Patent · US Active

Systems and methods for analyzing malicious PDF network content

US9438622B1 · kind B1 · utility

164Cited by
208References
32Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMar 30, 2015
Grant dateSep 6, 2016
Priority date
Expiry dateMar 30, 2035

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2463/144
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Systems and methods for analyzing malicious PDF network content are provided herein. According to some embodiments, a PDF parser examines a body portion of a PDF document received over a network and intended for a digital device and determines if one or more suspicious characteristics indicative of malicious network content are included in the examined body portion of the PDF document. The examined body portion of the PDF document is lesser in size than an entirety of the body portion of the PDF document. When the portion of the body section of the PDF document is determined to include one or more suspicious characteristics indicative of malicious network content, the PDF document is provided to one or more virtual machines associated with the digital device to verify the inclusion of malicious network content in the portion of the body section of the PDF document. Such verification comprises execution of a PDF reader application by the one or more virtual machines to process the portion of the body section of the PDF document and monitor behavior of the PDF document so as to determine if the portion of the body section of the PDF document includes malicious network content.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.