Dynamic Field Re-rendering for Web Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web content is vulnerable to malicious automation and interception by bots and other malicious software, which can exploit user interface elements to gather sensitive information or intercept user input, posing a threat to legitimate users and web servers.

Innovation Solution

Modifying web code, such as HTML and JavaScript, before it is served to clients by introducing multiple elements that visually overlap and split user input, making it difficult for malicious software to intercept and interpret data, while also adding distracting information and changing element names randomly to create a moving target, and incorporating instrumentation code to detect anomalous behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If web code is modified by replacing elements with multiple overlapping elements, then security against malicious automation is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against malicious automationVSAvoidweb code structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by replacing a single user interface element with multiple separate elements that visually overlap. Each element receives a portion of the input data, breaking up the data stream to prevent interception and interpretation by malicious software. The server system later reassembles the fragmented data into its original form, maintaining functionality while enhancing security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary server system that modifies web code between the original server and the client. This intermediary replaces elements with multiple overlapping elements, adds distracting information, and manages the complexity of the modifications centrally, allowing the original web application to remain simple while the client-side experience becomes more secure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If multiple overlapping elements are used to split user input, then difficulty of intercepting and interpreting data is improved, but manufacturing precision of data transmission is worsened

Engineering Contradiction:
Improveinterception and interpretation of dataVSAvoiddata reassembly accuracy
Core Design Contradiction:
Object-affected harmful factorsVSManufacturing precision

Solution Approach 1:

The patent implements feedback mechanisms where the server system receives fragmented data from multiple overlapping elements and uses feedback information (such as element identifiers or positioning data) to accurately reassemble the original data stream. This ensures that despite the fragmentation and visual overlapping, the data reassembly precision maintains the integrity of the original user input.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9584534B1Dynamic field re-rendering
Publication Date: 2017.02.28 SHAPE SECURITY INC
  • US9584534B1 patent drawing
  • US9584534B1 patent drawing
  • US9584534B1 patent drawing

AI summary

A computer-implemented method involves identifying an initial element for serving by a web server system to a client device and recoding the element by creating a plurality of different elements that each represent a portion of the initial element. The different elements are then served in place of the initial element. A response is received form the client device and has portions that correspond to the different elements, and a combined response is created by combining the received portions in a manner that corresponds to a manner in which the initial element was recoded to create the plurality of different elements.