DETECTING ATTACKS ON WEB APPLICATIONS USING SERVER LOGS

Patent №

US 11,223,637

Granted

2022-01-11

Filed 2018

Owner

MICROSOFT TECHNOLOGY LICENSING, LLC

AI components

2

ml · hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

15863956

A previously-unknown type of attack on a web application can be detected dynamically using server logs. An alert can be raised for an application that returns a valid response to the potential attacker (e.g., when an http (hypertext transfer protocol) status code of 200 is returned to the requestor). Server logs can be analyzed to identify an external computer that uses the same attack methodology on multiple targets. The external computer may attempt to access the same Uniform Resource Identifier (URI) on various web sites. In many cases, the http status code that is returned is an error code. Characteristics such as but not limited to fast crawling and numerous error status codes being returned to a particular requestor can be used by a machine learning (ML) system to identify potentially malicious external computing devices and/or vulnerable URIs.

Machine learningAI hardwareH04L 63/1425G06N 20/00G06N 20/20H04L 63/1408H04L 63/1416H04L 63/1433H04L 63/168

AI classification

Machine learning1.00
AI hardware0.99
Natural language0.24
Vision0.22
Knowledge representation0.04
Planning0.01
Evolutionary computation0.00
Speech0.00

Ownership

MICROSOFT TECHNOLOGY LICENSING, LLC

assignment · 453660820

Assignors

NEUVIRTH, HANI HANA, PLISKIN, RAM HAIM, KOREN, TOMER, WEIZMAN, JOSEF, REINSCH, KARL WILLIAM, HUDIS, EFIM

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC