IP Library › Granted Patent US 12,500,935
Granted Patent B2
US 12,500,935 · App. 18/066,842 · Granted Dec 16, 2025

Multi-layer browser-based context emulation detection

Inventors: Itamar Azulay (Mishmar Ayalon, IL); Nitzan Frogel (Tel Aviv, IL); Meir Baruch Blachman (Beer-Sheva, IL); Tomer Cherni (Gany Tikva, IL)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
H04L63/20H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,500,935
App. No.
18/066,842
Filed
Dec 15, 2022
Granted
Dec 16, 2025
Kind
B2
Art Unit
2432
USPC
726/1
Abstract

Methods, systems and computer program products are provided for multi-layer, browser-based context emulation detection, which may be implemented by a proxy for browsers. A policy may be enforced against requests if a request context indicates a restricted context. Context may be detected and indicated in a response header and body based on one or more context detection/indication rules. Context may be indicated by marking or not marking resources indicated in responses. Code may be injected to cause the client web browser to indicate context. A response may be forwarded to the client with a response header context, a response body context, and/or injected code, which a client browser may process to generate a request with one or more indications of request context.

Claims (78)

1 . A computing device that includes a proxy server, the proxy server comprising:

a processor; and

a memory device that stores program code structured to cause the processor to:

receive a request associated with a client web browser, the request comprising a request header and a request body;

receive a response associated with a web server, the response comprising a response header and a response body, the response header indicating a response header context and the response body indicating a response body context;

inspect the response header for the response header context;

inspect the response body for the response body context;

determine, based at least on context detection rules, whether to mark the response header to indicate the response header context;

determine, based at least on the context detection rules, whether to mark the response body to indicate the response body context; and

forward to the client a response indicating at least one of the response header context or the response body context.

2 . The computing device of claim 1 ,

wherein at least one of the response header context or the response body context indicates the restricted context; and

wherein at least one of the response header context or the response body context indicates an unrestricted context.

3 . The computing device of claim 2 ,

wherein the restricted context indicates a download action; and

wherein the unrestricted context indicates a webpage rendering resource.

4 . The computing device of claim 2 ,

wherein the unrestricted context in the response header context indicates whether a navigation response header in the response corresponds to a navigate resource; and

wherein the unrestricted context in the response body context indicates whether resource indicators in the response correspond to hypertext markup language (HTML) resources, JavaScript resources, style sheet resources, or image resources.

5 . The computing device of claim 1 , wherein the request is created based at least on the forwarded response.

6 . The computing device of claim 1 , wherein the program code is further structured to cause the processor to:

inspect the request header for an indication of a request context;

enforce a policy against the request in response to a determination the indication of the request context indicates a restricted context; and

inject code into the forwarded response, wherein the injected code is configured to cause the client web browser to mark the request with at least a portion of the request context.

7 . The computing device of claim 6 , wherein the injected code is configured to cause the client web browser to mark the request with at least a portion of the request context for dynamically generated request content.

8 . The computing device of claim 6 , wherein the injected code is configured to cause the client web browser to mark the request with at least a portion of the request context in response to a determination the request is captured by a client-side service worker.

9 . The computing device of claim 1 , wherein the program code is further structured to cause the processor to:

inspect the request header for an indication of a request context;

enforce a policy against the request in response to a determination the indication of the request context indicates a restricted context;

receive a plurality of requests associated with a plurality of client web browsers, including the request, where the request comprises a fetch metadata request header and at least one of the other plurality of requests does not comprise a fetch metadata request header; and

map an indication in the fetch metadata request header to the restricted context or to an unrestricted context.

10 . The computing device of claim 1 , wherein the client is an unmanaged client.

11 . A computer-implemented method comprising:

receiving a request associated with a client web browser, the request comprising a request header and a request body;

receiving a response associated with a web server, the response comprising a response header and a response body, the response header indicating a response header context and the response body indicating a response body context;

inspecting the response header for the response header context;

inspecting the response body for the response body context;

determining based at least on context detection rules whether to:

mark the response header to indicate the response header context;

mark the response body to indicate the response body context; or

inject code into the response, wherein the injected code is configured to cause the client web browser to mark the request with at least a portion of the request context; and

forwarding to the client a response indicating at least one of the response header context, the response body context, or including the injected code.

