IP Library › Granted Patent US 12,261,874
Granted Patent B2
US 12,261,874 · App. 18/169,692 · Granted Mar 25, 2025

Library security methods and systems using a web application firewall

Inventor: Jose Lejin P J (Bangalore, IN)
H04L63/1433H04L63/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,261,874
App. No.
18/169,692
Filed
Feb 15, 2023
Granted
Mar 25, 2025
Kind
B2
Art Unit
2497
USPC
726/25
Abstract

Database systems and methods are provided for securing an instance of a web application from vulnerabilities in third party libraries using a web application firewall. One method involves receiving, at a web application firewall between an application server and a client, vulnerability information associated with the web application, generating, at the web application firewall, executable code for securing the instance of the web application based at least in part on the vulnerability information, providing, by the web application firewall, the executable code to the client over a network, and thereafter detecting a vulnerable library associated with the instance of the web application, wherein the client executes the executable code to secure the instance of the web application in response to detecting the vulnerable library.

Claims (62)

1. A method of securely provisioning an instance of a web application from an application server to a client, the method comprising:

receiving, at a web application firewall between the application server and the client, vulnerability information associated with the web application;

generating, at the web application firewall, executable code for securing the instance of the web application based at least in part on the vulnerability information;

injecting, by the web application firewall, the executable code into a file associated with the web application retrieved from the application server prior to providing the file to a web browser application at the client over a network; and

thereafter detecting a vulnerable library associated with the instance of the web application, wherein the web browser application at the client executes the executable code within the file to provide a client-side library monitoring service configured in accordance with the vulnerability information to secure the instance of the web application in response to detecting the vulnerable library.

2. The method of claim 1 , wherein detecting the vulnerable library comprises:

determining a hash value of a function contained in a library retrieved from a third party system;

comparing the hash value of the function contained in the library to a reference hash value for a vulnerable function; and

identifying the library as the vulnerable library when the hash value of the function contained in the library retrieved from the third party system matches the reference hash value.

3. The method of claim 2 , wherein determining the hash value comprises:

converting contents of the function into a string representation; and

inputting the string representation of the contents of the function into a hashing algorithm to obtain the hash value.

4. The method of claim 3 , wherein receiving the vulnerability information comprises receiving at least one of the reference hash value for the vulnerable function and indication of the hashing algorithm selected by a web application administrator.

5. The method of claim 2 , further comprising:

identifying one of an obfuscated format or an unobfuscated format as a format of the function contained in the library; and

selecting the reference hash value associated with the identified one of the obfuscated format or the unobfuscated format.

6. The method of claim 1 , wherein:

receiving the vulnerability information comprises receiving indication of a vulnerable function associated with a library to be retrieved from a third party system in connection with the instance of the web application; and

generating the executable code comprises automatically generating executable code for a function detection component configurable to detect presence of a function corresponding to the vulnerable function within the library.

7. The method of claim 1 , wherein the client-side library monitoring service is configurable to identify a function contained in a library retrieved from a third party system corresponding to a vulnerable function defined by the vulnerability information, determining a hash value of the identified function, comparing the hash value of the identified function contained in the library to a reference hash value for the vulnerable function, and identifying the library as the vulnerable library when the hash value of the identified function matches the reference hash value for the vulnerable function.

8. The method of claim 7 , wherein the client-side library monitoring service is configurable to terminate the instance of the web application within the web browser application in response to identifying the library as the vulnerable library.

9. A method of securely provisioning an instance of a web application from an application server to a client, the method comprising:

receiving, at a web application firewall between the application server and the client, vulnerability information associated with the web application;

generating, at the web application firewall, executable code for securing the instance of the web application based at least in part on the vulnerability information;

providing, by the web application firewall, the executable code to the client over a network; and

thereafter:

obtaining, at the web application firewall, library vulnerability information associated with a third party library;

comparing, at the web application firewall, the library vulnerability information with library dependency information associated with the web application to determine whether the web application includes the third party library; and

providing, by the web application firewall, a vulnerability header in a response to the client, wherein:

the vulnerability header identifies the third party library and applicable web browser vulnerability information associated with the third party library; and

the client identifies the third party library as a vulnerable library when the applicable web browser vulnerability information in the vulnerability header corresponds to a web browser application being utilized to access the instance of the web application at the client.

