Methods for detecting malicious smart bots to improve network security and devices thereof

US10270792B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-10270792-B1
Application numberUS-201715404852-A
CountryUS
Kind codeB1
Filing dateJan 12, 2017
Priority dateJan 21, 2016
Publication dateApr 23, 2019
Grant dateApr 23, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods, non-transitory computer readable media, security management apparatuses, and network traffic management systems that send a web page to a client device in response to a received request for a web resource. The web page comprises injected capability analysis client-side code that is configured to obtain and return capability data for a web browser identified in a user agent header of the request. A response comprising the returned capability data is received and the returned capability data is compared with expected capability data for the web browser identified in the user agent header of the request. A score is generated based at least in part on the comparison and a determination is made when the score exceeds an established threshold. The web resource is retrieved and provided to the client device, when the determining indicates that the score exceeds the established threshold.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for detecting malicious smart bots to improve network security implemented by a network traffic management system comprising one or more security management apparatuses, server devices, or client devices, the method comprising: sending a web page to a client in response to a request for a web resource received from the client, wherein the web page comprises injected capability analysis client-side code that is configured to obtain and return capability data for a web browser identified in a user agent header of the request; receiving a response from the client, the response comprising the returned capability data, and comparing capabilities of the web browser indicated in the returned capability data with stored expected capabilities of the web browser; generating a score based at least in part on the comparison and determining when the score exceeds an established threshold; and retrieving the web resource and providing the web resource to the client, when the determining indicates that the score exceeds the established threshold. 2. The method of claim 1 , further comprising blocking the request or performing a security check on the client, when the determining indicates that the score does not exceed the established threshold. 3. The method of claim 1 , further comprising: determining when the request comprises an encrypted cookie and, when the determining indicates that the request comprises the encrypted cookie, determining when the encrypted cookie is valid; retrieving and providing the web resource to the client without sending the web page to the client, receiving the response, generating the score, or determining when the score exceeds the established threshold, when the determining indicates that the encrypted cookie is valid; and generating the encrypted cookie and providing the encrypted cookie to the client along with the web resource, when the determining indicates that the request does not comprise the encrypted cookie. 4. The method of claim 1 , wherein the score is generated based on a number or weight of matches between the capabilities of the web browser indicated in the returned capability data and the stored expected capabilities and the weight is based on a likelihood that one of the capabilities is associated with a malicious smart bot. 5. The method of claim 1 , further comprising sending an indication of the web resource along with the web page to the client, wherein the response further comprises the indication of the web resource and the web resource is retrieved using the indication of the web resource included in the response. 6. A security management apparatus, comprising memory comprising programmed instructions stored thereon and one or more processors configured to be capable of executing the stored programmed instructions to: send a web page to a client in response to a request for a web resource received from the client, wherein the web page comprises injected capability analysis client-side code that is configured to obtain and return capability data for a web browser identified in a user agent header of the request; receive a response from the client, the response comprising the returned capability data, and comparing capabilities of the web browser indicated in the returned capability data with stored expected capabilities of the web browser; generate a score based at least in part on the comparison and determine when the score exceeds an established threshold; and retrieve the web resource and provide the web resource to the client, when the determining indicates that the score exceeds the established threshold. 7. The security management apparatus of claim 6 , wherein the one or more processors are further configured to be capable of executing the stored programmed instructions to block the request or perform a security check on the client, when the determining indicates that the score does not exceed the established threshold. 8. The security management apparatus of claim 6 , wherein the one or more processors are further configured to be capable of executing the stored programmed instructions to: determine when the request comprises an encrypted cookie and, when the determining indicates that the request comprises the encrypted cookie, determine when the encrypted cookie valid; retrieve and provide the web resource to the client without sending the web page to the client, receiving the response, generating the score, or determining when the score exceeds the established threshold, when the determining indicates that the encrypted cookie is valid; and generate the encrypted cookie and provide the encrypted cookie to the client along with the web resource, when the determining indicates that the request does not comprise the encrypted cookie. 9. The security management apparatus of claim 6 , wherein the score is generated based on a number or weight of matches between the capabilities of the web browser indicated in the returned capability data and the stored expected capabilities and the weight is based on a likelihood that one of the capabilities is associated with a malicious smart bot. 10. The security management apparatus of claim 6 , wherein the one or more processors are further configured to be capable of executing the stored programmed instructions to send an indication of the web resource along with the web page to the client, wherein the response further comprises the indication of the web resource and the web resource is retrieved using the indication of the web resource included in the response. 11. A non-transitory computer readable medium having stored thereon instructions for detecting malicious smart bots to improve network security comprising executable code which when executed by one or more processors, causes the processors to: send a web page to a client in response to a request for a web resource received from the client, wherein the web page comprises injected capability analysis client-side code that is configured to obtain and return capability data for a web browser identified in a user agent header of the request; receive a response from the client, the response comprising the returned capability data, and comparing capabilities of the web browser indicated in the returned capability data with stored expected capabilities of the web browser; generate a score based at least in part on the comparison and determine when the score exceeds an established threshold; and retrieve the web resource and provide the web resource to the client, when the determining indicates that the score exceeds the established threshold. 12. The non-transitory computer readable medium of claim 11 , wherein the executable code, when executed by the one or more processors, further causes the one or more processors to block the request or perform a security check on the client, when the determining indicates that the score does not exceed the established threshold. 13. The non-transitory computer readable medium of claim 11 , wherein the executable code, when executed by the one or more processors, further causes the one or more processors to: determine when the request comprises an encrypted cookie and, when the determining indicates that the request comprises the encrypted cookie, determine when the encrypted cookie valid; retrieve and provide the web resource to the client without sending the web page to the client, receiving the response, generating the score, or determining when the score exceeds the established threshold, when the determining indicates that the encrypted cookie is valid; and generate the encrypted cookie and provide the encrypted cookie to the client al

Assignees

Inventors

Classifications

  • wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title

  • for controlling access to devices or network resources · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title

  • Vulnerability analysis · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10270792B1 cover?
Methods, non-transitory computer readable media, security management apparatuses, and network traffic management systems that send a web page to a client device in response to a received request for a web resource. The web page comprises injected capability analysis client-side code that is configured to obtain and return capability data for a web browser identified in a user agent header of th…
Who is the assignee on this patent?
F5 Networks Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1425. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 23 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 9 related publications on this page (citations in our corpus or others sharing the same primary CPC).