IP Library › Granted Patent US 12,737,494
Granted Patent B2
US 12,737,494 · App. 18/611,880 · Granted Sep 15, 2026

Systems and methods for detecting man-in-the-middle cybersecurity threats

Inventor: Avihay Cohen (Tel-Aviv, IL)
Assignee: Seraphic Algorithms Ltd.
G06F21/6245G06F16/986G06F21/54G06F21/554H04L63/1425H04L63/1483H04L63/1491G06F2221/033G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,737,494
App. No.
18/611,880
Filed
Mar 21, 2024
Granted
Sep 15, 2026
Kind
B2
Art Unit
2436
USPC
726/23
Abstract

Systems, methods, and computer readable medium are disclosed for performance of cybersecurity operations for detecting a communication discrepancy. Performance of cybersecurity operations for detecting a communication discrepancy includes transmitting at least one first request to an endpoint device; determining a first response time based on the transmitted at least one first request; transmitting at least one second request to the endpoint device; determining a second response time based on the transmitted at least one second request; determining a difference between the first response time and the second response time; and based on the determined difference between the first response time and the second response time, determining whether to implement a remedial action.

Claims (43)

1 . A non-transitory computer readable medium containing instructions that when executed by at least one processor cause the at least one processor to perform cybersecurity operations for detecting a communication discrepancy, the operations comprising:

transmitting at least one first request to an endpoint device;

determining a first response time based on the transmitted at least one first request;

transmitting at least one second request to the endpoint device;

determining a second response time based on the transmitted at least one second request;

determining a difference between the first response time and the second response time; and

based on the determined difference between the first response time and the second response time, determining whether to implement a remedial action, including determining to implement the remedial action when the difference between the first response time and the second response time exceeds a predetermined threshold, wherein the predetermined threshold is uncorrelated with a payload size associated with at least one of the at least one first request or the at least one second request.

2 . The non-transitory computer readable medium of claim 1 , wherein the endpoint device is an intended destination of an electronic communication sent by a client device associated with transmitting at least one of the at least one first request or the at least one second request.

3 . The non-transitory computer readable medium of claim 1 , wherein at least one of the first response time or the second response time is a Time to First Byte (TTFB).

4 . The non-transitory computer readable medium of claim 1 , wherein:

the at least one first request is a plurality of first requests;

the at least one second request is a plurality of second requests;

the first response time is a first metric of response times associated with the plurality of first requests; and

the second response time is a second metric of response times associated with the plurality of second requests.

5 . The non-transitory computer readable medium of claim 4 , wherein the first metric is an average of the response times associated with the plurality of first requests, and the second metric is an average of the response times associated with the plurality of second requests.

6 . The non-transitory computer readable medium of claim 1 , wherein the at least one first request includes a first payload and the at least one second request includes a second payload larger than the first payload.

7 . The non-transitory computer readable medium of claim 1 , wherein the transmission of at least one of the at least one first request or the at least one second request is caused by a cybersecurity web agent.

8 . The non-transitory computer readable medium of claim 7 , wherein the remedial action is implemented at a client device hosting the cybersecurity web agent.

9 . The non-transitory computer readable medium of claim 1 , wherein the remedial action includes issuing a prompt indicating that a connection associated with the at least one first request and the at least one second request is compromised.

10 . The non-transitory computer readable medium of claim 1 , wherein the remedial action includes logging digital information associated with an execution environment associated with a connection to the endpoint device.

11 . The non-transitory computer readable medium of claim 1 , wherein the remedial action includes influencing an execution environment associated with a web browser.

12 . A cybersecurity method for detecting a communication discrepancy, the method comprising:

transmitting at least one first request to an endpoint device;

determining a first response time based on the transmitted at least one first request;

transmitting at least one second request to the endpoint device;

determining a second response time based on the transmitted at least one second request;

determining a difference between the first response time and the second response time; and

based on the determined difference between the first response time and the second response time, determining whether to implement a remedial action, including determining to implement the remedial action when the difference between the first response time and the second response time exceeds a predetermined threshold, wherein the predetermined threshold is uncorrelated with a payload size associated with at least one of the at least one first request or the at least one second request.

13 . The method of claim 12 , wherein at least one of the first response time or the second response time is a Time to First Byte (TTFB).

14 . The method of claim 12 , wherein:

the at least one first request is a plurality of first requests;

the at least one second request is a plurality of second requests;

the first response time is a first metric of response times associated with the plurality of first requests; and

the second response time is a second metric of response times associated with the plurality of second requests.

15 . The method of claim 12 , wherein the at least one first request includes a first payload and the at least one second request includes a second payload larger than the first payload.

16 . A cybersecurity system for detecting a communication discrepancy between two communication parties, the system comprising:

at least one processor configured to:

transmit at least one first request to an endpoint device;

determine a first response time based on the transmitted at least one first request;

transmit at least one second request to the endpoint device;

determine a second response time based on the transmitted at least one second request;

determine a difference between the first response time and the second response time; and

based on the determined difference between the first response time and the second response time, determine whether to implement a remedial action, including determining to implement a remedial action when the difference between the first response time and the second response time exceeds a predetermined threshold, wherein the predetermined threshold is uncorrelated with a payload size associated with at least one of the at least one first request or the at least one second request.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Jun 25, 2026
From: HSBC BANK PLC
To: SERAPHIC ALGORITHMS LTD
Reel/Frame 075079/0275 →
SECURITY INTEREST Recorded May 12, 2025
From: SERAPHIC ALGORITHMS LTD
To: HSBC BANK PLC
Reel/Frame 071088/0637 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2024
From: COHEN, AVIHAY
To: SERAPHIC ALGORITHMS LTD.
Reel/Frame 066853/0575 →
Continuity (3)
Continuation PCTIB2022059418 · Oct 3, 2022
Provisional Application 63251651 · Oct 3, 2021
Related Publication 20240314168A1 · Sep 19, 2024
References Cited (10)
US 10887348B1 · Brandwine · 2021 [cited by examiner]
US 20130346302A1 · Purves et al. · 2013 [cited by applicant]
US 20140188976A1 · Plamondon · 2014 [cited by applicant]
US 20140282464A1 · El-Gillani · 2014 [cited by applicant]
US 20200396249A1 · Shabtai · 2020 [cited by examiner]
US 20210203670A1 · Woodland · 2021 [cited by examiner]
US 20210266344A1 · Soryal · 2021 [cited by examiner]
US 20210350277A1 · Agrawal · 2021 [cited by examiner]
US 20220286494A1 · Zheng · 2022 [cited by examiner]
International Search Report and Written Opinion for International Application No. PCT/IB2022/59418 dated Feb. 8, 2023 (19 pages). [cited by applicant]