10. The method of claim 1 , wherein:

the file comprises a HyperText Markup Language (HTML) file associated with the web application; and

the executable code comprises JavaScript incorporated into the HTML file.

11. The method of claim 9 , wherein providing the executable code to the client over the network comprises the web application firewall injecting the executable code into a file associated with the web application retrieved from the application server.

12. The method of claim 11 , wherein detecting the vulnerable library comprises the web browser application at the client executing the executable code to provide a client-side library monitoring service configured in accordance with the vulnerability information.

13. The method of claim 11 , wherein:

injecting the executable code comprises the web application firewall incorporating JavaScript into a HyperText Markup Language (HTML) file associated with the web application retrieved from the application server prior to providing the HTML file to the web browser application at the client; and

detecting the vulnerable library comprises the web browser application at the client executing the JavaScript within the HTML file to provide a client-side library monitoring service configured in accordance with the vulnerability information.

14. The method of claim 9 , wherein:

the vulnerability header identifies a fallback object for the third party library; and

the client automatically configures the instance of the web application at the client to utilize the fallback object in lieu of an original object of the third party library in response to identifying the third party library as the vulnerable library.

15. The method of claim 9 , wherein:

the vulnerability header identifies a dependency level associated with the third party library; and

the client automatically terminates the instance of the web application at the client based on the dependency level in response to identifying the third party library as the vulnerable library.

16. At least one non-transitory machine-readable storage medium that provides instructions that, when executed by at least one processor, are configurable to cause the at least one processor to perform operations comprising:

receiving, at a web application firewall between an application server and a client, vulnerability information associated with a web application;

generating, at the web application firewall, executable code for securing an instance of the web application based at least in part on the vulnerability information;

providing, by the web application firewall, the executable code to the client over a network by injecting the executable code into a file associated with the web application retrieved from the application server prior to providing the file to a web browser application at the client; and

thereafter detecting a vulnerable library associated with the instance of the web application, wherein the web browser application at the client executes the executable code within the file to provide a client-side library monitoring service configured in accordance with the vulnerability information to secure the instance of the web application in response to detecting the vulnerable library.

17. The non-transitory machine-readable storage medium of claim 16 , wherein the instructions are configurable to cause the at least one processor to detect the vulnerable library by:

determining a hash value of a function contained in a library retrieved from a third party system;

comparing the hash value of the function contained in the library to a reference hash value for a vulnerable function; and

identifying the library as the vulnerable library when the hash value of the function contained in the library retrieved from the third party system matches the reference hash value.

18. The non-transitory machine-readable storage medium of claim 16 , wherein the instructions are configurable to cause the at least one processor to:

obtain, at the web application firewall, indication of a vulnerable function associated with a library to be retrieved from a third party system in connection with the instance of the web application; and

automatically generate the executable code for a function detection component configurable to detect presence of a function corresponding to the vulnerable function within the library at the client.

19. The non-transitory machine-readable storage medium of claim 16 , wherein the instructions are configurable to cause the at least one processor to:

obtain library vulnerability information associated with a third party library; and

compare the library vulnerability information with library dependency information associated with the web application to determine whether the web application includes the third party library, wherein:

the client identifies the third party library as the vulnerable library when applicable web browser vulnerability information in the library vulnerability information corresponds to the web browser application being utilized to access the instance of the web application at the client.

