Invention Grant
- Patent Title: Analyzing web application behavior to detect malicious requests
-
Application No.: US15441169Application Date: 2017-02-23
-
Publication No.: US10652254B2Publication Date: 2020-05-12
- Inventor: Leon Kuperman , Kipras Mancevicius
- Applicant: Zenedge, Inc.
- Applicant Address: US FL Aventura
- Assignee: ZENEDGE, INC.
- Current Assignee: ZENEDGE, INC.
- Current Assignee Address: US FL Aventura
- Agency: Kraguljac Law Group, LLC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06N3/04 ; G06N3/08

Abstract:
A system is configured for protecting web applications at a host by analyzing web application behavior to detect malicious client requests. Example embodiments described herein include a proxy configured to handle network traffic between a host and clients. The proxy includes two request classification mechanisms, first a list of known clients, malicious and non-malicious, for identifying known malicious and known non-malicious requests and second a web application firewall for determining a classification for unknown requests (e.g., not originating from a known client). The classification itself may be distributed. The proxy determines whether a request is known non-malicious, known malicious, or unknown. The proxy collects request attributes for the known malicious and known non-malicious requests for the generation of a model based on the attributes of the known requests. The proxy passes the unknown requests to the WAF for determining a classification based on their attributes using the model.
Public/Granted literature
- US20170244737A1 Analyzing Web Application Behavior to Detect Malicious Requests Public/Granted day:2017-08-24
Information query