Detecting changes to web page characteristics using machine learning

US12401686B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12401686-B2
Application numberUS-201816636282-A
CountryUS
Kind codeB2
Filing dateJul 30, 2018
Priority dateAug 2, 2017
Publication dateAug 26, 2025
Grant dateAug 26, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A computer implemented method to detect an anomalous change to a web application, the web application executing with a web server, the method including receiving a first set of records for the web application operating in a training mode of operation, each record including characteristics of a content of a web page for the web application; generating a sparse distributed representation of the set of records to form a training set for a hierarchical temporal memory (HTM); training the HTM based on the training set in order that the trained HTM provides a model of the operation of the web application in the training mode of operation; receiving a second set of records for the web application, each record including characteristics of content of the web page; generating a sparse distributed representation of the second set of records to form an input set for the trained HTM; executing the trained HTM based on the input set to determine a degree of recognition of the records of the input set; and responsive to a determination that a degree of recognition of one or more records of the input set is below a threshold degree, identifying an anomalous change to the web page.

First claim

Opening claim text (preview).

The invention claimed is: 1. A computer implemented method to detect an anomalous change to a configuration of a web application, the web application executing with a web server, the method comprising: receiving a first set of distinct records for the web application operating in a training mode of operation during which the web application is isolated from a wide area network, each record in the first set of distinct records including characteristics of a content of a web page the web application during a training time period; generating a sparse distributed representation of the first set of distinct records to form a training set for a hierarchical temporal memory (HTM); training the HTM based on the training set in order that the trained HTM provides a model of operation of the web application in the training mode of operation, wherein the HTM evaluates an anomaly score for the records in the first set of distinct records and the HTM is trained until the anomaly score meets a predetermined threshold degree of anomaly; receiving a second set of distinct records for the web application, each record in the second set of distinct records including characteristics of the web application during an operational time period, the operational time period being distinct from the training time period; generating a sparse distributed representation of the second set of distinct records to form an input set for the trained HTM; executing the trained HTM based on the input set to determine a degree of recognition of the records of the input set; responsive to a determination that a degree of recognition of one or more records of the input set is below a threshold degree, identifying an anomalous change to the configuration of the web page; and in response to the identification of the anomalous change to the web page, causing a responsive measure to the anomalous change to be implemented that includes one or more of the following actions: interrupting operation of the web application; identifying client components in communication with the web application as potentially compromised; executing at least one of an intrusion detection, malware detection, virus removal, or a malware removal process for the web application; or effecting at least one of a redeployment, a reinstallation, or a reconfiguration of the web application. 2. The method of claim 1 , wherein the characteristics of the web page include records corresponding to hypertext markup language (HTML) tags in the web page. 3. A computer system comprising: a processor and memory storing computer program code for detecting an anomalous change to a configuration of a web application, the web application executing with a web server, by: receiving a first set of distinct records for the web application operating in a training mode of operation during which the web application is isolated from a wide area network, each record in the first set of distinct records including characteristics of a content of a web page for the web application during a training time period; generating a sparse distributed representation of the first set of distinct records to form a training set for a hierarchical temporal memory (HTM); training the HTM based on the training set in order that the trained HTM provides a model of operation of the web application in the training mode of operation, wherein the HTM evaluates an anomaly score for the records in the first set of distinct records and the HTM is trained until the anomaly score meets a predetermined threshold degree of anomaly; receiving a second set of records for the web application operating in a production mode of operation, each record in the second set of records including characteristics of content of the web page during an operational time period, the operational time period being distinct from the training time period and the production mode of operation being distinct from the training mode of operation; generating a sparse distributed representation of the second set of distinct records to form an input set for the trained HTM; executing the trained HTM based on the input set to determine a degree of recognition of the records of the input set; responsive to a determination that a degree of recognition of one or more records of the input set is below a threshold degree, identifying an anomalous change to the web page; and responsive to the identification of the anomalous change to the web page, causing a responsive measure to the anomalous change to be implemented that includes one or more of the following actions: interrupting operation of the web application; identifying client components in communication with the web application as potentially compromised; executing at least one of an intrusion detection, malware detection, virus removal, or a malware removal process for the web application; or effecting at least one of a redeployment, a reinstallation, or a reconfiguration of the web application. 4. A non-transitory computer-readable storage element comprising computer program code to, when loaded into a computer system and executed thereon, cause the computer system to perform the method as claimed in claim 1 .

Assignees

Inventors

Classifications

  • Quantised networks; Sparse networks; Compressed networks · CPC title

  • Combinations of networks · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • Organisation or management of web site content, e.g. publishing, maintaining pages or automatic linking · CPC title

  • Learning methods · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12401686B2 cover?
A computer implemented method to detect an anomalous change to a web application, the web application executing with a web server, the method including receiving a first set of records for the web application operating in a training mode of operation, each record including characteristics of a content of a web page for the web application; generating a sparse distributed representation of the s…
Who is the assignee on this patent?
British Telecomm
What technology area does this patent fall under?
Primary CPC classification H04L63/1483. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Aug 26 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).