20. The non-transitory machine-readable storage medium of claim 19 , wherein the client automatically configures the instance of the web application at the client to utilize a fallback object in lieu of an original object of the third party library in response to identifying the third party library as the vulnerable library.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 15, 2023
From: LEJIN P J, JOSE
To: SALESFORCE, INC.
Reel/Frame 062711/0918 →
Continuity (1)
Related Publication 20240275808A1 · Aug 15, 2024
References Cited (151)
US 5577188A · Zhu · 1996 [cited by applicant]
US 5608872A · Schwartz et al. · 1997 [cited by applicant]
US 5649104A · Carleton et al. · 1997 [cited by applicant]
US 5715450A · Ambrose et al. · 1998 [cited by applicant]
US 5761419A · Schwartz et al. · 1998 [cited by applicant]
US 5819038A · Carleton et al. · 1998 [cited by applicant]
US 5821937A · Tonelli et al. · 1998 [cited by applicant]
US 5831610A · Tonelli et al. · 1998 [cited by applicant]
US 5873096A · Lim et al. · 1999 [cited by applicant]
US 5918159A · Fomukong et al. · 1999 [cited by applicant]
US 5963953A · Cram et al. · 1999 [cited by applicant]
US 6092083A · Brodersen et al. · 2000 [cited by applicant]
US 6161149A · Achacoso et al. · 2000 [cited by applicant]
US 6169534B1 · Raffel et al. · 2001 [cited by applicant]
US 6178425B1 · Brodersen et al. · 2001 [cited by applicant]
US 6189011B1 · Lim et al. · 2001 [cited by applicant]
US 6216135B1 · Brodersen et al. · 2001 [cited by applicant]
US 6233617B1 · Rothwein et al. · 2001 [cited by applicant]
US 6266669B1 · Brodersen et al. · 2001 [cited by applicant]
US 6295530B1 · Ritchie et al. · 2001 [cited by applicant]
US 6324568B1 · Diec et al. · 2001 [cited by applicant]
US 6324693B1 · Brodersen et al. · 2001 [cited by applicant]
US 6336137B1 · Lee et al. · 2002 [cited by applicant]
US D454139S · Feldcamp et al. · 2002 [cited by applicant]
US 6367077B1 · Brodersen et al. · 2002 [cited by applicant]
US 6393605B1 · Loomans · 2002 [cited by applicant]
US 6405220B1 · Brodersen et al. · 2002 [cited by applicant]
US 6434550B1 · Warner et al. · 2002 [cited by applicant]
US 6446089B1 · Brodersen et al. · 2002 [cited by applicant]
US 6535909B1 · Rust · 2003 [cited by applicant]
US 6549908B1 · Loomans · 2003 [cited by applicant]
US 6553563B2 · Ambrose et al. · 2003 [cited by applicant]
US 6560461B1 · Fomukong et al. · 2003 [cited by applicant]
US 6574635B2 · Stauber et al. · 2003 [cited by applicant]
US 6577726B1 · Huang et al. · 2003 [cited by applicant]
US 6601087B1 · Zhu et al. · 2003 [cited by applicant]
US 6604117B2 · Lim et al. · 2003 [cited by applicant]
US 6604128B2 · Diec · 2003 [cited by applicant]
US 6609150B2 · Lee et al. · 2003 [cited by applicant]
US 6621834B1 · Scherpbier et al. · 2003 [cited by applicant]
US 6654032B1 · Zhu et al. · 2003 [cited by applicant]
US 6665648B2 · Brodersen et al. · 2003 [cited by applicant]
US 6665655B1 · Warner et al. · 2003 [cited by applicant]
US 6684438B2 · Brodersen et al. · 2004 [cited by applicant]
US 6711565B1 · Subramaniam et al. · 2004 [cited by applicant]
