Rendering of Context Security Information Determined within a Browser with Web Pages of Cloud and SAAS Vendors

The browser extension addresses the challenge of integrating cloud security solutions by fetching and displaying security information within the cloud vendor's web page, offering a streamlined and integrated view of security and service information.

JP2025519480APending Publication Date: 2025-06-26PALO ALTO NETWORKS INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024572045
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-06-09
Filing Date
2023-04-07
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Cloud security solutions struggle to integrate security information seamlessly with cloud-based services, leading to cumbersome navigation between multiple views and workflows for customers.

Method used

A browser extension that integrates security information from a security vendor with a cloud vendor's web page, using fingerprints of web page elements and URLs to retrieve and display contextual security information in a single view.

Benefits of technology

This solution provides a unified, intuitive interface for customers to view security information alongside cloud services, enhancing convenience and reducing navigation complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025519480000001_ABST
    Figure 2025519480000001_ABST
Patent Text Reader

Abstract

The browser extension generates a single view that includes the content of the target vendor's web page requested by the customer and the corresponding security information about the target vendor maintained for the customer. A fingerprint of the target vendor's web page URL and the web page elements corresponding to the resources are each determined. When the web browser searches a web page and the customer selects the web page elements that identify the resources, the browser extension matches the URL and / or HTML / XML syntax pattern of the searched web page with the fingerprint to determine the security information obtained from the backend storage. The type / granularity of the information to be searched can vary according to the identified fingerprint matching. The browser extension searches for the security information corresponding to the identified fingerprint match, generates a security summary therefrom, and integrates the security summary into the requested web page to generate an integrated multi-perspective view.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to digital data processing (e.g., CPC subclass G06F) and information retrieval (e.g., CPC subclass G06F 16 / 00).

Background Art

[0002] A cloud service provider (CSP) is a provider of cloud computing technology that delivers computing resources in the cloud. In cloud computing, applications and other computing resources that were conventionally hosted on-premise are delivered over the Internet by a CSP. Cloud computing services provided by a CSP include infrastructure as a service (IaaS), platform as a service (PaaS), and software as a service (SaaS), which provide cloud-based infrastructure, cloud-based platform, and cloud-based applications, respectively. With the increasing accessibility of cloud computing technology and the increasing popularity of CSPs, an increasing number of vendors are adopting cloud computing technology for the delivery of hardware technology and / or software technology in addition to, or instead of, providing on-premise solutions.

Brief Description of the Drawings

[0003] Aspects of the present disclosure may be better understood by referring to the accompanying drawings.

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

[0004] The following description includes exemplary systems, methods, techniques, and program flows that embody aspects of the present disclosure. However, it is understood that the present disclosure may be practiced without these specific details. For example, the present disclosure refers to generating a security profile of services provided by a CSP in an exemplary embodiment. Aspects of the present disclosure may also be applicable to services, features, and / or other functions provided by a SaaS application vendor / provider. In other instances, well-known instruction instances, protocols, structures, and techniques are not shown in detail so as not to obscure the description.

[0005] Term

[0006] This specification uses abbreviations related to cloud technology for the sake of efficiency and ease of explanation. When referring to "cloud" or "cloud environment", this description also refers to the resources of a CSP, also called cloud resources. For example, the cloud can include CSP servers, virtual machines, storage devices, and other cloud resources. In more general terms, cloud resources are resources owned / managed by a CSP entity that are accessible via a network connection. Often, access follows an application programming interface (API) or software development kit provided by the CSP.

[0007] This specification uses the phrase "browser extension" to refer to software for adding custom features to a web browser. A browser extension can extend the functionality of a web browser through various APIs supported by the web browser. Different web browsers may use different terms to refer to software that has these capabilities. As used in this specification, "browser extension" refers to software used by any web browser to support customization of the web browser.

[0008] The use of the phrase "at least one" preceding a list accompanied by the conjunction "and" should not be treated as an exclusive list and, in particular, should not be construed as a list of categories having one item from each category, unless otherwise specified. The phrase "at least one of A, B, and C" can violate only one of the listed items, a plurality of the listed items, and one or more of the listed items, as well as another item not listed.

[0009] Summary

[0010] Security vendors are increasingly adapting to the shift to cloud computing by offering cloud or SaaS security solutions to customers. Since the underlying infrastructure of these cloud-based protection targets (i.e., SaaS applications or cloud environments) is hosted off-site and owned by a CSP rather than on-premises by the customer, these security solutions obtain information about resources and applications that are secured by third parties by leveraging APIs provided by the vendors of these cloud-based protection targets (hereinafter, “target vendors”). The security information obtained by the security vendor and consumed by the customer is stored in the security vendor's repositories and systems, rather than together with those of the target vendor. As a result, the customer has separate accounts and corresponding separate views for both the target vendor (e.g., CSP) and the security vendor. Navigating between views and workflows to consume information about secured cloud environments or SaaS applications and their related security details can be cumbersome.

[0011] As described herein, the browser extension integrates the associated information retrieved from the security vendor with the target vendor's web page loaded by the web browser, thereby integrating the display rendered by the web browser. The result is a single view of both the target vendor's web page that may be requested by the customer and the security information corresponding to the target vendor's services and / or resources maintained by the security vendor for the customer, enabling the workflow to be integrated into a single display rather than spanning multiple displays and browser sessions. To onboard the target vendor for compatibility with the browser extension, the target vendor's web page URL and multiple fingerprints of web page elements are determined. The fingerprint can be a URL pattern that the URL of the web page requested by the customer may match, or a syntax pattern of the web page corresponding to selectable and / or visible web page elements with which the customer can interact (e.g., in a HyperText Markup Language (HTML) or Extensible Markup Language (XML) document). Since onboarding occurs once per target vendor, the URL of the target vendor's web page and the fingerprints of the elements are programmed into the browser extension to identify the target vendor's services, resources, or other offerings used by the customer at runtime, and any updates to the target vendor's offerings are represented in the updates to the browser extension.

[0012] During the login session of the browser extension, the browser extension matches the URLs and / or HTML / XML syntax patterns within the web pages searched by the browser with fingerprints to determine the associated security information for retrieval from the security vendor's backend storage system. The type and level of detail of the information that the browser extension searches for can vary depending on the fingerprint that matches the URL or HTML / XML syntax pattern. That is, the security information that is searched for and rendered is thus determined based on the context of the web page content determined from fingerprinting. For example, when the browser extension identifies a fingerprint match with the target vendor for the customer's account homepage or overview view, the browser extension can search for the general high-level security information maintained for the account and generate a security overview of the customer's account that is rendered along with the main / home page. Such information can include totals such as security issues identified by the security vendor for the customer's account with the target vendor, data / metadata regarding the last scan or security analysis performed on the customer's account with the target vendor. When the customer selects (e.g., through cursor hovering) web page elements corresponding to the individual resources provisioned for the customer, a more detailed overview can be generated. The browser extension detects these selection events, matches the selected elements to the resources based on the corresponding syntax pattern fingerprints, and retrieves the data / metadata about the resources for the generation of the security overview of that specific resource. The security overview generated for the customer at any level of detail is rendered together with the requested web page to generate an integrated multi-perspective view

[0013] Exemplary Explanation

[0014] Figure 1 is a conceptual diagram for integrating security information maintained by a security vendor with a web page of a cloud or cloud-based technology vendor. A context security information integrator (hereinafter, "integrator") 103 is provided by a security vendor 105 and implemented as a browser extension for a web browser 101 installed on a client device 131. The integrator 103 can communicate with a backend component of the security vendor 105 via an API 145 exposed by the security vendor 105. The web browser 101 can be any web browser that supports browser extensions. The security vendor 105 may be a cloud platform or may be hosted on-premises.

