IP Library Granted Patent US 8,196,176
Granted Patent B2
US 8,196,176 · App. 12/104,102 · Granted Jun 5, 2012

System and method for identifying a cookie as a privacy threat

Assignee: CA, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,196,176
App. No.
12/104,102
Granted
Jun 5, 2012
Kind
B2
Abstract

A system and method for identifying a cookie as a privacy threat is disclosed. The system and method include receiving a request to install a cookie. A privacy policy associated with the cookie is also received, and that privacy policy may be evaluated against a set of predefined criteria. Based on this evaluation, the cookie may be determined to be a privacy threat.

Claims (56)

1. A method for automatically identifying a cookie as a privacy threat, comprising:

receiving a request to install a cookie;

receiving a privacy policy associated with the cookie;

evaluating, using a processor, one or more tags of the privacy policy against a set of predefined criteria, wherein evaluating the one or more tags comprises classifying the one or more tags of the privacy policy into a plurality of types selected from the group consisting of required tags, mitigating tags, potentially failing tags, user interpreted tags, and automatically failing tags; and

determining that the cookie is a privacy threat based on the evaluation of the privacy policy.

2. The method of claim 1 , wherein the privacy policy comprises a compact Platform for Privacy Preferences (“P3P”) policy associated with the cookie.

3. The method of claim 2 , further comprising determining whether the compact Platform for Privacy Preferences (“P3P”) policy is well formed.

4. The method of claim 1 , wherein receiving the request comprises receiving the request from a third-party, and the cookie comprises a third-party cookie.

5. The method of claim 1 , further comprising contacting a set of predefined websites.

6. The method of claim 1 , wherein determining that the cookie is a privacy threat further comprises determining that a required tag is not included in the privacy policy.

7. The method of claim 1 , wherein determining that the cookie is a privacy threat further comprises determining that an automatically failing tag is included in the privacy policy.

8. The method of claim 1 , wherein determining that the cookie is a privacy threat further comprises determining that a potentially failing tag is present in the privacy policy and determining that a mitigating tag is not included in the privacy policy.

9. The method of claim 1 , further comprising collecting in a signature file a plurality of domain names associated with a corresponding plurality of cookies, each cookie of the plurality of cookies determined to be a privacy threat.

10. The method of claim 1 , wherein evaluating the privacy policy further comprises parsing the privacy policy into a first element and a second element.

11. The method of claim 10 , wherein evaluating the privacy policy further comprises classifying the first element as an automatically failing element; and

wherein determining that the cookie is a privacy threat is further based on the classification of the first element.

12. The method of claim 10 , wherein evaluating the privacy policy further comprises classifying the first element as a potentially failing element, and determining that a mitigating element is not included in the privacy policy; and

wherein determining that the cookie is a privacy threat is further based on the classification of the first element and the determination that the mitigating element is not included in the privacy policy.

13. Logic encoded in tangible, non-transitory computer-readable storage media and when executed on a processor operable to perform operations comprising:

receiving a request to install a cookie;

receiving a privacy policy associated with the cookie;

evaluating one or more tags of the privacy policy against a set of predefined criteria, wherein evaluating the one or more tags comprises classifying the one or more tags of the privacy policy into a plurality of types selected from the group consisting of required tags, mitigating tags, potentially failing tags, user interpreted tags, and automatically failing tags; and

determining that the cookie is a privacy threat based on the evaluation of the privacy policy.

14. The logic encoded in tangible, non-transitory computer-readable storage media of claim 13 , wherein the privacy policy comprises a compact Platform for Privacy Preferences (“P3P”) policy associated with the cookie.

15. The logic encoded in tangible, non-transitory computer-readable storage media of claim 14 , further operable to determine whether the compact Platform for Privacy Preferences (“P3P”) policy is well formed.

16. The logic encoded in tangible, non-transitory computer-readable storage media of claim 13 , wherein receiving the request comprises receiving the request from a third-party, and the cookie comprises a third-party cookie.

17. The logic encoded in tangible, non-transitory computer-readable storage media of claim 13 , further operable to contact a set of predefined websites.

18. The logic encoded in tangible, non-transitory computer-readable storage media of claim 13 , wherein determining that the cookie is a privacy threat further comprises determining that a required tag is not included in the privacy policy.

