Client/server security by an intermediary rendering modified in-memory objects
Summary by NHIP
Intermediary Client Security Method
A method intercepts server instructions defining objects, executes them via a headless browser to create data structures, and renders distinct second instructions for a remote client. The system caches these instructions and sends them to additional clients after determining the intercepted third instructions are equivalent to the original first set.
Claim Score by NHIP
Abstract
In an embodiment, a method comprises intercepting, from a server computer, a first set of instructions that define one or more objects and one or more operations that are based, at least in part, on the one or more objects; generating, in memory, one or more data structures that correspond to the one or more objects; performing the one or more operations on the one or more data structures; updating the one or more data structures, in response to performing the one or more operations, to produce one or more updated data structures; rendering a second set of instructions, which when executed by a remote client computer cause the remote client computer to generate the updated data structures in memory on the remote client computer, wherein the second set of instructions are different than the first set of instructions; sending the second set of instructions to the remote client computer.

Term
Projected expiry 25 February 2034.
- Priority and filed
- Granted
- Today
- Projected expiry
20 claims: 4 independent, 16 dependent
- 1Broadest claimClaim Score 29, narrow(NHIP)A method comprising:intercepting, from a server computer, a first set of instructions that define one or more objects;executing, by a headless browser, the first set of instructions to produce one or more data structures in memory that correspond to the one or more objects;updating the one or more data structures based, at least in part, on a configuration to produce one or more updated data structures;rendering a second set of instructions that are configured to cause a remote client computer, when executed by the remote client computer, to generate the one or more updated data structures in memory on the remote client computer, wherein the second set of instructions are different than the first set of instructions;sending the second set of instructions to the remote client computer;caching the second set of instructions;intercepting a third set of instructions;determining the first set of instructions and the third set of instructions are equivalent;in response to determining the first set of instructions and the third set of instructions are equivalent;sending the second set of instructions to a second remote client computer;wherein the method is performed by one or more computing devices.
- 9A method comprising:intercepting, from a web server computer, over HTTP, an original HTML document, a set of original Cascading Style Sheets (CSS) codes, and a set of original JavaScript codes that define one or more objects in an original Document Object Model (DOM) and one or more operations that are based, at least in part, on the one or more objects in the original DOM;executing the original HTML document, the set of original CSS codes, and the set of original JavaScript codes by a headless browser to produce one or more data structures in memory that correspond to the one or more objects in the original DOM;updating the one or more data structures based, at least in part, on a configuration to produce one or more updated data structures;rendering a modified HTML document, a set of modified CSS codes, and a set of modified JavaScript codes, which are configured to cause a remote client computer, when processed by the remote client computer, to generate the one or more updated data structures in memory on the remote client computer;wherein the modified HTML document defines a modified DOM that is different than the original DOM;wherein the modified HTML document, the set of modified CSS codes, and the set of modified JavaScript codes are different than the original HTML document, the set of original CSS codes, and the set of original JavaScript codes;generating a DOM mapping between the modified DOM and the original DOM;storing the DOM mapping;sending the modified HTML document, the set of modified CSS codes, and the set of modified JavaScript codes to the remote client computer;intercepting, from the remote client computer, a request based on the modified DOM;translating the request based, at least in part, on the DOM mapping to produce a translated request based on the original DOM;sending the translated request to the web server computer;wherein the method is performed by one or more computing devices.
- 11A computer system comprising:a server computer configured to receive requests from a browser executed on a remote client computer and to send data to the browser in response to received requests;an intermediary computer communicatively coupled the server computer and comprising: a memory;a browser backend module configured to intercept, from the server computer, a first set of instructions that define one or more objects and to execute the first set of instructions to produce one or more data structures in the memory that correspond to the one or more objects;a forward translation module configured to update the one or more data structures based, at least in part, on a configuration to produce one or more updated data structures;to render a second set of instructions that are configured to cause the remote client computer, when executed by the remote client computer, to generate the one or more updated data structures in memory on the remote client computer, wherein the second set of instructions are different than the first set of instructions;to send the second set of instructions to the remote client computer;wherein the browser backend module is further configured to: intercept a third set of instructions;to determine the first set of instructions and the third set of instructions are a same set of instructions;wherein the forward translation module is further configured to: cache the second set of instructions;in response to determining the first set of instructions and the third set of instructions are the same set of instructions, sending the second set of instructions that is cached to a second remote client computer.
- 19A computer system comprising:a web server computer configured to receive requests from a web browser executed on a first remote client computer;to send HTML, Cascading Style Sheets (CSS), and JavaScript codes over HTTP to the web browser in response to received requests;an intermediary computer communicatively coupled the web server computer and comprising;a memory;a browser backend module configured to intercept, from the web server computer, over HTTP, an original HTML document, a set of original CSS codes, and a set of original JavaScript codes that define one or more objects in an original Document Object Model (DOM) and one or more operations that are based, at least in part, on the one or more objects in the original DOM;to execute the original HTML document, the set of original CSS codes, and the set of original JavaScript codes by a headless browser to produce one or more data structures in memory that correspond to the one or more objects in the original DOM;a forward translation module configured to update the one or more data structures based, at least in part, on a configuration to produce one or more updated data structures;to render a modified HTML document, a set of modified CSS codes, and a set of modified JavaScript codes, which when processed by a remote client computer cause the remote client computer to generate the one or more updated data structures in memory on the remote client computer;to generate a DOM mapping between a modified DOM and the original DOM;to send the modified HTML document, the set of modified CSS codes, and the set of modified JavaScript codes to the first remote client computer;wherein the modified HTML document defines the modified DOM, which is different than the original DOM;wherein the modified HTML document, the set of modified CSS codes, and the set of modified JavaScript codes are different than the original HTML document, the set of original CSS codes, and the set of original JavaScript codes;a transaction store configured to store the DOM mapping;a reverse translation module configured to intercept, from the remote client computer, a request based on the modified DOM;to translate the request based, at least in part, on the DOM mapping to produce a translated request based on the original DOM;to send the translated request to the web server computer.
Independent claims4
174 paragraphs in 11 sections, as filed
FIELD OF THE DISCLOSURE
The present disclosure generally relates security techniques applicable to client/server systems, and relates more specifically to techniques for improving the security of web applications and data sent and/or received between web servers hosting the web applications and browser programs and/or components of browsers.
BACKGROUND
The approaches described in this section are approaches that could be pursued, but not necessarily approaches that have been previously conceived or pursued. Therefore, unless otherwise indicated, it should not be assumed that any of the approaches described in this section qualify as prior art merely by virtue of their inclusion in this section.
Computer fraud performed by obtaining information in non-secure communications transmissions between browser programs and server computers is big business for fraudsters. Fraud can be perpetrated by obtaining financial or personally identifying information that end users provide while using a browser to communicate with an application server computer. For example, in an exploit commonly termed “Man in the Browser”, a user's computer can be provided with malicious code that collects data from legitimate communications, such as communications with the user's bank. After the communications have been decrypted, for example, by a web browser on the user's computer, the malicious code may gather data that is displayed in particular fields or sections in the decrypted web page and provide the data to a malicious user or computer.
Malicious code may also gather data that is entered by a user before the user's data is encrypted and sent to the intended recipient. For example, a user may enter account information into a web browser that is displaying a web page from the user's bank. The web page may be a login page to access the user's account information and funds. The malicious code may scan particular fields in the web page for the user's account information before the user's account information is encrypted and sent to the user's bank, and then send data obtained from those fields to a malicious user or computer. Web browsers were first developed and deployed in the early 1990's, and thus there has been a need to improve browser security, web server security, web-based application security, and data security at and/or between end points.
SUMMARY
The appended claims may serve as a summary of the invention.
BRIEF DESCRIPTION OF THE DRAWINGS
In the drawings:
<figref idref="DRAWINGS">FIG. 1</figref> illustrates functional units of a web browser, in an example embodiment.
<figref idref="DRAWINGS">FIG. 2</figref> illustrates a computer system comprising a server security and re-rendering system, in an example embodiment.
<figref idref="DRAWINGS">FIG. 3</figref> illustrates an intermediary computer and a web infrastructure in an example embodiment.
<figref idref="DRAWINGS">FIG. 4</figref> illustrates objects and operations stored in memory by a browser backend, or headless browser, in an example embodiment.
<figref idref="DRAWINGS">FIG. 5</figref> illustrates a process for intercepting instructions for a server computer, rendering new instructions, and sending the new instructions to the intended client, in an example embodiment.
<figref idref="DRAWINGS">FIG. 6</figref> illustrates a process for storing and refreshing rendered instructions in response receiving the same original instructions from a web server, in an example embodiment.
<figref idref="DRAWINGS">FIG. 7</figref> illustrates a process for intercepting and modifying a request based on one or more stored attribute maps and/or DOM maps, in an example embodiment.
<figref idref="DRAWINGS">FIG. 8</figref> illustrates a process for intercepting instructions and requests between a HyperText Transfer Protocol (“HTTP”) server and an HTTP-based web browser over HTTP, in an example embodiment.
<figref idref="DRAWINGS">FIG. 9</figref> illustrates a computer system upon which an embodiment may be implemented.
While each of the drawing figures illustrates a particular embodiment for purposes of illustrating a clear example, other embodiments may omit, add to, reorder, and/or modify any of the elements shown in the drawing figures.
DETAILED DESCRIPTION
In the following description, for the purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of the present invention. It will be apparent, however, that the present invention may be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form in order to avoid unnecessarily obscuring the present invention.
Embodiments are described herein according to the following outline: <ul id="ul0001" list-style="none"><li id="ul0001-0001" num="0000"><ul id="ul0002" list-style="none"><li id="ul0002-0001" num="0019">1.0 Terms</li><li id="ul0002-0002" num="0020">2.0 General Overview</li><li id="ul0002-0003" num="0021">3.0 Network Topology <ul id="ul0003" list-style="none"><li id="ul0003-0001" num="0022">3.1 Visitor Browser <ul id="ul0004" list-style="none"><li id="ul0004-0001" num="0023">3.1.1 Browser Frontend</li><li id="ul0004-0002" num="0024">3.1.2 Browser Backend</li></ul></li><li id="ul0003-0002" num="0025">3.2 Web Infrastructure</li><li id="ul0003-0003" num="0026">3.3 Intermediary <ul id="ul0005" list-style="none"><li id="ul0005-0001" num="0027">3.3.1 Protocol Client</li><li id="ul0005-0002" num="0028">3.3.2 Browser Backend</li><li id="ul0005-0003" num="0029">3.3.3 Forward Translator</li><li id="ul0005-0004" num="0030">3.3.4 Protocol Handler</li><li id="ul0005-0005" num="0031">3.3.5 Transaction Store</li><li id="ul0005-0006" num="0032">3.3.6 Reverse Translator</li></ul></li></ul></li><li id="ul0002-0004" num="0033">4.0 Process Overview <ul id="ul0006" list-style="none"><li id="ul0006-0001" num="0034">4.1 Intercepting Instructions from a Content Server Computer and Generating New Instructions</li><li id="ul0006-0002" num="0035">4.2 Caching Rendered Instructions</li><li id="ul0006-0003" num="0036">4.3 Intercept a Request from a Client Computer and Translate the Request into a New Request based on a Stored Mapping</li><li id="ul0006-0004" num="0037">4.4 Methods for an HTTP-based System</li></ul></li><li id="ul0002-0005" num="0038">5.0 Implementation Mechanisms—Hardware Overview</li><li id="ul0002-0006" num="0039">6.0 Other Aspects of Disclosure</li></ul></li></ul>
1.0 TERMS
In certain embodiments:
A “computer” may be one or more physical computers, virtual computers, and/or computing devices. As an example, a computer may be one or more server computers, cloud-based computers, cloud-based cluster of computers, virtual machine instances or virtual machine computing elements such as virtual processors, storage and memory, data centers, storage devices, desktop computers, laptop computers, mobile devices, and/or any other special-purpose computing devices. Any reference to “a computer” herein may mean one or more computers, unless expressly stated otherwise.
