IP Library › Granted Patent US 11,860,761
Granted Patent B2
US 11,860,761 · App. 17/507,396 · Granted Jan 2, 2024

Detecting and identifying anomalies for single page applications

Inventor: Kunal Minda (Mandsaur, IN)
Assignee: Cisco Technology, Inc.
G06F11/3495G06F11/302H04L7/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,860,761
App. No.
17/507,396
Filed
Oct 21, 2021
Granted
Jan 2, 2024
Kind
B2
Examiner
DOAN, TAN
Art Unit
2442
USPC
709/217
Abstract

In one embodiment, a device obtains page load information corresponding to a loaded web application. The device detects, based on the page load information, an anomalous feature of the loaded web application. The device identifies a type of the anomalous feature based on a number of resource anomalies within the loaded web application, wherein the type of the anomalous feature is selected from a group consisting of: a page anomaly; a resource anomaly; and a domain anomaly. The device performs one or more mitigation actions according to the type of the anomalous feature.

Claims (43)

1. A method, comprising:

obtaining, at a device, page load information corresponding to a loaded web application;

detecting, by the device and based on the page load information, an anomalous feature of the loaded web application;

identifying, by the device, a type of the anomalous feature based on a number of resource anomalies within the loaded web application, wherein the type of the anomalous feature is one of: a page anomaly when the number of resource anomalies is zero, a resource anomaly when the number of resource anomalies is one, or a domain anomaly when the number of resource anomalies is greater than one; and

performing, by the device, one or more mitigation actions according to the type of the anomalous feature.

2. The method as in claim 1 , wherein the domain anomaly is:

a single domain anomaly when resource anomalies within the loaded web application belong to a particular domain, and

a multi-domain anomaly when the resource anomalies belong to a plurality of domains.

3. The method as in claim 1 , the method further comprising:

aggregating, by the device, page load information corresponding to the loaded web application; and

determining, by the device, one or more baselines of expected page load times for the loaded web application.

4. The method as in claim 3 , wherein detecting, by the device and based on the page load information, the anomalous feature of the loaded web application is further based on the one or more baselines of expected page load times.

5. The method as in claim 1 , the method further comprising:

generating, by the device and based on the page load information, a hierarchy of the loaded web application.

6. The method as in claim 1 , wherein the page load information comprises a page load time of a page of the loaded web application.

7. The method as in claim 1 wherein the page load information comprises a resource load time of a resource from a page of the loaded web application.

8. The method as in claim 1 , wherein the one or more mitigation actions comprises causing a graphical user interface to display an indication of the type of the anomalous feature at an end-user device.

9. The method as in claim 1 , wherein the page load information is obtained from an agent selected from a group consisting of: a cloud agent, an enterprise agent, and an endpoint agent.

10. A tangible, non-transitory, computer-readable medium having computer-executable instructions stored thereon that, when executed by a processor on a computer, cause the computer to perform a method comprising:

obtaining page load information corresponding to a loaded web application;

detecting, based on the page load information, an anomalous feature of the loaded web application;

identifying a type of the anomalous feature based on a number of resource anomalies within the loaded web application, wherein the type of the anomalous feature is one of: a page anomaly when the number of resource anomalies is zero, a resource anomaly when the number of resource anomalies is one, or a domain anomaly when the number of resource anomalies is greater than one; and

performing one or more mitigation actions according to the type of the anomalous feature.

11. The tangible, non-transitory, computer-readable medium as in claim 10 , wherein the domain anomaly is:

a single domain anomaly when resource anomalies within the loaded web application belong to a particular domain, and

a multi-domain anomaly when the resource anomalies belong to a plurality of domains.

12. The tangible, non-transitory, computer-readable medium as in claim 10 , wherein the method further comprises:

aggregating page load information corresponding to the loaded web application; and

determining one or more baselines of expected page load times for the loaded web application.

13. The tangible, non-transitory, computer-readable medium as in claim 12 , wherein detecting, based on the page load information, the anomalous feature of the loaded web application is further based on the one or more baselines of expected page load times.

14. The tangible, non-transitory, computer-readable medium as in claim 10 , wherein the method further comprises:

generating, based on the page load information, a hierarchy of the loaded web application.

15. The tangible, non-transitory, computer-readable medium as in claim 10 , wherein the page load information comprises a page load time of a page of the loaded web application.

16. The tangible, non-transitory, computer-readable medium as in claim 10 , wherein the page load information comprises a resource load time of a resource from a page of the loaded web application.

17. The tangible, non-transitory, computer-readable medium as in claim 10 , wherein the one or more mitigation actions comprises causing a graphical user interface to display an indication of the type of the anomalous feature at an end-user device.

18. An apparatus, comprising:

one or more network interfaces to communicate with a network;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process, when executed, configured to:

obtain page load information corresponding to a loaded web application;

detect, based on the page load information, an anomalous feature of the loaded web application;

identify a type of the anomalous feature based on a number of resource anomalies within the loaded web application, wherein the type of the anomalous feature is one of: a page anomaly when the number of resource anomalies is zero, a resource anomaly when the number of resource anomalies is one, or a domain anomaly when the number of resource anomalies is greater than one; and

perform one or more mitigation actions according to the type of the anomalous feature.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2021
From: MINDA, KUNAL
To: CISCO TECHNOLOGY, INC.
Reel/Frame 057868/0423 →
Continuity (1)
Related Publication 20230128202A1 · Apr 27, 2023