12 . The computer-implemented method of claim 11 ,

wherein at least one of the response header context or the response body context indicates, by marking or not marking, a download action; and

wherein at least one of the response header context or the response body context indicates, by marking or not marking, a webpage rendering resource.

13 . The computer-implemented method of claim 11 ,

wherein the header context indicates whether a navigation response header in the response corresponds to a navigate resource; and

wherein the response body context indicates whether resource indicators in the response correspond to hypertext markup language (HTML) resources, JavaScript resources, style sheet resources, or image resources.

14 . The computer-implemented method of claim 11 , further comprising:

inspecting the request header for an indication of a request context; and

enforcing a policy against the request in response to a determination the indication of the request context indicates a restricted context;

wherein the injected code is configured to cause the client web browser to mark the request with at least a portion of the request context for dynamically generated request content.

15 . The computer-implemented method of claim 11 , further comprising:

inspecting the request header for an indication of a request context; and

enforcing a policy against the request in response to a determination the indication of the request context indicates a restricted context;

wherein the injected code is configured to cause the client web browser to mark the request with at least a portion of the request context in response to a determination the request is captured by a client-side service worker.

16 . The computer-implemented method of claim 11 , further comprising:

inspecting the request header for an indication of a request context;

enforcing a policy against the request in response to a determination the indication of the request context indicates a restricted context;

receiving a plurality of requests associated with a plurality of client web browsers, including the request, where the request comprises a fetch metadata request header and at least one of the other plurality of requests does not comprise a fetch metadata request header; and

mapping an indication in the fetch metadata request header to the restricted context or to an unrestricted context.

17 . A computer-readable storage medium having program instructions recorded thereon that, when executed by a processing circuit, perform a method comprising:

receiving a request associated with a client web browser, the request comprising a request header and a request body;

inspecting the request header for an indication of a request context;

enforcing a policy against the request in response to a determination the indication of the request context indicates a restricted context;

receiving a response associated with a web server, the response comprising a response header and a response body, the response header indicating a response header context and the response body indicating a response body context;

inspecting the response header for the response header context;

inspecting the response body for the response body context;

determining based at least on context detection rules to inject code into a forwarded response, wherein the injected code is configured to cause the client web browser to mark the request with at least a portion of the request context; and

forwarding to the client a response indicating the injected code.

18 . The computer-readable storage medium of claim 17 ,

wherein at least one of the response header context or the response body context indicates, by marking or not marking, a download action; and

wherein at least one of the response header context or the response body context indicates, by marking or not marking, a webpage rendering resource.

19 . The computer-readable storage medium of claim 17 ,

wherein the header context indicates whether a navigation response header in the response corresponds to a navigate resource; and

wherein the response body context indicates whether resource indicators in the response correspond to hypertext markup language (HTML) resources, JavaScript resources, style sheet resources, or image resources.

20 . The computer-readable storage medium of claim 17 , the method further comprising:

