IP Library › Granted Patent US 12,335,287
Granted Patent B2
US 12,335,287 · App. 17/646,611 · Granted Jun 17, 2025

Automated detection of cross site scripting attacks

Inventor: Satya V. Gupta (Dublin, CA)
Assignee: Virsec Systems, Inc.
H04L63/1433H04L63/1416H04L2463/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,335,287
App. No.
17/646,611
Granted
Jun 17, 2025
Kind
B2
Abstract

Embodiments detect cross site scripting attacks. An embodiment captures a web request and captures a response to the captured web request. In turn, it is determined if one or more elements associated with the captured web request and one or more elements of the captured response, in combination, cause a malicious action. A cross site scripting attack is then declared in response to determining the one or more elements associated with the captured web request and the one or more elements of the captured response, in combination, cause a malicious action. Embodiments can take one or more protection actions in response to declaring a cross site scripting attack.

Claims (53)

1. A method of detecting a cross site scripting attack, the method comprising:

capturing a web request provided by a user, after the web request is decrypted and decoded, by capturing the web request at an entrance to a Hypertext Transfer Protocol (HTTP) pipeline;

capturing a response to the captured web request;

determining if one or more elements associated with the captured web request and one or more elements of the captured response, in combination, cause a malicious action, wherein the determining is based on (i) presence of interpreter syntax in user input, provided by the user, in the captured web request, and at least one of (ii) status of the user input being included in interpreter input, (iii) execution status of the interpreter, and (iv) presence of interpreter syntax in the captured response; and

declaring a cross site scripting attack in response to determining the one or more elements associated with the captured web request and the one or more elements of the captured response, in combination, cause a malicious action.

2. The method of claim 1 wherein the one or more elements associated with the captured web request and the one or more elements of the captured response include at least one of:

a scripting verb; and

a Document Object Model (DOM).

3. The method of claim 1 wherein the one or more elements associated with the captured web request include a first scripting verb and the one or more elements of the captured response include a second scripting verb and where, if the first scripting verb and the second scripting verb match, the determining identifies the first scripting verb in combination with the second script verb cause a malicious action.

4. The method of claim 1 wherein the one or more elements associated with the captured web request include a first Document Object Model (DOM) element and the one or more elements of the captured response include a second DOM element.

5. The method of claim 4 wherein:

the determining identifies the first DOM element in combination with the second DOM element cause a malicious action; and

the declared cross site scripting attack is a DOM scripting attack.

6. The method of claim 1 wherein the determining and the declaring are performed by computer programming code implemented in a browser associated with the web request.

7. The method of claim 6 wherein the computer programming code is in a scripting language.

8. The method of claim 1 wherein the captured response includes both a database response and a HTTP response.

9. The method of claim 8 wherein the one or more elements associated with the captured web request include a first scripting verb and the one or more elements of the captured response include a second scripting verb in the database response and a third scripting verb in the HTTP response.

10. The method of claim 9 wherein:

if the first scripting verb and the third scripting verb match: (i) the determining identifies the first scripting verb in combination with the third scripting verb cause a malicious action and (ii) the declared cross site scripting attack is a reflected cross site scripting attack; and

if the first scripting verb and the second scripting verb match: (i) the determining identifies the first scripting verb in combination with the second scripting verb cause a malicious action and (ii) the declared cross site scripting attack is a stored cross site scripting attack.

11. The method of claim 1 further comprising:

in response to declaring the cross site scripting attack, implementing a protection action.

12. The method of claim 11 wherein the protection action is at least one of:

executing a user indicated script;

terminating an Internet Protocol (IP) connection;

terminating a web session;

providing a compensating control to a web application firewall; and

displaying an indication of the cross site scripting attack to a user.

13. A system for detecting a cross site scripting attack, the system comprising:

a processor; and

a memory with computer code instructions stored thereon, the processor and the memory, with the computer code instructions, being configured to cause the system to:

capture a web request provided by a user, after the web request is decrypted and decoded, by capturing the web request at an entrance to a Hypertext Transfer Protocol (HTTP) pipeline;

capture a response to the captured web request;

determine if one or more elements associated with the captured web request and one or more elements of the captured response, in combination, cause a malicious action, wherein the determining is based on (i) presence of interpreter syntax in user input, provided by the user, in the captured web request, and at least one of (ii) status of the user input being included in interpreter input, (iii) execution status of the interpreter, and (iv) presence of interpreter syntax in the captured response; and

declare a cross site scripting attack in response to determining the one or more elements associated with the captured web request and the one or more elements of the captured response, in combination, cause a malicious action.

