Patents by Inventor Paul Melson
Paul Melson has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12603918Abstract: A website vulnerability test is performed by automatically checking that a website has not been compromised by malicious third party scripts. A system can test a dynamic behavior of a website that indicates a functional user flow through the website. A set of rules are applied against a log of dynamic behavior of the website, as well as static code of the website, to identify potential compromise by malicious scripts. Some rules can be configured for detecting modification of a third party script, or modified behavior of a third party script, in an attempt to detect security monitoring activity against the script and hide its presence from the security monitoring activity.Type: GrantFiled: September 29, 2023Date of Patent: April 14, 2026Assignee: Target Brands, Inc.Inventors: Paul Melson, Chris Carlson, Eric Brandel, Caleb Walch
-
Patent number: 12500918Abstract: A web server system hosts a website, the website server system being configured to receive a request for web content on the website, generate a response containing the web content, and transmit the response with the web content, receive, from a web security system, deceptive response instructions, modify, in response to receiving the deceptive response instructions, the response to contain different content from web content that has been requested, and transmit, to the client computing device, the response with the different content.Type: GrantFiled: April 11, 2023Date of Patent: December 16, 2025Assignee: Target Brands, Inc.Inventors: Steve Bennett, Timothy James Hruska, Paul Melson, Nupur Mungikar
-
Publication number: 20240348637Abstract: A web server system hosts a website, the website server system being configured to receive a request for web content on the website, generate a response containing the web content, and transmit the response with the web content, receive, from a web security system, deceptive response instructions, modify, in response to receiving the deceptive response instructions, the response to contain different content from web content that has been requested, and transmit, to the client computing device, the response with the different content.Type: ApplicationFiled: April 11, 2023Publication date: October 17, 2024Inventors: Steve Bennett, Timothy James Hruska, Paul Melson, Nupur Mungikar
-
Publication number: 20240022603Abstract: A website vulnerability test is performed by automatically checking that a website has not been compromised by malicious third party scripts. A system can test a dynamic behavior of a website that indicates a functional user flow through the website. A set of rules are applied against a log of dynamic behavior of the website, as well as static code of the website, to identify potential compromise by malicious scripts. Some rules can be configured for detecting modification of a third party script, or modified behavior of a third party script, in an attempt to detect security monitoring activity against the script and hide its presence from the security monitoring activity.Type: ApplicationFiled: September 29, 2023Publication date: January 18, 2024Inventors: Paul Melson, Chris Carlson, Eric Brandel, Caleb Walch
-
Patent number: 11811824Abstract: A website vulnerability test is performed by automatically checking that a website has not been compromised by malicious third party scripts. A system can test a dynamic behavior of a website that indicates a functional user flow through the website. A set of rules are applied against a log of dynamic behavior of the website, as well as static code of the website, to identify potential compromise by malicious scripts. Some rules can be configured for detecting modification of a third party script, or modified behavior of a third party script, in an attempt to detect security monitoring activity against the script and hide its presence from the security monitoring activity.Type: GrantFiled: June 8, 2021Date of Patent: November 7, 2023Assignee: Target Brands, Inc.Inventors: Paul Melson, Chris Carlson, Eric Brandel, Caleb Walch
-
Patent number: 11595436Abstract: A website anomaly test is performed by automatically checking that a website has not been compromised by malicious code. A system can test a dynamic behavior of a website that indicates a functional user flow through the website. A set of rules are applied against a log of dynamic behavior of the website, as well as static code of the website, to identify potential compromise by malicious scripts.Type: GrantFiled: January 25, 2021Date of Patent: February 28, 2023Assignee: Target Brands, Inc.Inventors: Paul Melson, Chris Carlson, Eric Brandel, Caleb Walch
-
Patent number: 11533323Abstract: This document generally describes computer systems, processes, program products, and devices for the rapid and automated collection, storage, and analysis of network events to provide improved and enhanced security analysis. The system can include an extensible framework for pipelines to process, normalize, and decorate network events created in response to network activity, which can permit the system to readily scale up and down to ingest large volumes and variations in network activity. For example, pipeline can match data in the network events with stored Indicators of Compromise (IoCs) and decorate the network events with the IoCs before the network events are stored and subsequently analyzed.Type: GrantFiled: September 1, 2020Date of Patent: December 20, 2022Assignee: Target Brands, Inc.Inventors: Chris Carlson, Paul Melson, Paul Dokas, Justice Renée Bovee, Adam Lesperance
