IP Library › Granted Patent US 12,603,918
Granted Patent B2
US 12,603,918 · App. 18/477,658 · Granted Apr 14, 2026

Security system for detecting malicious actor's observation

Inventors: Paul Melson (Minneapolis, MN); Chris Carlson (Minneapolis, MN); Eric Brandel (Minneapolis, MN); Caleb Walch (Minneapolis, MN)
Assignee: Target Brands, Inc.
H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,603,918
App. No.
18/477,658
Granted
Apr 14, 2026
Kind
B2
Abstract

A website vulnerability test is performed by automatically checking that a website has not been compromised by malicious third party scripts. A system can test a dynamic behavior of a website that indicates a functional user flow through the website. A set of rules are applied against a log of dynamic behavior of the website, as well as static code of the website, to identify potential compromise by malicious scripts. Some rules can be configured for detecting modification of a third party script, or modified behavior of a third party script, in an attempt to detect security monitoring activity against the script and hide its presence from the security monitoring activity.

Claims (64)

1 . A method for testing a website vulnerability, the method comprising:

retrieving website code of a website, the website code including a script;

debugging the website code;

searching for an indicator of malicious action during the debugging, wherein searching for the indicator of malicious action during the debugging comprises identifying that one or more messages are modified in a console log;

determining presence of a potential malicious script based on the indicator; and

returning an alert of the presence of the potential malicious script in the website.

2 . The method of claim 1 , wherein retrieving the website code includes retrieving the website code on a browser, the method further comprising:

running a code evaluation tool on the browser.

3 . The method of claim 1 , wherein the indicator is indicative of binding events to timing events.

4 . The method of claim 1 , wherein the indicator is indicative of accessing event calls for timing-related functions.

5 . The method of claim 1 , wherein the indicator is indicative of binding events to start and stop timings of an operation.

6 . The method of claim 1 , wherein based on retrieving the website code of the website, the method further comprises:

simulating a functional user flow on the website;

recording dynamic behavior of the website during simulation of the functional user flow;

retrieving malicious actor detection rules;

applying the retrieved rules to the recorded dynamic behavior of the website; and

detecting, based on applying the retrieved rules, the presence of the potential malicious script in the website.

7 . The method of claim 6 , wherein simulating the functional user flow on the website comprises:

applying a website test wrapper to the website code including the script; and

automatically executing, based on applying the wrapper to the website code including the script, an automation script that provides simulated user inputs to interact with the website.

8 . The method of claim 7 , further comprising:

generating, by the wrapper, a dynamic website log that records behavior of the website in response to the simulated user inputs provided by the automation script.

9 . The method of claim 1 , wherein searching for the indicator of malicious action during the debugging comprises detecting that a browser for the website is operating slower than an expected speed.

10 . The method of claim 1 , wherein searching for the indicator of malicious action during the debugging comprises detecting an unexpected crash of a browser for the website.

11 . The method of claim 1 , further comprising:

aggregating the indicator with a plurality of indicators; and

transmitting the aggregated indicators to a computing device of a security analyst.

12 . A client computing device for testing a website vulnerability, comprising:

a data processing apparatus; and

a memory device storing instructions that when executed by the data processing apparatus cause the client computing device to perform operations comprising:

retrieving website code of a website on a browser, the website code including a script;

running a code evaluation tool on the browser;

debugging the website code;

searching for an indicator of malicious action during the debugging;

determining presence of a potential malicious script based on the indicator; and

returning an alert of the presence of the potential malicious script in the website.

13 . The client computing device of claim 12 , wherein the indicator is indicative of at least one of:

binding events to timing events;

accessing event calls for timing-related functions; or

binding events to start and stop timings of an operation.

14 . The client computing device of claim 12 , wherein searching for the indicator of malicious action during the debugging comprises identifying that one or more messages are removed from a console log.

15 . The client computing device of claim 12 , wherein based on retrieving the website code of the website, the operations further comprising:

simulating a functional user flow on the website;

recording dynamic behavior of the website during simulation of the functional user flow;

retrieving malicious actor detection rules;

applying the retrieved rules to the recorded dynamic behavior of the website; and

detecting, based on applying the retrieved rules, the presence of the potential malicious script in the website.

16 . The client computing device of claim 15 , wherein simulating the functional user flow on the website comprises:

applying a website test wrapper to the website code including the script; and

automatically executing, based on applying the wrapper to the website code including the script, an automation script that provides simulated user inputs to interact with the website.

17 . The client computing device of claim 16 , the operations further comprising:

generating, by the wrapper, a dynamic website log that records behavior of the website in response to the simulated user inputs provided by the automation script.

18 . A method for testing a website vulnerability, the method comprising:

retrieving website code of a website, the website code including a script;

debugging the website code;

searching for an indicator of malicious action during the debugging, wherein searching for the indicator of malicious action during the debugging comprises identifying that one or more messages are removed in a console log;

determining presence of a potential malicious script based on the indicator; and

returning an alert of the presence of the potential malicious script in the website.

19 . The method of claim 18 , wherein the indicator is indicative of at least one of:

binding events to timing events;

accessing event calls for timing-related functions; or

binding events to start and stop timings of an operation.

