IP Library Granted Patent US 12,688,293
Granted Patent B2
US 12,688,293 · App. 19/032,097 · Granted Jul 21, 2026

Proactive browser content analysis

Inventors: Joe Jaroch (Elk Grove Village, IL); Harry Murphey McCloy, III (Longmont, CO); Robert Edward Adams (Sunnyvale, CA)
Assignee: OPEN TEXT INC.
G06F21/566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,688,293
App. No.
19/032,097
Filed
Jan 19, 2025
Granted
Jul 21, 2026
Kind
B2
Art Unit
2495
USPC
726/23
Abstract

A protection module operates to analyze threats, at the protocol level (e.g., at the HTML level), by intercepting all requests that a browser engine resident in a computing device sends and receives, and the protection agent completes the requests without the help of the browser engine. And then the protection module analyzes and/or modifies the completed data before the browser engine has access to it, to, for example, display it. After performing all of its processing, removing, and/or adding any code as needed, the protection module provides the HTML content to the browser engine, and the browser engine receives responses from the protection agent as if it was speaking to an actual web server, when in fact, browser engine is speaking to an analysis engine of the protection module.

Claims (48)

1 . A malware protection method, comprising:

at a protection agent executing on a client,

receiving, from a web browser, a request for content stored on a server device;

forwarding, over a network, the request for content to the server device;

receiving, over the network, the content from the server device;

assembling a web page based on the received content;

communicating with a security center comprising a malware management component that is configured to perform cloud verification on one or more portions of web page content of the assembled web page;

receiving, over the network from the security center, results of cloud verification regarding a plurality of malware threats;

identifying at least one malware threat in the received content based on the received results of cloud verification; and

regenerating the received content, the regenerating comprising modifying the received content by removing or deactivating the at least one malware threat in the received content; and

forwarding, to the web browser, the modified received content for display.

2 . The method of claim 1 , wherein the server device comprises a web server, and the protection agent forwards the modified received content to the web browser for display.

3 . The method of claim 2 , further comprising annotating, by the protection agent, the modified received content to denote whether a website reference is malicious.

4 . The method of claim 2 , further comprising performing a Uniform Resource Locator analysis; and

performing a JavaScript and Hypertext Markup Language analysis.

5 . The method of claim 4 , further comprising:

aggregating the results of the Uniform Resource Locator analysis and the JavaScript and Hypertext Markup Language.

6 . The method of claim 4 , wherein the Uniform Resource Locator analysis and the JavaScript and Hypertext Markup Language analysis are performed independent from one another.

7 . The method of claim 1 , wherein the at least one malware threat in the received content comprises at least one of: illicit images, advertisements, fake password request forms, malicious exploits, and cross site scripting attacks.

8 . The method of claim 1 , wherein regenerating the received content further comprises supplementing the received content with indicators regarding a vulnerability of one or more links within the received content.

9 . The method of claim 1 , further comprising determining whether the request for content stored on the server device is a first request.

10 . The method of claim 1 , wherein modifying the received content by removing or deactivating the at least one malware threat in the content further comprises performing one or more of pre-process data decryption, de-chunking, and decompressing.

11 . A malware protection system comprising:

at least one processor; and

memory encoding computer executable instructions that, when executed by the at least one processor, perform a method comprising:

at a protection agent executing on a client,

receiving, from a web browser, a request for content stored on a server device;

forwarding, over a network, the request for content to the server device;

receiving, over the network, the content from the server device;

assembling a web page based on the received content;

communicating with a security center comprising a malware management component that is configured to so that the malware management component can perform cloud verification on one or more portions of web page content of the assembled web page;

receiving, over the network from the security center, results of cloud verification regarding a plurality of malware threats;

identifying at least one malware threat in the received content based on the received malware threat information; and

regenerating the received content, the regenerating comprising:

modifying the received content by removing or deactivating the at least one malware threat in the received content; and

forwarding, to the web browser, the modified received content for display.

12 . The system of claim 11 , wherein the server device comprises a web server, and the protection agent forwards the modified received content to the web browser for display.