An “object” may be a data structure that can be identified by an identifier and/or a relationship with another object. For example, an object may have a unique identifier that is a string, such as a document, customer number, or username. Accordingly, the object may be referenced and/or retrieved using the identifier. Also for example, if a particular object is the first child object of a parent object, then the particular object may be referenced and/or retrieved using a pointer to the parent object and then retrieving a pointer to the first child object. A method of referencing objects by identifier and/or relationships is called XPath. An object may be a particular type of object. For example, one object may be a button, another object may be an input, or specifically a text field, and another object may be an image.
An “attribute” may be data that identifies and/or describes the appearance, behavior, and/or content of an object. For example, an attribute may be a unique identifier, such as a name. An attribute may indicate that an object is a type of input, such as a text field, text area, checkbox, and/or radio button. An attribute may indicate that an object is a password text field; accordingly, a client application rendering the text field object on a monitor need not cause the characters that are entered into the field object to be displayed. An attribute associated with the text field object may be updated to include the value entered in the text field. Other attributes may define or describe dimension, position, color, visibility, value, and any other functional or visual aspect of an object.
A “document object model” (“DOM”) may be a cross-platform and language-independent representation of one or more objects that are interrelated. For example, a DOM may represent one or more objects in an object tree and/or hierarchy. An object within the hierarchy may be a parent object, which has one or more child objects. A child object may also have one or more child objects.
“Creating, updating, and/or removing an object” may mean creating, updating, and/or removing a data structure in memory that represents an object, an object's attributes, and/or relationships between an object and one or more other objects; because these processes directly or indirectly involve changing the state of registers or other structures in electronic digital memory circuits, the processes necessarily involve using a computer to transform the state of tangible things.
An “operation” may be any function, method, script, and/or any other code, which when executed operates on an object.
“Operating on an object” may mean creating, removing, and/or updating an object. Additionally, “operating on an object” may mean performing one or more operations that use an object, attribute, and/or relationship between an object and one or more other objects as input.
“Instructions” may mean one or more codes that define one or more objects and/or one or more operations. For example, instructions may comprise HyperText Markup Language (“HTML”), eXtensible Markup Language (“XML”), cascading style sheets (“CSS”), JavaScript, and/or any other standard or proprietary languages or codes that define objects, attributes, relationships between objects, and/or operations.
“Performing instructions” or “executing instructions” may mean creating one or more objects and/or performing one or more operations defined by the instructions.
“Rendering instructions” may mean generating one or more instructions based on objects and/or operations stored in memory, such that when the generated one or more instructions are executed the same objects and/or same operations are created in memory.
A first object may be the “same” as a second object if the first object maintains the same one or more values, attributes, and/or relationships as the second object. The underlying representation of the first object in memory need not be the same as the underlying representation of the second object in memory. For purposes of illustrating a clear example, assume that a first program is allocated a first memory segment; a second program is allocated a second segment; the first program maintains a first object in the first memory segment; the second program maintains a second object in the second memory segment; the first object comprises a value: six; the second object comprises a value: six. In this situation, the first object and the second object may be the same object because the first object maintains the same value as the second object, even though the first object and the second object are located in different memory segments.
If the value stored in the first memory segment is stored as an 8-bit integer and the value stored in the second memory segment is stored as an American Standard Code for Information Interchange (“ASCII”) string, then the first object and the second object may be the same object because the first object maintains the same value as the second object, even though the underlying representation of the value in the first memory segment is stored differently than the representation of the value in the second memory segment.
As another example, assume that the first program is running on a first computer that comprises a 32-bit processor and addresses memory using 32-bit addresses; the second program is running on a second computer that comprises a 64-bit processor and addresses memory using 64-bit addresses; the first object is a parent object and comprises a pointer to a child object stored in the first memory segment; the second object is a parent object and comprises a pointer to a child object stored in the second memory segment. In this situation, the first object and the second object may be the same object because the first object maintains the same values and relationships as the second object, even though the pointer to the child stored in the first memory segment may be a 32-bit pointer and the pointer in the second memory segment may be a 64-bit pointer.
If the first program stores the data that represents the first object contiguously in the first memory segment and the second program stores the data that represents the second object scattered throughout the second memory segment, then the first object and the second object may be the same object, even though the underlying data structure that represents the first object is stored differently than the underlying data structure that represents the second object.
Or, for example, assume the first program is a first HTTP browser; the second program is a second, different HTTP browser; the first object may have an attribute, “id”; the second object may have an attribute, “id”; the value for the “id” attribute is “MyObject” for both the first object and the second object is. In this situation, the underlying representation of the first object in the first browser may be drastically different than the underlying representation of the second object in the second browser. However, the operations that operate on the two objects may be programmatically identical. For example, the same JavaScript executed by the first HTTP browser and the second HTTP browser may retrieve the first object maintained by the first HTTP browser and the second object, respectively: document.getElementById(“MyObject”).
Other factors that may result in a different underlying representation of the same object may include the endianness of a processor, amount of memory available, different applications, and/or any other different hardware and/or software configurations.
“Data” may mean any data and/or instructions in electronic digital memory.
An “attribute map” may be a map from one attribute name and/or value to one or more other names and/or values. For example, assume an object has an attribute, “id”, which defines a unique identifier: “MyObject”. An attribute map may associate “MyObject” with a different unique identifier, such as “tcejbOyM”. Additionally, an attribute map may be used to map a modified attribute name and/or value to an original name and/or value. An attribute map may be an operation, hash map, and/or any other method or associative data structure.
A “DOM map” may be a map from a first DOM to a second, different DOM. For example, a DOM map may be a collection of attribute maps. Each attribute map in the DOM map may be an attribute map for an attribute of an object in a first DOM with a modified attribute in a second DOM. Additionally or alternatively, a DOM map may map one hierarchy to another, different hierarchy, and back again. For example, a DOM map may modify a relationship between a first object and a second object, such that a first object is not related to a second object in a first DOM, and the first object is a parent object to the second object in the second DOM.
A “browser” may be one or more computer programs or other software elements stored in electronic digital memory and running on a computer that receives instructions from a server computer, performs one or more of the received instructions, causes to display content, provides a user interface (“UI”) to receive user inputs, and/or receives and responds to one or more inputs from a user based on or according to the one or more performed instructions. A browser and/or components of a browser may be implemented into an application. For example, a browser and/or components of a browser may be implemented into a mobile application as part of a web view, and/or web view controller, to send and/or receive data over HTTP and/or other protocol. A user may use a browser to send data to a server computer. The server computer may respond with additional instructions.
A “headless browser” may be a browser that does not cause visually displaying or rendering graphical images of objects that are defined in a set of received instructions according to the received set of instructions. Additionally or alternatively, a “headless browser” may be a browser that does not respond to user inputs according to a set of received instructions.
“Sending and/or receiving data over HTTP” may mean sending and/or receiving data and/or instructions using HyperText Transfer Protocol. Additionally or alternatively, “sending and/or receiving data over HTTP” may mean sending and/or receiving data and/or instructions using a subset of the HTTP, such as secure HTTP (HTTPS). Additionally or alternatively, one or more other protocols may be used, such as SPDY.
A “web browser” may be a browser that receives instructions comprising HTML, CSS, and/or JavaScript over HTTP or some derivative thereof, such as HTTPS.
A “bot” may mean a computer and/or software executed by a computer that automates sending and/or receiving data. For example, a bot may be a web scraper, web crawler, automatic web browser, and/or any other tool designed to submit and/or receive data from one or more web servers. A bot may comprise complex logic designed to respond to data received from one or more web servers.
2.0 GENERAL OVERVIEW
In an embodiment, performing one or more of the methods discussed herein may prevent, and/or reduce the effectiveness of, one or more various attacks, such as a denial of service (“DOS”) attack, credential stuffing, fake account creation, ratings or results manipulation, man in the browser attacks, reserving rival goods or services, scanning for vulnerabilities, and/or exploitation of vulnerabilities. For example, if an intermediary computer intercepts an improper request from a visitor browser, such as a request that does not include one or more identifiers that match one or more attribute map identifiers, DOM map identifiers, and/or transaction identifiers, then the intermediary computer need not reverse translate and/or forward the improper request on to the targeted web server computer. Thus, the targeted web server computer, or an application running on the targeted web server computer, need not be burdened with processing improper and/or malicious requests that are part of an attack.
In an embodiment, after an intermediary computer intercepts a request with a particular identifier, based on a rendered set of instructions by the intermediary computer, the particular identifier may no longer be valid. Accordingly, if the same visitor browser and/or a different visitor browser uses the same particular identifier in an additional request, the intermediary computer need not reverse translate and/or forward the improper request to the targeted web server computer. Thus, the targeted web server computer, or an application running on the targeted web server computer, need not be affected by one or more attacks, such as a DOS attack and/or cross-site request forgery.
In an embodiment, each time a web page is requested, such as an account creation page, order page, voting page, and/or other page from a web server computer, the intermediary computer may modify the identifiers in the returned page. Thus, a bot may receive a different set of instructions after each request and may not observe the same one or more field identifiers twice. Without receiving the same one or more identifiers, the bot may be incapable of determining what data should be entered in and/or associated with each field to create a fake account, order and/or reserve one or more goods or services, vote, inject malicious SQL, and/or submit any other malicious content.
In an embodiment, the DOM hierarchy, a portion of the DOM hierarchy, and/or one or more particular identifiers are modified each time a web page is requested. For example, a container that stores the definition of a word or phrase may, in the originally intercepted instructions, be in a particular spot in the DOM hierarchy and/or include a particular identifier: “definition”. However, the intermediary computer may manipulate the DOM hierarchy and/or identifier each time the page or a similar page is served. Thus, a bot may not be able to determine which container holds the target content. Furthermore, an automated vulnerability bot may not be able to determine whether target content was inserted and/or changed. For example, if a bot submits content designed to employ SQL, HTML, JavaScript, and/or any other code injection, the bot may not be able to determine which container is supposed to contain content generated by a successful attack.
In an embodiment, a bot, such as a website scraper may be whitelisted. If the bot includes a particular password or other code, then the intermediary computer may send the original instructions and/or a portion of the original instructions to the bot. Thus, the intermediary computer may allow the authorized bot to perform an automated task on an entire page and/or a portion of the page. Otherwise, the intermediary computer may use one or more of the methods discussed herein.
In an embodiment, a method comprises intercepting, from a server computer, a first set of instructions that define one or more objects and one or more operations that are based, at least in part, on the one or more objects; generating, in memory, one or more data structures that correspond to the one or more objects; performing the one or more operations on the one or more data structures; updating the one or more data structures, in response to performing the one or more operations, to produce one or more updated data structures; rendering a second set of instructions, which when executed by a remote client computer cause the remote client computer to generate the one or more updated data structures in memory on the remote client computer, wherein the second set of instructions are different than the first set of instructions; sending the second set of instructions to the remote client computer.
In an embodiment, wherein each object of the one or more objects includes an original identifier, the method comprises generating a data structure, for each object of the one or more objects, wherein the data structure corresponds to the object and includes the original identifier included in the object; updating the original identifier included in the data structure for each object to produce a modified identifier and a modified data structure of the one or more updated data structures.
