US2020296115A1PendingUtilityA1
Detection of malware features in a content item
Est. expiryOct 5, 2027(~1.2 yrs left)· nominal 20-yr term from priority
Inventors:Niels ProvosYunkai ZhouClayton Woodward Bavor, Jr.Eric L. DavisMark PalatucciKamal P. NigamChristopher K. MonsonPanayiotis MavrommatisRachel Nakauchi
G06N 20/00H04L 43/0876G06F 21/577G06F 2221/2119H04L 63/145G06F 21/564H04L 67/02
68
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Intrusion features of a landing page associated with sponsored content are identified. A feature score for the landing page based on the identified intrusion features is generated, and if the feature score for the landing page exceeds a feature threshold, the landing page is classified as a candidate landing page. A sponsor account associated with the candidate landing page can be suspended, or sponsored content associated with the candidate landing page can be suspended.
Claims
exact text as granted — not AI-modified1 . (canceled)
2 . A computer-implemented method comprising:
simulating, by one or more processors, selection of a content item that is linked to a landing page; evaluating, by the one or more processors, one or more additional pages that differ from the landing page and that are in a redirect chain followed in response to the simulated selection of the content item for characteristics of malware; flagging, by the one or more processors, the content item as malware when the evaluating detects malware in the one or more additional pages that are in the redirect chain; and preventing, by the one or more processors, the content item from being served while the content item is flagged as malware.
3 . The method of claim 2 , wherein evaluating the one or more additional pages comprises evaluating one or more of iFrame features, URL features, or script features of the one or more pages.
4 . The method of claim 2 , wherein simulating selection of a content item comprises simulating the selection using a virtual machine.
5 . The method of claim 4 , wherein the virtual machine is configured to:
monitor usage of system files by the sponsored content item; and monitor processes created by the sponsored content item.
6 . The method of claim 2 , further comprising:
evaluating features of the landing page using a first malware detection process; and determining that the landing page is a malware candidate based on the evaluation of the features of the landing page.
7 . The method of claim 2 , wherein evaluating the one or more additional pages comprises evaluating the one or more additional pages using an intrusion detection engine that generates intrusion scores for the one or more additional pages.
8 . The method of claim 7 , further comprising aggregating intrusion scores for one or more features of the one or more additional pages, wherein flagging the content item as malware is based on the aggregate intrusion scores for the one or more features of the one or more additional pages.
9 . A system comprising:
one or more computers; and one or more storage devices storing instructions that, when executed by the one or more computers, cause the one or more computers to perform operations comprising:
simulating selection of a content item that is linked to a landing page;
evaluating one or more additional pages that differ from the landing page and that are in a redirect chain followed in response to the simulated selection of the content item for characteristics of malware;
flagging the content item as malware when the evaluating detects malware in the one or more additional pages that are in the redirect chain; and
preventing the content item from being served while the content item is flagged as malware.
10 . The system of claim 9 , wherein evaluating the one or more additional pages comprises evaluating one or more of iFrame features, URL features, or script features of the one or more pages.
11 . The system of claim 9 , wherein simulating selection of a content item comprises simulating the selection using a virtual machine.
12 . The system of claim 11 , wherein the virtual machine is configured to:
monitor usage of system files by the sponsored content item; and monitor processes created by the sponsored content item.
13 . The system of claim 9 , wherein the instructions cause the one or more computers to perform operations further comprising:
evaluating features of the landing page using a first malware detection process; and determining that the landing page is a malware candidate based on the evaluation of the features of the landing page.
14 . The system of claim 9 , wherein evaluating the one or more additional pages comprises evaluating the one or more additional pages using an intrusion detection engine that generates intrusion scores for the one or more additional pages.
15 . The system of claim 14 , wherein the instructions cause the one or more computers to perform operations further comprising aggregating intrusion scores for one or more features of the one or more additional pages, and wherein flagging the content item as malware is based on the aggregate intrusion scores for the one or more features of the one or more additional pages.
16 . A non-transitory computer-readable medium storing software comprising instructions executable by one or more computers which, upon such execution, cause the one or more computers to perform operations comprising:
simulating selection of a content item that is linked to a landing page; evaluating one or more additional pages that differ from the landing page and that are in a redirect chain followed in response to the simulated selection of the content item for characteristics of malware; flagging the content item as malware when the evaluating detects malware in the one or more additional pages that are in the redirect chain; and preventing the content item from being served while the content item is flagged as malware.
17 . The non-transitory computer-readable medium of claim 16 , wherein evaluating the one or more additional pages comprises evaluating one or more of iFrame features, URL features, or script features of the one or more pages.
18 . The non-transitory computer-readable medium of claim 16 , wherein simulating selection of a content item comprises simulating the selection using a virtual machine.
19 . The non-transitory computer-readable medium of claim 18 , wherein the virtual machine is configured to:
monitor usage of system files by the sponsored content item; and monitor processes created by the sponsored content item.
20 . The non-transitory computer-readable medium of claim 16 , wherein the instructions cause the one or more computers to perform operations further comprising:
evaluating features of the landing page using a first malware detection process; and determining that the landing page is a malware candidate based on the evaluation of the features of the landing page.
21 . The non-transitory computer-readable medium of claim 16 , wherein evaluating the one or more additional pages comprises evaluating the one or more additional pages using an intrusion detection engine that generates intrusion scores for the one or more additional pages.Join the waitlist — get patent alerts
Track US2020296115A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.