US2019373018A1PendingUtilityA1

Polymorphic Obfuscation of Executable Code

Assignee: SHAPE SECURITY INCPriority: Aug 31, 2015Filed: Aug 13, 2019Published: Dec 5, 2019
Est. expiryAug 31, 2035(~9.1 yrs left)· nominal 20-yr term from priority
H04L 63/1466H04L 63/1483G06F 21/56G06F 21/54
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

This document generally relates to systems, method, and other techniques for identifying and interfering with the operation of computer malware, as a mechanism for improving system security. Some implementations include a computer-implemented method by which a computer security server system performs actions including receiving a request for content directed to a particular content server system; forwarding the request to the particular content server system; receiving executable code from the particular content server system; inserting executable injection code into at least one file of the executable code; applying a security countermeasure to the combined executable code and executable injection code to create transformed code; and providing the transformed code to a client computing device.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method, comprising:
 receiving, at a computer security server system located between the Internet and a client computing device that makes requests over the Internet, a request for content that is directed to a particular content server system;   forwarding, by the computer security server system, the received request to the particular content server system;   in response to the request, receiving, from the particular content server system, executable code;   inserting into at least one file of the executable code, and to create combined code, executable injection code that, when executed by the client computing device, does not (i) alter, from a user's perspective, an execution of the received executable code or (ii) perform actions observable by the user;   applying a security countermeasure to the combined code to create transformed code; and   providing the transformed code to the client computing device.   
     
     
         2 . The method of  claim 1 , wherein:
 the executable code is included in a file that is received from the content server system, and   inserting the executable injection code comprises, inserting the injection code into the file at multiple different locations separated by lines of the executable code in the file.   
     
     
         3 . The method of  claim 1 , wherein the injection code, when executed by the client computing device, determines whether malware is present on the client computing device. 
     
     
         4 . The method of  claim 1 , comprising:
 determining one or more locations within the received executable code to insert the injection code for the injection code to not (i) alter, from the user's perspective, the execution of the received executable code or (ii) perform actions observable by the user.   
     
     
         5 . The method of  claim 1 , wherein applying a security countermeasure to the combined code to create transformed code comprises:
 renaming one or more variables or functions of the combined code.   
     
     
         6 . The method of  claim 1 , comprising:
 receiving, from the client computing device, a request to execute a portion of the transformed code that corresponds to the received code; and   determining the received executable code that corresponds to the portion of the transformed code.   
     
     
         7 . The method of  claim 1 , further comprising, in response to receiving a second request for the content, inserting the injection code into the executable code at one or more locations different than a location at which the executable injection code was previously inserted into the executable code. 
     
     
         8 . The method of  claim 7 , further comprising intermingling the executable injection code into the executable code at locations in the executable content at locations that change for each of multiple different servings in response to requests for the content, so as to interfere with malware on the client device that attempts to interact with the content, the executable code, or both. 
     
     
         9 . The method of  claim 8 , further comprising periodically updating a map that defines where, in the executable code, the executable injection code will be inserted when served to a requesting client computing device. 
     
     
         10 . A computing system comprising:
 one or more computers and one or more storage devices storing instructions that are operable, when executed by the one or more computers, to cause performance of operations comprising:
 receiving, at the computing system, a request for content directed to a particular content server system, wherein the computing system is located between the Internet and a client computing device that makes requests over the Internet; 
 forwarding, by the computing system, the received request to the particular content server system; 
 in response to the request, receiving, from the particular content server system, executable code; 
 inserting into at least one file of the executable code, and to create combined code, executable injection code that, when executed by the client computing device, does not (i) alter, from a user's perspective, an execution of the received executable code or (ii) perform actions observable by the user; 
 applying a security countermeasure to the combined code to create transformed code; and 
 providing the transformed code to the client computing device. 
   
     
     
         11 . The computing system of  claim 10 , wherein:
 the executable code is included in a file that is received from the content server system, and   inserting the executable injection code comprises, inserting the injection code into the file at multiple different locations separated by lines of the executable code in the file.   
     
     
         12 . The computing system of  claim 10 , wherein the injection code, when executed by the client computing device, determines whether malware is present on the client computing device. 
     
     
         13 . The computing system of  claim 10 , wherein the operations comprise determining one or more locations within the received executable code to insert the injection code for the injection code to not (i) alter, from the user's perspective, the execution of the received executable code or (ii) perform actions observable by the user. 
     
     
         14 . The computing system of  claim 10 , wherein applying a security countermeasure to the combined code to create transformed code comprises renaming one or more variables or functions of the combined code. 
     
     
         15 . The computing system of  claim 10 , wherein the operations comprise:
 receiving, from the client computing device, a request to execute a portion of the transformed code that corresponds to the received code; and   determining the received executable code that corresponds to the portion of the transformed code.   
     
     
         16 . The computing system of  claim 10 , wherein the operations comprise, in response to receiving a second request for the content, inserting the injection code into the executable code at one or more locations different than a location at which the executable injection code was previously inserted into the executable code. 
     
     
         17 . The computing system of  claim 16 , further comprising intermingling the executable injection code into the executable code at locations in the executable content at locations that change for each of multiple different servings in response to requests for the content, so as to interfere with malware on the client device that attempts to interact with the content, the executable code, or both. 
     
     
         18 . The computing system of  claim 17 , wherein the operations comprise periodically updating a map that defines where, in the executable code, the executable injection code will be inserted when served to a requesting client computing device.

Join the waitlist — get patent alerts

Track US2019373018A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.