In an embodiment, the method comprises storing a mapping between the modified identifier and the original identifier for each object; intercepting, from the remote client computer, a request that includes one or more modified identifiers; determining the original identifier for each modified identifier included in the request; replacing each modified identifier in the request with the original identifier to produce a modified request; sending the modified request to the server computer.
In an embodiment, a method comprises intercepting, from a web server computer, over HTTP, an original HTML document, a set of original CSS codes, and a set of original JavaScript codes that define one or more objects in an original DOM and one or more operations that are based, at least in part, on the one or more objects in the original DOM; generating one or more data structures that correspond with the one or more objects in the original DOM; processing the set of original CSS codes and the set of original JavaScript codes on the one or more data structures; updating the one or more data structures, in response to processing the set of original CSS codes and the set of original JavaScript codes, to produce one or more updated data structures; rendering a modified HTML document, a set of modified CSS codes, and a set of modified JavaScript codes, which when processed by a remote client computer cause the remote client computer to generate the one or more updated data structures in memory on the remote client computer; wherein the modified HTML document defines a modified DOM that is different than the original DOM; wherein the modified HTML document, the set of modified CSS codes, and the set of modified JavaScript codes are different than the original HTML document, the set of original CSS codes, and the set of original JavaScript codes; generating a DOM mapping between the modified DOM and the original DOM; storing the DOM mapping; sending the modified HTML document, the set of modified CSS codes, and the set of modified JavaScript codes to the remote client computer; intercepting, from the remote client computer, a request based on the modified DOM; translating the request based, at least in part, on the DOM mapping to produce a translated request based on the original DOM; sending the translated request to the web server computer.
3.0 NETWORK TOPOLOGY
<figref idref="DRAWINGS">FIG. 1</figref> illustrates functional units of a web browser, in an example embodiment. <figref idref="DRAWINGS">FIG. 2</figref> illustrates a system comprising a server security and a re-rendering system, in an example embodiment. Referring first to <figref idref="DRAWINGS">FIG. 2</figref>, system <b>200</b> includes web infrastructure <b>205</b>, visitor computer <b>299</b>, intermediary computer <b>230</b>, and data storage <b>240</b>, distributed across a plurality of interconnected networks. While each of the components listed above are illustrated as if running on a separate, remote computer from each other, one or more of the components listed above may be part of and/or executed on the same computer. For example, HTTP intermediary computer <b>230</b>, data storage <b>240</b>, and/or web infrastructure <b>205</b> may be executed on the same computer, local area, and/or wide area network. Additionally or alternatively, intermediary computer <b>230</b> is a proxy server for web infrastructure <b>205</b>. Additionally or alternatively, intermediary computer <b>230</b> may be in line between a router and web infrastructure <b>205</b>, such that all network data sent to, and/or sent from, web infrastructure <b>205</b> over one or more protocols may be intercepted by intermediary computer <b>230</b>.
3.1 Visitor Browser
Visitor browser <b>295</b> may be a browser that is executed on visitor computer <b>299</b> and operated by a user using visitor computer <b>299</b>. For example, visitor browser <b>295</b> may be a web browser. <figref idref="DRAWINGS">FIG. 1</figref> illustrates a more detailed view of a web browser, in an example embodiment. In this context, “visitor” refers to any user who is using the computer <b>299</b> to contact, communicate with or otherwise conceptually visit the web infrastructure <b>205</b>. Furthermore, visitor browser <b>295</b> may be described with reference to browser <b>100</b> in <figref idref="DRAWINGS">FIG. 1</figref>, but using the particular arrangement illustrated in <figref idref="DRAWINGS">FIG. 1</figref> is not required in other embodiments.
Referring now to <figref idref="DRAWINGS">FIG. 1</figref>, browser <b>100</b> includes browser backend <b>101</b>, browser frontend <b>120</b>, operating system (“OS”) system application programming interface (“API”) layer <b>150</b>, and OS frontend API layer <b>160</b>.
3.1.1 Browser Frontend
Browser frontend <b>120</b> comprises rendering engine <b>122</b>, interactivity module <b>124</b>, and user interface <b>126</b>. Each of the components may cause, through OS frontend API layer <b>160</b>, one or more objects to be presented and/or updated visually and/or audibly to a user using visitor computer <b>299</b>.
Rendering engine <b>122</b> may determine how objects are presented to a user. For example, rendering engine <b>122</b> may determine the color, shape, orientation, position, and/or any other visual and/or audio attribute of an image, text field, button, and/or any other object defined by a set of received instructions. Furthermore, rendering engine <b>122</b> may cause a button to be displayed on a monitor coupled to visitor computer <b>299</b> through OS frontend API layer <b>160</b>.
User interface <b>126</b> may determine what may be presented to a user. For example, user interface <b>126</b> may determine that a “submit” button should be hidden until data has been entered in one or more text fields. After data has been entered in the one or more text fields, user interface <b>126</b> may notify rendering engine <b>122</b> to render the “submit” button accordingly.
Interactivity module <b>124</b> may receive one or more inputs through OS Frontend API layer <b>160</b>. For example, in response to a user pressing a button on a mouse coupled to visitor computer <b>299</b>, the operating system running on visitor computer <b>299</b> may send a message to interactivity module <b>124</b>, through OS frontend API layer <b>160</b>, to indicate that a user pressed a button on a mouse. Interactivity module <b>124</b> may determine that a user selected a particular button currently presented on a monitor. Interactively module <b>124</b> may notify user interface <b>126</b> and/or rendering engine <b>122</b> to update to update the UI accordingly.
3.1.2 Browser Backend
Browser backend <b>101</b> comprises protocol module <b>102</b>, domain name server (“DNS”) module <b>104</b>, local storage module <b>106</b>, image parser <b>108</b>, CSS parser <b>110</b>, HTML parser <b>112</b>, JavaScript parser <b>114</b>, extension execution environment <b>116</b>, document object model (“DOM”) module <b>118</b>, and JavaScript execution environment <b>119</b>. Other embodiments may use other protocols, modules, and/or parsers. A browser that includes a browser backend, but does not include a browser frontend, may be a headless browser.
Protocol module <b>102</b>, DNS module <b>104</b>, and local storage module <b>106</b> may send and/or receive data through OS System API layer <b>150</b>. For example, protocol module <b>102</b> may send and/or receive data over any protocol, such as HTTP, to/from intermediary computer <b>230</b> and/or web infrastructure <b>205</b> through OS system API layer <b>150</b>. Data received through protocol module <b>102</b> may reference data sources by one or more domain names. DNS module <b>104</b> may resolve the one or more domain names referenced by interfacing with one or more remote domain name servers through OS system API layer <b>150</b>. Local storage module may store and/or recall data from memory through OS system API layer <b>150</b>.
Image parser <b>108</b>, CSS Parser <b>110</b>, HTML parser <b>112</b>, and JavaScript parser <b>114</b> may parse data received through protocol module <b>102</b>. HTML parser <b>112</b> may parse HTML data. CSS parser <b>110</b> may parse CSS data. JavaScript parser <b>114</b> may parse JavaScript data. Image parser <b>108</b> may parse image data. Each parser may generate and/or update objects in a DOM maintained by DOM module <b>118</b>.
Browser backend <b>101</b> may comprise one or more programmable engines, such as extension execution environment <b>116</b> and JavaScript execution environment <b>119</b>. Extensions may be written one or more programming languages include JavaScript, Python, Ruby, and/or any other language. Each programmable engine may have access to DOM module <b>118</b> and may operate on one or more objects from a DOM maintained by DOM module <b>118</b>. For example, JavaScript execution environment <b>119</b> may execute JavaScript parsed by JavaScript parser <b>114</b> and in response, create, update, and/or delete one or more objects managed by DOM module <b>118</b>.
3.2 Web Infrastructure
Referring again to <figref idref="DRAWINGS">FIG. 2</figref>, web infrastructure <b>205</b> may be one or more server computers that receive requests for data from users, such as a user using visitor browser <b>295</b>, through intermediary computer <b>230</b>. In response, web infrastructure <b>205</b> may send data to visitor browser <b>295</b>, through intermediary computer <b>230</b>. As illustrated in <figref idref="DRAWINGS">FIG. 2</figref> the data sent from web infrastructure <b>205</b> may include instructions: HTML, JavaScript, and CSS <b>210</b>.
<figref idref="DRAWINGS">FIG. 3</figref> illustrates a web infrastructure in an example embodiment. The web infrastructure <b>205</b> may be described with reference to original web server computer <b>302</b> and third party web server computers <b>306</b> in <figref idref="DRAWINGS">FIG. 3</figref>, but using the particular arrangement illustrated in <figref idref="DRAWINGS">FIG. 3</figref> is not required in other embodiments.
Original web server computer <b>302</b> may be a server computer that receives requests for data and responds with data. For example, original web server computer <b>302</b> may be an HTTP-based web server that receives HTTP requests and responds with data comprising HTML, CSS, and/or JavaScript instructions. Additionally or alternatively, original web server computer <b>302</b> may respond with data that references data on other server computers, such as third party web server computers <b>306</b>.
Third party web server computers <b>306</b> may be one or more server computers that store additional data referenced by instructions sent from original web server computer <b>302</b>. For example, data from original web server computer <b>302</b> may include a reference to a JavaScript file stored on third party web server computers <b>306</b>. Accordingly, a browser backend, such as a browser backend <b>101</b>, may request the referenced JavaScript file from third party web server computers <b>306</b>. Also for example, data from original web server computer <b>302</b> may include a reference to an image stored on third party web server computers <b>306</b>. Accordingly, a browser backend, such as browser backend <b>101</b>, may request the referenced image from third party web server computers <b>306</b>.
3.3 Intermediary
Returning now to <figref idref="DRAWINGS">FIG. 2</figref>, intermediary computer <b>230</b> may intercept instructions sent from web infrastructure <b>205</b>, generate new instructions, and send the new instructions to visitor browser <b>295</b>. For example, intermediary computer <b>230</b> may intercept HTML, JavaScript, and CSS <b>210</b>, generate HTML, JavaScript, and CSS <b>290</b> (which may be different than HTML, JavaScript, and CSS <b>210</b>), and send HTML, JavaScript, and CSS <b>290</b> to visitor browser <b>295</b>. Additionally, intermediary computer <b>230</b> may intercept a request from visitor browser <b>295</b>, generate a new, modified request, and send the new, modified request to web infrastructure <b>205</b>.
In <figref idref="DRAWINGS">FIG. 2</figref>, intermediary computer <b>230</b> may be an HTTP intermediary that intercepts and modifies HTML, JavaScript, CSS, and HTTP requests for HTTP web browsers. However, intermediary computer <b>230</b> may be an intermediary for any other standard and/or proprietary protocol. Furthermore, each of the components discussed, which intermediary computer <b>230</b> is comprised of, may be configured to perform any of the processes and/or methods discussed herein for any standard and/or proprietary protocol.