[0015] Integrator 103 determines security information (i.e., security data and / or metadata) based on context information identified from the content of a web page related to a cloud or cloud-based technology vendor (hereinafter referred to as the "target vendor") that is the protection target searched by web browser 101, searches for it, and incorporates the searched security information into a security summary that is rendered together with the web page for viewing in a single display alongside the web page content. The security information determined by Integrator 103 is said to be based on context information identified from the web page content. This is because Integrator 103 performs "fingerprinting" of the web page URL and / or syntax pattern in order to quickly determine the security perspective related to the web page, rather than fully parsing and scanning the web page URL and / or syntax. The target vendor can be a CSP or a SaaS application vendor. In this example, the CSP that provides at least a storage service is Target Vendor 141 of Integrator 103.

[0016] Figure 1 assumes that user 133 is a registered user of target vendor 141 and belongs to organization 143 named "ex-app-1" which is a tenant of target vendor 141. For example, target vendor 141 can allocate a virtual private cloud (VPC) to organization 143 within the public cloud environment. Figure 1 also assumes that organization 143 is a tenant of security vendor 105 / has an account with security vendor 102, and user 133 can access Integrator 103 (e.g., via login) after installing Integrator 103 on the client device where web browser 101 is installed.

[0017] FIG. 1 is annotated with a series of characters A - E. These characters represent stages of operation. These stages are ordered for this example, but these stages are provided as one example to aid in understanding the present disclosure and should not be used to limit the claims. The subject matter within the scope of the claims may vary with the order of operations and with respect to some operations.

[0018] In stage A, integrator 103 detects an event that triggers security overview generation. Integrator 103 listens for security overview generation trigger events and includes event listener 129, which may be implemented as a background crypto. The triggering event includes a search for and loading of a web page with a URL that matches the first of a set of URL patterns 139, which is a generalized pattern of the URLs of the web pages of target vendor 141. When web browser 101 searches for a web page of target vendor 141 requested by user 133 with an associated URL that matches one of URL patterns 139, integrator 103 should become active (i.e., the program code of integrator 103 should be executed). URL pattern 139 may be defined in a manifest file associated with integrator 103. Event listener 129 determines whether the URL of the searched web page matches the first of URL patterns 139 to determine whether security overview generation should be triggered. The triggering of security overview generation by event listener 129 may be implemented as triggering the execution of one or more content scripts included in integrator 103.

[0019] In this example, user 133 requests access to web page 119 of target vendor 141, which is maintained by server 117 (e.g., a physical or cloud-based web server) and has URL 137, where web page 119 is the home page of the cloud storage service of target vendor 141. Web browser 101 communicates a request 135 (e.g., a Hypertext Transfer Protocol (HTTP) GET request) to server 117 that instructs the server to search for web page 119 using URL 137. When web browser 101 searches for web page 119, event listener 129 identifies that URL 137 matches the first of URL patterns 139. By way of example, FIG. 1 shows URL 137 as “https: / / https.com / storage / home” and event listener 129 matches this URL to the first pattern of URL pattern 139 that includes the pattern “https: / / cloudvendor.com / *”.

[0020] In stage B, based on identifying a match between URL 137 and fingerprint 113A defined for target vendor 141, integrator 103 determines the content to search for inclusion in security profile 121. Integrator 103 is preconfigured using multiple fingerprints 113 of target vendor 141. Fingerprints 113 include a predetermined URL pattern and / or syntax pattern of the markup language (e.g., HTML or XML) of the web page of target vendor 141. The fingerprint of a URL can include a URL pattern having a variable name at the position of the name related to the service, feature, or other display of the web page content of target vendor 141 in the URL. Upon identifying a match between the URL and the URL fingerprint, integrator 103 can extract (e.g., copy) the substring of the URL corresponding to the position of the variable name in the matching fingerprint and determine the service / grouping to which the associated web page corresponds. The fingerprint of the syntax pattern in the markup language of the web page can be represented using a query or expression for identifying elements of interest in the web page markup language, such as an XML Path Language (XPath) expression and / or a jQuery selector for web pages including HTML / XML. Fingerprinting of the URL and / or syntax pattern of the retrieved web page notifies integrator 103 of the content of the web page retrieved by web browser 101. Matching with different ones of fingerprints 113 can trigger the execution of different code units (e.g., routines / subroutines) of integrator 103. As another example, each of fingerprints 113 can indicate (e.g., via a pointer) the code unit to be executed upon identification of a match with the fingerprint.

[0021] When searching web page 119, using the variable corresponding to the position of the service name that matches the substring "storage" in the path of URL 137, integrator 103 matches URL 137 of web page 119 against fingerprint 113A. By way of example, the fingerprint 113A shown in FIG. 1 to which URL 137 matches is "https: / / cloudvendor.com / SVC_NAME / *", and the substring "storage" matches the position specified by the variable "SVC_NAME". Integrator 103 can be preconfigured with the name of the service of target vendor 141 that can match the variable name in fingerprint 113, including that the substring "storage" indicates the cloud storage service of target vendor 141. Integrator 103 thus determines that web page 119 corresponding to URL 137 is associated with the cloud storage service provided by target vendor 141.

[0022] In stage C, integrator 103 queries one or more repositories of security vendor 105 to retrieve security information maintained for the accounts associated with user 133. FIG. 1 depicts security vendor 105 as maintaining repositories 107 and 109 (collectively “repositories 107, 109”), although a security vendor can maintain any number of repositories, each of which can be implemented as a database, data lake, data warehouse, etc. Repository 107 contains data on cloud resources for which target vendor 141 has been provisioned for organization 143 and which has been documented by security vendor 105. Repository 109 contains security reports generated by security vendor 105 for organization 143 based on the execution of security analysis. Repositories 107, 109 can include cloud resources and security reports corresponding only to organization 143, or, depending on whether security vendor 105 is a cloud-based service and whether it is implemented with a single-tenant or multi-tenant function, can also include those of other tenants of security vendor 105.

[0023] Each of the repositories 107, 109 can be queried through the invocation of the API 145 published by the security vendor 105. The integrator 103 submits at least a first query 123 to the repository 107 and / or the repository 109 by calling at least a first function of the API 145. The integrator 103 provides one or more parameter values using a function call corresponding to the query 123 that specifies at least the tenant of the security vendor 105 (i.e., the identifier of the organization). By way of example, FIG. 1 depicts the integrator 103 as calling an exemplary function of the API 145 named "get_storage_overview" that accepts the tenant name as a parameter and provides data and / or metadata including an overview of the security and use of the cloud storage service for the resources of the specified tenant. The integrator 103 can determine the tenant name based on the login session information for the login session initiated by the user 133 to log in, such that the integrator 103 is implemented using a browser extension, or based on one of the fingerprints 113 where the tenant name is placed and can be extracted from the HTML / XML of the web page 119.