19. The logic encoded in tangible, non-transitory computer-readable storage media of claim 13 , wherein determining that the cookie is a privacy threat further comprises determining that an automatically failing tag is included in the privacy policy.

20. The logic encoded in tangible, non-transitory computer-readable storage media of claim 13 , wherein determining that the cookie is a privacy threat further comprises determining that a potentially failing tag is present in the privacy policy and determining that a mitigating tag is not included in the privacy policy.

21. The logic encoded in tangible, non-transitory computer-readable storage media of claim 13 , further comprising collecting in a signature file a plurality of domain names associated with a corresponding plurality of cookies, each cookie of the plurality of cookies determined to be a privacy threat.

22. The logic encoded in tangible, non-transitory computer-readable storage media of claim 13 , wherein evaluating the privacy policy further comprises parsing the privacy policy into a first element and a second element.

23. The logic encoded in tangible, non-transitory computer-readable storage media of claim 22 , wherein evaluating the privacy policy further comprises classifying the first element as an automatically failing element; and

wherein determining that the cookie is a privacy threat is further based on the classification of the first element.

24. The logic encoded in tangible, non-transitory computer-readable storage media of claim 22 , wherein evaluating the privacy policy further comprises classifying the first element as a potentially failing element, and determining that a mitigating element is not included in the privacy policy; and

wherein determining that the cookie is a privacy threat is further based on the classification of the first element and the determination that the mitigating element is not included in the privacy policy.

25. A system, comprising:

an interface operable to perform operations comprising:

receiving a request to install a cookie;

receiving a privacy policy associated with the cookie; and

a processor coupled to the interface being operable to perform operations comprising:

evaluating one or more tags of the privacy policy against a set of predefined criteria, wherein evaluating the one or more tags comprises classifying the one or more tags of the privacy policy into a plurality of types selected from the group consisting of required tags, mitigating tags, potentially failing tags, user interpreted tags, and automatically failing tags; and

determining that the cookie is a privacy threat based on the evaluation of the privacy policy.

26. The system of claim 25 , wherein the privacy policy comprises compact Platform for Privacy Preferences (“P3P”) policy associated with the cookie.

27. The system of claim 26 , wherein the processor is further operable to determine whether the compact Platform for Privacy Preferences (“P3P”) policy is well formed.

28. The system of claim 25 , wherein receiving the request comprises receiving the request from a third-party, and the cookie comprises a third-party cookie.

29. The system of claim 25 , wherein the processor is further operable to contact a set of predefined websites.

30. The system of claim 25 , wherein determining that the cookie is a privacy threat further comprises determining that a required tag is not included in the privacy policy.

31. The system of claim 25 , wherein determining that the cookie is a privacy threat further comprises determining that an automatically failing tag is included in the privacy policy.

32. The system of claim 25 , wherein determining that the cookie is a privacy threat further comprises determining that a potentially failing tag is present in the privacy policy and determining that a mitigating tag is not included in the privacy policy.

33. The system of claim 25 , further comprising collecting in a signature file a plurality of domain names associated with a corresponding plurality of cookies, each cookie of the plurality of cookies determined to be a privacy threat.

34. The system of claim 25 , wherein evaluating the privacy policy further comprises parsing the privacy policy into a first element and a second element.

35. The system of claim 34 , wherein evaluating the privacy policy further comprises classifying the first element as an automatically failing element; and

wherein determining that the cookie is a privacy threat is further based on the classification of the first element.

36. The system of claim 34 , wherein evaluating the privacy policy further comprises classifying the first element as a potentially failing element, and determining that a mitigating element is not included in the privacy policy; and

wherein determining that the cookie is a privacy threat is further based on the classification of the first element and the determination that the mitigating element is not included in the privacy policy.

Assignments (2)
MERGER Recorded May 9, 2012
From: COMPUTER ASSOCIATES THINK, INC.
To: CA, INC.
Reel/Frame 028182/0452 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2008
From: BERTEAU, STEFAN A.; GRUCZ, MICHAEL L.; GOLDSMITH, KEVIN C.
To: COMPUTER ASSOCIATES THINK, INC.
Reel/Frame 020813/0104 →
Continuity (2)
Provisional Application 60912590 · Apr 18, 2007
Related Publication 20080263627A1 · Oct 23, 2008