Intermediary computer <b>230</b> may be a server computer that is located on the same network as web infrastructure <b>205</b>. Additionally or alternatively, intermediary computer <b>230</b> may be topologically located between a public-facing router and web infrastructure <b>205</b>. Accordingly, requests from visitor browser <b>295</b> to web infrastructure <b>205</b> may be passed through and/or modified by intermediary computer <b>230</b>. Furthermore, instructions from web infrastructure <b>205</b> to visitor browser <b>295</b> may be passed through and/or modified by intermediary computer <b>230</b>. Additionally or alternatively, intermediary computer <b>230</b> may be a proxy server and/or router. Additionally or alternatively, intermediary computer <b>230</b> and/or components of intermediary computer <b>230</b> may be a software layer, executed on one or more computers in web infrastructure <b>205</b>. Additionally or alternatively, intermediary computer <b>230</b> may be a server computer that one or more domain name servers list as a destination IP address. Accordingly, intermediary computer <b>230</b> may receive requests sent to the one or more domains from visitor browser <b>295</b>. Based on the domain name in a request, intermediary computer <b>230</b> may forward the request, or a modified request, to a server computer in web infrastructure <b>205</b>, such as original web server computer <b>302</b>.
<figref idref="DRAWINGS">FIG. 3</figref> illustrates, among other things, a more detailed view of intermediary computer <b>230</b>, in an example embodiment. The intermediary computer <b>230</b> may be described with reference to several components illustrated in <figref idref="DRAWINGS">FIG. 3</figref> and discussed in detail below, but using the particular arrangement illustrated in <figref idref="DRAWINGS">FIG. 3</figref> is not required in other embodiments. Turning now to <figref idref="DRAWINGS">FIG. 3</figref>, intermediary computer <b>230</b> may comprise protocol client <b>332</b>, browser backend <b>334</b>, forward translator <b>336</b>, protocol handler <b>338</b>, transaction store <b>340</b>, and reverse translator <b>342</b>. In an embodiment, each of the functional units of intermediary computer <b>230</b> may be implemented using any of the techniques further described herein in connection with <figref idref="DRAWINGS">FIG. 9</figref>; for example, the intermediary computer may comprise a general-purpose computer configured with one or more stored programs which when executed cause performing the functions described herein for the intermediary computer, or a special-purpose computer with digital logic that is configured to execute the functions, or digital logic that is used in other computing devices.
3.3.1 Protocol Client
Protocol client <b>332</b> may intercept data over any standard or proprietary protocol. For example, protocol client <b>332</b> may intercept data over HTTP. Accordingly, protocol client <b>332</b> may be communicatively coupled with web infrastructure <b>205</b>, original web server computer <b>302</b>, and third party web server computers <b>306</b>.
3.3.2 Browser Backend
Browser backend <b>334</b> may be an HTTP-based headless browser similar to browser backend <b>101</b>. Additionally or alternatively, browser backend <b>334</b> may be a headless browser based on one or more other standard and/or proprietary protocols.
Browser backend <b>334</b> may perform instructions intercepted by protocol client <b>332</b>. After performing the instructions, browser backend <b>334</b> may notify forward translator <b>336</b> to begin rendering instructions based on the objects created by browser backend <b>334</b> that are currently in memory. Accordingly, browser backend <b>334</b> and forward translator <b>336</b> may be communicatively coupled.
Browser backend <b>334</b> may make requests for additional data. For example, if instructions received from Protocol client <b>332</b> reference additional instructions stored on a third party web server, browser backend <b>334</b> may request the additional instructions through protocol client <b>332</b>. Accordingly, browser backend <b>334</b> and protocol client <b>332</b> are communicatively coupled.
3.3.3 Forward Translator
Forward translator <b>336</b> may operate on the objects created by browser backend <b>334</b> and generate one or more attribute maps and/or DOM maps. Additionally or alternatively, forward translator <b>336</b> may render a new set of instructions based on the one or more objects and/or operations in memory. Forward translator <b>336</b> may operate on objects and/or render instructions based on one or more configurations specified in configuration <b>232</b>. Accordingly, forward translator <b>336</b> may be communicatively coupled to configuration <b>232</b>. Forward translator <b>336</b> may send the rendered instructions to protocol handler <b>338</b>. Accordingly, forward translator <b>336</b> may be communicatively coupled to protocol handler <b>338</b>.
3.3.4 Protocol Handler
Protocol handler <b>338</b> may receive the instructions generated by forward translator <b>336</b> and send the generated instructions to visitor browser <b>195</b>. Additionally or alternatively, protocol handler <b>338</b> may intercept requests from visitor browser <b>195</b> and forward the requests to transaction store <b>340</b>. Accordingly, protocol handler <b>338</b> may be communicatively coupled to visitor browser <b>195</b>, forward translator <b>336</b>, and transaction store <b>340</b>.
3.3.5 Transaction Store
Transaction store <b>340</b> may receive requests intercepted by protocol handler <b>338</b> from visitor browser <b>295</b>. Transaction store <b>340</b> may retrieve one or more attribute maps and/or DOM maps, based on data in the request, and forward the request with the retrieved one or more attribute maps and/or DOM maps to reverse translator <b>342</b>. Accordingly, transaction store <b>340</b> may be communicatively coupled with reverse translator <b>342</b>.
3.3.6 Reverse Translator
Reverse translator <b>342</b> may translate requests intercepted by protocol handler <b>338</b>, which are based on instructions generated by forward translator <b>336</b>, into requests that would have been generated by visitor browser <b>195</b> had visitor browser <b>195</b> received the original instructions sent from original web server computer <b>302</b>. Reverse translator <b>342</b> may translate requests based on the one or more attribute maps and/or DOM maps retrieved by transaction store <b>340</b>. Reverse translator <b>342</b> may send the translated request to original web server computer <b>302</b> through protocol client <b>332</b>. Accordingly, reverse translator <b>342</b> may be communicatively coupled with protocol client <b>332</b>.
4.0 PROCESS OVERVIEW
In an embodiment, a data processing method may be configured to intercept instructions from a server computer and generate new, different instructions based on the intercepted instructions. In an embodiment, a data processing method may be configured for caching new instructions, intercepting client requests to a server computer, translating the request to produce a new request, and/or sending the new request to a server computer. Various embodiments may use HTTP and/or specialized web-based instructions, such as HTML, CSS, and/or JavaScript, and/or standard and/or proprietary protocol(s) and/or instructions.
4.1 Intercepting Instructions from a Content Server Computer and Generating New Instructions
<figref idref="DRAWINGS">FIG. 5</figref> illustrates a process for intercepting instructions for a server computer, rendering new instructions, and sending the new instructions to the intended client, in an example embodiment. For purposes of illustrating a clear example, <figref idref="DRAWINGS">FIG. 5</figref> may be described with reference to <figref idref="DRAWINGS">FIG. 3</figref> and <figref idref="DRAWINGS">FIG. 4</figref>, but using the particular arrangements illustrated in <figref idref="DRAWINGS">FIG. 3</figref> or <figref idref="DRAWINGS">FIG. 4</figref> are not required in other embodiments.
Turning now to step <b>510</b>, in <figref idref="DRAWINGS">FIG. 5</figref>, an intermediary computer intercepts a first set of instructions from a remote server computer. For example, protocol client <b>332</b> may receive instructions from original web server computer <b>302</b>, in response to a request from visitor browser <b>295</b>. The instructions may comprise HTML, CSS, and/or JavaScript.
In step <b>520</b>, the intermediary computer generates one or more objects in memory based on the instructions. For example, protocol client <b>332</b> may send the HTML, CSS, and/or JavaScript to browser backend <b>334</b>. Browser backend <b>334</b> may generate a DOM in memory containing objects defined in the instructions. <figref idref="DRAWINGS">FIG. 4</figref> illustrates objects and operations stored in memory by browser backend <b>334</b>, in an example embodiment. HTML parser <b>412</b> may parse the HTML received by browser backend <b>334</b>. Based on the parsed HTML, DOM module <b>418</b> may create DOM <b>450</b> and objects in DOM <b>450</b>: object <b>452</b> and object <b>454</b>. Furthermore, based on the parsed HTML, DOM module <b>418</b> may define object <b>452</b> to be the parent object of object <b>454</b> in DOM <b>450</b>. Additionally, one or more objects in DOM <b>450</b> may comprise one or more attributes based on the parsed HTML.
In step <b>530</b>, the intermediary computer performs one or more instructions which operate on the objects. For purposes of illustrating a clear example, assume object <b>452</b> comprises an attribute that is a unique identifier. Also assume one or more CSS instructions identify object <b>452</b> by its unique identifier and define one or more attributes to assign to, and/or associate with, object <b>452</b>. Accordingly, CSS parser <b>410</b> may parse the CSS received by browser backend <b>334</b>. DOM module <b>418</b> may create and/or update other property information <b>430</b> to include the one or more attributes defined in the CSS instructions. DOM module <b>418</b> may associate other property information <b>430</b>, and/or one or more attributes in other property information <b>430</b>, to object <b>452</b>.
As an example, the JavaScript instructions define one or more operations, which when performed operate on one or more objects defined in the HTML instructions. One or more JavaScript instructions may indicate that the one or more operations may be performed after the objects defined in the HTML instructions are loaded in memory and/or after the CSS instructions have been performed without additional user input. The JavaScript parser <b>414</b> may parse the JavaScript received by browser backend <b>334</b>. JavaScript execution environment <b>419</b> may execute the one or more operations, which operate on the one or more the objects, one or more attributes of objects, and/or relationships between the objects in DOM <b>450</b>.
Instructions performed after the objects defined in the HTML instructions are loaded in memory may drastically change the DOM and/or the objects in the DOM. For example, one or more JavaScript operations may change object <b>452</b> to a different type of object. Also for example, one or more JavaScript operations may create, update, and/or delete object <b>452</b>. Additionally or alternatively, one or more JavaScript operations may create, update, and/or delete data included and/or associated with object <b>452</b>. Additionally or alternatively, one or more JavaScript operations may create, update, and/or remove associations between objects. For example, one or more JavaScript operations may associate object <b>452</b> with object <b>454</b>, such that object <b>452</b> may become a parent object of object <b>454</b>, as illustrated by the dashed line between object <b>452</b> and object <b>454</b>.
In step <b>540</b>, the intermediary computer associates one or more operations with one or more objects. As an example, the JavaScript instructions may define an operation, which when performed, operate on one or more objects defined in DOM <b>450</b>; the operation references object <b>454</b> by an identifier; object <b>454</b> is the second child of object <b>452</b>; object <b>454</b> is a particular type of object, which is different than the other objects that are children objects of object <b>452</b>; and one or more JavaScript instructions indicate that the operation may be performed upon some event, such as a user selecting button and/or entering an input.
JavaScript parser <b>414</b> may parse the JavaScript received by browser backend <b>334</b>, which defines the operation. JavaScript parser <b>414</b>, DOM module <b>418</b>, and/or JavaScript execution environment <b>419</b> may generate JavaScript engine state info <b>440</b> included in in-memory data structures <b>400</b>. JavaScript parser <b>414</b>, DOM module <b>418</b>, and/or JavaScript execution environment <b>419</b> may generate a representation of the operation that references object <b>454</b> in JavaScript engine state info <b>440</b>. The representation of the operation in JavaScript engine state info <b>440</b> may include a cross reference to an identifier for object <b>454</b>. Additionally or alternatively, the representation of the operation in JavaScript engine state info <b>440</b> may include a cross reference to an identifier for object <b>454</b> based on the topology of object <b>454</b> in DOM <b>450</b>: second child of object <b>452</b> and/or first child of object <b>452</b> that is the particular type, which is a different type than the type(s) of other child objects of object <b>452</b>. JavaScript engine state info <b>440</b> may include one or more other operations and/or representations of one or more other operations.
In step <b>550</b>, the intermediary computer modifies one or more of the objects. For example, forward translator <b>336</b> may create, update, and/or delete identifiers for one or more of the objects in DOM <b>450</b>, such as the names of the one or more objects. Forward translator <b>336</b> may implement one or more methods to modify identifiers, such as generating random identifiers.