14. The system of claim 13 wherein the one or more elements associated with the captured web request and the one or more elements of the captured response include at least one of:

a scripting verb; and

a Document Object Model (DOM).

15. The system of claim 13 wherein the one or more elements associated with the captured web request include a first Document Object Model (DOM) element and the one or more elements of the captured response include a second DOM element.

16. The system of claim 15 wherein:

the determining identifies the first DOM element in combination with the second DOM element cause a malicious action; and

the declared cross site scripting attack is a DOM scripting attack.

17. The system of claim 13 wherein (i) the captured response includes both a database response and a HTTP response and (ii) the one or more elements associated with the captured web request include a first scripting verb and the one or more elements of the captured response include a second scripting verb in the database response and a third scripting verb in the HTTP response, and where:

if the first scripting verb and the third scripting verb match: (i) the determining identifies the first scripting verb in combination with the third scripting verb cause a malicious action and (ii) the declared cross site scripting attack is a reflected cross site scripting attack; and

if the first scripting verb and the second scripting verb match: (i) the determining identifies the first scripting verb in combination with the second scripting verb cause a malicious action and (ii) the declared cross site scripting attack is a stored cross site scripting attack.

18. The system of claim 13 wherein the processor and the memory, with the computer code instructions, are further configured to cause the system to:

in response to declaring the cross site scripting attack, implement a protection action.

19. A computer program product for detecting a cross site scripting attack, the computer program product comprising:

one or more non-transitory computer read-able storage devices and program instructions stored on at least one of the one or more storage devices, the program instructions, when loaded and executed by a processor, cause an apparatus associated with the processor to:

capture a web request provided by a user, after the web request is decrypted and decoded, by capturing the web request at an entrance to a Hypertext Transfer Protocol (HTTP) pipeline;

capture a response to the captured web request;

determine if one or more elements associated with the captured web request and one or more elements of the captured response, in combination, cause a malicious action, wherein the determining is based on (i) presence of interpreter syntax in user input, provided by the user, in the captured web request, and at least one of (ii) status of the user input being included in interpreter input, (iii) execution status of the interpreter, and (iv) presence of interpreter syntax in the captured response; and

