Browser Extension Security System for Automated Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In enterprise networks, manually reviewing and whitelisting web browser extensions is time-consuming and costly, and existing solutions lack automation, making it difficult to efficiently manage and secure browser extensions across multiple user devices.

Innovation Solution

A computer-implemented method that uses a special-purpose browser extension, known as a gatherer extension, to automatically generate risk scores for browser extensions based on requested permissions, compare these scores to organizational thresholds, and whitelist approved extensions, thereby streamlining the whitelisting process and reducing administrative burden.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network administrators manually review user requests to install browser extensions, then network security is maintained, but the review process is time-consuming and reduces productivity

Engineering Contradiction:
Improvenetwork securityVSAvoidextension installation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service by allowing browser extensions to automatically assess their own risk levels and submit whitelisting requests based on predefined organizational policies, eliminating the need for manual administrator review of low-risk extensions while maintaining security oversight

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

An automated risk assessment system acts as an intermediary between extension developers and network administrators, evaluating extensions against organizational security policies and automatically approving or flagging them for review, thereby reducing administrator workload while maintaining security standards

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If end-users are permitted to install browser extensions without oversight, then ease of operation is improved, but network security is compromised

Engineering Contradiction:
Improveextension installation convenienceVSAvoidnetwork security risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Extensions perform self-assessment of their risk characteristics and automatically submit whitelisting requests, enabling users to install safe extensions without administrator intervention while maintaining security controls for potentially harmful extensions

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary risk assessment and automated evaluation of extensions before they are installed on user devices, pre-approving low-risk extensions and blocking or flagging high-risk extensions, thereby preventing security issues before they affect the network

Inventive Principle:
Principle #10Preliminary action

3Productivity

If automated risk assessment is implemented for browser extensions, then productivity is improved by reducing manual review, but device complexity increases due to the assessment system

Engineering Contradiction:
Improveextension management efficiencyVSAvoidwhitelisting system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The risk assessment system is segmented into modular components including risk evaluation modules, policy enforcement modules, and automated decision-making modules, allowing the complex functionality to be distributed and managed in manageable units across the browser and server infrastructure

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11468172B2Browser extension security system
Publication Date: 2022.10.11 CISCO TECHNOLOGY INC
  • US11468172B2 patent drawing
  • US11468172B2 patent drawing
  • US11468172B2 patent drawing

AI summary

Presented herein are techniques for automatically generating information about risks associated with browser extensions used by browsers in an enterprise network for purposes of determining whether to whitelist a browser extension in response to a request from a user. A request to install a browser extension is obtained from a user device of a plurality of user devices associated with an organization, wherein the request comprises an extension identifier for the browser extension. A risk score is generated for the browser extension based on risk values for each of one or more permissions requested by the browser extension. The risk score is compared to a threshold value to determine whether the browser extension satisfies risk standards of the organization, and if so, the browser extension is automatically added to a whitelist of permitted extensions for future installation on the plurality of user devices.