In step <b>560</b>, the intermediary computer modifies one or more operations associated with the modified objects. For example, forward translator <b>336</b> may update the references in JavaScript engine state info <b>440</b> to use the new identifiers from step <b>550</b>.
In step <b>570</b>, the intermediary computer renders a second set of instructions based on the current state of the objects and operations. As discussed earlier, the originally received instructions need not be HTML, CSS, and/or JavaScript instructions. Furthermore, the rendered instructions need not be HTML, CSS, and/or JavaScript instructions. However, for purposes of illustrating a clear example, assume that the originally received instructions in step <b>510</b> comprise HTML, CSS, and JavaScript instructions. Furthermore, assume that forward translator <b>336</b> is configured to generate HTML, CSS, and/or JavaScript instructions. The forward translator <b>336</b> may render instructions, which when executed, generate the same objects and/or operations as currently existing in in-memory data structures <b>400</b>. However, the rendered instructions may comprise different HTML, CSS, and/or JavaScript codes that the originally receive HTML, CSS, and JavaScript instructions. For example, the rendered instructions may use different identifiers for the objects defined in the rendered instructions than the original instructions.
Additionally or alternatively, the original instructions may comprise HTML, CSS, and/or JavaScript instructions and the rendered instructions may have one or more of the object attributes originally defined in the CSS instructions integrated into the HTML instructions and/or the JavaScript instructions. Accordingly, in an embodiment, the rendered instructions may comprise HTML and JavaScript instructions, but not CSS instructions. However, the new, rendered HTML and JavaScript instructions, when executed, may generate objects and/or operations that are the same as the objects and/or operations in in-memory data structures <b>400</b> when the new HTML and JavaScript instructions were rendered.
Additionally or alternatively, the rendered instructions may comprise HTML and/or CSS instruction that define fewer objects than defined in in-memory data structures <b>400</b>. However, the rendered JavaScript instructions may define operations, which when executed generate objects that were not defined in the rendered HTML and/or CSS instructions. Therefore, the new, rendered HTML, CSS, and JavaScript instructions, when executed, may generate objects and/or operations that are the same as the objects and/or operations in in-memory data structures <b>400</b> when the new instructions were rendered.
Additionally or alternatively, the rendered instructions may comprise one or more HTML documents, which comprise the original CSS instructions and/or JavaScript instructions embedded into the one or more HTML documents. Accordingly, the new, rendered HTML instructions, when executed, may generate objects and/or operations as currently existing in in-memory data structures <b>400</b> when the new HTML instructions were rendered.
Additionally or alternatively, the rendered CSS and/or JavaScript instructions may reference objects by XPath commands instead of by one or more unique identifiers, or vice versa. XPath commands may be used to identify objects in a DOM and/or hierarchy by the topology of the DOM and/or hierarchy. Accordingly, the new, rendered HTML, CSS, and JavaScript instructions, when executed, may generate objects and/or operations that are the same as the objects and/or operations in in-memory data structures <b>400</b> when the new instructions were rendered.
Additionally or alternatively, the rendered HTML instructions may define objects in in-memory data structures <b>400</b>, but without one or more attributes. However, the rendered CSS instructions and/or JavaScript instructions may define operations, which when executed, update the objects to include the missing attributes. Accordingly, the new, rendered HTML, CSS, and JavaScript instructions, when executed, may generate objects and/or operations that are the same as the objects and/or operations in in-memory data structures <b>400</b> when the new instructions were rendered.
Additionally or alternatively, the rendered HTML instructions may define the objects in in-memory data structures <b>400</b>, but in a different hierarchy, such as the relationship between object <b>452</b> and object <b>454</b> is not defined. However, the rendered JavaScript instructions may define operations, which when executed may update and/or re-organize the relationships between the objects such that object <b>452</b> is the parent object of object <b>454</b>.
Additionally or alternatively, the rendered instructions need not comprise the same programming language(s), scripting language(s), and/or data interchange format(s) as the original instructions intercepted in step <b>510</b>. For example, the rendered instructions may comprise one or more other standard and/or proprietary languages, formats, and/or codes that are not included in the originally intercepted instructions: Dynamic HTML, XML, eXtensible Stylesheet Language, VBScript, Lua, YAML Ain't Markup Language (“YAML”), JavaScript Object Notation (“JSON”), shell script, Java, Ruby, Python, and/or Lisp.
Additionally or alternatively, the rendered instructions may reference the IP address and/or domain name of intermediary computer <b>230</b>. For example, a link defined in the original instructions may include the IP address of original web server computer <b>302</b>. Accordingly, forward translator may replace the IP address of original web server computer <b>302</b>, with the address of intermediary computer <b>230</b>. If a user selects the link through a user interface (for example through visitor browser <b>195</b>), then a request may be sent to the IP address of intermediary computer <b>230</b> instead of the IP address of original web server computer <b>302</b>.
Forward translator <b>336</b> may use configuration <b>232</b> to determine which method(s) to use to perform step <b>560</b> and/or step <b>570</b>. Accordingly, one or more of the methods discussed herein, alone or in combination, may be a polymorphic protocol defined in configuration <b>232</b>. Additionally or alternatively, configuration <b>232</b> may define which objects and/or types of objects may be modified based on one or more of the methods discussed herein. Additionally or alternatively, configuration <b>232</b> may define which objects and/or or types of objects need not be modified based on one or more of the methods discussed herein. Configuration <b>232</b> may be a database, a configuration file, and/or any other method of storing preferences. Configuration <b>232</b> may store more than one configuration for one or more web servers in web infrastructure <b>205</b>. Intermediary computer <b>230</b> may select a configuration in configuration <b>232</b> based on any number of factors. For example, intermediary computer <b>230</b> may select a configuration in configuration <b>232</b> based on a domain associated with the server computer that the instructions were intercepted from. Additionally or alternatively, intermediary computer <b>230</b> may select a configuration in configuration <b>232</b> based on a random variable seeded by time. Additionally or alternatively, intermediary computer <b>230</b> may select a configuration in configuration <b>232</b> based on attributes and/or properties of visitor browser <b>295</b>. For example, intermediary computer <b>230</b> may select a configuration based on what types of instructions visitor browser <b>295</b> is capable of interpreting and/or processing.
In step <b>580</b>, the intermediary computer sends the rendered, second set of instructions to the remote client computer. For example, forward translator <b>336</b> sends the rendered instructions to protocol handler <b>338</b>. Protocol handler <b>338</b> sends the rendered instructions to visitor browser <b>295</b>, which was the originally intended recipient of the data intercepted in step <b>510</b>.
4.2 Caching Rendered Instructions
Intermediary computer <b>230</b> may render different instructions each time it receives instructions from web infrastructure <b>205</b> and/or original web server computer <b>302</b>, regardless of whether the intercepted instructions are the same as a previous set of instructions. However, rendering instructions may be processor and/or memory intensive and take a substantial amount of time. Accordingly, intermediary computer <b>230</b> may cache instructions rendered by intermediary computer <b>230</b> in data storage <b>240</b>. In response to receiving the same instructions from web infrastructure <b>205</b> and/or original web server computer <b>302</b>, intermediary computer <b>230</b> may send the rendered instructions already cached in data storage <b>240</b>, instead of re-rendering the intercepted instructions. While intermediary computer <b>230</b> may reduce its processing load by sending cached, rendered instructions, bots may be updated based on the cached, rendered instructions. Accordingly, intermediary computer <b>230</b> may refresh the cached instructions periodically and/or in response to one or more conditions.
<figref idref="DRAWINGS">FIG. 6</figref> illustrates a process for storing and refreshing rendered instructions in response receiving the same original instructions from a web server, in an example embodiment. For purposes of illustrating a clear example, <figref idref="DRAWINGS">FIG. 6</figref> may be described with reference to <figref idref="DRAWINGS">FIG. 2</figref> and <figref idref="DRAWINGS">FIG. 3</figref>, but using the particular arrangements illustrated in <figref idref="DRAWINGS">FIG. 2</figref> and/or <figref idref="DRAWINGS">FIG. 3</figref> is not required in other embodiments.
Turning now to step <b>610</b>, in <figref idref="DRAWINGS">FIG. 6</figref>, subsequent to rendering a set of instructions in response to intercepting an original set of instructions, the intermediary computer may store the set of instructions. Additionally, the intermediary computer may store a timestamp. For example, forward translator <b>336</b> may store a set of rendered instructions and a timestamp in data storage <b>240</b>. Additionally, intermediary computer <b>230</b>, or a component of therein, may store a key associated with the stored, rendered set of instructions. The key may be based on the original set of instructions received. For example, the key may be based on a hashing algorithm using the original set of instructions as a parameter. Also for example, the original set of instructions may include the key.
In step <b>620</b>, the intermediary computer intercepts a set of instructions from the server computer and determines that the cached, rendered set of instructions is based on the newly intercepted instructions. For example, browser backend <b>334</b> may generate a new key based on the newly intercepted instruction. Browser backend <b>334</b> may search the stored keys for a matching key. For purposes of illustrating a clear example, assume that browser backend <b>334</b> finds a matching key stored from step <b>610</b>.
In step <b>630</b>, the intermediary computer determines whether one or more conditions trigger a new set of instructions to be rendered. For example, the intermediary computer may determine that the time elapsed since the rendered instructions were stored is greater than a threshold amount. Browser backend <b>334</b> may compare a current timestamp, to the timestamp stored in data storage <b>240</b> in step <b>610</b>. In response to determining that the elapsed time is greater than a threshold, control proceeds to step <b>640</b>; otherwise, control proceeds to step <b>650</b>. Additionally or alternatively, the intermediary computer may determine that a particular subset of the intercepted instructions changed. In response to determining that the particular subset of the instructions has changed, control may proceed to step <b>640</b>; otherwise, control may proceed to step <b>650</b>. The conditions under which intermediary computer <b>230</b> may render a new, different set of instructions may be stored in configuration <b>232</b>.
In step <b>640</b>, the intermediary computer generates a new set of instructions that is different than the set of instructions previously stored. For example, browser backend <b>334</b> and/or forward translator <b>336</b> performs step <b>520</b> through step <b>580</b> and renders a new, different set of instructions. Control then returns to step <b>610</b>. For example, forward translator <b>336</b> may store the new set of rendered instructions and a current timestamp in data storage <b>240</b>. Browser backend <b>334</b> and/or forward translator <b>336</b> may associate the stored key with the new stored set of rendered instructions. Forward translator <b>336</b> may, but need not, generate a new key.
In step <b>650</b>, the intermediary computer recalls and sends the stored set of instructions to the intended client computer. For example, browser backend <b>334</b> may instruct forward translator <b>336</b> to send the previously stored set of rendered instructions to the intended client computer: visitor browser <b>295</b>.