declare a cross site scripting attack in response to determining the one or more elements associated with the captured web request and the one or more elements of the captured response, in combination, cause a malicious action.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2022
From: GUPTA, SATYA V.
To: VIRSEC SYSTEMS, INC.
Reel/Frame 058571/0129 →
Continuity (2)
Provisional Application 63133173 · Dec 31, 2020
Related Publication 20220210180A1 · Jun 30, 2022
References Cited (105)
US 6321334B1 · Jerger et al. · 2001 [cited by applicant]
US 8347267B2 · Givoni et al. · 2013 [cited by applicant]
US 9246935B2 · Lietz et al. · 2016 [cited by applicant]
US 9374390B1 · Teal et al. · 2016 [cited by applicant]
US 9418230B2 · Archer et al. · 2016 [cited by applicant]
US 9501650B2 · Chess et al. · 2016 [cited by applicant]
US 9578060B1 · Brisebois et al. · 2017 [cited by applicant]
US 9589560B1 · Vitaladevuni et al. · 2017 [cited by applicant]
US 10116681B2 · Cornell et al. · 2018 [cited by applicant]
US 10354074B2 · Gupta · 2019 [cited by applicant]
US 10387659B1 · Youngberg et al. · 2019 [cited by applicant]
US 10395041B1 · Youngberg et al. · 2019 [cited by applicant]
US 10447730B2 · Gupta · 2019 [cited by applicant]
US 10467419B1 · Youngberg et al. · 2019 [cited by applicant]
US 10963565B1 · Xu et al. · 2021 [cited by applicant]
US 11615061B1 · Malik et al. · 2023 [cited by applicant]
US 11907378B2 · Gupta · 2024 [cited by applicant]
US 12158958B2 · Gupta et al. · 2024 [cited by applicant]
US 20030074207A1 · Pace et al. · 2003 [cited by applicant]
US 20040046785A1 · Keller · 2004 [cited by applicant]
US 20050102534A1 · Wong · 2005 [cited by applicant]
US 20070199000A1 · Shekhel et al. · 2007 [cited by applicant]
US 20080052527A1 · Siedlarz · 2008 [cited by examiner]
US 20090119769A1 · Ross · 2009 [cited by examiner]
US 20130111595A1 · Amit · 2013 [cited by examiner]
US 20140082735A1 · Beskrovny et al. · 2014 [cited by applicant]
US 20140082739A1 · Chess et al. · 2014 [cited by applicant]
US 20140165192A1 · Zhu · 2014 [cited by examiner]
US 20150215332A1 · Curcic et al. · 2015 [cited by applicant]
US 20150261653A1 · Lachambre et al. · 2015 [cited by applicant]
US 20150309813A1 · Patel · 2015 [cited by applicant]
US 20160164891A1 · Satish et al. · 2016 [cited by applicant]
US 20160241582A1 · Boia et al. · 2016 [cited by applicant]
US 20170270303A1 · Roichman et al. · 2017 [cited by applicant]
US 20170288878A1 · Lee et al. · 2017 [cited by applicant]
US 20170353434A1 · Al-Saber · 2017 [cited by examiner]
US 20180349602A1 · Johns · 2018 [cited by applicant]
US 20190138725A1 · Gupta · 2019 [cited by applicant]
US 20190286833A1 · Takumi et al. · 2019 [cited by applicant]
US 20190377877A1 · Johns · 2019 [cited by examiner]
US 20200004963A1 · Zheng et al. · 2020 [cited by applicant]
US 20200042714A1 · Gupta · 2020 [cited by applicant]
US 20200065166A1 · Myneni et al. · 2020 [cited by applicant]
US 20200097662A1 · Hufsmith et al. · 2020 [cited by applicant]
US 20200134193A1 · Youngberg et al. · 2020 [cited by applicant]
US 20200134194A1 · Youngberg et al. · 2020 [cited by applicant]
US 20200134195A1 · Youngberg et al. · 2020 [cited by applicant]
US 20200167477A1 · Ionescu et al. · 2020 [cited by applicant]
US 20200336507A1 · Lee et al. · 2020 [cited by applicant]
US 20210086089A1 · Pardeshi et al. · 2021 [cited by applicant]
US 20210099483A1 · Shukla · 2021 [cited by applicant]
US 20210160273A1 · Choi et al. · 2021 [cited by applicant]
US 20220046031A1 · Kaidi · 2022 [cited by examiner]
US 20220067174A1 · Gupta · 2022 [cited by applicant]
US 20220147635A1 · Copty et al. · 2022 [cited by applicant]
US 20220198025A1 · Gupta et al. · 2022 [cited by applicant]
US 20220207151A1 · Gupta · 2022 [cited by applicant]
US 20220214928A1 · Gupta et al. · 2022 [cited by applicant]
US 20220391506A1 · Gupta · 2022 [cited by applicant]
US 20230004652A1 · Gupta · 2023 [cited by applicant]
WO 2015007166A1 · 2015 [cited by applicant]
WO 2016130372A1 · 2016 [cited by applicant]
WO 2020026228A1 · 2020 [cited by applicant]
WO 2022047245A1 · 2022 [cited by applicant]
WO 2022147474A1 · 2022 [cited by applicant]
WO 2022147478A1 · 2022 [cited by applicant]
WO 2022155685A1 · 2022 [cited by applicant]
WO 2022155687A1 · 2022 [cited by applicant]
WO 2022246436A1 · 2022 [cited by applicant]
WO 2022246437A1 · 2022 [cited by applicant]
WO 2023133586A1 · 2023 [cited by applicant]
“ATT&CK (Registered)”, The Mitre, Available online at: < https://attack.mitre.org>, Sep. 14, 2023, 1 page. [cited by applicant]
“Welcome to YARA's documentation-yara 4.3.2 documentation” Available online at: <https://yara.readthedocs.io/en/stable/>, retrieved on Sep. 14, 2023, 4 pages. [cited by applicant]
“CAPEC—Common Attack Pattern Enumeration and Classification”, (CAPEC(Trademark)), Available on https://capec.mitre.org, Jan. 2, 2022, 2 pages. [cited by applicant]