[0024] In response to calling the API 145 function, the integrator 103 receives security information 127 of the security status of the cloud storage service of the target vendor 141 of the organization 143. The security information retrieved from the security vendor 105, including security data and / or metadata, may include, for example, a count of security issues identified for the organization 143 associated with the cloud storage service (for resources of the cloud storage service provisioned to the organization 143), an indication of the most critical security issues, etc. This example shows the security vendor 105 as providing an API 145 function that returns security summary data / metadata to the integrator 103 when invoked. That is, in other words, the security information 127 contains summary-level, or summarized / aggregated, security data and / or metadata maintained for the use of the storage service by the organization 143. In an implementation, the API function of the security vendor may return raw (i.e., non-summary) security data / metadata, and as a result, the summarization, aggregation, or other preprocessing of the data / metadata to generate its summary is performed by the integrator 103 after receiving the response to the API function call.

[0025] At stage D, when the integrator 103 is used by the organization 143 to be rendered together with the content of the web page 119, it generates a security summary 121 for the storage service. The integrator 103 includes a content generator 125 that generates content to be rendered by the web browser 101. The content generator 125 generates a security summary 121 that includes security information 127 of the storage service. For example, the content generator 125 may generate the security summary 121 by modifying the HTML / XML document of the web page 119 so as to include the security information 127 in summary form. Generating the security summary 121 can also include aggregating, summarizing, or otherwise preprocessing at least a subset of the security information 127 for incorporation into the HTML / XML document. The content generator 125 can modify the HTML / XML document of the web page 119 via the web page document object model (DOM), and thus the content of the security summary 121 is also rendered on a single screen (e.g., within the sidebar / side panel of the GUI) together with the content of the web page 119. The modification of the web page 119 by the content generator 125 results in a security summary extended web page ("extended web page") 119' that includes the content of the web page 119 and the security summary 121.

[0026] At stage E, the web browser 101 renders the extended web page 119' on the screen of the client device 131. As a result of rendering the extended web page 119', the content of both the web page 119 and the security summary 121 is displayed in a single view on the screen of the client device 131. The user 133 can thus view, without navigating between multiple views and browser sessions, the home page of the cloud storage service of the target vendor 141 and the relevant summary of the security status of the services for the organization 143, based on the information collected and maintained by the security vendor 105, which creates a more convenient and intuitive experience for the user 133.

[0027] Figure 2 is a conceptual diagram related to an exemplary GUI depiction of a security summary integrated with a target vendor's web page. Continuing to refer to Figure 1, the exemplary GUI of Figure 2 shows the integration of security information into the target vendor's web page with additional details. In Figure 1, the integrator 103 generates a security summary for the target vendor's services used by the tenant and integrates the security summary into the home page of the service. As shown in Figure 2, the integrator 103 can also search for and generate a security summary of individual resources of the target vendor that are provisioned for the tenant for integration into the target vendor's web page. This example assumes that the user 133 has requested the web page of the target vendor 141 that includes a list of cloud storage instances provisioned for the organization 143.

[0028] To perform resource-level security profile generation, the integrator 103 is preconfigured with events defined for user interaction with web page elements corresponding to individual resources. Web page elements refer to structural elements in an HTML / XML document of a web page represented using one or more tags. Thus, a web page element corresponding to an individual resource, such as resource 205 named "storage-instance-C" shown in FIG. 2, is a specific structural element in the corresponding HTML / XML document (e.g., It can be represented using tags). An event can thus be defined for a structural element in an HTML / XML document corresponding to an individual resource, or for its sequence. Here, one or more of the fingerprints 113 represent a syntactic pattern corresponding to a structural element by which a resource can be identified. Events defined for structural elements corresponding to resources can be similar events corresponding to mouseover / hover events, click events, or selection of elements on a web page based on the positioning of the cursor 203. Detection of an event defined for a structural element refers to the occurrence of a specified selection event and calling the integrator 103.

[0029] When the integrator 103 detects such a selection event, the integrator determines the identifier of the resource selected based on the corresponding web page element. The integrator 103 can determine the resource identifier based on the fingerprint of the web page element corresponding to the resource identifier. For example, the fingerprint 113 can include one or more XPath expressions and / or jQuery selectors for evaluating the HTML / XML document of the web page that, as a result, generates values stored in the HTML / XML nodes corresponding to individual resources. By way of illustration, an example of a fingerprint 113A implemented using jQuery for an HTML / XML node that contains the text "EC2 Instance" and thus corresponds to this type of cloud resource is "$(\"#instanceID\").text()==\"EC2 Instance\"".

[0030] In this example, integrator 103 evaluates the HTML / XML of the web page corresponding to resource 205 following the selection of resource 205 via mouse over, click, etc. of cursor 203 detected for the corresponding web page element. Integrator 103 can evaluate the HTML / XML of the web page based on an XPath expression, a jQuery selector, or other expressions for HTML / XML document manipulation triggered by a selection event. The result of the expression based on which integrator 103 evaluates the HTML / XML document indicates that the resource identifier corresponding to the web page element where the selection event was detected is "storage-instance-c". Integrator 103 calls one or more functions of API 145 to query the security data / metadata of resource 205 maintained for organization 143. Here, the query submitted includes at least the determined resource identifier. The response to the API call includes the data / metadata maintained by security vendor 105 for resource 205.

[0031] Upon searching for the data and / or metadata of resource 205, integrator 103 generates a security overview 201 that is rendered with the web page. Integrator 103 can generate the security overview 201 by displaying the security overview 201 panel (e.g., in the side panel of the GUI) and modifying the web page content via DOM manipulation to incorporate the security data / metadata of resource 205. The security overview 201 generated by integrator 103 includes resource metadata 207, alerts overview 209, remediation command 211, and policy interface 213. These components of the security overview 201 are included as one example, and in an implementation, other and / or different components may be included in the security overview.

[0032] The represented resource metadata 207 includes the metadata of the resource 205 obtained by the integrator 103 from the security vendor 105. In this example, the resource metadata 207 includes an identifier of the resource 205 and an indication of the network exposure of the resource determined by the security vendor 105 (e.g., based on a previous security analysis of the resource 205). The alert summary 209 includes an overview of security issues such as vulnerabilities and / or misconfigurations of the resource 205 identified for the resource 205 organized by count and severity ratings (i.e., critical, medium, and low). The remediation command 211 is a web page element that can be selected (e.g., clicked) by the user to trigger the correction of the security issues identified for the resource 205 reflected in the alert summary 209. For example, the selection of a GUI element corresponding to the remediation command 211 can call the function of the API 145 that triggers a remediation playbook for the resource 205 to be executed by the security vendor 105 when called for the resource 205. The policy interface 213 includes a text box at the time of submission where the user can write a new policy for the resource 205 to be applied to the resource 205. For example, the selection of a GUI element corresponding to the submission option of the policy interface 213 can call the function of the API 145 that communicates the content of the text box and the display of the resource 205 to the components of the security vendor 105 that manage policy creation and enforcement. As shown by this example, when the user wants to view security information about the resource 205, the user can stay within the same browser session and view the security information in a single display, rather than switching between displays as in conventional solutions.

