IP Library Granted Patent US 9,213,837
Granted Patent B2
US 9,213,837 · App. 13/312,767 · Granted Dec 15, 2015

System and method for detecting malware in documents

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,213,837
App. No.
13/312,767
Granted
Dec 15, 2015
Kind
B2
Abstract

In one embodiment, a method includes identifying, using one or more processors, a plurality of characteristics of a Portable Document Format (PDF) file. The method also includes determining, using the one or more processors, for each of the plurality of characteristics, a score corresponding to the characteristic. In addition, the method includes comparing, using the one or more processors, the determined scores to a first threshold. Based at least on the comparison of the determined scores to the first threshold, the method includes determining, using the one or more processors, that the PDF file is potential malware.

Claims (39)

1. A method, comprising:

identifying, using one or more processors, a plurality of characteristics of a Portable Document Format (PDF) file, wherein the plurality of characteristics comprise: a time zone, metadata, language, font type, incorrect syntax, duplicate object numbers, and an embedded executable;

determining, using the one or more computer processors, for each characteristic of the plurality of characteristics, a score corresponding to the characteristic, wherein the score for each of the characteristics is determined based on the frequency with which each characteristic occurs in a set of PDF files known to be malware and the frequency with which each characteristic occurs in a set of PDF files known not to be malware;

comparing, using the one or more computer processors, the determined scores to a first threshold; and

based at least on the comparison of the determined scores to the first threshold, determining, using the one or more processors, that the PDF file is potential malware.

2. The method of claim 1 , wherein:

the method comprises comparing the determined scores to a second threshold; and

the PDF file is determined to be potential malware by determining that the determined scores are less than the second threshold and greater than the first threshold.

3. The method of claim 1 , further comprising sending, in response to determining that the PDF file is potential malware, the PDF file, the plurality of characteristics, and the determined scores to a human review module for review by a human analyst.

4. The method of claim 1 , wherein comparing the determined scores to the first threshold comprises comparing a weighted sum of the determined scores to the first threshold.

5. The method of claim 1 , wherein the plurality of characteristics comprises existence of Javascript.

6. The method of claim 1 , wherein the plurality of characteristics comprises the presence of markers between PDF objects.

7. The method of claim 1 , wherein the plurality of characteristics comprises multiple PDF objects having the same object number.

8. A system, comprising:

one or more computer processors configured to:

identify a plurality of characteristics of a Portable Document Format (PDF) file, wherein the plurality of characteristics comprise: a time zone, metadata, language, font type, incorrect syntax, duplicate object numbers, and an embedded executable;

determine for each characteristic of the plurality of characteristics, a score corresponding to the characteristic, wherein the score for each of the characteristics is determined based on the frequency with which each characteristic occurs in a set of PDF files known to be malware and the frequency with which each characteristic occurs in a set of PDF files known not to be malware;

compare the determined scores to a first threshold; and

based at least on the comparison of the determined scores to the first threshold, determine that the PDF file is potential malware.

9. The system of claim 8 , wherein:

the one or more processors are configured to compare the determined scores to a second threshold; and

the PDF file is determined to be potential malware by determining that the determined scores are less than the second threshold and greater than the first threshold.

10. The system of claim 8 , wherein the one or more processors are configured to send, in response to determining that the PDF file is potential malware, the PDF file, the plurality of characteristics, and the determined scores to a human review module for review by a human analyst.

11. The system of claim 8 , wherein the one or more processors are configured to compare the determined scores to the first threshold by comparing a weighted sum of the determined scores to the first threshold.

12. The system of claim 8 , wherein the plurality of characteristics comprises existence of Javascript.

13. The system of claim 8 , wherein the plurality of characteristics comprises the presence of markers between PDF objects.

14. The system of claim 8 , wherein the plurality of characteristics comprises multiple PDF objects having the same object number.

15. At least one non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, are configured to:

identify a plurality of characteristics of a Portable Document Format (PDF) file, wherein the plurality of characteristics comprise: a time zone, metadata, language, font type, incorrect syntax, duplicate object numbers, and an embedded executable;

determine for each characteristic of the plurality of characteristics, a score corresponding to the characteristic, wherein the score for each of the characteristics is determined based on the frequency with which each characteristic occurs in a set of PDF files known to be malware and the frequency with which each characteristic occurs in a set of PDF files known not to be malware;

compare the determined scores to a first threshold; and

based at least on the comparison of the determined scores to the first threshold, determine that the PDF file is potential malware.

16. The at least one computer-readable medium of claim 15 , wherein:

the instructions are configured to compare the determined scores to a second threshold; and

the PDF file is determined to be potential malware by determining that the determined scores are less than the second threshold and greater than the first threshold.

17. The at least one computer-readable medium of claim 15 , wherein the instructions are configured to compare the determined scores to the first threshold by comparing a weighted sum of the determined scores to the first threshold.

18. The method of claim 1 , wherein comparing the determined scores to a first threshold includes comparing the determined scores to a first threshold, the first threshold based on a context of how the PDF file was received.

19. The system of claim 8 , wherein the first threshold is based on a context of how the PDF file was received.

20. The at least one computer-readable medium of claim 15 , wherein the instructions configured to compare the determined scores to a first threshold are further configured to compare the determined scores to a first threshold, the first threshold based on a context of how the PDF file was received.

Assignments (15)
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070585/0524 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0309 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0207 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 27, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 052045/0482 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: FORCEPOINT FEDERAL LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0460 →
CHANGE OF NAME Recorded Feb 16, 2016
From: RAYTHEON CYBER PRODUCTS, LLC
To: FORCEPOINT FEDERAL LLC
Reel/Frame 037821/0818 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
CHANGE OF NAME Recorded Jun 2, 2015
From: RAYTHEON CYBER PRODUCTS, INC.
To: RAYTHEON CYBER PRODUCTS, LLC
Reel/Frame 035806/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2015
From: RAYTHEON COMPANY
To: RAYTHEON CYBER PRODUCTS, INC.
Reel/Frame 035774/0322 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2012
From: RICHARD, MATTHEW; LEE, JESSE J.
To: RAYTHEON COMPANY
Reel/Frame 028602/0528 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2011
From: MCDOUGAL, MONTY D.; JENNINGS, RANDY S.; STERNS, WILLIAM E.
To: RAYTHEON COMPANY
Reel/Frame 027338/0854 →