US2019327265A1PendingUtilityA1
Quarantining malicious injected code
Est. expirySep 23, 2034(~8.2 yrs left)· nominal 20-yr term from priority
H04L 63/1491G06F 21/54H04L 63/1416G06F 2221/2119G06F 16/958H04L 63/1466
58
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Methods and apparatus are described for quarantining malicious injected code. target code is identified, in web page code requested by a client device, that is vulnerable to a code injection attack by malware. The web page code is modified by obfuscating the target code, and adding decoy code to the web page code that is vulnerable to the code injection attack. After modifying, the web page code is transmitted to the client device
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system comprising:
one or more hardware processors; at least one memory coupled to the one or more hardware processors and storing one or more instructions which, when executed by the one or more hardware processors, cause the one or more hardware processors to: identify, in web page code requested by a client device, target code that is vulnerable to a code injection attack by malware; modify the web page code by:
obfuscating the target code, and
adding decoy code to the web page code that is vulnerable to the code injection attack;
after modifying, transmit the web page code to the client device.
2 . The system of claim 1 , wherein the decoy code is an un-obfuscated version of the target code.
3 . The system of claim 1 , wherein the target code comprises one or more form elements that request at least one of credentials and sensitive personal information.
4 . The system of claim 1 , wherein the target code is determined with reference to the specific configurations of known malware.
5 . The system of claim 4 , wherein the target code is obfuscated to hide the target code from the known malware.
6 . The system of claim 4 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to:
analyze the known malware to extract a malware signature for the known malware; wherein identifying the target code and modifying the web page code is based on the malware signature for the known malware.
7 . The system of claim 1 , wherein obfuscating the target code comprises changing a variable name in the target code.
8 . The system of claim 1 , wherein obfuscating the target code comprises modifying the web page code to have a different structure.
9 . The system of claim 1 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to:
add monitoring code to the web page code, wherein the monitoring code is configured to detect interaction between malware and the decoy code when the web page code is executed at the client device.
10 . The system of claim 1 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to:
detect a change in the decoy code at the client device; based on detecting the change, determining that a malicious code injection attack has occurred at the client device.
11 . A method comprising:
identifying, in web page code requested by a client device, target code that is vulnerable to a code injection attack by malware; modifying the web page code by:
obfuscating the target code, and
adding decoy code to the web page code that is vulnerable to the code injection attack;
after modifying, transmitting the web page code to the client device; wherein the method is performed by one or more computing devices.
12 . The method of claim 11 , wherein the decoy code is an un-obfuscated version of the target code.
13 . The method of claim 11 , wherein the target code comprises one or more form elements that request at least one of credentials and sensitive personal information.
14 . The method of claim 11 , wherein the target code is determined with reference to the specific configurations of known malware.
15 . The method of claim 14 , wherein the target code is obfuscated to hide the target code from the known malware.
16 . The method of claim 14 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to:
analyze the known malware to extract a malware signature for the known malware; wherein identifying the target code and modifying the web page code is based on the malware signature for the known malware.
17 . The method of claim 11 , wherein obfuscating the target code comprises changing a variable name in the target code.
18 . The method of claim 11 , wherein obfuscating the target code comprises modifying the web page code to have a different structure.
19 . The method of claim 11 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to:
add monitoring code to the web page code, wherein the monitoring code is configured to detect interaction between malware and the decoy code when the web page code is executed at the client device.
110 . The method of claim 11 , wherein the one or more instructions, when executed by the one or more hardware processors, cause the one or more hardware processors to:
detect a change in the decoy code at the client device; based on detecting the change, determining that a malicious code injection attack has occurred at the client device.Join the waitlist — get patent alerts
Track US2019327265A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.