20 . The method of claim 18 , wherein retrieving the website code includes retrieving the website code on a browser, the method further comprising:

running a code evaluation tool on the browser.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2023
From: MELSON, PAUL; CARLSON, CHRIS; BRANDEL, ERIC; WALCH, CALEB
To: TARGET BRANDS, INC.
Reel/Frame 065074/0354 →
Continuity (3)
Continuation 17341589 · Jun 8, 2021
Provisional Application 63036204 · Jun 8, 2020
Related Publication 20240022603A1 · Jan 18, 2024
References Cited (62)
US 8176556B1 · Farrokh · 2012 [cited by examiner]
US 8499283B2 · Mony · 2013 [cited by applicant]
US 8789178B2 · Kejriwal et al. · 2014 [cited by applicant]
US 8806646B1 · Daswani · 2014 [cited by examiner]
US 8850570B1 · Ramzan · 2014 [cited by examiner]
US 8984632B1 · Laffoon · 2015 [cited by examiner]
US 9009834B1 · Ren et al. · 2015 [cited by applicant]
US 9038184B1 · Mann · 2015 [cited by examiner]
US 9154364B1 · Daswani et al. · 2015 [cited by applicant]
US 9178904B1 · Gangadharan · 2015 [cited by examiner]
US 9367415B1 · Lachwani et al. · 2016 [cited by applicant]
US 9398032B1 · Wan · 2016 [cited by examiner]
US 9923916B1 · McClintock · 2018 [cited by examiner]
US 10140451B2 · Xu et al. · 2018 [cited by applicant]
US 10586045B2 · Pyles et al. · 2020 [cited by applicant]
US 10880322B1 · Jakobsson et al. · 2020 [cited by applicant]
US 11019096B2 · Takata · 2021 [cited by examiner]
US 11082438B2 · Peinador et al. · 2021 [cited by applicant]
US 11089055B1 · Sadovyi · 2021 [cited by examiner]
US 11444970B2 · Melson · 2022 [cited by examiner]
US 11451565B2 · Zhou et al. · 2022 [cited by applicant]
US 11595436B2 · Melson · 2023 [cited by examiner]
US 11704386B2 · Suzani et al. · 2023 [cited by applicant]
US 11811824B2 · Melson · 2023 [cited by examiner]
US 20070174915A1 · Gribble et al. · 2007 [cited by applicant]
US 20100186088A1 · Banerjee · 2010 [cited by examiner]
US 20110239294A1 · Kim · 2011 [cited by examiner]
US 20110283356A1 · Fly · 2011 [cited by examiner]
US 20110296244A1 · Fu · 2011 [cited by examiner]
US 20130263272A1 · Banerjee · 2013 [cited by examiner]
US 20130275951A1 · Dolby et al. · 2013 [cited by applicant]
US 20140143872A1 · Lee · 2014 [cited by examiner]
US 20140373087A1 · Ciu · 2014 [cited by examiner]
US 20160088015A1 · Sivan · 2016 [cited by examiner]
US 20170195353A1 · Taylor et al. · 2017 [cited by applicant]
US 20180069880A1 · Kupreev · 2018 [cited by examiner]
US 20180077184A1 · Thom · 2018 [cited by examiner]
US 20180103047A1 · Turgeman et al. · 2018 [cited by applicant]
US 20180191777A1 · Volkov · 2018 [cited by examiner]
US 20180198807A1 · Johns et al. · 2018 [cited by applicant]
US 20180239821A1 · Summers, II · 2018 [cited by examiner]
US 20190028497A1 · Karabchevsky et al. · 2019 [cited by applicant]
US 20190042736A1 · Krebs · 2019 [cited by examiner]
US 20190156039A1 · Harsany et al. · 2019 [cited by applicant]
US 20190158535A1 · Kedem et al. · 2019 [cited by applicant]
US 20190163905A1 · Woodworth · 2019 [cited by examiner]
US 20190311132A1 · Arnoth et al. · 2019 [cited by applicant]
US 20190342328A1 · Rivner et al. · 2019 [cited by applicant]
US 20200014702A1 · Dasgupta · 2020 [cited by examiner]
US 20200076840A1 · Peinador et al. · 2020 [cited by applicant]
US 20200195694A1 · Kalinin · 2020 [cited by examiner]
US 20200293592A1 · Kumar · 2020 [cited by examiner]
US 20200356661A1 · Stoletny · 2020 [cited by examiner]
US 20210075826A1 · Johnson · 2021 [cited by examiner]
US 20210092146A1 · Melson · 2021 [cited by examiner]
US 20210194921A1 · Guajardo Merchan · 2021 [cited by examiner]
US 20210314353A1 · Melson · 2021 [cited by examiner]
US 20210344661A1 · Krylov · 2021 [cited by examiner]
US 20210385245A1 · Melson · 2021 [cited by examiner]
US 20220030029A1 · Kagan · 2022 [cited by examiner]
US 20220247773A1 · Caithness · 2022 [cited by examiner]
US 20240022603A1 · Melson · 2024 [cited by examiner]