Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

393 results about "Web application" patented technology

In computing, a web application or web app is a client–server computer program that the client (including the user interface and client-side logic) runs in a web browser. Common web applications include webmail, online retail sales, online banking, and online auction.

Web application internationalization

A system and method is described for internationalization of web pages by extracting translatable content from extensible mark-up language (XML), or similar data-centric meta-language representations of web pages or data used to build web pages. The extracted translatable content is stored in a translation task repository (TTR) accessible by the web developer and the translator. The XML representation is then modified to include selection control logic to select the appropriate translations for insertion into the final web page. The translator accesses the TTR to translate the appropriate content and saves the translations back to the TTR associated with the original translatable data. The translations are obtained from the TTR as selection cases for the selection control logic of the XML representation. As the XML is converted into the web source code, the selection logic and translations are embedded therein facilitating building the web site in multiple different languages.
Owner:ADOBE INC

File uploading attack interception method based on semantic entropy enhancement

The invention provides a file uploading attack interception method based on semantic entropy enhancement, and aims at overcoming the defects of an existing file uploading security protection technology in the face of complex attacks. The method specifically comprises the steps that S1, file format analysis and content extraction are conducted, hidden scripts are mined through nested content recognition, and intermediate representation is generated through grammar cleaning and coding specifications; s2, constructing an abstract syntax tree and semantic entropy calculation, tracking a pollution chain, analyzing a high-risk function, identifying a high-entropy character string, modeling and controlling flow complexity, and generating a semantic entropy vector; s3, dynamic scoring and decision making are carried out, and accurate judgment is carried out in combination with white list perception, feature comparison, multi-modal model scoring, adaptive threshold and sandbox observation; and S4, carrying out real-time interception and feature synchronization, blocking malicious file landing, generating an attack log and synchronizing an attack fingerprint. The method takes the semantic entropy vector as a core, breaks through the limitation of static features, remarkably improves the recognition rate of complex attacks, reduces missed judgment, and guarantees the safety of Web applications.
Owner:CHINA LIFE INSURANCE CO LTD

XML semantic editing system and method based on aviation knowledge graph

The invention belongs to the field of Web application technology, XML document processing technology and online editor technology, and discloses an XML semantic editing system based on an aviation knowledge graph. The system comprises a front-end application module, an XML processing engine module, a DTD rule verification module, a visual editing module, a plug-in extension module, a collaborative editing module and an aviation knowledge graph integration module. According to the method, professional and efficient editing of XML documents in the aviation field is achieved through the full-process design of front-end interaction, XML processing, DTD verification, visual editing, semantic assistance and collaborative management, and the Web technology, the XML processing technology, the DTD verification technology, the knowledge graph technology and the collaborative editing technology are integrated, so that the XML documents in the aviation field are edited in a professional and efficient mode. The problems that an existing XML editing tool is difficult to deploy, poor in compliance, low in efficiency and weak in cooperation in the aviation maintenance field are solved, and a specialized and efficient XML semantic editing scheme is provided for the aviation maintenance industry.
Owner:WUHAN YIFAN IOT TECHNOLOGY CO LTD

Voice Interface Integration System and Method for Mobile, Computer and Web Applications

A method for voice-based interaction between a user (e.g., a shopper) and online stores includes capturing an initial voice input from a user and converting the voice input to text. The text is analyzed and initial search terms are created such as product name, product description, product category, product brand name, product manufacturer and retailer. One or more searches are conducted using the initial search terms to identify one or more retailers meeting the search terms. One or more identified online retailers are accessed and searches are executed at the one or more identified retailers, generating search results. The identified online retailers have a user interface allowing purchases of the identified product or item. The search results are returned to the user.
Owner:OMNIBEK IP HLDG LLC

System And Methods Of Defense Against DDoS Attacks Via Autonomous Agents For Applications On A Multi-Substrate Multi-Ingress Shared Infrastructure With Multiple Cloud Architectures

A computing services environment may include application gateways receiving application-layer request messages from various sources. The computing services environment may also include an autonomous agent platform configured to instantiate and execute an autonomous agent to evaluate network traffic associated with a portion of the computing services environment. The computing services environment may also include an orchestration engine configured to determine one or more mitigation policies corresponding with one or more of the application gateways based on identification of the application-layer distributed denial of service attack by the autonomous agent. The computing services environment may also include application-layer web application firewalls corresponding to the plurality of application gateways and implementing the one or more mitigation policies to prevent a subset of subsequent application-layer request messages from the subset of the sources from reaching one or more components of the computing services environment.
Owner:SALESFORCE INC

