| CPC G06F 21/566 (2013.01) [G06F 9/44526 (2013.01); G06F 21/54 (2013.01); G06F 21/577 (2013.01); G06F 2221/033 (2013.01)] | 18 Claims |

|
1. A computing platform, comprising:
at least one processor;
a communication interface communicatively coupled to the at least one processor; and
memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:
send, via the communication interface, to a master browser extension on a computing device, rule information including a set of rules defining reportable behavior associated with one or more other browser extensions;
in response to detecting startup of a web browser on the computing device, cause the master browser extension to discover one or more other browser extensions on the computing device and scan the one or more other browser extensions on the computing device to identify browser extensions exhibiting reportable behavior defined by the set of rules;
receive, via the communication interface, from the master browser extension on the computing device, report information identifying an other browser extension of the one or more other browser extensions that exhibits the reportable behavior defined by at least one rule of the set of rules in the rule information, wherein receiving the report information from the master browser extension on the computing device comprises receiving information indicating that the identified other browser extension of the one or more other browser extensions is sending data to third parties;
based on receiving the report information, determine that the identified other browser extension is a malicious extension, wherein determining that the identified other browser extension is a malicious extension includes identifying that the other browser extension has met at least a threshold number of rules in the set of rules; and
send, via the communication interface, to the master browser extension on the computing device, one or more commands directing the master browser extension on the computing device to disable or remove the identified other browser extension.
|