4.3 Intercept a Request from a Client Computer and Translate the Request into a New Request Based on a Stored Mapping
Intermediary computer <b>230</b> may intercept and modify requests from a client computer based on one or more stored attribute maps and/or DOM maps. <figref idref="DRAWINGS">FIG. 7</figref> illustrates a process for intercepting and modifying a request based on one or more stored attribute maps and/or DOM maps, in an example embodiment. For purposes of illustrating a clear example, <figref idref="DRAWINGS">FIG. 7</figref> may be described with reference to <figref idref="DRAWINGS">FIG. 2</figref> and/or <figref idref="DRAWINGS">FIG. 3</figref>, but using the particular arrangements illustrated in <figref idref="DRAWINGS">FIG. 2</figref> and/or <figref idref="DRAWINGS">FIG. 3</figref> are not required in other embodiments. Turning now to step <b>710</b>, in <figref idref="DRAWINGS">FIG. 7</figref>, an intermediary computer modifies identifiers of one or more objects defined in an intercepted, original set of instructions. For purposes of illustrating a clear example, assume that intermediary computer <b>230</b> intercepted an original set of instructions from original web server computer <b>302</b> to be sent to visitor browser <b>195</b>; browser backend <b>334</b> generated in-memory data structures <b>400</b> based on the original set of instructions; object <b>452</b> has an attribute that is a unique identifier: “452”; and forward translator <b>336</b> translates an identifier of object <b>452</b> identifier to “ABC”.
In step <b>720</b>, the intermediary computer stores one or more mappings between the original identifiers and the modified identifiers. Additionally or alternatively, forward translator <b>336</b> may store a transaction identifier. Forward translator <b>336</b> may associate the transaction identifier with each mapping. The transaction identifier may be used to recall the mappings associated with the set of original instructions and/or a rendered set of instructions. The transaction identifier may be a modified identifier, such as the identifier of a form object in DOM <b>450</b>. For purposes of illustrating a clear example, assume that forward translator <b>336</b> stores a mapping between “452” and “ABC”, in transaction store <b>340</b> and/or data storage <b>240</b> and that forward translator <b>336</b> generates a transaction identifier, “T1”, and associates the transaction identifier “T1” with the mapping between “452” and “ABC”.
Accordingly, forward translator <b>336</b> may send the mapping between “452” and “ABC” and the transaction identifier, “T1”, to transaction store <b>340</b>. Additionally or alternatively, forward translator <b>336</b> and/or transaction store <b>340</b> may store the mapping and the transaction identifier in data storage <b>240</b>.
In step <b>730</b>, the intermediary computer sends the second set of instructions with the modified identifiers to the remote client computer. For purposes of illustrating a clear example, assume forward translator <b>336</b> renders a second set of instructions based on the current state of the data structures and the operations, using one or more of the methods discussed herein. Accordingly, forward translator <b>336</b> may send the rendered, second set of instructions to visitor browser <b>295</b> through protocol handler <b>338</b>.
In step <b>740</b>, the intermediary computer intercepts a request from a remote client computer to a server computer with the modified identifiers. For purposes of illustrating a clear example, assume the following: Visitor browser <b>295</b> receives the rendered, second set of instructions; visitor browser <b>295</b> executes the rendered, second set of instructions and generates the same objects in memory as were stored in in-memory data structures <b>400</b> to render the second set of instructions; visitor browser <b>295</b> generates a user interface based on the objects in memory; a user using visitor browser <b>295</b>, enters data into a field with an identifier, ABC, and selects a “submit” button, through the user interface generated from the rendered, second set of instructions; and visitor browser <b>295</b> sends a request to original web server computer <b>302</b> with the identifier “ABC”, data associated with “ABC”, and the identifier “T1”.
Accordingly, intermediary computer <b>230</b> may intercept the request. For example, protocol handler <b>338</b> may receive the request. Protocol handler <b>338</b> may send the request to transaction store <b>340</b>.
Additionally or alternatively, if a request is received for which there is no stored attribute maps and/or DOM maps, then the intermediary computer <b>230</b> may determine that the request is not an authorized request to be sent to original web server computer <b>302</b>. Accordingly, the intermediary computer may not forward the request to original web server computer <b>302</b> for which the request was intended. Additionally or alternatively, intermediary computer <b>230</b> may return an error code, such as HTTP error <b>500</b>, to the client computer that made the request. Additionally or alternatively, intermediary computer <b>230</b> may return a success code, such as HTTP error <b>200</b>, to the client computer that made the request.
In step <b>750</b>, the intermediary computer modifies the request by replacing the modified identifiers with the original identifiers based on the mapping. For example, based on the identifier “T1”, transaction store <b>340</b> may recall the mapping between “452” and “ABC”. Transaction store <b>340</b> may send the request and the mapping between “452” and “ABC” to reverse translator <b>342</b>. Reverse translator <b>342</b> may modify the request based on the mapping: reverse translator <b>342</b> may associate the data associated with identifier “ABC” in the request, with identifier “452” defined in the original set of instructions. Additionally or alternatively, reverse translator <b>342</b> may modify the request causing a response to the modified request from original web server computer <b>302</b> to be sent to and intercepted by intermediary computer <b>320</b>, instead of visitor browser <b>295</b>.
In step <b>760</b>, the intermediary computer sends a modified request to the server computer. For example, reverse translator <b>342</b> may send the modified request to original web server computer <b>302</b> through protocol client <b>332</b>. Original web server computer <b>302</b> may send a set of instructions in response to the received request to visitor browser <b>295</b>, which in turn may be intercepted by intermediary computer <b>230</b>.
4.4 Methods for an HTTP-Based System
The processes and methods discussed herein may be used for any protocol(s) and/or type(s) of instructions. However, to illustrate a clear example of one or more of the methods discussed above, <figref idref="DRAWINGS">FIG. 8</figref> illustrates a process for intercepting instructions and requests between an HTTP server and an HTTP-based web browser over HTTP, in an example embodiment. For purposes of illustrating a clear example, <figref idref="DRAWINGS">FIG. 8</figref> may be described with reference to <figref idref="DRAWINGS">FIG. 2</figref> and/or <figref idref="DRAWINGS">FIG. 3</figref>, but using the particular arrangements illustrated in <figref idref="DRAWINGS">FIG. 2</figref> and/or <figref idref="DRAWINGS">FIG. 3</figref> are not required in other embodiments. Turning now to step <b>805</b>, in <figref idref="DRAWINGS">FIG. 8</figref>, an intermediary computer intercepts HTML, CSS, and JavaScript from a web server computer over HTTP to a remote client computer running a web browser. For purposes of illustrating a clear example, assume the following:
Original web server computer <b>302</b> hosts a website that sends and receives content through HTTP.
Visitor computer <b>299</b> is a remote client computer that executes visitor browser <b>295</b>, which a web browser, that receives and processes HTML, CSS, and/or JavaScript instructions, and sends requests, over HTTP.
Visitor browser <b>295</b> generates a DOM maintained in memory on visitor computer <b>299</b>, based on the received HTML, CSS, and/or JavaScript instructions.
Visitor browser causes a user interface to be displayed on a monitor connected to visitor computer <b>299</b> based on the DOM maintained in memory on visitor computer <b>299</b>.
Intermediary computer <b>230</b> is an in-line computer between original web server computer <b>302</b> and visitor computer <b>299</b>, such that all data sent and/or received between original web server computer <b>302</b> and visitor computer <b>299</b> is sent and/or received through intermediary computer <b>230</b>.
Protocol client <b>332</b> is an HTTP protocol client.
Protocol handler <b>338</b> is an HTTP protocol handler.
In response to a request for data from a user, through visitor browser <b>295</b>, original web server computer <b>302</b> sends a first set of instructions comprising HTML, CSS, and JavaScript instructions.
The HTML instructions comprise the following text: <form id=“452”><input type=“text” id=“454” name=“454”/></form>.
The CSS instructions comprise the following text: #452{width: 52px;}.
The JavaScript instructions comprise a first function that references the object with an identifier attribute of “454” and sets the value of the object to a key “12345”.
The JavaScript instructions comprise an instruction that causes the first function to be executed after each of the objects defined in the HTML have been loaded, regardless of user interaction.
The JavaScript instructions comprise a second function that submits the value of the field identified as “454” to original web server computer <b>302</b>.
Accordingly, intermediary computer <b>230</b>, through protocol client <b>332</b> may receive the HTML, CSS, and JavaScript instructions intended to be sent to visitor computer <b>299</b>. Protocol client <b>332</b> may send the HTML, CSS, and JavaScript instructions to browser backend <b>334</b>.
In step <b>810</b>, the intermediary computer generates one or more objects in memory from the intercepted HTML using a browser backend. For purposes of illustrating a clear example, assume browser backend <b>334</b> is a headless, HTTP, web browser backend that process HTML, CSS, and/or JavaScript instructions and generates objects in memory based on the HTML, CSS, and JavaScript instructions received. Accordingly, browser backend <b>334</b> may generate object <b>452</b>, which represents a form with the identifier “452” in DOM <b>450</b> stored in in-memory data structures <b>400</b>, from the received HTML instructions. Furthermore, browser backend <b>334</b> may generate object <b>454</b>, which represents an input with the identifier “454” which is a child of object <b>452</b>, in DOM <b>450</b>, in-memory data structures <b>400</b> from the received HTML.
In step <b>815</b>, the intermediary computer associates attributes and operations defined in CSS and JavaScript instructions with the data structures. For example, browser backend <b>334</b> may generate other property information <b>430</b>, which comprises an attribute named “width”, with a value “52px”. Browser backend <b>334</b> may associate the attribute named “width” with object <b>452</b>. Also for example, browser backend <b>334</b> may generate JavaScript engine state info <b>440</b> which comprises a representation of the first operation and a representation of the second operation. Browser backend <b>334</b> may associate first operation and the second operation with object <b>454</b>.
In step <b>820</b>, the intermediary computer updates the data structures based on one or more operations defined by the received CSS and JavaScript instructions. For example, browser backend <b>334</b> may store the attribute named “width”, and the attribute's value, in object <b>452</b>. Also for example, browser backend <b>334</b> may perform the first operation represented in JavaScript engine state info <b>440</b>. Accordingly, object <b>454</b> may include the value “12345”. Since no instruction indicates that the second operation should be executed after the objects defined in the HTML are loaded, browser backend <b>334</b> need not perform the second operation.
Since the CSS attribute name “width” has already been integrated into the associated object, the attribute may be deleted from other property information <b>430</b>. Similarly, since the first operation has already been performed, the representation of the first operation in JavaScript engine state info may be deleted. However, for purposes of illustrating a clear example, assume that attribute named “width” and the first operation have not been deleted.
In step <b>825</b>, the intermediary computer modifies one or more objects and generates a DOM mapping. For example, forward translator <b>336</b> may modify the identifier for object <b>452</b> to “ABC” and the identifier for object <b>454</b> to “DEF” to produce a modified DOM. Accordingly, forward translator <b>336</b> may generate a mapping from the original DOM to the modified DOM to produce a DOM mapping, which includes two attribute mappings: “452” with “ABC”, and “454” with “DEF”.
Forward translator <b>336</b> may select the new identifier, “ABC”, to be the transaction identifier for the DOM mapping. Forward translator <b>336</b> may select the identifier “ABC” because it is the identifier of a form; accordingly, forward translator <b>336</b> may associate all mappings of identifiers in the form with the transaction identifier “ABC”: the mapping of “452” with “ABC” and/or the mapping of “454” with “DEF”. Additionally or alternatively, forward translator may generate a transaction identifier for each form and/or link defined in the original and/or modified DOM. Each mapping may be associated with each transaction identifier. Additionally or alternatively, forward translator <b>336</b> may select an identifier for any other reason as the transaction identifier. Additionally or alternatively, forward translator <b>336</b> may generate a transaction identifier that is not based on any identifier. Forward translator <b>336</b> may store the DOM mapping in data storage <b>240</b> and/or transaction store <b>340</b>.