[0033] The level of detail included in the security summaries that are generated for and then rendered for resources can vary across implementations. FIG. 2 shows an example where a security summary 201 of a resource 205 includes a high-level overview of details regarding the security of the resource 205. For example, when generating a security summary 201 with a high-level overview of security details, the functionality of API 145 called by integrator 103 can provide results that include the raw data / metadata of resource 205 and / or the summarized, aggregated, or otherwise pre-processed data / metadata of resource 205. In the former case, integrator 103 can pre-process the retrieved data / metadata as part of generating security summary 201. As one example, the security data of resource 205 corresponding to alert summary 209 obtained by integrator 103 can include an indication of the alerts currently associated with resource 205, including the alert severity and details regarding the alerts. Integrator 103 can determine the aggregated count of alerts for each severity rating and pre-process the alert data to create alert summary 209 using the aggregated counts and severity ratings rather than the details of each individual alert. In other examples, the security data of resource 205 obtained in response to a call to an API 145 function can include a summary view of the current alerts for the resource. Thus, integrator 103 can create alert summary 209 without additional pre-processing. A more detailed and lower-level security summary generated by integrator 103 for resource 205 can include at least a subset of the raw data / metadata retrieved for resource 205, such as the name or type of the alerts represented in alert summary 209, in addition to the count and severity rating. The exemplary GUI of FIG. 2 is shown for illustrative purposes. Implementations can instead display the raw data / metadata of the resource, or a combination of the raw data / metadata and pre-processed data / metadata. Implementations can also search for and render different types of data / metadata.

[0034] Figures 3-6 are flowcharts relating to exemplary operations for rendering context security information determined in-browser using the web pages of CSP and SaaS providers. The exemplary operations are described with reference to a context security information integrator implemented as a browser extension (hereinafter, “integrator”), or a security vendor that provides the integrator for consistency with previous figures. As used in the exemplary operations, “security vendor” refers to an entity that provides the integrator for installation, and “target vendor” refers to the provider / vendor of a CSP or SaaS application. The names chosen for program code do not limit the claims. The structure and organization of the program can vary due to the platform, the preferences of the programmer / architect, the programming language, etc. Additionally, the names of code units (programs, modules, methods, functions, etc.) vary for the same reason and can be arbitrary.

[0035] Figure 3 is a flowchart relating to exemplary operations for integrating context security information with a requested web page within a browser of a target vendor. The security information that is contextually relevant to the requested web page depends on both the security vendor account associated with the requester and the content of the web page. The exemplary operations assume that the integrator is preconfigured using multiple fingerprints of the target vendor. Here, the fingerprints can be URL fingerprints and / or HTML / XML syntax pattern fingerprints.

[0036] In block 301, a browser extension login session starts. The login session starts when a user having an account with a security vendor that provides an integrator logs in to the browser extension. The login session information can include a username and password, or additionally can include an account or tenant name (e.g., the name of the organization with which the user is registered).

[0037] In block 303, the integrator starts listening for events corresponding to a match between the URL of the requested web page and a specified URL pattern. When the login session starts, the integrator's background script starts listening for events that trigger the integrator's activity. Here, the integrator's activity includes the execution of non-background scripts (e.g., content scripts). The integrator is preconfigured (e.g., within the browser extension manifest file) with one or more patterns of URLs associated with the target vendor that trigger the integrator's activity when the URL of the web page matches the pattern. The event that triggers the browser extension's activity is thus matching the URL of the searched web page against the URL pattern maintained by the integrator.

[0038] In block 305, the integrator matches the URL of the searched web page with the URL pattern, which triggers the activity of the browser extension. The integrator identifies a match based on applying the URL pattern to the URL of the web page searched by the browser. Matching the URL against the URL pattern triggers the activity of the browser extension (i.e., the execution of the content script). The identified match is often the account home page that is searched and then displayed to the user of the target vendor following a successful login.

[0039] In block 306, the integrator determines the account associated with the login session. The account determination is performed to determine the identifier of the account (e.g., tenant name / identifier, account identifier, etc.) known to the security vendor where the security information should be retrieved. The integrator can determine the account based on the account information associated with the maintained login session. Alternatively, or additionally, the account information can be placed on the retrieved web page. The integrator can determine the account information by evaluating the web page HTML / XML document based on a pre-determined XPath expression, a jQuery selector, or other expression that describes the location of the account information in the HTML / XML document of the target vendor's web page.

[0040] In an implementation, the integrator can verify that an account with an associated target vendor known to the security vendor before proceeding. An account is known to the security vendor if the security vendor is actively performing security monitoring on the services and resources of the target vendor associated with the account. For example, the integrator can query the security vendor's backend storage to determine whether an account of the target vendor is being monitored by the security vendor. If the account is not being monitored, the integrator may present a prompt to the user asking for confirmation as to whether the user desires to onboard the account with the security vendor for security monitoring. If an input indicating affirmation is received, the integrator triggers the onboarding of the account with the target vendor before proceeding to block 307. Onboarding can be triggered by calling a function of the security vendor's API that triggers any relevant permission requests from the user, starting a scan of the account's resources, etc.

[0041] In block 307, the integrator performs security profile generation while the requested web page URL matches the URL pattern that triggers browser extension activity and while the login session is active. While these conditions are met, the integrator generates a security profile tailored to the web page content based on the detection of a trigger event. The trigger event may include the retrieval of a web page by the web browser. The security profile generation triggered by the retrieval of a web page may be implemented as described with reference to FIG. 4. Alternatively, or additionally, the trigger event may also include the selection of a web page element that triggers an action (e.g., based on user interaction with a GUI element). The security profile generation triggered by the selection of a web page element may be implemented as described with reference to FIG. 5.

[0042] FIG. 4 is a flowchart relating to exemplary operations for generating and displaying a security profile for the content of a requested web page. In block 401, the integrator detects the retrieval of a web page having a first URL by the web browser. The first URL may be the URL of the retrieved web page for which a pattern match was identified in block 305, or may be the URL of a web page retrieved later. The integrator may detect the retrieval of the web page based on receipt of a response (e.g., a response to an HTTP GET request) that includes the web page content. Alternatively, or additionally, the integrator may detect the retrieval of the web page based on detecting that the browser is retrieving a web page HTML / XML document and that the document is accessible for manipulation via the DOM of the web page. The integrator can determine the URL of the retrieved web page by calling the functionality of an API provided by the web browser or the browser extension platform.

[0043] In block 405, the integrator evaluates the first URL and / or syntax pattern of a web page based on a fingerprint defined for the web page owner (i.e., the target vendor). The integrator maintains one or more fingerprints of the HTML / XML syntax pattern and / or URL of the web page, such that the web page can be "fingerprinted" to determine the content of the web page. The fingerprints are predetermined for the target vendor's web pages, as described below with reference to FIG. 6. Each fingerprint corresponds to the type of security profile to be generated. Thus, fingerprinting notifies the integrator of security information to search for in order to generate a security profile of the web page. The web page content that can be determined from fingerprinting can be a general account overview presented at login, or information regarding a particular service of the target vendor (e.g., different services of a CSP).

