US2019327265A1PendingUtilityA1

Quarantining malicious injected code

Assignee: SHAPE SECURITY INCPriority: Sep 23, 2014Filed: Jul 2, 2019Published: Oct 24, 2019
Est. expirySep 23, 2034(~8.2 yrs left)· nominal 20-yr term from priority
H04L 63/1491G06F 21/54H04L 63/1416G06F 2221/2119G06F 16/958H04L 63/1466
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods and apparatus are described for quarantining malicious injected code. target code is identified, in web page code requested by a client device, that is vulnerable to a code injection attack by malware. The web page code is modified by obfuscating the target code, and adding decoy code to the web page code that is vulnerable to the code injection attack. After modifying, the web page code is transmitted to the client device

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system comprising:
 one or more hardware processors;   at least one memory coupled to the one or more hardware processors and storing one or more instructions which, when executed by the one or more hardware processors, cause the one or more hardware processors to:   identify, in web page code requested by a client device, target code that is vulnerable to a code injection attack by malware;   modify the web page code by:
 obfuscating the target code, and 
 adding decoy code to the web page code that is vulnerable to the code injection attack; 
   after modifying, transmit the web page code to the client device.   
     
     
         2 . The system of  claim 1 , wherein the decoy code is an un-obfuscated version of the target code. 
     
     
         3 . The system of  claim 1 , wherein the target code comprises one or more form elements that request at least one of credentials and sensitive personal information. 
     
     
         4 . The system of  claim 1 , wherein the target code is determined with reference to the specific configurations of known malware. 
     
     
         5 . The system of  claim 4 , wherein the target code is obfuscated to hide the target code from the known malware. 
     
     
         6 . The system of  claim 4 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to:
 analyze the known malware to extract a malware signature for the known malware;   wherein identifying the target code and modifying the web page code is based on the malware signature for the known malware.   
     
     
         7 . The system of  claim 1 , wherein obfuscating the target code comprises changing a variable name in the target code. 
     
     
         8 . The system of  claim 1 , wherein obfuscating the target code comprises modifying the web page code to have a different structure. 
     
     
         9 . The system of  claim 1 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to:
 add monitoring code to the web page code, wherein the monitoring code is configured to detect interaction between malware and the decoy code when the web page code is executed at the client device.   
     
     
         10 . The system of  claim 1 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to:
 detect a change in the decoy code at the client device;   based on detecting the change, determining that a malicious code injection attack has occurred at the client device.   
     
     
         11 . A method comprising:
 identifying, in web page code requested by a client device, target code that is vulnerable to a code injection attack by malware;   modifying the web page code by:
 obfuscating the target code, and 
 adding decoy code to the web page code that is vulnerable to the code injection attack; 
   after modifying, transmitting the web page code to the client device;   wherein the method is performed by one or more computing devices.   
     
     
         12 . The method of  claim 11 , wherein the decoy code is an un-obfuscated version of the target code. 
     
     
         13 . The method of  claim 11 , wherein the target code comprises one or more form elements that request at least one of credentials and sensitive personal information. 
     
     
         14 . The method of  claim 11 , wherein the target code is determined with reference to the specific configurations of known malware. 
     
     
         15 . The method of  claim 14 , wherein the target code is obfuscated to hide the target code from the known malware. 
     
     
         16 . The method of  claim 14 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to:
 analyze the known malware to extract a malware signature for the known malware;   wherein identifying the target code and modifying the web page code is based on the malware signature for the known malware.   
     
     
         17 . The method of  claim 11 , wherein obfuscating the target code comprises changing a variable name in the target code. 
     
     
         18 . The method of  claim 11 , wherein obfuscating the target code comprises modifying the web page code to have a different structure. 
     
     
         19 . The method of  claim 11 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to:
 add monitoring code to the web page code, wherein the monitoring code is configured to detect interaction between malware and the decoy code when the web page code is executed at the client device.   
     
     
         110 . The method of  claim 11 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to:
 detect a change in the decoy code at the client device;   based on detecting the change, determining that a malicious code injection attack has occurred at the client device.

Join the waitlist — get patent alerts

Track US2019327265A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.