Invention Grant
- Patent Title: Detecting web resources spoofing through stylistic fingerprints
-
Application No.: US17551563Application Date: 2021-12-15
-
Publication No.: US11985165B2Publication Date: 2024-05-14
- Inventor: Xu Lin , Frederico Araujo , Teryl Paul Taylor
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Maeve M. Carpenter
- Main IPC: H04L9/40
- IPC: H04L9/40 ; G06F16/958

Abstract:
A method of detecting deceptive web activity is implemented in an intermediary located between a requesting client device, and a server that hosts a web application. Following a bootstrap phase used to generate a database of information identifying characteristics of clients, the method begins by receiving a page directed to the client from the server. The server injects an invisible DOM element having a set of style properties associated therewith, with one of the set of style properties assigned a random value, to generate a modified page, which is returned to the client. As the client interacts with the modified page, the intermediary tracks the device's styles and uses them to identify the client from information in the database. Once the device is identified, the intermediary then detects whether a spoofing attack has occurred. By leveraging the tracked styles, a spoofing attack on the DOM element's styles may also be detected.
Public/Granted literature
- US20230188565A1 DETECTING WEB RESOURCES SPOOFING THROUGH STYLISTIC FINGERPRINTS Public/Granted day:2023-06-15
Information query