US 12,335,287 B2
Automated detection of cross site scripting attacks
Satya V. Gupta, Dublin, CA (US)
Assigned to Virsec Systems, Inc., San Jose, CA (US)
Filed by Virsec Systems, Inc., San Jose, CA (US)
Filed on Dec. 30, 2021, as Appl. No. 17/646,611.
Claims priority of provisional application 63/133,173, filed on Dec. 31, 2020.
Prior Publication US 2022/0210180 A1, Jun. 30, 2022
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/1433 (2013.01) [H04L 63/1416 (2013.01); H04L 2463/146 (2013.01)] 19 Claims
OG exemplary drawing
 
1. A method of detecting a cross site scripting attack, the method comprising:
capturing a web request provided by a user, after the web request is decrypted and decoded, by capturing the web request at an entrance to a Hypertext Transfer Protocol (HTTP) pipeline;
capturing a response to the captured web request;
determining if one or more elements associated with the captured web request and one or more elements of the captured response, in combination, cause a malicious action, wherein the determining is based on (i) presence of interpreter syntax in user input, provided by the user, in the captured web request, and at least one of (ii) status of the user input being included in interpreter input, (iii) execution status of the interpreter, and (iv) presence of interpreter syntax in the captured response; and
declaring a cross site scripting attack in response to determining the one or more elements associated with the captured web request and the one or more elements of the captured response, in combination, cause a malicious action.