IP Library Granted Patent US 9,177,142
Granted Patent B2
US 9,177,142 · App. 13/274,077 · Granted Nov 3, 2015

Identification of electronic documents that are likely to contain embedded malware

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,177,142
App. No.
13/274,077
Granted
Nov 3, 2015
Kind
B2
Abstract

The present invention provides a method for determining the likelihood that an electronic document contains embedded malware. After parsing or sequencing an electronic document, the metadata structures that make up the document are analyzed. A number of pre-established rules are then applied with respect to certain metadata structures that are indicative of embedded malware. The application of these rules results in the generation of a score for the electronic document being tested for embedded malware. The score is then compared to a threshold value, where the threshold value was previously generated based on a statistical model relating to electronic documents having the same format as the document being tested. The result of the comparison can then be used to determine whether the document being tested is or is not likely to contain embedded malware.

Claims (53)

1. A method of determining a likelihood that an electronic document contains embedded malware, the method comprising:

processing one or more signals that represent a contents of the electronic document to identify one or more pre-defined metadata structures that, at least in part, make up the electronic document;

applying a set of pre-established rules to the one or more pre-defined metadata structures such that a numerical score is attributed to the electronic document;

comparing the numerical score attributed to the electronic document with a pre-established model threshold value; and

determining whether the electronic document is likely to contain embedded malware based on a result of the comparing.

2. The method of claim 1 , wherein processing the one or more signals that represent the contents of the electronic document so as to identify the one or more pre-defined metadata structures includes:

parsing the one or more signals that represent the contents of the electronic document so as to identify the metadata structures that make up the electronic document; and

identifying the one or more pre-defined metadata structures from amongst the metadata structures that make up the electronic document.

3. The method of claim 1 , further including:

determining the number of occurrences of a given one of the identified, pre-defined metadata structures; and

incrementing a weighting value attributed to the given one of the identified, pre-defined metadata structures by an amount based on the number of occurrences.

4. The method of claim 3 , wherein incrementing the weighting value by an amount based on the number of occurrences includes:

multiplying the weighting value attributed to the given one of the identified, pre-defined metadata structures by the number of occurrences.

5. The method of claim 3 , wherein incrementing the weighting value by an amount based on the number of occurrences includes: incrementing the weighting value attributed to the given one of the identified, pre-defined metadata structures by an amount that varies with each additional occurrence.

6. The method of claim 5 , wherein the amount increases in value with each additional occurrence.

7. The method of claim 5 , wherein the amount decreases in value with each additional occurrence.

8. The method of claim 1 , wherein the pre-established model threshold value is a function of a prior parsing and analysis of a plurality of pre-existing electronic documents having the same format as the electronic document.

9. The method of claim 1 , wherein determining whether the electronic document is likely to contain embedded malware based on a result of the comparison includes:

determining whether the numerical score attributed to the electronic document is less than the pre-established model threshold value or greater than or equal to the pre-established model threshold value.

10. The method of claim 9 , wherein determining whether the electronic document is likely to contain embedded malware based on a result of the comparison further includes:

determining that the electronic document is likely to contain embedded malware if it is determined that the numerical score attributed to the electronic document is greater than or equal to the pre-established model threshold value.

11. The method of claim 9 , wherein determining whether the electronic document is likely to contain embedded malware based on a result of the comparison further includes:

determining that the electronic document is not likely to contain embedded malware if it is determined that the numerical score attributed to the electronic document is less than the pre-established model threshold value.

12. A method of determining a likelihood that an electronic document contains embedded malware, the method comprising:

processing one or more signals that represent a contents of the electronic document so as to identify one or more pre-defined metadata structures that, at least in part, make up the electronic document;

attributing a weighting value to each of the identified, one or more pre-defined metadata structures; wherein the weighting value attributed to each identified, pre-defined metadata structure reflects a degree to which the corresponding, pre-defined metadata structure relates to the likelihood the document contains embedded malware;

generating a numerical score for the electronic document by combining the weighting values that were attributed to each of the identified, one or more pre-defined metadata structures;

comparing the numerical score attributed to the electronic document to a pre-established model threshold value; and

determining whether the electronic document is likely to contain embedded malware based on a result of the comparison.