In step <b>830</b>, the intermediary computer renders new HTML, CSS, and JavaScript instructions based on the current state of the objects in memory. For purposes of illustrating a clear example, assume the following: The rendered HTML comprises the following text: <form id=“ABC”><input type=“text” id=“DEF” name=“DEF” value=“12345”/></form>; the rendered CSS comprises the following text: #ABC{width: 52px;}; the rendered JavaScript instructions comprise an operation that submits the value of the field identified as “DEF” to original web server computer <b>302</b>.
In step <b>835</b>, the intermediary computer sends the rendered, new HTML, CSS, and JavaScript instructions to the remote client computer. For example, forward translator <b>336</b> may send visitor browser <b>295</b> the new HTML, CSS, and JavaScript instructions rendered in step <b>830</b>, through protocol handler <b>338</b>, over HTTP. Upon executing the new HTML, CSS, and JavaScript instructions, visitor browser <b>295</b> may generate the same objects and/or operations in memory as existed in in-memory data structures <b>400</b> when the new instructions were rendered with the modified DOM.
In step <b>840</b>, the intermediary computer intercepts a request from the remote client computer based on the modified DOM. For purposes of illustrating a clear example, assume the following: The user using visitor computer <b>299</b> input text into visitor browser <b>295</b>, which was associated with object DEF in visitor computer's memory; the user using visitor computer <b>299</b> selected a submit button, which caused visitor browser to execute the operation defined by the rendered JavaScript instructions, which submits a request that includes the value of the field identified as “DEF”, associated with the identifier “DEF”; the submitted request includes that associates the value of the field identified as “DEF” and/or the identifier “DEF” with identifier “ABC”.
Accordingly, protocol handler <b>338</b> intercepts the request and sends the request to transaction store <b>340</b>. Transaction store <b>340</b> may recall the DOM mapping associated with “ABC” from transaction store <b>340</b> and/or data storage <b>240</b>. Transaction store <b>340</b> may send the DOM mapping and the request to reverse translator <b>342</b>.
In step <b>845</b>, the intermediary computer translates the request based on the DOM mapping to produce a new, translated request. For example, reverse translator <b>342</b> receives the request and the DOM mapping. Reverse translator <b>342</b> translates the request into a new request based on the original DOM, using the DOM mapping. Accordingly, the new request may include the value from the received request associated with the identifier “454”, instead of identifier “DEF”. Additionally, the new request may include data associating the value and/or the identifier “454” with the identifier “452”. The new request may be the request visitor browser <b>295</b> would have sent in response to the same user input in step <b>840</b> had the original instructions, not the modified instructions, been sent to visitor browser <b>295</b>.
In step <b>850</b>, the intermediary computer sends the translated request to the web server computer. For example, reverse translator <b>342</b> sends the translated, new request to original web server computer <b>302</b> through protocol client <b>332</b>. Accordingly, original web server computer <b>302</b> may respond to the new request and respond with HTML, CSS, and/or JavaScript instruction, at which point intermediary computer <b>230</b> may revisit step <b>805</b>.
5.0 HARDWARE OVERVIEW
According to one embodiment, the techniques described herein are implemented by one or more special-purpose computing devices. The special-purpose computing devices may be hard-wired to perform the techniques, or may include digital electronic devices such as one or more application-specific integrated circuits (ASICs) or field programmable gate arrays (FPGAs) that are persistently programmed to perform the techniques, or may include one or more general purpose hardware processors programmed to perform the techniques pursuant to program instructions in firmware, memory, other storage, or a combination. Such special-purpose computing devices may also combine custom hard-wired logic, ASICs, or FPGAs with custom programming to accomplish the techniques. The special-purpose computing devices may be desktop computer systems, portable computer systems, handheld devices, networking devices or any other device that incorporates hard-wired and/or program logic to implement the techniques.
For example, <figref idref="DRAWINGS">FIG. 9</figref> is a block diagram that illustrates a computer system <b>900</b> upon which an embodiment of the invention may be implemented. Computer system <b>900</b> includes a bus <b>902</b> or other communication mechanism for communicating information, and a hardware processor <b>904</b> coupled with bus <b>902</b> for processing information. Hardware processor <b>904</b> may be, for example, a general purpose microprocessor.
Computer system <b>900</b> also includes a main memory <b>906</b>, such as a random access memory (RAM) or other dynamic storage device, coupled to bus <b>902</b> for storing information and instructions to be executed by processor <b>904</b>. Main memory <b>906</b> also may be used for storing temporary variables or other intermediate information during execution of instructions to be executed by processor <b>904</b>. Such instructions, when stored in non-transitory storage media accessible to processor <b>904</b>, render computer system <b>900</b> into a special-purpose machine that is customized to perform the operations specified in the instructions.
Computer system <b>900</b> further includes a read only memory (ROM) <b>908</b> or other static storage device coupled to bus <b>902</b> for storing static information and instructions for processor <b>904</b>. A storage device <b>910</b>, such as a magnetic disk or optical disk, is provided and coupled to bus <b>902</b> for storing information and instructions.
Computer system <b>900</b> may be coupled via bus <b>902</b> to a display <b>912</b>, such as a cathode ray tube (CRT), for displaying information to a computer user. An input device <b>914</b>, including alphanumeric and other keys, is coupled to bus <b>902</b> for communicating information and command selections to processor <b>904</b>. Another type of user input device is cursor control <b>916</b>, such as a mouse, a trackball, or cursor direction keys for communicating direction information and command selections to processor <b>904</b> and for controlling cursor movement on display <b>912</b>. This input device typically has two degrees of freedom in two axes, a first axis (e.g., x) and a second axis (e.g., y), that allows the device to specify positions in a plane.
Computer system <b>900</b> may implement the techniques described herein using customized hard-wired logic, one or more ASICs or FPGAs, firmware and/or program logic which in combination with the computer system causes or programs computer system <b>900</b> to be a special-purpose machine. According to one embodiment, the techniques herein are performed by computer system <b>900</b> in response to processor <b>904</b> executing one or more sequences of one or more instructions contained in main memory <b>906</b>. Such instructions may be read into main memory <b>906</b> from another storage medium, such as storage device <b>910</b>. Execution of the sequences of instructions contained in main memory <b>906</b> causes processor <b>904</b> to perform the process steps described herein. In alternative embodiments, hard-wired circuitry may be used in place of or in combination with software instructions.
The term “storage media” as used herein refers to any non-transitory media that store data and/or instructions that cause a machine to operation in a specific fashion. Such storage media may comprise non-volatile media and/or volatile media. Non-volatile media includes, for example, optical or magnetic disks, such as storage device <b>910</b>. Volatile media includes dynamic memory, such as main memory <b>906</b>. Common forms of storage media include, for example, a floppy disk, a flexible disk, hard disk, solid state drive, magnetic tape, or any other magnetic data storage medium, a CD-ROM, any other optical data storage medium, any physical medium with patterns of holes, a RAM, a PROM, and EPROM, a FLASH-EPROM, NVRAM, any other memory chip or cartridge.
Storage media is distinct from but may be used in conjunction with transmission media. Transmission media participates in transferring information between storage media. For example, transmission media includes coaxial cables, copper wire and fiber optics, including the wires that comprise bus <b>902</b>. Transmission media can also take the form of acoustic or light waves, such as those generated during radio-wave and infra-red data communications.
Various forms of media may be involved in carrying one or more sequences of one or more instructions to processor <b>904</b> for execution. For example, the instructions may initially be carried on a magnetic disk or solid state drive of a remote computer. The remote computer can load the instructions into its dynamic memory and send the instructions over a telephone line using a modem. A modem local to computer system <b>900</b> can receive the data on the telephone line and use an infra-red transmitter to convert the data to an infra-red signal. An infra-red detector can receive the data carried in the infra-red signal and appropriate circuitry can place the data on bus <b>902</b>. Bus <b>902</b> carries the data to main memory <b>906</b>, from which processor <b>904</b> retrieves and executes the instructions. The instructions received by main memory <b>906</b> may optionally be stored on storage device <b>910</b> either before or after execution by processor <b>904</b>.
Computer system <b>900</b> also includes a communication interface <b>918</b> coupled to bus <b>902</b>. Communication interface <b>918</b> provides a two-way data communication coupling to a network link <b>920</b> that is connected to a local network <b>922</b>. For example, communication interface <b>918</b> may be an integrated services digital network (ISDN) card, cable modem, satellite modem, or a modem to provide a data communication connection to a corresponding type of telephone line. As another example, communication interface <b>918</b> may be a local area network (LAN) card to provide a data communication connection to a compatible LAN. Wireless links may also be implemented. In any such implementation, communication interface <b>918</b> sends and receives electrical, electromagnetic or optical signals that carry digital data streams representing various types of information.
Network link <b>920</b> typically provides data communication through one or more networks to other data devices. For example, network link <b>920</b> may provide a connection through local network <b>922</b> to a host computer <b>924</b> or to data equipment operated by an Internet Service Provider (ISP) <b>926</b>. ISP <b>926</b> in turn provides data communication services through the world wide packet data communication network now commonly referred to as the “Internet” <b>928</b>. Local network <b>922</b> and Internet <b>928</b> both use electrical, electromagnetic or optical signals that carry digital data streams. The signals through the various networks and the signals on network link <b>920</b> and through communication interface <b>918</b>, which carry the digital data to and from computer system <b>900</b>, are example forms of transmission media.
Computer system <b>900</b> can send messages and receive data, including program code, through the network(s), network link <b>920</b> and communication interface <b>918</b>. In the Internet example, a server <b>930</b> might transmit a requested code for an application program through Internet <b>928</b>, ISP <b>926</b>, local network <b>922</b> and communication interface <b>918</b>.
The received code may be executed by processor <b>904</b> as it is received, and/or stored in storage device <b>910</b>, or other non-volatile storage for later execution.
6.0 OTHER ASPECTS OF DISCLOSURE
Using the networked computer arrangements, intermediary computer, and/or processing methods described herein, security in client-server data processing may be significantly increased. In particular, the use of browser programs becomes significantly more secure. Forward translating and reverse translating techniques herein effectively permit obfuscating data field and/or container identifiers and DOM modification for data that is financial, personal, or otherwise sensitive so that attackers cannot determine which fields and/or containers in a web page include the sensitive data. Consequently, one or more various attacks, such as a denial of service (“DOS”) attack, credential stuffing, fake account creation, ratings or results manipulation, man in the browser attacks, reserving rival goods or services, scanning for vulnerabilities, and/or exploitation of vulnerabilities, are frustrated because all fields and/or containers appear to the attacker to be gibberish, or at least cannot be identified as indicating credit card data, bank account numbers, personally identifying information, confidential data, sensitive data, proprietary data, and/or other data.
In the foregoing specification, embodiments of the invention have been described with reference to numerous specific details that may vary from implementation to implementation. The specification and drawings are, accordingly, to be regarded in an illustrative rather than a restrictive sense. The sole and exclusive indicator of the scope of the invention, and what is intended by the applicants to be the scope of the invention, is the literal and equivalent scope of the set of claims that issue from this application, in the specific form in which such claims issue, including any subsequent correction.