Autonomous Agent Generation, Review, And Correction Of Mitigation Plans Against DDoS Attacks In A Shared Infrastructure Computing Environment

A computing services environment may include application gateways receiving application-layer request messages from a plurality of sources. The computing services environment may also include an orchestration engine configured to identify an application-layer distributed denial of service attack based on input data characterizing network traffic received at the application gateways and to determine a mitigation plan update to address the application-layer distributed denial of service attack. The computing services environment may also include an autonomous AI agent platform configured to instantiate and execute an autonomous AI agent instance configured to determine whether to approve or reject the mitigation plan update by evaluating the mitigation plan update via a generative language model. The computing services environment may also include application-layer web application firewalls corresponding to application gateways. The orchestration engine may instruct the application-layer web application firewalls to implement the mitigation plan update upon approval by the autonomous AI agent instance.
Owner:SALESFORCE INC

Web application firewall attack real-time traceability system based on real-time monitoring

The invention discloses a web application firewall attack real-time traceability system based on real-time monitoring, and relates to the technical field of monitoring analysis, and the system comprises the steps: carrying out the attack behavior fingerprint clustering analysis according to the attack technique difference data, obtaining the attack behavior fingerprint clustering data, carrying out the cross-session attack association evaluation based on the attack behavior fingerprint clustering data, and carrying out the cross-session attack association evaluation based on the cross-session attack association evaluation. Cross-session attack association data is obtained, and attacker group portrait estimation is carried out according to the cross-session attack association data to obtain attacker group portrait data; performing context influence factor identification on the attacker group portrait data to obtain a context influence factor, and performing portrait correction on the attacker group portrait data based on the context influence factor to obtain corrected attacker group portrait data; and carrying out attacker traceability model construction on the corrected attacker group portrait data to obtain an attacker traceability model so as to execute attack real-time traceability and alarm response. The method has the effect of improving the attack tracing efficiency.
Owner:CGN INTELLECTUAL TECH SHENZHEN CO LTD

System and method for predictive protection of cloud-based applications and services

Apparatus and method for predictive protection of cloud-based applications and services. For example, a web application firewall (WAF) detects vulnerabilities in the data traffic and collects relevant information including, for example, the payload type, structure, and specific vulnerability information. For certain vulnerabilities associated with views, the view document object model (DOM) and history of views may be collected. For vulnerabilities related to API calls, the corresponding the API path and history of API calls may be retrieved. The WAF includes a signature controller which decodes the payload (e.g., the JavaScript Object Notation (JSON) structure) and creates a signature of the vulnerability based on the relevant information including, but not limited to, the API path, the web application domain, and / or the URL path. The WAF distributes collected and generated vulnerability information to web browser extensions of the web application which perform mitigations such as generating notifications when a vulnerability is encountered.
Owner:SALESFORCE INC

Web application firewall rule generation method and device, equipment and medium

The invention relates to a Web application firewall rule generation method and device, equipment and a medium, and the method comprises the steps: obtaining attack feature description information based on log information, latest vulnerability information and user demand information through a large language model; the log information comprises Web request information sent by the client; the newest vulnerability information represents newest vulnerabilities injected in the Web request information; the user demand information represents Web request information needing to be protected by the Web application firewall; calling a target tool through a model context protocol module; generating a Web application firewall rule based on the attack feature description information through the target tool; the target tool is a tool related to Web application firewall rule generation, and the efficiency and accuracy of Web application firewall rule generation are improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Using an LLM to generate API and application vulnerability mitigation policies for API gateways, web application firewalls, next generation firewalls, and IPS / IDS tools

The method for generating mitigation policies may include receiving, by a large language model (LLM), a plurality of inputs including textual description of vulnerabilities, code with one or more vulnerability exploits, and meta-data; generating, by the LLM, API and application vulnerability mitigation policies based on the received inputs; generating, by a feedback loop automation engine (FLAE), feedback data based on the API and application vulnerability mitigation policies and the code with one or more vulnerability exploits; and updating, by the LLM, the API and application vulnerability mitigation policies based on the feedback data generated by the FLAE.
Owner:WALLARM INC

Service layer methods for offloading IoT application message generation and response handling

