computer coupled to secured online resources, cause the computer to perform a method of detecting unauthorized accesses of those secured online resources, the method comprising:

monitoring a current user activity session in which a client device sends a series of access requests to a server device which is constructed and arranged to provide access to the secured online resources,

from the series of access requests sent by the client device, providing a set of current frequency measurements, each of the set of current frequency measurements indicating a number of times the client device (i) receives a first webpage from the server device and (ii) sends a request to the server device for a second webpage within a predefined range of time after receiving the first webpage from the server device, and

comparing the set of current frequency measurements to a set of average frequency measurements from an average user activity session model to produce an anomaly score which indicates whether the current user activity session is indicative of a hidden session by an attacker;

wherein providing the set of current frequency measurements includes:

providing a first frequency value indicating a number of times the client device (i) receives the first webpage from the server device and (ii) sends a request to the server device for the second webpage within a first range of time after receiving the first webpage from the server device, and

providing a second frequency value indicating a number of times the client device (i) receives the first webpage from the server device and (ii) sends a request to the server device for the second webpage within a second range of time after receiving the first webpage from the server device, the first range of time and the second range of time being nonoverlapping and finite; and

wherein comparing the set of current frequency measurements to the set of average frequency measurements includes:

outputting the anomaly score based on the first frequency value and the second frequency value.

Assignments (13)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2013
From: SILVER TAIL SYSTEMS HOLDINGS INC.
To: EMC CORPORATION
Reel/Frame 030659/0488 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2013
From: SILVER TAIL SYSTEMS LLC
To: SILVER TAIL SYSTEMS HOLDINGS INC.
Reel/Frame 030654/0584 →
CHANGE OF NAME Recorded Jun 19, 2013
From: SILVER TAIL SYSTEMS, INC.
To: SILVER TAIL SYSTEMS LLC
Reel/Frame 030657/0827 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2011
From: WITTENSTEIN, ANDREAS; EYNON, MICHAEL; LLOYD, JAMES; MATHER, LAURA
To: SILVER TAIL SYSTEMS, INC.
Reel/Frame 026086/0296 →
Continuity (2)
Provisional Application 61298300 · Jan 26, 2010
Related Publication 20110185421A1 · Jul 28, 2011