IP Library › Granted Patent US 11,411,918
Granted Patent B2
US 11,411,918 · App. 16/883,641 · Granted Aug 9, 2022

User interface for web server risk awareness

Inventor: Danut Antoche Albisor (Sammamish, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/0236H04L63/20H04L67/02H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,411,918
App. No.
16/883,641
Granted
Aug 9, 2022
Kind
B2
Abstract

Web server security is assessed. Some embodiments analyze data exchanged with a web server to determine a risk associated with accessing the web server. For example, one or more of a type of web application accessed via the web server, a type of interpreted language used to implement the web server, and/or a type and/or version of an http server operable on the web server are examined. Based on the analysis, the risk associated with accessing the web server is determined. Some embodiments then block access to the web server based on the analysis. Alternatively, in some embodiments, a user may be alerted to the risk, and then allowed to proceed upon accepting the risks. Some embodiments share the determined risk assessment with other client devices via a web server risk data store.

Claims (65)

1. A method performed by a client device, comprising:

receiving a series of network messages from a web server, two or more messages of the series of network messages indicating uniform resource locators (URLs) retrieved by a web application;

determining, based on the series of network messages:

a type of hyper-text transfer protocol (http) server application of the web server including a name of the http server application and a version of the http server application,

a type of the web application, including a name of the web application, by identifying a sequence of the URLs, comparing the sequence of the URLs to respective sequences of URLs retrieved by known web applications, determining, based on the comparing, a matching sequence of URLs, and determining, based on the matching URL sequence of URLs, the type of web application, and

a type of interpreted language used to implement the web server including a name of the interpreted language;

generating, based on the type of http server application, type of web application, and type of interpreted language, a risk score of the web server;

identifying a security policy;

determining, based on the identified security policy and the risk score, an action; and

performing the determined action.

2. The method of claim 1 , further comprising:

determining, based on the series of network messages, a client executable framework or library, wherein the generating of the risk score is further based on the determined client executable framework or library.

3. The method of claim 1 , further comprising:

identifying, based on one or more messages of the series of network messages, a sequence of document object model (DOM) xpath patterns;

comparing the sequence of DOM identifiers to DOM signatures of a known plug-in, theme, or extension,

determining, based on the comparing, a matching DOM signature; and

determining, based on the matching DOM signature, a plug-in, theme.

4. The method of claim 1 , further comprising:

decoding a server header of a network message of the series of network messages;

second determining, based on the decoded server header, an operating system of the web server, wherein the generating of the risk score is further based on the second determining.

5. The method of claim 1 , wherein performing the determined action comprises displaying a user interface on the client device, the user interface configured to display information derived from the risk score.

6. The method of claim 5 , wherein the user interface is configured to display a control, the control configured to submit a network message of the series of network messages for further processing by the client device.

7. The method of claim 1 , wherein performing the determined action comprises blocking further processing of the series of network messages by the client device.

8. A non-transitory computer readable storage medium comprising instructions that when executed configure hardware processing circuitry to perform operations comprising:

receiving a series of network messages from a web server, two or more network messages of the series of network messages indicating uniform resource locators (URLs) retrieved by a web application;

determining based on the series of network message:

a type of hyper-text transfer protocol (http) server application of the web server including a name of the http server application and a version of the http server application,

a type of the web application including a name of the web application, by identifying a sequence of the URLs, comparing the sequence of the URLs to respective sequences of URLs retrieved by known web applications, determining, based on the comparing, a matching sequence of URLs, and determining, based on the matching URL sequence of URLs, the type of web application, and

a type of interpreted language used to implement the web server including a name of the interpreted language;

generating, based on the type of http, type of web application, and type of interpreted language, a risk score of the web server;

identifying a security policy;

determining, based on the identified security policy and the risk score, an action; and

performing the determined action.

9. A system, comprising:

hardware processing circuitry;

one or more hardware memories storing instructions that when executed configure the hardware processing circuitry to perform operations comprising:

receiving a series of network messages from a web server, two or more network messages of the series of network messages indicating uniform resource locators (URLs) retrieved by a web application;

determining based on the series of network messages:

a type of hyper-text transfer protocol (http) server application of the web server including a name of the http server application and a version of the http server application,

a type of the web application including a name of the web application, by identifying a sequence of the URLs, comparing the sequence of the URLs to respective sequences of URLs retrieved by known web applications, determining, based on the comparing, a matching sequence of URLs, and determining, based on the matching URL sequence of URLs, the type of web application, and

a type of interpreted language used to implement the web server including a name of the interpreted language;

generating, based on the type of http, type of web application, and type of interpreted language, a risk score of the web server;

identifying a security policy;

determining, based on the identified security policy and the risk score, an action; and

performing the determined action.

10. The system of claim 9 , the operations further comprising:

determining, based on the series of network messages, a client executable framework or library, wherein the generating of the risk score is further based on the determined client executable framework or library.

11. The system of claim 9 , the operations further comprising:

identifying, based on one or more network messages of the series of network messages, a sequence of document object model (DOM) xpath patterns;

comparing the sequence of DOM identifiers to DOM signatures of a known plug-in, theme, or extension,

determining, based on the comparing, a matching DOM signature; and

determining, based on the matching DOM signature, a plug-in, theme or a library.

12. The system of claim 9 , the operations further comprising:

injecting an expression into a document defined by a network message of the series of network messages;

causing the expression to be evaluated;

determining, based on the evaluation, a presence of or a version of a plug-in, theme, or a library.

13. The system of claim 9 , the operations further comprising:

decoding a server header of a network message of the series of network messages;

second determining, based on the decoded server header, an operating system of the web server, wherein the generating of the risk score is further based on the second determining.

14. The system of claim 9 , wherein performing the determined action comprises causing display of a user interface, the user interface configured to display information derived from the risk score.

15. The system of claim 9 , the operations further comprising:

determining a version of the web application; and

comparing the version of the web application against a vulnerability data store, wherein the risk score is further based on the comparing.

16. The system of claim 9 , wherein a network message of the series of network messages is an http response message, and the risk score is based on a security indicator of the http response message, the security indicator including one or more of a content security policy header, an X-frame-options header, an X-XSS-Protection header, a server header, a http strict-transport-security (HSTS) header, an X-content-Type-Options header, a referrer policy, or a feature policy.

17. The system of claim 16 , wherein the security indicator indicates one or more of whether mime-sniffing is disabled by the http response, whether the referrer policy is set to unsafe-url, whether the http response header indicates a request for access to a microphone or camera, whether the HSTS header specifies use of encrypted connections, or whether the X-XSS-Protection header enables an XSS filter.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2020
From: ANTOCHE ALBISOR, DANUT
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 052813/0047 →
Continuity (1)
Related Publication 20210377217A1 · Dec 2, 2021