13. The method of claim 12 , wherein processing the one or more signals that represent the contents of the electronic document so as to identify the one or more pre-defined metadata structures includes:

parsing the one or more signals that represent the contents of the electronic document so as to identify the metadata structures that make up the electronic document; and

identifying the one or more pre-defined metadata structures from amongst the metadata structures that make up the electronic document.

14. The method of claim 12 , further including:

determining the number of occurrences of a given one of the identified, one or more pre-defined metadata structures; and

incrementing a weighting value attributed to the given one of the identified, pre-defined metadata structures by an amount based on the number of occurrences.

15. The method of claim 14 , wherein incrementing the weighting value by an amount based on the number of occurrences includes:

multiplying the weighting value attributed to the given one of the identified, pre-defined metadata structures by the number of occurrences.

16. The method of claim 14 , wherein incrementing the weighting value by an amount based on the number of occurrences includes:

incrementing the weighting value attributed to the given one of the identified, pre-defined metadata structures by an amount that varies with each additional occurrence.

17. The method of claim 16 , wherein the amount increases in value with each additional occurrence.

18. The method of claim 16 , wherein the amount decreases in value with each additional occurrence.

19. The method of claim 12 , wherein the pre-established model threshold value is a function of a prior parsing and analysis of a plurality of pre-existing electronic documents having the same format as the electronic document.

20. The method of claim 12 , wherein determining whether the electronic document is likely to contain embedded malware based on a result of the comparison includes:

determining whether the numerical score attributed to the electronic document is less than the pre-established model threshold value or greater than or equal to the pre-established model threshold value.

21. The method of claim 20 , wherein determining whether the electronic document is likely to contain embedded malware based on a result of the comparison further includes:

determining that the electronic document is likely to contain embedded malware if it is determined that the numerical score attributed to the electronic document is greater than or equal to the pre-established model threshold value.

22. The method of claim 20 , wherein determining whether the electronic document is likely to contain embedded malware based on a result of the comparison further includes:

determining that the electronic document is not likely to contain embedded malware if it is determined that the numerical score attributed to the electronic document is less than the pre-established model threshold value.

23. A storage disk or storage device comprising instructions that, when executed, cause a machine to determine a likelihood that an electronic document contains embedded malware by:

processing one or more signals that represent a contents of the electronic document to identify one or more pre-defined metadata structures that, at least in part, make up the electronic document;

applying a set of pre-established rules to the one or more pre-defined metadata structures such that a numerical score is attributed to the electronic document;

comparing the numerical score attributed to the electronic document with a pre-established model threshold value; and

determining whether the electronic document is likely to contain embedded malware based on a result of the comparing.

Assignments (12)
SECURITY INTEREST Recorded Feb 18, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 073824/0146 →
SECURITY INTEREST Recorded Jan 30, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 073649/0743 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 071508/0540 Recorded Aug 18, 2025
From: LEVELBLUE, LLC
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 072510/0679 →
SECURITY INTEREST Recorded Jun 24, 2025
From: TRUSTWAVE HOLDINGS, INC.
To: LEVELBLUE, LLC
Reel/Frame 071508/0540 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 070952/0452 Recorded Jun 24, 2025
From: STG V, L.P.; STG VI, L.P.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 071723/0263 →
SECURITY INTEREST Recorded Apr 25, 2025
From: TRUSTWAVE HOLDINGS, INC.
To: STG V, L.P.; STG VI, L.P.
Reel/Frame 070952/0452 →
SECURITY INTEREST Recorded Oct 22, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: CYBEREASON INC.
Reel/Frame 068974/0691 →
SECURITY INTEREST Recorded Sep 12, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: CYBEREASON INC.
Reel/Frame 068572/0937 →
SECURITY INTEREST Recorded Jan 8, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: SINGTEL ENTERPRISE SECURITY (US), INC.
Reel/Frame 066050/0947 →
SECURITY AGREEMENT Recorded May 23, 2013
From: TRUSTWAVE HOLDINGS, INC.
To: WELLS FARGO CAPITAL FINANCE, LLC, AS AGENT
Reel/Frame 030486/0550 →
MERGER Recorded Nov 10, 2011
From: TRUSTWAVE CORPORATION
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 027204/0919 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2011
From: MONTORO, RODRIGO RIBEIRO
To: TRUSTWAVE CORPORATION
Reel/Frame 027139/0702 →