IP Library Granted Patent US 10,187,408
Granted Patent B1
US 10,187,408 · App. 15/645,787 · Granted Jan 22, 2019

Detecting attacks against a server computer based on characterizing user interactions with the client computing device

Inventors: Justin D. Call (Santa Clara, CA); Xinran Wang (San Ramon, CA); Yao Zhao (Fremont, CA); Timothy Dylan Peacock (San Francisco, CA)
Assignee: SHAPE SECURITY, INC.
H04L63/1416H04L43/04H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,187,408
App. No.
15/645,787
Granted
Jan 22, 2019
Kind
B1
Abstract

A computer-implemented method includes providing, for use by a third-party, injectable computer code that is capable of being served with other code provided by the third-party to client computing devices; receiving data from client computing devices that have been served the code by the third-party, the data including data that characterizes (a) the client computing devices and (b) user interaction with the client computing devices; classifying the client computing devices as controlled by actual users or instead by automated software based on analysis of the received data from the client computing devices; and providing to the third party one or more reports that characterize an overall level of automated software activity among client computing devices that have been served code by the third party.

Claims (15)

1. A method comprising:

sending a set of instrumentation code to a plurality of client computers;

receiving a set of telemetry data from the plurality of client computers that executed the set of instrumentation code, wherein the telemetry data comprises screen or browser data;

analyzing the set of telemetry data to identify one or more clusters of malicious activities;

associating a security policy with one or more activities in the one or more clusters of malicious activities;

receiving a resource from a server computer;

generating a set of modified code that comprises the resource and the set of instrumentation code;

sending the set of modified code to a particular client computer;

receiving, from the particular client computer, a report indicating that the particular client computer has performed a particular activity identified to be malicious, and responding with the security policy.

2. The method of claim 1 , wherein the security policy is automatically assigned to the one or more clusters of malicious activities.

3. The method of claim 1 , further comprising associating the security policy with a particular cluster of the one or more clusters of malicious activities.

4. The method of claim 1 , wherein responding with the security policy comprises determining that the particular activity is an activity associated with the security policy.

5. The method of claim 1 , wherein analyzing the set of telemetry data to identify one or more clusters of malicious activities comprises determining whether an activity includes a call to a particular method.

6. The method of claim 1 , wherein analyzing the set of telemetry data to identify one or more clusters of malicious activities comprises determining whether an activity includes a pattern of user interactions that is inconsistent with human user interactions.

7. The method of claim 1 , wherein analyzing the set of telemetry data to identify one or more clusters of malicious activities comprises determining whether an activity includes a user interaction at a first client computer that matches user interactions from other client computers.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 4, 2019
From: CALL, JUSTIN D; WANG, XINRAN; ZHAO, YAO; PEACOCK, TIMOTHY DYLAN
To: SHAPE SECURITY, INC.
Reel/Frame 050910/0185 →
Continuity (2)
Continuation 14672879 · Mar 30, 2015
Continuation 14255248 · Apr 17, 2014
Cited By (2)
US 12,229,249 US 12,737,437