Systems and methods for detecting man-in-the-middle cybersecurity threats
Systems, methods, and computer readable medium are disclosed for performance of cybersecurity operations for detecting a communication discrepancy. Performance of cybersecurity operations for detecting a communication discrepancy includes transmitting at least one first request to an endpoint device; determining a first response time based on the transmitted at least one first request; transmitting at least one second request to the endpoint device; determining a second response time based on the transmitted at least one second request; determining a difference between the first response time and the second response time; and based on the determined difference between the first response time and the second response time, determining whether to implement a remedial action.
1 . A non-transitory computer readable medium containing instructions that when executed by at least one processor cause the at least one processor to perform cybersecurity operations for detecting a communication discrepancy, the operations comprising:
transmitting at least one first request to an endpoint device;
determining a first response time based on the transmitted at least one first request;
transmitting at least one second request to the endpoint device;
determining a second response time based on the transmitted at least one second request;
determining a difference between the first response time and the second response time; and
based on the determined difference between the first response time and the second response time, determining whether to implement a remedial action, including determining to implement the remedial action when the difference between the first response time and the second response time exceeds a predetermined threshold, wherein the predetermined threshold is uncorrelated with a payload size associated with at least one of the at least one first request or the at least one second request.
2 . The non-transitory computer readable medium of claim 1 , wherein the endpoint device is an intended destination of an electronic communication sent by a client device associated with transmitting at least one of the at least one first request or the at least one second request.
3 . The non-transitory computer readable medium of claim 1 , wherein at least one of the first response time or the second response time is a Time to First Byte (TTFB).
4 . The non-transitory computer readable medium of claim 1 , wherein:
the at least one first request is a plurality of first requests;
the at least one second request is a plurality of second requests;
the first response time is a first metric of response times associated with the plurality of first requests; and
the second response time is a second metric of response times associated with the plurality of second requests.
5 . The non-transitory computer readable medium of claim 4 , wherein the first metric is an average of the response times associated with the plurality of first requests, and the second metric is an average of the response times associated with the plurality of second requests.
6 . The non-transitory computer readable medium of claim 1 , wherein the at least one first request includes a first payload and the at least one second request includes a second payload larger than the first payload.
7 . The non-transitory computer readable medium of claim 1 , wherein the transmission of at least one of the at least one first request or the at least one second request is caused by a cybersecurity web agent.
8 . The non-transitory computer readable medium of claim 7 , wherein the remedial action is implemented at a client device hosting the cybersecurity web agent.
9 . The non-transitory computer readable medium of claim 1 , wherein the remedial action includes issuing a prompt indicating that a connection associated with the at least one first request and the at least one second request is compromised.
10 . The non-transitory computer readable medium of claim 1 , wherein the remedial action includes logging digital information associated with an execution environment associated with a connection to the endpoint device.
11 . The non-transitory computer readable medium of claim 1 , wherein the remedial action includes influencing an execution environment associated with a web browser.
12 . A cybersecurity method for detecting a communication discrepancy, the method comprising:
transmitting at least one first request to an endpoint device;
determining a first response time based on the transmitted at least one first request;
transmitting at least one second request to the endpoint device;
determining a second response time based on the transmitted at least one second request;
determining a difference between the first response time and the second response time; and
based on the determined difference between the first response time and the second response time, determining whether to implement a remedial action, including determining to implement the remedial action when the difference between the first response time and the second response time exceeds a predetermined threshold, wherein the predetermined threshold is uncorrelated with a payload size associated with at least one of the at least one first request or the at least one second request.
13 . The method of claim 12 , wherein at least one of the first response time or the second response time is a Time to First Byte (TTFB).
14 . The method of claim 12 , wherein:
the at least one first request is a plurality of first requests;
the at least one second request is a plurality of second requests;
the first response time is a first metric of response times associated with the plurality of first requests; and
the second response time is a second metric of response times associated with the plurality of second requests.
15 . The method of claim 12 , wherein the at least one first request includes a first payload and the at least one second request includes a second payload larger than the first payload.
16 . A cybersecurity system for detecting a communication discrepancy between two communication parties, the system comprising:
at least one processor configured to:
transmit at least one first request to an endpoint device;
determine a first response time based on the transmitted at least one first request;
transmit at least one second request to the endpoint device;
determine a second response time based on the transmitted at least one second request;
determine a difference between the first response time and the second response time; and
based on the determined difference between the first response time and the second response time, determine whether to implement a remedial action, including determining to implement a remedial action when the difference between the first response time and the second response time exceeds a predetermined threshold, wherein the predetermined threshold is uncorrelated with a payload size associated with at least one of the at least one first request or the at least one second request.