“CAPEC VIEW: Mechanisms of Attack”, View ID: 1000, (Version 3.6), Available online https://capec.mitre.org/data/definitions/1000.html, Jan. 2, 2022, 2 pages. [cited by applicant]
“Configuration Management Database (CMDB)”, 2023, 15 pages. [cited by applicant]
“CWE VIEW: Software Development” View ID: 699, Individual Dictionary Definition (4.6), Available on https://cwe.mitre.org/data/definitions/699.html, Jan. 2, 2022, 2 pages. [cited by applicant]
“Integrated Risk Management (IRM)”, Gartner Glossary, Available on https://www.gartner.com/en/information-technology/glossary/integrated-risk-management-irm, Jan. 2, 2022, 5 pages. [cited by applicant]
“Javap—The Java Class File Disassembler”, Oracle, Java SE Documentation, Available on https://docs.oracle.com/javase/7/docs/technotes/tools/windows/javap.html, Jan. 2, 2022, 3 pages. [cited by applicant]
“The Shadow Brokers”, Wikipedia, Available on https://en.wikipedia.org/wiki/The_Shadow_Brokers, Jan. 2, 2022, 8 pages. [cited by applicant]
“Windows Print Spooler Remote Code Execution Vulnerability”, Security Vulnerability, CVE-2021-34527, Available on https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527#title, Jun. 13, 2023, 1 page. [cited by applicant]
Caputo, D., et al: “Droids in Disarray: Detecting Frame Confusion in Hybrid Android Apps”, Jun. 11, 2019 (Jun. 11, 2019), Advances in Databases and Information Systems; [Lecture Notes in Computer Science; Lect.Notes Com… [cited by applicant]
Chen et al., “Automated system change discovery and management in the cloud”, IBM Journal of Research and Development, vol. 60, No. 2-3, Mar. 1, 2016, pp. 2:1-2:10. [cited by applicant]
Chen et al., “Detecting and Identifying System Changes in the Cloud via Discovery by Example”, 2014 IEEE International Conference on Big Data, Oct. 27, 2014, pp. 90-99. [cited by applicant]
Chen, Lu., et al, “Research on Mobile Application Local Denial of Service Vulnerability Detection Technology Basec on Rule Matching”, 2019 IEEE International Conference on Energy Internet (ICEI), IEEE, May 27, 2019 (May… [cited by applicant]
David Stahl, “What's an RFC and what can they do for me?”, Global Knowledge, Available on https://www.globalknowledge.com/us-en/resources/resource-library/articles/whats-an-rfc-and-what-can-they-do-for-me/, Sep. 16, 200… [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2021/048077, mailed on Dec. 20, 2021, 11 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2021/073197, mailed on Mar. 21, 2022, 10 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2021/073201, mailed on Apr. 7, 2022, 10 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2022/070236, mailed on Apr. 8, 2022, 15 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2022/070240, mailed on Apr. 7, 2022, 17 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2022/072416, mailed on Sep. 8, 2022, 13 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2022/072417, mailed on Sep. 8, 2022, 15 pages. [cited by applicant]
Johns, M., et al., “XSSDS: Server-Side Detection of Cross-Site Scripting Attacks”, Computer Security Applications Conference, 2008. Acsac, Dec. 8, 2008, pp. 335-344. [cited by applicant]
Koutroumpouchos, K., et al., “ObjectMap: detecting insecure object deserialization”, PCI '19: Proceedings of the 23rd Pan-Hellenic Conference on Informatics, Nov. 28, 2019, pp. 67-72. [cited by applicant]
Prevelakis et al., “Sandboxing Applications”, USENIX, The Advanced Computing Systems Association, Feb. 25, 2019, pp. 1-9. [cited by applicant]
Secure execution of privileged scripts ED-Darl Kuhn, ip.com, ip.com Inc., West Henrietta, Sep. 18, 2009, XP013134389. [cited by applicant]
Sun, F., et al., “Client-Side Detection of XSS Worms by Monitoring Payload Propagation”, Advances In Databases And Information Systems, Sep. 21, 2009, pp. 539-554. [cited by applicant]
Xia, M. et al: “Effective Real-Time Android Application Auditing”, 2015 IEEE Symposium on Security and Privacy, IEEE, May 17, 2015 (May 17, 2015), pp. 899-914. [cited by applicant]
Dizdar, A. , “Why are SAST solutions not always the best option for AST?”, Bright, Jan. 22, 2020, 10 pages. [cited by applicant]
Horvath, M., et al., “Magic Quadrant for Application Security Testing” Gartner Reprint, (33 pages) Apr. 29, 2020, 33 pages, retrieved from https://www.gartner.com/doc/reprints?id=1-1YWZKUB5&ct=200429&st=sb. [cited by applicant]
Potdar, S., “The Curious Case of False Positives in Application Security”, Security Zone, May 13, 2019, 4 pages. [cited by applicant]
QwietAI “ShiftLeft Achieves Highest Ever SAST Score on OWASP Benchmark”, Nov. 1, 2023, 7 pages, retrieved from https://qwiet.ai/news-press/shiftleft-achieves-highest-ever-sast-score-on-owasp-benchmark/. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2023/060379, mailed on Apr. 19, 2023, 15 pages. [cited by applicant]
Yang Ji, “Efficient and refinable attack investigation,” A Dissertation Presented to The Academic Faculty, Georgia Institute of Technology, Dec. 2019, pp. 123. [cited by applicant]