US 6724399B1 · Katchour et al. · 2004 [cited by applicant]
US 6728702B1 · Subramaniam et al. · 2004 [cited by applicant]
US 6728960B1 · Loomans et al. · 2004 [cited by applicant]
US 6732095B1 · Warshavsky et al. · 2004 [cited by applicant]
US 6732100B1 · Brodersen et al. · 2004 [cited by applicant]
US 6732111B2 · Brodersen et al. · 2004 [cited by applicant]
US 6754681B2 · Brodersen et al. · 2004 [cited by applicant]
US 6763351B1 · Subramaniam et al. · 2004 [cited by applicant]
US 6763501B1 · Zhu et al. · 2004 [cited by applicant]
US 6768904B2 · Kim · 2004 [cited by applicant]
US 6772229B1 · Achacoso et al. · 2004 [cited by applicant]
US 6782383B2 · Subramaniam et al. · 2004 [cited by applicant]
US 6804330B1 · Jones et al. · 2004 [cited by applicant]
US 6826565B2 · Ritchie et al. · 2004 [cited by applicant]
US 6826582B1 · Chatterjee et al. · 2004 [cited by applicant]
US 6826745B2 · Coker · 2004 [cited by applicant]
US 6829655B1 · Huang et al. · 2004 [cited by applicant]
US 6842748B1 · Warner et al. · 2005 [cited by applicant]
US 6850895B2 · Brodersen et al. · 2005 [cited by applicant]
US 6850949B2 · Warner et al. · 2005 [cited by applicant]
US 7062502B1 · Kesler · 2006 [cited by applicant]
US 7069231B1 · Cinarkaya et al. · 2006 [cited by applicant]
US 7181758B1 · Chan · 2007 [cited by applicant]
US 7289976B2 · Kihneman et al. · 2007 [cited by applicant]
US 7340411B2 · Cook · 2008 [cited by applicant]
US 7356482B2 · Frankland et al. · 2008 [cited by applicant]
US 7401094B1 · Kesler · 2008 [cited by applicant]
US 7412455B2 · Dillon · 2008 [cited by applicant]
US 7508789B2 · Chan · 2009 [cited by applicant]
US 7620655B2 · Larsson et al. · 2009 [cited by applicant]
US 7698160B2 · Beaven et al. · 2010 [cited by applicant]
US 7730478B2 · Weissman · 2010 [cited by applicant]
US 7779475B2 · Jakobson et al. · 2010 [cited by applicant]
US 8014943B2 · Jakobson · 2011 [cited by applicant]
US 8015495B2 · Achacoso et al. · 2011 [cited by applicant]
US 8032297B2 · Jakobson · 2011 [cited by applicant]
US 8082301B2 · Ahlgren et al. · 2011 [cited by applicant]
US 8095413B1 · Beaven · 2012 [cited by applicant]
US 8095594B2 · Beaven et al. · 2012 [cited by applicant]
US 8209308B2 · Rueben et al. · 2012 [cited by applicant]
US 8275836B2 · Beaven et al. · 2012 [cited by applicant]
US 8457545B2 · Chan · 2013 [cited by applicant]
US 8484111B2 · Frankland et al. · 2013 [cited by applicant]
US 8490025B2 · Jakobson et al. · 2013 [cited by applicant]
US 8504945B2 · Jakobson et al. · 2013 [cited by applicant]
US 8510045B2 · Rueben et al. · 2013 [cited by applicant]
US 8510664B2 · Rueben et al. · 2013 [cited by applicant]
US 8566301B2 · Rueben et al. · 2013 [cited by applicant]
US 8646103B2 · Jakobson et al. · 2014 [cited by applicant]
US 20010044791A1 · Richter et al. · 2001 [cited by applicant]
US 20020072951A1 · Lee et al. · 2002 [cited by applicant]
US 20020082892A1 · Raffel · 2002 [cited by applicant]
US 20020129352A1 · Brodersen et al. · 2002 [cited by applicant]
US 20020140731A1 · Subramanian et al. · 2002 [cited by applicant]
US 20020143997A1 · Huang et al. · 2002 [cited by applicant]