[0044] Fingerprints can be implemented in two forms. That is, URL fingerprints or markup language fingerprints. A URL fingerprint may include a URL pattern with variable names that match a URL substring indicating web page content (e.g., service name). By way of example, referring to FIG. 1, a URL fingerprint for identifying a CSP service corresponding to a web page may be "https: / / cloudvendor.com / SVC_NAME / *". Here, the substring that matches the position of "SVC_NAME" indicates the name of the service corresponding to the web page. The integrator can evaluate the web page URL based on the URL fingerprint by determining whether a match between the URL and the URL fingerprint can be identified. A markup language fingerprint may include an XPath expression, a jQuery selector, and / or other expressions for HTML / XML document operations of a DOM tree created for an HTML / XML document of a web page, or other tree representation (e.g., HTML DOM tree), the value of which indicates web page content, describing nodes of the tree representation.

[0045] In block 407, the integrator determines whether a fingerprint match can be identified. A fingerprint match is identified when the URL of the web page matches the first URL fingerprint and / or the evaluation of the HTML / XML document of the web page based on an XPath expression, a jQuery selector, or other expression yields a value (i.e., the nodes described by the XPath expression, jQuery selector, or other expression exist in the tree representation of the HTML / XML document). If a fingerprint match cannot be identified, the operation continues to block 409. If a fingerprint match can be identified, the operation continues to block 411.

[0046] In block 409, the integrator presents a prompt for the next action with the requested web page. The lack of a fingerprint match may indicate that the security vendor has not yet been monitoring the target vendor's services corresponding to the account's web page. The integrator may display a prompt asking for input regarding whether the user wishes to monitor the services corresponding to the web page (e.g., by modifying the web page via the DOM). Upon receiving an input indicating affirmation, the integrator may communicate a request to the backend security monitoring system to initiate a process for monitoring the services (e.g., by invoking the functionality of the API of the backend system).

[0047] In block 411, the integrator queries the security vendor's backend storage for security information corresponding to the fingerprinted element. The backend storage can be one or more repositories, databases, data lakes, or other types of data storage that expose an API. The query that the integrator submits to the backend storage can indicate the account information (e.g., tenant name / identifier) determined in block 403, and one or more types of security information (i.e., data and / or metadata) to be searched. The type of security information indicated in the query can vary depending on the fingerprint for which a match was identified. For example, the identification of different fingerprint matches can trigger the invocation of different functions of the API for the retrieval of corresponding security information, such as based on fingerprints corresponding to code units (e.g., routines / subroutines) that are called when a fingerprint match is identified. By way of illustration, if the target vendor is a CSP and the fingerprinted element corresponds to a particular service of the CSP, the integrator can query the backend storage for security information maintained for the account associated with that service via an API function call. Examples of such security information include the total number of security issues identified for the account corresponding to the service (e.g., security issues identified for the resources corresponding to the service), and / or a list of the most critical security issues. When retrieving security information, the integrator can cache the security information for a configurable number of security profile generation events (e.g., 5 generation events). Caching of security information facilitates the rapid retrieval of security information corresponding to frequently searched web pages, such as those corresponding to services frequently used by the user associated with the account.

[0048] In block 413, the integrator generates a security summary for the content of the web page using the retrieved security information. The integrator generates a GUI depiction of the retrieved security information that is displayed alongside the web page. The integrator can generate the GUI depiction by modifying the web page via the web page DOM. The security information retrieved from the backend storage device may already include summary information and can be directly incorporated into the GUI display. As another example, the integrator can preprocess at least a subset of the security information before incorporating the subset of the security information into the GUI rendering. For example, the integrator can aggregate and / or generate a summary of a subset of the security information and incorporate the aggregated or summarized security information into the GUI rendering. The integrator modifies the document constituting the web page via the DOM to incorporate the security information and / or the preprocessed security information. For example, the integrator can add and / or modify an HTML / XML and / or Cascading Style Sheet (CSS) document via the DOM, and then the added and / or modified document is rendered.

[0049] In block 415, the web browser extended by the integrator renders the security summary alongside the web page. The security summary is integrated into the content rendered on the screen of the client device on which the web browser is installed. As a result, the security summary is available for viewing alongside the web page content.

[0050] FIG. 5 is a flowchart relating to exemplary operations for generating and displaying a security summary of a resource based on detecting an interaction of a web page element. The exemplary operations assume that the web page has already been rendered by a web browser, and thus, the user can interact with GUI elements corresponding to the elements of the web page.

[0051] In block 501, the integrator detects a selection of a resource based on a user interaction with an element of the web page corresponding to the resource. The integrator has one or more events (such as HTML events such as onmouseover and / or onclick events, etc.) defined for the web page elements corresponding to the individual resources, and thus, are treated as resource selection events. The web page elements corresponding to the individual resources and having the defined events can be web page elements including HTML / XML attributes having a resource identifier as a value. The integrator detects the selection of the resource when the defined event occurs, and triggers the execution of the integrator's program code corresponding to the event.

[0052] In block 503, the integrator determines the identifier of the selected resource based on the selected web page element. The integrator fingerprints the HTML / XML document corresponding to the web page and determines the resource identifier based on a syntactic pattern pre-determined to correspond to the position of the resource identifier within the HTML / XML of the web page. To fingerprint the HTML / XML document, the integrator may have an XPath expression and / or a jQuery selector defined in relation to the resource selection event. Here, the XPath expression or the jQuery selector describes / selects the nodes of the HTML / XML document (e.g., in the tree representation of the document) that contain the attribute value corresponding to the identifier of the selected resource. The integrator determines, as an attribute value, the node containing the resource identifier based on the evaluation of the detected event against the web page element defined using the XPath expression or the jQuery selector. From the determined node containing the attribute value, the integrator can extract the resource identifier.

[0053] In block 505, the integrator queries the security vendor's backend storage about the security information maintained for the selected resource. As described above in block 411 with reference to FIG. 4, the backend storage can be one or more repositories, databases, data lakes, or other types of data storage that expose an API. The query that the integrator submits to the backend storage can indicate the account information and resource identifier determined for the login session. The query can also specify one or more types of security information to be searched for the resource. By way of example, if the target vendor is a CSP and the selected resource is a cloud resource, the integrator can query the backend storage about the data and / or metadata maintained for the cloud resource via an API function call. Examples of such data and / or metadata include the count of security issues identified for the cloud resource (e.g., misconfiguration and / or vulnerability of the cloud resource), and / or the count of security issues identified for the cloud resource for each severity classification. When searching for security information about a resource, the integrator can cache the security information for a configurable number of security profile generation events. Caching the security information for a resource facilitates the rapid retrieval of security information for frequently interacted web page elements corresponding to the resource, such as those corresponding to highly used and / or publicly exposed resources.

