Web injection protection method and system
US-2017104783-A1 · Apr 13, 2017 · US
US2017237771A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2017237771-A1 |
| Application number | US-201615044479-A |
| Country | US |
| Kind code | A1 |
| Filing date | Feb 16, 2016 |
| Priority date | Feb 16, 2016 |
| Publication date | Aug 17, 2017 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method, computer program product and/or system receives information pertaining to network data traffic from and/or to a network accessible resource, analyzes the information to determine whether a user is engaged in potential hacking transaction(s) with respect to the resource. On condition that the user is determined to be engaged in potential hacking transaction(s), a “scarecrow” message designed for display to the user, is generated and sent to the user.
Opening claim text (preview).
What is claimed is: 1 . A computer-implemented method comprising: receiving information pertaining to network data traffic being communicated from and/or to a user's computer which is operated by a user; analyzing the information to determine whether the user is engaged in potential hacking transaction(s) with respect to a network accessible resource; and on condition that the user is determined to be engaged in potential hacking transaction(s): generating a scarecrow message designed for display in human understandable form and format to the user on a computer operated by the user, and sending the scarecrow message to the user's computer; wherein potential hacking transaction(s) are defined as any set of communication(s) to and/or from the user's computer that tend to indicate that the user's computer is engaged in subverting computer security for malicious purposes. 2 . The computer-implemented method of claim 1 wherein potential hacking transaction(s) of the user includes at least one of the following: a transaction by a user previously known to have engaged in hacking transaction(s); the user requests information from the network accessible resource at a rate that exceeds a pre-determined threshold; data accessed, by the user, includes information of a predefined format; data access attempts, by the user, generate errors at a rate exceeding a pre-defined threshold; and the user's computer hostname exists in more than a pre-defined number of sessions with the network accessible resource. 3 . The computer-implemented method of claim 1 further comprising: on condition that the user is engaged in potential hacking transaction(s): receiving data from the network accessible resource, altering the data to generate altered data, and sending the altered data to a computer operated by the user. 4 . The computer-implemented method of claim 1 wherein the scarecrow message is sent to the user in a form and format that is displayable by software running on a computer operated by the user. 5 . The computer-implemented method of claim 1 wherein the scarecrow message includes at least one of the following: (i) the user's internet protocol (IP) address; (ii) indication that the user's activities are being monitored; (iii) indication that a connection profile of the computer operated by the user is being monitored; (iv) a phantom background process; and/or (v) the user's log-in chain. 6 . The computer-implemented method of claim 3 wherein altering the data includes at least one of the following: (i) adding an electronic watermark; (ii) adding a warning message; and/or (iii) preventing transmission to the user's computer of at least a portion of the data. 7 . A computer program product comprising a computer readable storage medium having stored thereon: first program instructions programmed to receive information pertaining to network data traffic being communicated from and/or to a user's computer which is operated by a user; second program instructions programmed to analyze the information to determine whether the user is engaged in potential hacking transaction with respect to a network accessible resource; and on condition that the user is determined to be engaged in potential hacking conduct: third program instructions programmed to generate scarecrow message designed for display in human understandable form and format to the user on a computer operated by the user, and fourth program instructions programmed to send the scarecrow message to the user's computer; wherein potential hacking transaction(s) are defined as any set of communication(s) to and/or from the user's computer that tend to indicate that the user's computer is engaged in subverting computer security for malicious purposes. 8 . The computer program product of claim 7 wherein potential hacking activity of the user includes at least one of the following: a transaction by a user previously known to have engaged in hacking transactions; the user requests information from the network accessible resource at a rate that exceeds a pre-determined threshold; data accessed, by the user, includes information of a predefined format; data access attempts, by the user, generate errors at a rate exceeding a pre-defined threshold; and a computer hostname exists in more than a pre-defined number of sessions. 9 . The computer program product of claim 7 further comprising: on condition that the user is engaged in potential hacking transactions: fifth program instructions programmed to receive data from the network accessible resource, sixth program instructions programmed to alter the data to generate altered data, and seventh program instructions programmed to send the altered data to a computer operated by the user. 10 . The computer program product of claim 7 wherein the scarecrow message is sent to the user in a form and format that is displayable by software running on the computer operated by the user. 11 . The computer program product of claim 7 wherein the scarecrow message includes at least one of the following: (i) the user's internet protocol (IP) address; (ii) indication that the user's activities are being monitored; (iii) indication that a connection profile of the computer operated by the user is being monitored; (iv) a phantom background process; and/or (v) the user's log-in chain. 12 . The computer program product of claim 9 wherein altering the data includes at least one of the following: (i) adding an electronic watermark; (ii) adding a warning message; and/or (iii) preventing transmission to the user's computer of at least a portion of the data. 13 . A computer system comprising: a processor(s) set; and a computer readable storage medium; wherein: the processor(s) set is structured, located, connected and/or programmed to run program instructions stored on the computer readable storage medium; and the program instructions include: first program instructions programmed to receive information pertaining to network data traffic being communicated from and/or to a user's computer which is operated by a user; second program instructions programmed to analyze the information to determine whether the user is engaged in potential hacking transaction with respect to a network accessible resource; and on condition that the user is determined to be engaged in potential hacking conduct: third program instructions programmed to generate scarecrow message designed for display in human understandable form and format to the user on a computer operated by the user, and fourth program instructions programmed to send the scarecrow message to the user's computer; wherein potential hacking transaction(s) are defined as any set of communication(s) to and/or from the user's computer that tend to indicate that the user's computer is engaged in subverting computer security for malicious purposes. 14 . The computer system of claim 13 wherein potential hacking activity of the user includes at least one of the following: a transaction by a user previously known to have engaged in hacking transactions; the user requests information from the network accessible resource at a rate that exceeds a pre-determined threshold; data accessed, by the user, includes information of a predefined format; data access attempts, by the user, generate errors at a rate exceeding a pre-defined threshold; and a computer hostname exists in more than a pre-defined number of sessions. 15 . The computer system of claim 13 further comprising: on condition that the user is engaged in potential hac
by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title
Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks · CPC title
Traffic logging, e.g. anomaly detection · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.