US 20020162090A1 · Parnell et al. · 2002 [cited by applicant]
US 20020165742A1 · Robbins · 2002 [cited by applicant]
US 20030004971A1 · Gong · 2003 [cited by applicant]
US 20030018705A1 · Chen et al. · 2003 [cited by applicant]
US 20030018830A1 · Chen et al. · 2003 [cited by applicant]
US 20030066031A1 · Laane et al. · 2003 [cited by applicant]
US 20030066032A1 · Ramachandran et al. · 2003 [cited by applicant]
US 20030069936A1 · Warner et al. · 2003 [cited by applicant]
US 20030070000A1 · Coker et al. · 2003 [cited by applicant]
US 20030070004A1 · Mukundan et al. · 2003 [cited by applicant]
US 20030070005A1 · Mukundan et al. · 2003 [cited by applicant]
US 20030074418A1 · Coker et al. · 2003 [cited by applicant]
US 20030120675A1 · Stauber et al. · 2003 [cited by applicant]
US 20030151633A1 · George et al. · 2003 [cited by applicant]
US 20030159136A1 · Huang et al. · 2003 [cited by applicant]
US 20030187921A1 · Diec et al. · 2003 [cited by applicant]
US 20030189600A1 · Gune et al. · 2003 [cited by applicant]
US 20030204427A1 · Gune et al. · 2003 [cited by applicant]
US 20030206192A1 · Chen et al. · 2003 [cited by applicant]
US 20030225730A1 · Warner et al. · 2003 [cited by applicant]
US 20040001092A1 · Rothwein et al. · 2004 [cited by applicant]
US 20040010489A1 · Rio et al. · 2004 [cited by applicant]
US 20040015981A1 · Coker et al. · 2004 [cited by applicant]
US 20040027388A1 · Berg et al. · 2004 [cited by applicant]
US 20040128001A1 · Levin et al. · 2004 [cited by applicant]
US 20040186860A1 · Lee et al. · 2004 [cited by applicant]
US 20040193510A1 · Catahan et al. · 2004 [cited by applicant]
US 20040199489A1 · Barnes-Leon et al. · 2004 [cited by applicant]
US 20040199536A1 · Barnes-Leon et al. · 2004 [cited by applicant]
US 20040199543A1 · Braud et al. · 2004 [cited by applicant]
US 20040249854A1 · Barnes-Leon et al. · 2004 [cited by applicant]
US 20040260534A1 · Pak et al. · 2004 [cited by applicant]
US 20040260659A1 · Chan et al. · 2004 [cited by applicant]
US 20040268299A1 · Lei et al. · 2004 [cited by applicant]
US 20050050555A1 · Exley et al. · 2005 [cited by applicant]
US 20050091098A1 · Brodersen et al. · 2005 [cited by applicant]
US 20060021019A1 · Hinton et al. · 2006 [cited by applicant]
US 20080249972A1 · Dillon · 2008 [cited by applicant]
US 20090063414A1 · White et al. · 2009 [cited by applicant]
US 20090100342A1 · Jakobson · 2009 [cited by applicant]
US 20090177744A1 · Marlow et al. · 2009 [cited by applicant]
US 20110247051A1 · Bulumulla et al. · 2011 [cited by applicant]
US 20120042218A1 · Cinarkaya et al. · 2012 [cited by applicant]
US 20120218958A1 · Rangaiah · 2012 [cited by applicant]
US 20120233137A1 · Jakobson et al. · 2012 [cited by applicant]
US 20130212497A1 · Zelenko et al. · 2013 [cited by applicant]
US 20130218948A1 · Jakobson · 2013 [cited by applicant]
US 20130218949A1 · Jakobson · 2013 [cited by applicant]
US 20130218966A1 · Jakobson · 2013 [cited by applicant]
US 20130247216A1 · Cinarkaya et al. · 2013 [cited by applicant]
US 20210014245A1 · McKendall · 2021 [cited by examiner]
Cited By (1)
US 12,476,976