Headless Browser Data Leakage Detection and Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Webpages using third-party sub-resources can compromise user privacy and security without the user's knowledge or consent, as data leakage occurs hidden from the user's view.

Innovation Solution

A computer-implemented method using a headless browser to detect data leakage from webpages and provide users with real-time notifications to authorize or prevent such leakage, employing remedial actions like blocking communication with third-party systems or preventing data storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a webpage uses third-party sub-resources to add dynamic functionality, then the webpage becomes more useful, but user privacy and security are compromised without user knowledge

Engineering Contradiction:
Improvewebpage functionalityVSAvoiddata leakage
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary detection of data leakage risks before the user is affected. A headless browser proactively visits the webpage and analyzes third-party sub-resources to detect potential data leakage mechanisms in advance, allowing the system to warn or block the user before actual data compromise occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a headless browser as an intermediary between the user's browser and the webpage. This intermediary analyzes the webpage content and third-party resources without the user directly interacting with them, detecting data leakage risks and providing warnings to the user before actual data transmission occurs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If third-party sub-resources are allowed to operate hidden from the user, then the webpage can function dynamically, but data leakage occurs without user consent

Engineering Contradiction:
Improvewebpage operationVSAvoiduser data leakage
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system implements feedback by continuously monitoring third-party sub-resource operations and providing real-time information to the user. When the headless browser detects data leakage attempts by third-party resources, it generates warnings that are presented to the user, enabling informed consent or rejection of data transmission.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The headless browser serves as an intermediary that makes hidden third-party operations visible to the user through warnings. It intercepts and analyzes communications between the webpage and third-party systems, translating hidden data leakage attempts into user-comprehensible alerts that enable informed decision-making.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a headless browser is used to detect data leakage in parallel, then data leakage can be detected, but system resources and processing time increase

Engineering Contradiction:
Improvedata leakage detectionVSAvoidbrowser system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates a copy of the webpage analysis process using a headless browser that operates in parallel with the user's visible browser. This copy performs security analysis without requiring the user to interact with a second interface, detecting data leakage risks while the user experiences normal browsing.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The headless browser is designed as a temporary, disposable analysis environment that is created when needed for security scanning and discarded after analysis. This approach avoids the need for permanent complex security infrastructure, using lightweight automated scripts that perform detection and are then discarded.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS10902135B1Thwarting data leakage from a webpage
Publication Date: 2021.01.26 GEN DIGITAL INC
  • US10902135B1 patent drawing
  • US10902135B1 patent drawing
  • US10902135B1 patent drawing

AI summary

Thwarting data leakage from a webpage. In some embodiments, a method may include detecting, at a browser on the network device, a visit to the webpage, directing a headless browser on the network device to visit the webpage in parallel to the browser visiting the webpage, detecting, at the headless browser, data leakage from the webpage, presenting, at the browser, a notification regarding the data leakage that allows a user to indicate whether the data leakage should be allowed, receiving, at the browser, an indication that the data leakage should not be allowed, and in response to receiving the indication that the data leakage should not be allowed, thwarting the data leakage by performing a remedial action at the network device to protect the network device from the data leakage.