[0054] In block 507, the integrator generates a security profile of the resource using the retrieved security information. The integrator generates a GUI depiction of the retrieved security information that is displayed alongside the web page. The integrator can generate the GUI depiction by modifying the web page via the web page DOM. The security information retrieved from the backend storage already includes resource-level security information and can be directly incorporated into the GUI display. Alternatively, the integrator can preprocess at least a subset of the security information before incorporating it into the GUI display. For example, the integrator can aggregate and / or generate a summary of a subset of the security information and incorporate the aggregated or summarized subset of the security information into the GUI rendering. One example is to determine the count of security issues associated with the resource based on retrieving security issue data from the backend storage. The integrator modifies one or more documents constituting the web page via the DOM to incorporate the resource's security information and / or the preprocessed security information. For example, the integrator can add and / or modify HTML / XML and / or CSS documents via the DOM for rendering the added and / or modified documents.

[0055] The integrator can include elements within the content rendered for the selected resource, in addition to the security summary. For example, the integrator can also incorporate a web page element that accepts input corresponding to an action performed on the resource selected by the security vendor into the rendered content. For example, the integrator can incorporate a selectable HTML / XML element (e.g., a button) that a user can select to trigger the correction of a security issue identified for the resource within the rendered content. The selection of this element triggers a function call to the security vendor's API to initiate a remediation workflow (e.g., a playbook) for the resource. Alternatively, or additionally, the integrator can incorporate an HTML / XML element (e.g., a text box and a corresponding button to submit the content of the text box) into which a policy applied to the resource can be typed and submitted. The submission of the policy via this element triggers a function call to the security vendor's API to initiate a workflow for policy creation and enforcement. As a result, the correction of misconfigured or vulnerable resources and / or the creation of policies to be implemented on the resources can be initiated within the browser without navigating to different browser sessions and displays.

[0056] In block 509, the web browser renders the security summary of the resource alongside the web page. The security summary is integrated into the content rendered on the screen of the client device on which the web browser is installed. As a result, the security summary is available for viewing alongside the web page content corresponding to the resource selected by the user.

[0057] FIG. 6 is a flowchart relating to exemplary operations for onboarding a vendor to support in-browser integration of a security summary based on web page content. The exemplary operations are performed once per target vendor to make a target vendor secured by a security vendor compatible with a browser extension including an integrator. The exemplary operations may be performed when generating corresponding updates for the integrator to support updates published by the target vendor when the target vendor begins to offer new services and / or new resource types. The security vendor may perform the exemplary operations based on expertise or domain knowledge and as part of developing the integrator.

[0058] In block 601, the security vendor begins fingerprint determination for each web page into which security information is to be integrated. One or more URLs corresponding to web pages to be fortified with security information may be determined in advance. Each web page is retrieved via its URL and made available for analysis and processing (e.g., via developer tools provided by a web browser in which a browser extension is provided). Since the specific content of a web page may vary across accounts with the target vendor, the web page may be general or representative of the general structure of the web page HTML / XML document. Additionally, while subsequent operations refer to a single web page, some sets of web pages (i.e., two or more web pages) may correspond to the same service or other grouping, such as a set of web pages for which a single URL fingerprint is determined. In such cases, subsequent operations may be performed on the set of web pages.

[0059] In block 603, the security vendor determines the type of fingerprint to determine about the web page. A fingerprint of web page elements defined with respect to the syntax pattern (e.g., HTML / XML structural elements), URL, or both can be determined. If at least a first web page element fingerprint should be determined, the operation proceeds to block 605. That is, if multiple web page element fingerprints should be determined, subsequent operations are executed for each of the web page elements. If the URL of the web page should be fingerprinted, the operation follows block 611.

[0060] In block 605, the security vendor identifies the position of at least a first element fingerprinted within the HTML / XML document of the web page. A tree representation of the HTML / XML document, such as a DOM tree, can be created first based on the processing of the HTML / XML document. The position of the element is identified based on the corresponding node in the tree representation of the HTML / XML document. Since the elements of the web page can depend on the account for which a login session with the target vendor has been established, such as elements corresponding to specific resources provisioned for the account, the position in the tree representation can be generalized to the path of the node (e.g., the "branch" of the tree) where the node corresponding to the resource is added therefrom.

[0061] In block 607, the security vendor determines a representation that describes the location of an element in an HTML / XML document. The representation can be an XPath expression, a jQuery selector, or another type of representation that can be used to manipulate an HTML / XML document (e.g., a representation / function provided by an open source library for traversing and manipulating an HTML / XML DOM tree). This representation describes at least a first node in a tree representation corresponding to a web page element. The node described by this representation can be a node corresponding to an HTML / XML attribute of a web page element that stores a value of interest (e.g., a resource identifier). As an example, this representation is <button>Nodes that contain the name attribute of an element or another visible / selectable element can be described.

[0062] In block 609, the security vendor adds an expression to the program code of the browser extension. This expression is added into the program code to be executed based on the detection of a trigger event for extracting information from the web page content, which is identified based on the evaluation of the expression against the web page HTML / XML document (e.g., through traversing the HTML / XML DOM tree based on the expression). That is, generally, this trigger event is either the search for a web page having a predetermined URL (i.e., a URL that matches the URL fingerprint), or the interaction with the GUI element corresponding to the web page element.

[0063] In block 611, the security vendor determines a generalized pattern of the URL web page that includes at least a first variable name of a URL substring that represents web page content. The URL pattern generalizes the URL to reflect the content of the web page, regardless of the specific account that requests the web page. The pattern includes an asterisk for specific account information and can include variable names in the position of a substring of the URL (e.g., in the URL path) that corresponds to the name of the service or other indication of the content of the web page. As an example, referring to FIG. 1, the URL "https: / / cloudvendor.com / storage / home" can be generalized to the pattern "https: / / cloudvendor.com / SVC_NAME / *" to reflect that the substring that matches the variable name "SVC_NAME" indicates the service of the target vendor corresponding to the web page. As another example, the URL "https: / / cloudvendor.com / storage / home?region=us-east" can be generalized to the pattern "https: / / cloudvendor.com / SVC_NAME / *region=REGION" to reflect that the substrings that match the variable names "SVC_NAME" and "REGION" indicate, respectively, the service of the target vendor corresponding to the web page and the region to which the instance of the service corresponds.

[0064] In addition, to handle cases where a URL matches multiple URL patterns, a rank or priority can be determined for the URL patterns and variable names. The ranking or priority assigned to a URL pattern allows the integrator to indicate, at runtime, the URL pattern that matches the URL when there are multiple possible matches for the URL. One example of a ranking / priority scheme that can be implemented is a scheme in which URL patterns are assigned to ranked tiers, where one or more URL patterns are assigned to each tier, and the integrator performs URL pattern matching for the URL patterns in each tier in descending order of rank. In this example, the security vendor determines the tiers for assigning URL patterns.

[0065] In block 613, the security vendor adds URL patterns with variable names to the browser extension program code. The URL patterns are added to the set of URL patterns that the integrator attempts to match against the URL of the web page being searched. If a rank or priority is determined for the URL patterns, an indication of the rank or priority is also added to the browser extension program code. Matching the URL to the first pattern among the patterns can further trigger the generation of a security profile of the type corresponding to the matched URL pattern, such as based on variable names indicating web page content. For example, matching the URL to the first pattern among the patterns having variable names corresponding to the services of the target vendor can trigger the generation of a security profile regarding the use of accounts for that service.

