Patent · US Active

Malicious script detection using context-dependent script emulation

US9444831B1 · kind B1 · utility

5Cited by
2References
4Claims
0Family size

Assignee

Inventors

Key dates

Filing dateOct 22, 2015
Grant dateSep 13, 2016
Priority date
Expiry dateOct 22, 2035

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1441
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

One embodiment relates to a computer-implemented process for detecting malicious scripts at a client computer using a malicious script detector. A web page interceptor intercepts an access of web page data at a universal resource locator address. A script preprocessor determines script fragments embedded in the web page data and extracts variable and function names from the script fragments. A context analyzer determines whether the script fragments reference known-good scripts. The context analyzer may check variable and function names in the script fragment against a database of known-good contexts. Those script fragments which were determined to reference known-good scripts may be categorized as non-malicious. An emulator may perform emulation on remaining script fragments which were not determined to reference known-good scripts and not perform emulation on the script fragments which were determined to reference known-good scripts. Other embodiments, aspects and features are also disclosed.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.