A service layer may be configured to offload requests and responses on behalf of IoT applications in order to reduce congestion and / or overhead on underlying networks, applications and devices. The service layer may be enabled with the capability to script and generate IoT application requests such that the requests can be initiated by the service layer without the IoT application having to re-issue the same request repeatedly (e.g., to periodically retrieve a sensor reading). This scripting may be initiated by request originators. The service layer may support the capability to monitor and detect repetitive request patterns and initiate the scripting itself. This scripting functionality may enable the service layer to perform operations on behalf of IoT applications. As a result, the messaging overhead on IoT applications and devices as well as underlying networks can be minimized.
Owner:IPLA HLDG INC

Methods and systems for identifying phishing attacks

Provided are systems, software, and methods for phishing analysis and detection. The provided systems, software, and methods may comprise interfaces configured to capture and scan network session activity in real-time to detect a phishing attack using a set of trained machine learning classifiers, detect a phishing attach, classify the attack into one or more phishing classes, block the phishing attack and provide a safe preview of the blocked phishing attack. The machine learning classifiers may be deployed remotely. The systems, software, and methods may further comprise a web application programing interface configured to integrate the one or more analysis interfaces into at least one external software or application.
Owner:VARONIS SYSTEMS INC

Security test system

To grasp appropriate operation procedures of a Web site including operation with sequentiality and to efficiently / effectively perform automatic patrol.SOLUTION: A security test system 1 examining whether or not there is security vulnerability in a Web application acquires and analyzes a Web page to be patrolled in an object Web site 3, sets to prompt information related to a content of the acquired Web page, and inputs it to a LLM 4, creates operation procedure information on the Web page, simulates operation regarding the Web page according to the operation procedure information, acquires an URL related to a link in the Web page, and registers it to a page list 14 to be patrolled.SELECTED DRAWING: Figure 1
Owner:UB SECURE CO LTD

AI-Driven Defect Remediation System Based on Bias Detection

PendingUS20260086928A1Software testing/debuggingEngineeringDistributed testing
Systems and methods for bias testing and remediation are disclosed. Decentralized Web Application Testing Systems use a Holochain framework to distribute testing workloads across Full Nodes and Lightning Nodes. A Holochain Node Management Application for configuring nodes, a UI Application creates test cases, and a Version Management System tracks changes. Test results are stored and analyzed in a Test Result Store, with a Bias Intelligence module detecting biases and generating additional test cases. A Consensus Algorithm validates test cases through decentralized nomination. An AI-Driven Defect Remediation System automates defect detection, root cause analysis, and remediation using AI modules. Machine learning algorithms identify patterns and anomalies, while NLP techniques generate code fixes. Predictive maintenance monitors application performance to preemptively address issues. A feedback loop mechanism continuously improves AI models through reinforcement learning. Together, these systems provide a holistic approach to web application testing and maintenance.
Owner:BANK OF AMERICA CORP

Web application observability with distributed tracking and custom header

A method is provided that includes injecting a trace agent within a side-car container on a first microservice that runs in a point-of-delivery (POD) on a compute device; when an API request is made from the first microservice to a second microservice the trace agent adds traceability metadata in a header within application data of the API request and within an application-layer protocol header of the API request. A mapping table is generated or updated, the mapping table including entries for identification information associated with the API request. When an API reply is received at the first microservice from the second microservice, the identification information in the mapping table is updated. The mapping table may be exported to a collector device that is configured to reconcile API communications between the first microservice and the second microservice using contents of the mapping table.
Owner:CISCO TECHNOLOGY INC

Network security data analysis method and system based on large model, and medium

The invention relates to the technical field of network security, in particular to a network security data analysis method and system based on a large model and a medium. According to the technical scheme, the network security data analysis method based on the large model comprises the following steps: acquiring a multi-source heterogeneous log in real time from a firewall, an intrusion detection system or an intrusion prevention system, a Web application firewall, a server operating system and a service application through a distributed acquisition agent; performing data cleaning on the original log: removing repeated entries, filling missing fields, unifying a timestamp format, and extracting key structured fields including a source IP address, a target IP address, an operation type and a user ID; and performing deep semantic analysis on the cleaned log by using a pre-training large model based on a Transform architecture, and generating vectorized feature representation fused with context semantics. The semantic understanding accuracy of security terminologies is remarkably improved, and the misjudgment defect caused by domain knowledge deficiency of a traditional model is thoroughly overcome.
Owner:STATE GRID HEBEI ELECTRIC POWER CO LTD +1