[0066] In block 615, if there is another web page remaining for fingerprinting, the operation proceeds. If there are additional web pages remaining, the operation continues at block 601. Otherwise, the operation is complete.

[0067] FIG. 1 - FIG. 6 relate to an implementation in which context security information integration is performed based on a browser extension that implements a context security summary integrator (referred to above as "integrator 103") that determines the content of a web page after the web page is searched and fingerprinted. In this case, it is assumed that the target vendor does not provide native support for the integration of context security information. Some target vendors may natively support the in-browser integration of context security information. Using the native support for in-browser context security information integration, the browser extension implementing integrator 103 can "hook into" the target vendor's web page via hooking. In such an implementation, the target vendor web page where security information is integrated includes one or more code hooks provided by the target vendor, or positions in the program code where execution is intercepted by integrator 103 to search for security information related to the web page there, and performs any preprocessing before the web page and security summary including the retrieved security information are rendered. Since integrator 103 can execute in the same context as the web page program code rather than as an external entity, integrator 103 can then directly determine the service, resource, or other content of the web page for which the corresponding security information should be retrieved. In other words, this information can be determined directly from the web page elements accessible to integrator 103 rather than indirectly via fingerprinting as described above.

[0068] FIG. 7 shows an exemplary GUI depiction including information regarding a selected resource in an instance where the target vendor natively supports in-browser integration of context security information. Continuing to refer to FIG. 1 and additionally referring to FIG. 2, the GUI shown in FIG. 7 is one example of a screen resulting from the selection (e.g., click) of a GUI element corresponding to resource 205. In this example, since the target vendor supports the integration of security information retrieved by integrator 103, the security summary generated by integrator 103 can be displayed along with the content of the corresponding web page of the target vendor instead of a separate GUI element as in FIG. 2. By way of example, the detailed view 705 of resource 205 includes a plurality of tabs 707 and the user can navigate between these tabs to view various details regarding resource 205. The tabs 707 include a security overview tab 703 in addition to other tabs conventionally supported by the target vendor. Selection of the security overview tab 703 results in the security summary 701 generated by integrator 103 being displayed for the currently displayed resource 205. As shown by the detailed view 705 of resource 205, when the target vendor natively supports in-browser integration of context security information, the security summary can be incorporated as part of the web page content and rendered together.

[0069] Furthermore, the type and / or granularity of security information that is retrieved and then rendered using in-browser security information integration can also be customizable by the customer, regardless of whether the functionality of integrator 103 is provided as an external browser extension or natively supported by the target vendor (as shown in FIGS. 2 and 7, respectively). For example, referring to FIG. 7, a customer for whom the resource "storage-instance-C" has been provisioned can configure integrator 103 to display resource metadata, alert summaries, remediation commands, and policy interfaces in the security summary tab 703 corresponding to the selected resource. Other customers may choose to display more or less information regarding individual resources and, accordingly, configure integrator 103.

[0070] Integrator 103 can be further configurable to incorporate security information of different elements, and / or types, or granularities into security summaries generated and rendered for users with different roles assigned by a customer (e.g., by the customer's system administrator). For example, at the start of a login session, Integrator 103 can determine the role of the user for whom the login session is maintained (e.g., based on an organizational directory accessible to Integrator 103). Integrator 103 can be configured using additional policies that specify the role of the user and, for each role, one or more types of security information and / or one or more GUI elements to be incorporated into the security summary rendered during the login session. By way of illustration, referring to FIG. 2, Integrator 103 can be configured using a policy to search for and display resource metadata 207 for a user with any role, and another policy to search for and display alert summary 209 for a user with a more privileged role. As another example, Integrator 103 can be further configured using a policy that instructs that modification command 211 and policy interface 213 should be incorporated into the security summary for a user with a role having the highest level of privilege.

[0071] Variations

[0072] The flowchart is provided to assist in the understanding of the example and should not be used to limit the scope of the claims. The flowchart shows exemplary operations that can vary within the scope of the claims. Additional operations may be performed, fewer operations may be performed, operations may be performed in parallel, and operations may be performed in a different order. It will be understood that each block of the flowchart and / or block diagram, and combinations of blocks in the flowchart and / or block diagram, can be implemented by program code. The program code can be provided to a processor of a general purpose computer, a special purpose computer, or other programmable machine or device.

[0073] As will be appreciated, aspects of the present disclosure can be embodied as a system, method, or program code / instructions stored on one or more machine-readable media. Accordingly, the aspects can take the form of hardware, software (including firmware, resident software, microcode, etc.), or a combination of software aspects and hardware aspects that can generally be referred to herein as a "circuit", "module", or "system". The functionality presented as individual modules / units in the exemplary diagrams can be organized differently depending on one or more of the platform (operating system and / or hardware), application ecosystem, interface, programmer preference, programming language, administrator preference, etc.

[0074] Any combination of one or more machine-readable media may be utilized. The machine-readable media may be a machine-readable signal medium or a machine-readable storage medium. The machine-readable storage medium may be, but is not limited to, for example, a system, apparatus, or device that employs any one or combination of electronic, magnetic, optical, electromagnetic, infrared, or semiconductor technologies for storing program code. More specific examples (a non-exhaustive list) of the machine-readable storage medium may include the following. A portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the context of this specification, the machine-readable storage medium may be any tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable storage medium (storage medium) is not a machine-readable signal medium.

[0075] The machine-readable signal medium may include, for example, a propagated data signal in which the machine-readable program code is embodied, either in baseband or as part of a carrier wave. Such a propagated signal may take any of a variety of forms, including, but not limited to, electromagnetic, optical, or any suitable combination thereof. The machine-readable signal medium is not a machine-readable storage medium and may be any machine-readable medium that can communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.

[0076] The program code embodied in the machine-readable medium may be transmitted using any appropriate medium, including, but not limited to, wireless, wireline, fiber optic cable, RF, etc., or any suitable combination of the foregoing.

[0077] Program code / instructions may also be stored in a machine-readable medium that can instruct a machine to function in a particular manner, such that the instructions stored in the machine-readable medium produce a product that includes instructions for performing the functions / operations specified in one or more blocks of a flowchart and / or block diagram.

[0078] FIG. 8 shows an exemplary computer system having a context security information integrator. The computer system includes a processor 801 (which may in some cases include multiple processors, multiple cores, multiple nodes, and / or implement multithreading, etc.). The computer system includes a memory 807. The memory 807 can be system memory or any one or more of the possible realizations of the machine-readable medium described above. The computer system also includes a bus 803 and a network interface 805. The system also includes a context security information integrator 811. The context security information integrator 811 can perform in-browser integration of context security information related to the content of a retrieved web page. Any one of the functions described previously can be implemented partially (or entirely) in hardware and / or in the processor 801. For example, functionality can be implemented in the logic implemented within the processor 801 using an application-specific integrated circuit, in a coprocessor on a peripheral device or card, etc. Further, a realization can include fewer or additional components (e.g., a video card, an audio card, an additional network interface, peripheral devices, etc.) not shown in FIG. 8. The processor 801 and the network interface 805 are coupled to the bus 803. Although shown as being coupled to the bus 803, the memory 807 may be coupled to the processor 801.

