US 12,141,221 B2
Browser application extension for payload detection
Nicholas Walter O'Reilly, Dallas, TX (US)
Assigned to BANK OF AMERICA CORPORATION, Charlotte, NC (US)
Filed by Bank of America Corporation, Charlotte, NC (US)
Filed on Jul. 18, 2022, as Appl. No. 17/866,960.
Prior Publication US 2024/0020347 A1, Jan. 18, 2024
Int. Cl. G06F 16/957 (2019.01); G06F 16/958 (2019.01)
CPC G06F 16/9574 (2019.01) [G06F 16/9577 (2019.01); G06F 16/958 (2019.01)] 20 Claims
OG exemplary drawing
 
1. A method for detecting content transfers through a browser application, the method comprising:
executing, by the browser application, a data transfer extension associated with the browser application;
determining, by the browser application using the data transfer extension, data associated with user interactions with one or more sites visited using the browser application;
detecting, by the browser application using the data transfer extension, a user instruction to transfer content comprising redirection data which further comprises at least one unexpected redirection to or from a remote network location;
initiating, by the browser application, a transfer of the content to or from the remote network location;
storing, by the browser application using the data transfer extension, the determined data in association with a record of the content transfer, wherein the determined data comprises one or more content pages accessed by the browser application prior to detecting the user instruction to transfer content comprising redirection data, a hash of the content at the remote network location, and a hash of the content at a destination of the content transfer; and
transmitting the determined data in association with the record of the content transfer to an analysis server, wherein the analysis server validates the determined data of the content transfer based on validating at least one of a source or the destination of the content transfer, comparing the redirection data to a redirection threshold and determining the redirection data is less than the redirection threshold, and comparing the hash of the content at the remote network location and the hash of the content at the destination of the content transfer and determining the hash of the content at the remote network location matches the hash of the content at the destination of the content transfer.