receiving a plurality of requests associated with a plurality of client web browsers, including the request, where the request comprises a fetch metadata request header and at least one of the other plurality of requests does not comprise a fetch metadata request header; and mapping an indication in the fetch metadata request header to the restricted context or to an unrestricted context.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2022
From: AZULAY, ITAMAR; BLACHMAN, MEIR BARUCH; CHERNI, TOMER; FROGEL, NITZAN
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 062180/0566 →
Continuity (1)
Related Publication 20240205265A1 · Jun 20, 2024
References Cited (31)
US 9268958B1 · Kessler · 2016 [cited by applicant]
US 10216857B2 · Perret · 2019 [cited by applicant]
US 10860351B1 · Lewin et al. · 2020 [cited by applicant]
US 11019101B2 · Narayanaswamy et al. · 2021 [cited by applicant]
US 11425569B2 · Akkad et al. · 2022 [cited by applicant]
US 11811829B2 · Agarwal · 2023 [cited by examiner]
US 20070220599A1 · Moen · 2007 [cited by examiner]
US 20140317489A1 · Lal et al. · 2014 [cited by applicant]
US 20170264619A1 · Narayanaswamy et al. · 2017 [cited by applicant]
US 20180096203A1 · King et al. · 2018 [cited by applicant]
US 20200236102A1 · Azulay · 2020 [cited by examiner]
US 20200358786A1 · Bergbom · 2020 [cited by examiner]
“Content Security Policy”, Retrieved From: https://web.archive.org/web/20161003202457/https://csp.withgoogle.com/docs/index.html, Retrieved Date: Oct. 3, 2016, 2 Pages. [cited by applicant]
“Fetch Metadata Request Headers”, Retrieved From: https://w3c.github.io/webappsec-fetch-metadata/, Jul. 20, 2021, 16 Pages. [cited by applicant]
“Fetch Metadata Request Headers”, Retrieved From: https://web.archive.org/web/20201028045104/https://secmetadata.appspot.com/, Retrieved Date: Oct. 28, 2020, 1 Page. [cited by applicant]
“Sec-Fetch-Dest”, Retrieved From: https://http.dev/sec-fetch-dest, Jun. 20, 2022, 10 Pages. [cited by applicant]
Andrew, et al., “url()”, Retrieved From: https://developer.mozilla.org/en-US/docs/Web/CSS/url, Sep. 27, 2022, 4 Pages. [cited by applicant]
Anforowicz, Lukasz, “Sec-Fetch-Dest is not trustworthy #10”, Retrieved From: https://github.com/w3c/webappsec-fetch-metadata/issues/10, Jan. 16, 2019, 3 Pages. [cited by applicant]
Aquariuslt, et al., “FetchEvent.respondWith()”, Retrieved From: https://developer.mozilla.org/en-US/docs/Web/API/FetchEvent/respondWith, Sep. 13, 2022, 3 Pages. [cited by applicant]
Barua, et al., “Server Side Detection of Content Sniffing Attacks”, In Proceedings of IEEE 22nd International Symposium on Software Reliability Engineering., Nov. 29, 2011, pp. 20-29. [cited by applicant]
Evans, Chris, “Generic cross-browser cross-domain theft”, Retrieved From: https://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.html, Dec. 28, 2009, 6 Pages. [cited by applicant]
Janc, et al., “Securing web apps with modern platform features”, Retrieved From: https://webappsec.dev/assets/pub/Google_IO-Securing_Web_Apps_with_Modern_Platform_Features.pdf, 2019, 60 Pages. [cited by applicant]
Kesteren, Annev. , “Is Sec-Fetch-Dest necessary? #16”, Retrieved From: https://github.com/w3c/webappsec-fetch-metadata/issues/16, Mar. 9, 2019, 10 Pages. [cited by applicant]
Rahman, et al., “Fetch metadata request header”, Retrieved From: https://developer.mozilla.org/en-US/docs/Glossary/Fetch_metadata_request_header, Sep. 21, 2022, 2 Pages. [cited by applicant]
Timothygu, et al., “Sec-Fetch-Dest”, Retrieved From: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Sec-Fetch-Dest, Sep. 9, 2022, 4 Pages. [cited by applicant]
Weichselbaum, Lukas, “Protect your resources from web attacks with Fetch Metadata”, Retrieved From: https://web.dev/fetch-metadata/, Jun. 4, 2020, 12 Pages. [cited by applicant]
Wulf, Pierred. , “How to Use a Proxy With Node-Fetch?”, Retrieved From: https://www.scrapingbee.com/blog/proxy-node-fetch/, Nov. 9, 2020, 10 Pages. [cited by applicant]
“HTTP headers—HTTP I MDN,” Retrieved from the Internet: URL: https://web.archive.org/web/20221210232449/https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers, Dec. 10, 2022, 21 Pages. [cited by applicant]
“Policy Enforcement with Proxy Applications,” Retrieved from the Internet: URL: https://docs.tibco.com/pub/policydirector/1.0.1/doc/html/GUIDB940BB42-BC2D-4BE5-BE90-D46495856C90.html, May 22, 2014, 01 Page. [cited by applicant]
International Search Report and Written Opinion received for PCT Application No. PCT/US23/081055, Feb. 23, 2024, 12 pages. [cited by applicant]
International Preliminary Report on Patentability (Chapter I) received for PCT Application No. PCT/US23/081055, mailed on Jun. 26, 2025, 9 Pages. [cited by applicant]