Electronic device and method for using web application

A method of an electronic device according to an embodiment of the present disclosure may comprise the operations of: identifying switching from a first user account to a second user account while a web application is being executed on the basis of the first user account; on the basis of identifying the switching from the first user account to the second user account, changing cookie data for a web browser used for executing the web application from first cookie data associated with the first user account to second cookie data associated with the second user account while maintaining the execution of the web application; and receiving a user input for executing the web application on the basis of the second user account. Maintaining execution of the web application may include maintaining execution of at least one process associated with the web application.
Owner:SAMSUNG ELECTRONICS CO LTD

Launching versions of cloud based enterprise multi tenant web applications based on tenant

One or more systems, computer program products and / or computer-implemented methods provided herein relate to launching different versions of an enterprise multi-tenant cloud based web application in a single URL. Accordingly, a system can comprise a memory that stores computer executable components. The system can further comprise a processor that executes at least one of the computer executable components. The computer executable components can comprise an origin component that retrieves application version metadata, determines a first origin corresponding to a first version of an application and a second origin corresponding to a second version of the application, and resolves a network route to either the first origin or the second origin. The computer executable components can further comprise a token component that generates a token, embeds a claim within the token, and issues the token. The computer executable components can additionally comprise a compatibility component that selects which origin to use.
Owner:GE PRECISION HEALTHCARE LLC

Reusable generic worker for secure loading and compilation of WebAssembly in web applications

A system for secure dynamic loading and execution of web workers and WebAssembly modules in web-based communication applications employs a reusable generic worker approach. The system includes a main application executing in its own environment subject to a first content security policy, which loads a first web worker from a resource indicated by this policy. The first web worker executes in its own environment, specifies a second content security policy, and dynamically loads and executes additional web workers or compiles WebAssembly modules upon request from the main application. This approach improves flexibility, efficiency, and security by offloading resource-intensive tasks, simplifying security implementations, enhancing scalability, and boosting performance for real-time audio and video processing in communication applications.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Automated login framework for interacting with dynamically generated login forms

ActiveUS12719858B2Web applicationWeb browser
An automated login framework for dynamic application security testing is disclosed. A web application executing on a computing device is accessed and an automated login framework (ALF) is injected into an onload event of a web browser associated with the web application. The ALF is then accessed with a credential associated with the web application. A login page associated with application is identified by matching links or buttons with a user-defined regular expression and a user-defined wordlist. Then, a login form in the login page is detected by executing a signature technique, a dictionary technique, and a multistep signature technique. The login form is populated using the credential and submitted for authentication, and a status with a confidence score is received indicating whether the authentication was successful or failed.
Owner:RAPID7 INC

Data processing method, device and equipment of web application, and readable storage medium

The application provides a webpage application data processing method and device, equipment and readable storage medium; the method comprises the following steps: sending the path of a dynamic link library to a browser process in a browser embedded framework through a host process, so as to trigger the browser process to create a webpage application; creating a rendering process through the browser process, wherein the rendering process is used for rendering a data item in the webpage application; calling an extension plug-in in the browser embedded framework through the rendering process to perform the following processing: loading the dynamic link library according to the path, and starting a calculation thread; sending the data item to the calculation thread through the browser process, so as to trigger the calculation thread to obtain the calculation result of the data item through a calculation function in the dynamic link library; sending the calculation result to the rendering process through the browser process, so as to trigger the rendering process to display the calculation result in the webpage application. Through the application, the data processing efficiency of the webpage application can be improved and the memory occupation can be reduced.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

A cross-application communication method, system and device based on a micro-frontend architecture and a storage medium

The application relates to the technical field of front-end architecture, in particular to a cross-application communication method, system and device based on a micro front-end architecture and a storage medium. The cross-application communication system based on the micro front-end architecture comprises a communication hub module, a protocol standardization module, a security handshake module, a routing distribution module and a state synchronization module. With the development of enterprise-level web applications in the direction of modularization and multi-team cooperation, the micro front-end architecture becomes a key technology for solving the splitting and integration of complex applications.
Owner:BEIJING DAOYUN SURVEYING & MAPPING TECH CO LTD