Contents11
10 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10
Every citation, both waysCites: the store holds 179 of 180
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2017315971A1 | Cited by | United States of America | Search report |
| US2016142428A1 | Cited by | United States of America | Search report |
| US10482172B2 | Cited by | United States of America | Search report |
| US11044268B2 | Cited by | United States of America | Search report |
| US2018121680A1 | Cited by | United States of America | Search report |
| US2016142428A1 | Cited by | United States of America | Pre-grant |
| US10572584B1 | Cited by | United States of America | Applicant |
| US10552530B1 | Cited by | United States of America | Applicant |
| US2018121680A1 | Cited by | United States of America | Search report |
| US10789378B1 | Cited by | United States of America | Applicant |
| US11283833B2 | Cited by | United States of America | Applicant |
| US11943255B2 | Cited by | United States of America | Applicant |
| US10958682B2 | Cited by | United States of America | Applicant |
| US2018121667A1 | Cited by | United States of America | Search report |
| US2018121680A1 | Cited by | United States of America | Search report |
| US12368753B2 | Cited by | United States of America | Applicant |
| US2003159063A1 | Cites | United States of America | Applicant |
| US2004101142A1 | Cites | United States of America | Applicant |
| US2004162994A1 | Cites | United States of America | Applicant |
| US2004249938A1 | Cites | United States of America | Applicant |
| US2006015941A1 | Cites | United States of America | Applicant |
| US2006034455A1 | Cites | United States of America | Applicant |
| US2006053295A1 | Cites | United States of America | Applicant |
| US2006195588A1 | Cites | United States of America | Applicant |
| US2007011295A1 | Cites | United States of America | Applicant |
| US2007064617A1 | Cites | United States of America | Applicant |
| US2007074227A1 | Cites | United States of America | Applicant |
| US2008025496A1 | Cites | United States of America | Applicant |
| US2008222736A1 | Cites | United States of America | Applicant |
| US2008229394A1 | Cites | United States of America | Applicant |
| US2008320567A1 | Cites | United States of America | Applicant |
| US2009007243A1 | Cites | United States of America | Applicant |
| US2009193497A1 | Cites | United States of America | Applicant |
| US2009193513A1 | Cites | United States of America | Applicant |
| US2009241174A1 | Cites | United States of America | Applicant |
| US2009254572A1 | Cites | United States of America | Applicant |
| US2009282062A1 | Cites | United States of America | Applicant |
| US2009292984A1 | Cites | United States of America | Applicant |
| WO2010046314A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| US2010083072A1 | Cites | United States of America | Applicant |
| US2010131512A1 | Cites | United States of America | Applicant |
| US2010172494A1 | Cites | United States of America | Applicant |
| US2010186089A1 | Cites | United States of America | Applicant |
| US2010235637A1 | Cites | United States of America | Applicant |
| US2010235910A1 | Cites | United States of America | Applicant |
| US2010262780A1 | Cites | United States of America | Applicant |
| US2011015917A1 | Cites | United States of America | Applicant |
| US2011022846A1 | Cites | United States of America | Applicant |
| US2011047169A1 | Cites | United States of America | Applicant |
| US2011107077A1 | Cites | United States of America | Applicant |
| US2011131416A1 | Cites | United States of America | Applicant |
| US2011154021A1 | Cites | United States of America | Applicant |
| US2011178973A1 | Cites | United States of America | Applicant |
| US2011239113A1 | Cites | United States of America | Applicant |
| US2011255689A1 | Cites | United States of America | Applicant |
| US2011296391A1 | Cites | United States of America | Applicant |
| US2012011262A1 | Cites | United States of America | Applicant |
| US2012022942A1 | Cites | United States of America | Applicant |
| US2012023394A1 | Cites | United States of America | Applicant |
| US2012030248A1 | Cites | United States of America | Applicant |
| US2012096116A1 | Cites | United States of America | Applicant |
| US2012117649A1 | Cites | United States of America | Applicant |
| US2012124372A1 | Cites | United States of America | Applicant |
| US2012173699A1 | Cites | United States of America | Applicant |
| US2012173870A1 | Cites | United States of America | Applicant |
| US2012174225A1 | Cites | United States of America | Applicant |
| US2012198528A1 | Cites | United States of America | Applicant |
| US2012255006A1 | Cites | United States of America | Applicant |
| US2013091582A1 | Cites | United States of America | Applicant |
| US2013198607A1 | Cites | United States of America | Applicant |
| US2013219256A1 | Cites | United States of America | Applicant |
| US2013227397A1 | Cites | United States of America | Applicant |
| US2013232234A1 | Cites | United States of America | Applicant |
| US2013263264A1 | Cites | United States of America | Applicant |
| US2014053059A1 | Cites | United States of America | Applicant |
| US2014165197A1 | Cites | United States of America | Applicant |
| US2014189499A1 | Cites | United States of America | Applicant |
| US2014223290A1 | Cites | United States of America | Applicant |
| US2014281535A1 | Cites | United States of America | Applicant |
| US2014282872A1 | Cites | United States of America | Applicant |
| US5003596A | Cites | United States of America | Applicant |
| US5315657A | Cites | United States of America | Applicant |
| US5987611A | Cites | United States of America | Applicant |
| US6006328A | Cites | United States of America | Applicant |
| US6170020B1 | Cites | United States of America | Applicant |
| US6401077B1 | Cites | United States of America | Applicant |
| US6938170B1 | Cites | United States of America | Applicant |
| US7103180B1 | Cites | United States of America | Applicant |
| US7117429B2 | Cites | United States of America | Applicant |
| US7180895B2 | Cites | United States of America | Applicant |
| US7464326B2 | Cites | United States of America | Applicant |
| US7500099B1 | Cites | United States of America | Applicant |
| US7580521B1 | Cites | United States of America | Applicant |
| US7707223B2 | Cites | United States of America | Applicant |
| US7895653B2 | Cites | United States of America | Applicant |
| US7940657B2 | Cites | United States of America | Applicant |
| US7961879B1 | Cites | United States of America | Applicant |
| US7975308B1 | Cites | United States of America | Applicant |
| US8020193B2 | Cites | United States of America | Applicant |
| US8077861B2 | Cites | United States of America | Applicant |
11 members in 5 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 201314099437 | United States of America | A | |
| US201314099437 | – | – | – |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| US8892687B1 | United States of America | B1 | |
| CA2930708A1 | Canada | A1 | |
| US2015163201A1 | United States of America | A1 | |
| WO2015084833A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US9270647B2This record | United States of America | B2 | |
| US2016057111A1 | United States of America | A1 | |
| AU2014360734A1 | Australia | A1 | |
| EP3078178A1 | European Patent Office (EPO) | A1 | |
| US10027628B2 | United States of America | B2 | |
| US2018309729A1 | United States of America | A1 | |
| US11088995B2 | United States of America | B2 |
138 transactions on the USPTO file
Allowed without a rejection on record.
- Non-final rejections
- 0
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Expire PatentEXP. | EXP. | |
| Maintenance Fee Reminder MailedREM. | REM. | |
| Entity Status Set To Undiscounted (Initial Default Setting or Status Change)BIG. | BIG. | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Payment of Maintenance Fee, 4th Yr, Small EntityM2551 | M2551 | |
| Post Issue Communication - Certificate of CorrectionN423 | N423 | |
| Mail Certificate of Correction MemoMCOCM | MCOCM | |
| Certificate of Correction MemoCOCM | COCM | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Workflow - Informational Disclosure Statement - FinishFIDS | FIDS | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Dispatch to FDCD1935 | D1935 | |
| Email NotificationEML_NTR | EML_NTR | |
| Mailing Corrected Notice of AllowabilityMCNOA | MCNOA | |
| Corrected Notice of AllowabilityCNOA | CNOA | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Pubs Case Remand to TCPUBTC | PUBTC | |
| Workflow - Request for RCE - FinishFRCE | FRCE | |
| Workflow - Request for RCE - FinishFRCE | FRCE | |
| Quick Path IDS RequestQPREQ | QPREQ | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Fee Payment Recorded (fees filed separately e.g. not with original papers, etc).FEE. | FEE. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Mail-Record Petition Decision of Granted to Withdraw from Issue - with assigned Patent NO.MP015 | MP015 | |
| Record Petition Decision of Granted to Withdraw from Issue - with assigned Patent NO.P015 | P015 | |
| Withdrawal Patent Case from IssueWFIS | WFIS | |
| Petition EnteredPET. | PET. | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Email NotificationEML_NTR | EML_NTR | |
| Printer Rush- No mailingTCPB | TCPB | |
| Mail Miscellaneous Communication to ApplicantMM327 | MM327 | |
| Miscellaneous Communication to Applicant - No Action CountM327 | M327 | |
| Pubs Case Remand to TCPUBTC | PUBTC | |
| Dispatch to FDCD1935 | D1935 | |
| Mail PUB Notice of non-compliant IDSMM327-B | MM327-B | |
| PUB Notice of non-compliant IDSM327-B | M327-B | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Printer Rush- No mailingTCPB | TCPB | |
| Mail Miscellaneous Communication to ApplicantMM327 | MM327 | |
| Miscellaneous Communication to Applicant - No Action CountM327 | M327 | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Pubs Case Remand to TCPUBTC | PUBTC | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Printer Rush- No mailingTCPB | TCPB | |
| Mail Miscellaneous Communication to ApplicantMM327 | MM327 | |
| Miscellaneous Communication to Applicant - No Action CountM327 | M327 | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Pubs Case Remand to TCPUBTC | PUBTC | |
| Printer Rush- No mailingTCPB | TCPB | |
| Mail Miscellaneous Communication to ApplicantMM327 | MM327 | |
| Miscellaneous Communication to Applicant - No Action CountM327 | M327 | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Pubs Case Remand to TCPUBTC | PUBTC | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| Mail Examiner's AmendmentMEX.A | MEX.A | |
| Mail Reasons for AllowanceMEX.R | MEX.R | |
| Mail Interview Summary - Examiner Initiated - TelephonicMEXET | MEXET | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Reasons for AllowanceEX.R | EX.R | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Paralegal or electronic terminal disclaimer approvedP574 | P574 | |
| Terminal Disclaimer FiledDIST | DIST | |
| Interview Summary - Examiner Initiated - TelephonicEXET | EXET | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS |
14 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Lapsed due to failure to pay maintenance feeLapsedFP | FP | |
| Lapse for failure to pay maintenance feesLapsedPATENT EXPIRED FOR FAILURE TO PAY MAINTENANCE FEES (ORIGINAL EVENT CODE: EXP.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYLAPS | LAPS | |
| Information on status: patent discontinuationPATENT EXPIRED DUE TO NONPAYMENT OF MAINTENANCE FEES UNDER 37 CFR 1.362STCH | STCH | |
| Fee payment procedureMAINTENANCE FEE REMINDER MAILED (ORIGINAL EVENT CODE: REM.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Fee payment procedureENTITY STATUS SET TO UNDISCOUNTED (ORIGINAL EVENT CODE: BIG.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Certificate of correctionCC | CC | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| Notice of allowance and fees dueORIGINAL CODE: NOAZAAA | ZAAA | |
| Notice of allowance mailedORIGINAL CODE: MN/=.ZAAB | ZAAB | |
| Notice of allowance and fees dueORIGINAL CODE: NOAZAAA | ZAAA | |
| AssignmentAS | AS |
Numbers
- Publication
- 09270647
- Publication, DOCDB
- 9270647
- Publication, EPODOC
- US9270647
- Application
- 14099437
- Application, DOCDB
- 201314099437
- Application, EPODOC
- US201314099437
Titles
- English
- Client/server security by an intermediary rendering modified in-memory objects
Patent term adjustment
- A delay
- +178 daysthe office missed an examination deadline
- Applicant delay
- −97 days
- Net adjustment
- 81 days
Classification
- CPC, 8
- H04L63/0281
- H04L63/04
- H04L63/1466
- G06F9/45529
- H04L29/06972
- H04L63/168
- H04L67/42
- H04L67/01
- IPC, 5
- H04L29 06
- G06F9 44
- G06F9 455
- G06F11 36
- G06F21 00
- USPC, 1
- 001001000