-
Patent number: 11444970Abstract: A website vulnerability test is performed by automatically checking that a website has not been compromised by malicious third party scripts. A system can test a dynamic behavior of a website that indicates a functional user flow through the website. Instead of merely analyzing static code of a website, the system automatically tests the website in their runtime environments for the presence of malicious third party scripts.Type: GrantFiled: September 1, 2020Date of Patent: September 13, 2022Assignee: Target Brands, Inc.Inventors: Paul Melson, Chris Carlson, Eric Brandel, Caleb Walch, Richard Agostino
-
Patent number: 11374948Abstract: A plurality of network sensors are configured to sense the operations of a data network and, responsive to sensing the operations of the data network, generate event data objects that record the operations of the data network. One or more decorator pipelines are configured to decorate the event data objects with data other than from operations of the data network. A security frontend is configured to generate a graphical user interface (GUI) configured to provide, to a user, query-authoring tools, receiving a query in a structured language, provide responsive to receiving the query, results to the query from historic event data that was decorated before the query was received, receive approval for the query, and later execute the query on new event data that has been decorated after the approval for the query is received.Type: GrantFiled: January 24, 2020Date of Patent: June 28, 2022Assignee: Target Brands, Inc.Inventors: Eric Brandel, Chris Carlson, Paul Melson, Caleb Walch, Adam Lesperance
-
Publication number: 20210385245Abstract: A website vulnerability test is performed by automatically checking that a website has not been compromised by malicious third party scripts. A system can test a dynamic behavior of a website that indicates a functional user flow through the website. A set of rules are applied against a log of dynamic behavior of the website, as well as static code of the website, to identify potential compromise by malicious scripts. Some rules can be configured for detecting modification of a third party script, or modified behavior of a third party script, in an attempt to detect security monitoring activity against the script and hide its presence from the security monitoring activity.Type: ApplicationFiled: June 8, 2021Publication date: December 9, 2021Inventors: Paul Melson, Chris Carlson, Eric Brandel, Caleb Walch
-
Publication number: 20210314353Abstract: A website anomaly test is performed by automatically checking that a website has not been compromised by malicious code. A system can test a dynamic behavior of a website that indicates a functional user flow through the website. A set of rules are applied against a log of dynamic behavior of the website, as well as static code of the website, to identify potential compromise by malicious scripts.Type: ApplicationFiled: January 25, 2021Publication date: October 7, 2021Inventors: Paul Melson, Chris Carlson, Eric Brandel, Caleb Walch
-
Publication number: 20210112082Abstract: This document generally describes computer systems, processes, program products, and devices for the rapid and automated collection, storage, and analysis of network events to provide improved and enhanced security analysis. The system can include an extensible framework for pipelines to process, normalize, and decorate network events created in response to network activity, which can permit the system to readily scale up and down to ingest large volumes and variations in network activity. For example, pipeline can match data in the network events with stored Indicators of Compromise (IoCs) and decorate the network events with the IoCs before the network events are stored and subsequently analyzed.Type: ApplicationFiled: September 1, 2020Publication date: April 15, 2021Inventors: Chris Carlson, Paul Melson, Paul Dokas, Justin Bovee, Adam Lesperance
-
Publication number: 20210092146Abstract: A website vulnerability test is performed by automatically checking that a website has not been compromised by malicious third party scripts. A system can test a dynamic behavior of a website that indicates a functional user flow through the website. Instead of merely analyzing static code of a website, the system automatically tests the website in their runtime environments for the presence of malicious third party scripts.Type: ApplicationFiled: September 1, 2020Publication date: March 25, 2021Inventors: Paul Melson, Chris Carlson, Eric Brandel, Caleb Walch, Richard Agostino
-
Publication number: 20200244680Abstract: A plurality of network sensors are configured to sense the operations of a data network and, responsive to sensing the operations of the data network, generate event data objects that record the operations of the data network. One or more decorator pipelines are configured to decorate the event data objects with data other than from operations of the data network. A security frontend is configured to generate a graphical user interface (GUI) configured to provide, to a user, query-authoring tools, receiving a query in a structured language, provide responsive to receiving the query, results to the query from historic event data that was decorated before the query was received, receive approval for the query, and later execute the query on new event data that has been decorated after the approval for the query is received.Type: ApplicationFiled: January 24, 2020Publication date: July 30, 2020Inventors: Eric Brandel, Chris Carlson, Paul Melson, Caleb Walch, Adam Lesperance