IP Library Granted Patent US 8,881,278
Granted Patent B2
US 8,881,278 · App. 13/158,106 · Granted Nov 4, 2014

System and method for detecting malicious content

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,881,278
App. No.
13/158,106
Granted
Nov 4, 2014
Kind
B2
Abstract

A system and method for detecting malicious code in web content is described. A controller receives information, routes the information to the appropriate module and determines whether a user receives the web content or a report of a detection of malicious code. A vulnerability definition generator generates vulnerability definitions. A parser parses web content into static language constructions. A translation engine translates the static language constructions into trap rules, translates the web content into application programming interface (API) calls and determines whether the API calls trigger any of the trap rules. A sandbox engine generates an environment that mimics a browser and executes dynamic parts of the web content and determines whether a dynamic part triggers a trap rule.

Claims (37)

1. A computer-implemented method for detecting malicious code in web content received from a web server, the method comprising:

loading an application interface (API) trap rule associated with a vulnerability definition into a simulator of a web browser to modify an API function of the web browser to intercept malicious code;

extracting metadata from network protocol information associated with the web content;

extracting a dynamic part of the web content;

simulating, via the simulator, the web browser using the extracted metadata in a sandbox to execute the dynamic part of the web content;

determining that the execution of the dynamic part of the web content includes an API call that triggers the API trap rule; and

in response to the triggered API trap rule, monitoring execution of the associated API function in the simulator to identify a match with the vulnerability definition.

2. The computer-implemented method of claim 1 , further comprising fetching an external resource.

3. The computer-implemented method of claim 2 , wherein the external resource is at least one of a file written in JavaScript, Cascading Style Sheet (CSS) and HyperText Markup Language (HTML).

4. The computer-implemented method of claim 1 , wherein the API call of the dynamic part includes a request for a data change.

5. The computer-implemented method of claim 1 , further comprising, responsive to the API call of the dynamic part not triggering the API trap rule, transmitting the web content to a user device.

6. The computer-implemented method of claim 1 , further comprising, responsive to the API call of the dynamic part triggering the API trap rule, reporting detection of the malicious code.

7. The computer-implemented method according to claim 1 , wherein simulating a web browser in the sandbox comprises simulating a first portion of the dynamic part in a first sandbox when the first portion of the dynamic part is identified as a first type of content and simulating a second portion of the dynamic part in a second sandbox when the second portion is identified as a second type of content.

8. The computer-implemented method of claim 1 , wherein the simulator comprises a plurality of language-specific sandbox virtual environments.

9. A system for detecting malicious code in web content comprising:

an extractor to extract metadata from network protocol information associated with the web content and to extract a dynamic part of the web content; and

a sandbox engine in communication with the extractor, the sandbox engine to:

load an application programming interface (API) trap rule associated with a vulnerability definition into a simulator of a web browser to modify an API function of the web browser to intercept malicious code,

simulate the web browser using the extracted metadata in a sandbox to execute the dynamic part of the web content; and

determine that the execution of the dynamic part of the web content includes an API call that triggers the API trap rule; and

in response to the triggered API trap rule, monitoring execution of the associated API function in the simulator to identify a match with the vulnerability definition.

10. The system of claim 9 , wherein, responsive to the sandbox determining that the API call of the dynamic part does not trigger the API trap rule, the sandbox engine is to instruct a communication unit to transmit the web content to a user device.

11. The system of claim 9 , wherein, in response to the determining that the API call of the dynamic part triggers the API trap rule, the sandbox engine is to instruct a graphical user interface to report detection of malicious code to a user.

12. The system of claim 9 , further comprising a vulnerability definition generator to generate the vulnerability definition.

13. The system of claim 9 , further comprising a fetcher to fetch external resources.

14. The system of claim 9 , wherein the dynamic part comprises a request for a data change.

15. The system of claim 9 , wherein the sandbox engine is to generate a plurality of language-specific sandbox virtual environments.

16. A tangible computer readable storage disc or storage device comprising instructions that, when executed, cause a machine to at least:

load an application interface (API) trap rule associated with a vulnerability definition into a simulator of a web browser to modify an API function of the web browser to intercept malicious code;

extract metadata from network protocol information associated with the web content;

extracting a dynamic part of web content received from a web server;

simulate, via the simulator, the web browser using the extracted metadata in a sandbox to execute the dynamic part of the web content;

determine that the execution of the dynamic part of the web content includes an API call that triggers the API trap rule; and

in response to the triggered API trap rule, monitoring execution of the associated API function in the simulator to identify a match with the vulnerability definition.

17. The tangible computer readable storage disc or storage device of claim 16 , wherein the instructions further cause the machine to fetch an external resource.

18. The tangible computer readable storage disc or storage device of claim 16 , wherein the instructions further cause the machine to, in response to the API call of the dynamic part triggering the API trap rule, reporting detection of the malicious code.

19. The tangible computer readable storage disc or storage device of claim 16 , wherein the instructions further cause the machine to, in response to the API call of the dynamic part not triggering the API trap rule, transmitting the web content to a user device.

Assignments (15)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 73649/0743 Recorded Apr 30, 2026
From: ANKURA TRUST COMPANY, LLC
To: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
Reel/Frame 075371/0363 →
SECURITY INTEREST Recorded Feb 18, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 073824/0146 →
SECURITY INTEREST Recorded Jan 30, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 073649/0743 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 071508/0540 Recorded Aug 18, 2025
From: LEVELBLUE, LLC
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 072510/0679 →
SECURITY INTEREST Recorded Jun 24, 2025
From: TRUSTWAVE HOLDINGS, INC.
To: LEVELBLUE, LLC
Reel/Frame 071508/0540 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 070952/0452 Recorded Jun 24, 2025
From: STG V, L.P.; STG VI, L.P.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 071723/0263 →
SECURITY INTEREST Recorded Apr 25, 2025
From: TRUSTWAVE HOLDINGS, INC.
To: STG V, L.P.; STG VI, L.P.
Reel/Frame 070952/0452 →
SECURITY INTEREST Recorded Oct 22, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: CYBEREASON INC.
Reel/Frame 068974/0691 →
SECURITY INTEREST Recorded Sep 12, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: CYBEREASON INC.
Reel/Frame 068572/0937 →
MERGER Recorded Feb 14, 2024
From: TW SECURITY CORP.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 066584/0338 →
SECURITY INTEREST Recorded Feb 14, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: SINGTEL ENTERPRISE SECURITY (US), INC.
Reel/Frame 066584/0330 →
MERGER Recorded Mar 12, 2015
From: M86 SECURITY, INC.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 035147/0632 →
SECURITY AGREEMENT Recorded Aug 30, 2012
From: TRUSTWAVE HOLDINGS, INC.; TW SECURITY CORP.
To: WELLS FARGO CAPITAL FINANCE, LLC, AS AGENT
Reel/Frame 028885/0090 →
MERGER Recorded Aug 9, 2012
From: M86 SECURITY, INC.
To: TW SECURITY CORP.
Reel/Frame 028761/0156 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2011
From: KAPLAN, MARK; FRIGER, ALEXANDER; NOVIKOV, PETER
To: M86 SECURITY, INC.
Reel/Frame 026428/0544 →