Transaction method with multimedia data display

The invention relates to a transaction method comprising the steps of: during a payment transaction between a customer and a merchant (ML1), establishing a communication link between a payment terminal (TP1) of the merchant and a mobile terminal (MT1) of the customer; acquiring, via the payment terminal (TP1), a payment device identifier (CI1); transmitting transaction data to a server (PSRV); transmitting, via the server, to the customer's terminal an access link (PNLK) to an application (WP); upon activation of the access link, transmitting, via the mobile terminal, to the server, an access request to the application containing the access link and the payment device identifier; upon receipt of the access request, generating and transmitting, via the server, a progressive web application to the mobile terminal; and receiving and executing the application via the mobile terminal. Figure 2
Owner:BANKS & ACQUIRERS INT HLDG SAS

A black box web vulnerability scanning entry collection method and device

The application discloses a black box Web vulnerability scanning entry collection method and device, and relates to the technical field of network security. The method comprises the following steps: identifying all the interactive elements in a Web page by traversing a DOM tree; obtaining events bound to each interactive element; performing simulation operation on the events bound to each interactive element; judging whether a new Web page generated in response to the simulation operation reaches a stable state; if yes, traversing an updated DOM sub-tree, locating newly added interactive elements in the current Web page, and performing deduplication processing on the newly added interactive elements; repeatedly performing the above steps on the new Web page until a maximum recursion depth is reached or the Web page no longer generates new interactive elements. The application improves the authenticity and comprehensiveness of Web application request collection, thereby improving the detection rate of black box Web vulnerabilities.
Owner:BEIJING CHAITIN TECH CO LTD +1

Web application low-performance terminal adaptation method and system based on layered rendering

The invention discloses a Web application low-performance terminal adaptation method and system based on layered rendering, and belongs to the technical field of Web graphic rendering and cloud computing crossing. Performing layered rendering and publishing; and subscribing and synthesizing by a terminal. According to the method, a'one-step 'full-frame transmission mode is abandoned, the computing load is optimally distributed between the cloud and the terminal by performing structured layering on the rendering content at the cloud and dynamically adapting the transmission strategy according to the terminal performance and the network condition, and thus the dependence on the network bandwidth and the requirement on the terminal performance are greatly reduced.
Owner:USTC SINOVATE SOFTWARE

Accelerating in-browser tasks for unprivileged web applications

The device establishes a communication channel between a first web application executing within a first browsing context and a second web application executing within a second browsing context, the first browsing context being not cross-source isolated and the second browsing context being cross-source isolated. This includes loading the proxy page within a third browsing context of the web browser, the loading initiated by the first browsing context, and loading the worker instance using a script provided by the proxy page. The content of the proxy page is served by a source associated with the second web application. The device passes the first message from the first web application to the second web application over the communication channel. The first message requests the second web application to execute the compute job. The device also passes a second message from the second web application to the first web application, the second message including a result of the computing job.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Systems and methods for calendar sharing by enterprise web applications

The described technology relates to integrating events electronically scheduled in enterprise web applications and other event applications. A capability is provided for events created by an enterprise web application and events from other external event streams to be presented in a consolidated calendar in the enterprise web application. Capabilities are also provided for sharing the calendar among enterprise users and non-enterprise users, and for efficiently generating the shared calendar.
Owner:NASDAQ INC

Ai conversation driven login

A login agent interacts with a foundation model(s) until successful login to an application or an assessment of a failed login can be obtained. Initially, a web page corresponding to login for a web application will be indicated to the login agent. The login agent captures interactive elements of the web page. The login agent prompts a foundation model(s) to select which of the captured interactive elements to interact with and how to interact with the selected elements. The login agent determines commands based on the response(s) and, with the commands, uses a tool to automatically interact with the web page via a browser. The login agent captures a web page resulting from the user emulated interaction and prompts the foundation model(s) to determine whether log in was successful or failed. The response from the foundation model(s) guides the login agent to either retry login or report results.
Owner:VERACODE INC

Systems and methods for automated website security testing

Systems and methods are provided for automated website security testing. The systems and methods reduce or eliminate the need for a user to manually click through a web application to perform application security testing by embedding one or more API calls to the application security testing service within an already-existing automated user interface test. When a web page is reached during the user interface that that is desired to be tested using the application security test, a cookie associated with the web page is obtained and provided to the API associated with the application security test. The application security test then returns a result and the user interface test continues. Any number of additional API calls for to the application security test service may be performed for any other number of web pages as the user interface test progresses through the web pages as well.
Owner:AMAZON TECH INC