Patent · US Active

Method for detecting malicious scripts through modeling of script structure

US11314862B2 · kind B2 · utility

2Cited by
20References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateApr 16, 2018
Grant dateApr 26, 2022
Priority date
Expiry dateNov 18, 2038

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/033
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

Disclosed herein are enhancements for operating a communication network to detect malware in scripts of web applications. In one implementation, a method for modeling the structure of embedded unclassified scripts to compare the abstract dynamism of similar scripts. The method may determine structure of unclassified end user browser script by building abstract structure using code from unclassified end user browser script; compare determined structure of unclassified end user browser script with a plurality of generalized abstract structures; if the determined structure of unclassified end user browser script matches within a predetermined threshold of any of the plurality of generalized abstract structures, then the unclassified end user browser script is classified as benign, otherwise the determined structure is classified as malicious. This, in turn, provides a scalable and efficient way of identifying benign, malicious, known and unknown scripts from a script available in full or in part.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.