[0079] Aspects of the present disclosure have been described with reference to various implementations and uses, but it will be understood that these aspects are exemplary and the claims are not limited thereto. In general, techniques for rendering context security information determined within a browser using web pages of CSP and SaaS providers as described herein may be implemented using any hardware system or facilities consistent with a plurality of hardware systems. Many variations, modifications, additions, and improvements are possible.

[0080] Multiple instances may be provided for a component, operation, or structure described herein as a single instance. Ultimately, the boundaries between various components, operations, and data stores are somewhat arbitrary, and a particular operation is shown in the context of a particular exemplary configuration. Other assignments of functionality are assumed and may be included within the scope of the present disclosure. In general, structures and functions presented as separate components in an exemplary configuration may be implemented as a combined structure or component. Similarly, structures and functions presented as a single component may be implemented as separate components. These and other variations, modifications, additions, and improvements may be included within the scope of the present disclosure.< / button>

Claims

1. A method comprising: detecting a request for a first web page of the vendor during a login session of an account with the vendor, the first web page having a first Uniform Resource Locator (URL); identifying a match between the first URL and a first fingerprint of a plurality of fingerprints of the vendor based on evaluating the first URL against the plurality of fingerprints; determining a first type of security profile to be generated for use of the vendor associated with the account based on the first fingerprint with which the first URL matches; retrieving first security information maintained for the account with the vendor corresponding to the first type of security profile; generating the first type of security profile from the first security information; A method comprising the above steps.

2. The method further comprises: rendering the security profile using the first web page. The method according to claim 1, comprising the above step.

3. The plurality of fingerprints includes a plurality of URL patterns determined from URLs of the vendor; The vendor includes a cloud service provider or a software as a service (SaaS) provider; and The step of identifying the match between the first URL and the first fingerprint comprises: identifying a match between the first URL and a corresponding one of the plurality of URL patterns. The method according to claim 1, comprising the above step.

4. Each of the plurality of URL patterns includes a variable name; The step of determining the first type of security profile to be generated comprises: determining a substring of the first URL that matches a first variable name of the corresponding one of the plurality of URL patterns; The first variable name corresponds to a name of the service of the vendor; and The first type of security profile includes a security profile of the service of the vendor. The method according to claim 3, comprising the above steps.

5. The first security information includes at least one of security data and security metadata maintained for the account. The step of generating the security summary includes including at least one of the steps of summarizing and aggregating at least a subset of the first security information, The step of generating the security summary from the first security information includes generating the security summary from at least one of the summarized subset and the aggregated subset of the first security information, The method according to claim 1.

6. The step of generating the security summary includes modifying the Hypertext Markup Language (HTML) or Extensible Markup Language (XML) document of the first web page through the Document Object Model (DOM) of the HTML or XML document, The method according to claim 1.

7. The method further includes based on detecting a selection of an element of a second web page, determining a resource corresponding to the selected element based on a syntax pattern of the HTML or XML document of the second web page corresponding to the selected element, where the syntax pattern includes at least one of an XML Path Language (XPath) expression and a jQuery selector corresponding to a node of the HTML or XML document of the second web page, and the node includes an attribute having an indication of the resource as a value, The syntax pattern includes at least one of an XML Path Language (XPath) expression and a jQuery selector corresponding to a node of the HTML or XML document of the second web page, The node includes an attribute having an indication of the resource as a value, step and searching for second security information maintained for the resource, generating a security summary of the resource based on the second security information, rendering the security summary of the resource for display alongside the second web page, The method according to claim 1, including

8. A non-transitory computer-readable storage medium storing program code, the program code including computer instructions that, when executed, cause the computer to Detect a first event initiated by a user who requested a first web page, the first event including a search for the first web page by a web browser or a selection of an element of the first web page by the user, Based on the first event, determine which subset of a plurality of security data and metadata maintained for an account associated with the user should be retrieved, Obtain the determined subset of security data and metadata, and Integrate the determined subset of security data and metadata into the content of the first web page for rendering, A non-transitory computer-readable storage medium.

9. The first event includes a search for the first web page, The program code further includes computer instructions that, when executed, cause the computer to Match a uniform resource locator (URL) of the first web page to a first URL pattern among a plurality of URL patterns, the first URL pattern including a variable name, and a first substring of the URL matching the position of the variable name, The instructions for determining the subset of security data and metadata include instructions for determining the subset based on the first substring of the URL, The non-transitory computer-readable storage medium according to claim 8.

10. The first event includes the selection of the element of the first web page, The program code further includes instructions for evaluating the markup language document of the first web page based on a first representation describing a position in the markup language document of a display of a resource corresponding to the selected element, The instructions for retrieving the subset of security data and metadata include instructions for retrieving security data and metadata maintained for the resource based on a display of the resource corresponding to the selected element, The non-transitory computer-readable storage medium according to claim 8 or 9.

11. The instructions for evaluating the markup language document of the first web page include instructions for evaluating a hypertext markup language (HTML) or extensible markup language (XML) document, and The first expression includes at least one of an XPath expression and a jQuery selector. The non-transitory computer-readable storage medium according to claim 10. **Claim 12** An apparatus including a processor and a computer-readable storage medium storing instructions, wherein when the instructions are executed by the processor, the apparatus is caused to: detect a request for a first web page of the vendor during a login session of an account with the vendor, the first web page having a first Uniform Resource Locator (URL); identify a match between the first URL and a first URL pattern among a plurality of URL patterns defined for the vendor based on an evaluation of the first URL against the plurality of URL patterns; determine a first subset of security information maintained for searching for the account based on the first URL pattern; and integrate the first subset of the security information into the first web page as a security summary of the content of the first web page based on a search of the determined first subset of the security information. An apparatus. **Claim 13** Each of the plurality of URL patterns includes a variable name indicating which of the security information should be searched, and the instructions executable by the processor to cause the apparatus to determine the first subset of the security information include instructions executable by the processor to cause the apparatus to determine a substring of the first URL that matches a first variable name of the first URL pattern. The apparatus according to claim 12. **Claim 14** The apparatus further comprises instructions executable by the processor, and the apparatus is caused to: evaluate a markup language of a second web page based on detection of selection of an element of the second web page to determine a corresponding resource of the selected element; the instructions for evaluating the markup language include instructions for evaluating at least one of an Extended Markup Language Path Language (XPath) expression and a jQuery selector defined for the vendor. At least one of the XPath expression and the jQuery selector evaluates or selects nodes of the markup language of the second web page that include an indication of the resource, generates a security profile of the resource based on a second subset of the security information corresponding to the resource, and based on a search for the second subset of the security information, and integrates the second subset of the security information into the second web page as a security profile of the resource, The apparatus according to claim 12, causing the apparatus to perform the above.

15. The instructions executable by the processor that cause the apparatus to integrate the first subset of the security information into the first web page are to cause the apparatus to modify a Hypertext Markup Language (HTML) or Extensible Markup Language (XML) document of the first web page through a Document Object Model (DOM) of the HTML or XML document to include the first subset of the security information, The apparatus comprising instructions executable by the processor, causing the apparatus to perform the above. The apparatus according to any one of claims 12 to 14.