13 . The system of claim 12 , the system further comprising annotating, by the protection agent, the modified content to denote whether a website reference is malicious.

14 . The system of claim 11 , further comprising:

performing a Uniform Resource Locator analysis; and

performing a JavaScript and Hypertext Markup Language analysis.

15 . The system of claim 14 , further comprising:

aggregating the results of the Uniform Resource Locator analysis and Hypertext Markup Language analysis.

16 . The system of claim 14 , wherein the Uniform Resource Locator analysis and the JavaScript and Hypertext Markup Language analysis are performed independent from one another.

17 . The system of claim 11 , wherein the at least one malware threat in the received content comprises at least one of: illicit images, advertisements, fake password request forms, malicious exploits, and cross site scripting attacks.

18 . The system of claim 11 , wherein regenerating the received content further comprises supplementing the received content with indicators regarding a vulnerability of one or more links within the received content.

19 . The system of claim 11 , the system further comprising determining whether the request for content stored on the server device is a first request.

20 . The system of claim 11 , wherein modifying the received content by removing or deactivating the at least one malware threat in the received content further comprises performing one or more of pre-process data decryption, de-chunking, and decompressing.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2025
From: JAROCH, JOE; MCCLOY, HARRY MURPHEY, III; ADAMS, ROBERT EDWARD
To: WEBROOT INC.
Reel/Frame 070173/0618 →
CERTIFICATE OF CONVERSION Recorded Feb 11, 2025
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 070173/0631 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Feb 11, 2025
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 070173/0800 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Feb 11, 2025
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 070617/0816 →
Continuity (6)
Continuation 18158218 · Jan 23, 2023
Continuation 17221028 · Apr 2, 2021
Continuation 16036022 · Jul 16, 2018
Continuation 13633956 · Oct 3, 2012
Provisional Application 61542693 · Oct 3, 2011
Related Publication 20250165603A1 · May 22, 2025
References Cited (19)
US 7647417B1 · Taneja · 2010 [cited by examiner]
US 8464318B1 · Hallak · 2013 [cited by examiner]
US 12598206B2 · Giffard · 2026 [cited by examiner]
US 20060206936A1 · Liang · 2006 [cited by examiner]
US 20080072325A1 · Repasi · 2008 [cited by examiner]
US 20090249440A1 · Platt · 2009 [cited by examiner]
US 20100100958A1 · Jeremiah · 2010 [cited by examiner]
US 20100228963A1 · Kassab · 2010 [cited by examiner]
US 20110078309A1 · Bloch · 2011 [cited by examiner]
US 20120216133A1 · Barker · 2012 [cited by examiner]
US 20130042294A1 · Colvin · 2013 [cited by examiner]
US 20130305375A1 · Attanasio · 2013 [cited by examiner]
US 20210385243A1 · Ali-Ahmad · 2021 [cited by examiner]
US 20250165603A1 · Jaroch · 2025 [cited by examiner]
Pearce et al., “Development and Evaluation of a Secure Web Gateway Using Existing ICAP Open Source Tools”, School of Computer and Information Science, Edith Cowan University, 8th Australian Information Security Mangemen… [cited by examiner]
Pearce, Michael Bruce. Development and evaluation of a secure web gateway with messaging functionality. Diss. University of Canterbury, 2010, p. 1- 197. (Year: 2010). [cited by examiner]
C. Adrián Martínez, G. Isaza Echeverri and A. G. Castillo Sanz, “Malware detection based on Cloud Computing integrating Intrusion Ontology representation,” 2010 IEEE Latin-American Conference on Communications, Bogota, … [cited by examiner]
Mansoori, Masood, and Ray Hunt. “An ISP Based Notification and Detection System to Maximize Efficiency of Client Honeypots in Protection of End Users.” International Journal of Network Security & Its Applications 3.5 (2… [cited by examiner]
David Scott and Richard Sharp. 2002. Abstracting application-level web security. In Proceedings of the 11th international conference on World Wide Web (WWW '02). Association for Computing Machinery, New York, NY, USA, 3… [cited by examiner]