Cloud-Based Web Session Auditing via Client-Side Header Capture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for auditing network applications, particularly in e-commerce and web-based services, face challenges in accurately capturing and analyzing user interactions due to uncertainty in data communication and lack of rationale for incomplete transactions, with server-side capture being costly and inflexible, and client-side capture being impractical for diagnosing conversion barriers.
Innovation Solution
A method and system that captures server and request headers during a web session, using code modules to send uplink journey reports to a processing server for real-time interaction interpretation, coupled with a neural network to identify anomalies and correlations, allowing for flexible and comprehensive auditing without the need for a network TAP behind a firewall.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If server-side capture is used to audit network applications, then comprehensive data can be captured, but it is costly and inflexible
Solution Approach 1:
The patent introduces a data TAP (Traffic Access Point) as an intermediary component that sits between the server and the audit system. This TAP captures network traffic without requiring changes to the existing server infrastructure, thereby providing comprehensive data capture while reducing the complexity and cost of server-side implementation. The TAP acts as a mediator that enables auditing functionality without directly modifying the server system.
2Reliability
If a network TAP is placed behind a company firewall for on-premise delivery, then data security is maintained, but access and installation issues arise
Solution Approach 1:
The patent implements a cloud-based capture box that creates a virtual copy of the on-premise audit system. Instead of requiring physical installation behind firewalls, the system replicates the auditing functionality in the cloud, allowing remote access and analysis of user journeys while maintaining security through controlled data transmission channels. This copying approach eliminates installation barriers while preserving security requirements.
3Measurement precision
If client-side capture with tag code is implemented, then local events can be captured, but it is complex and expensive to implement
Solution Approach 1:
The patent extracts the complex client-side capture logic from the end-user browser and consolidates it into a centralized cloud-based capture box. The system uses simplified client-side agents that only need to transmit basic telemetry data, while the complex analysis, event correlation, and processing functions are performed remotely in the cloud. This extraction reduces client-side complexity while maintaining comprehensive event capture capability.
4Reliability
If on-premise data storage is required for auditing, then data control is maintained, but system deployment becomes time-consuming and expensive
Solution Approach 1:
The patent transitions the audit system from a single on-premise dimension to a multi-dimensional architecture combining cloud-based capture box, remote servers, and hybrid data storage. User journey data can be stored and processed in the cloud while maintaining the option for on-premise storage if required. This dimensional shift enables rapid deployment through cloud services while preserving data control options, eliminating the time-consuming setup of traditional on-premise systems.
Data Source
AI summary
An auditing system and method is configured to capture and report an interactive client journey between a web browser and a website. Instantiation of control code at an end-user computing device brings about the capture of server and request headers from the perspective of the locally-executing web browser. The control code causes the sending of an uplink journey report to a cloud-based processing server that uses the report to interpret the server and request headers to imply real-time interactions between the end-user. Capture may be based on AJAX requests related to end-user interaction; and data calls made to the e-commerce server during the web session. Client-side capture provides installation of control code that can be delivered directly from a content distribution network. The processing server correlates the server and request headers with predefined flagged events.


