IP Library Granted Patent US 10,025,928
Granted Patent B2
US 10,025,928 · App. 13/633,956 · Granted Jul 17, 2018

Proactive browser content analysis

Inventors: Joe Jaroch (Elk Grove Village, IL); Harry Murphey McCloy, III (Longmont, CO); Robert Edward Adams (Sunnyvale, CA)
Assignee: WEBROOT INC.
G06F21/566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,025,928
App. No.
13/633,956
Granted
Jul 17, 2018
Kind
B2
Abstract

A protection module operates to analyze threats, at the protocol level (e.g., at the HTML level), by intercepting all requests that a browser engine resident in a computing device sends and receives, and the protection agent completes the requests without the help of the browser engine. And then the protection module analyzes and/or modifies the completed data before the browser engine has access to it, to, for example, display it. After performing all of its processing, removing, and/or adding any code as needed, the protection module provides the HTML content to the browser engine, and the browser engine receives responses from the protection agent as if it was speaking to an actual web server, when in fact, browser engine is speaking to an analysis engine of the protection module.

Claims (42)

1. A content analysis and malware prevention method comprising:

intercepting, by a protection agent, a request from a web browser;

determining, by the protection agent, whether the request is associated with known malicious content;

when the request is associated with known malicious content, blocking, by the protection agent, the request; and

when the request is not associated with known malicious content:

sending, by the protection agent, the request to one or more web servers;

receiving, at the protection agent on a remote computer, web content from the one or more web servers, wherein web content comprises data for assembling a web page, and wherein the web content is received in response to the request;

identifying, by the protection agent, a malware threat within the web content;

in response to identifying the malware threat, modifying, by the protection agent, the web content, wherein modifying the web content comprises modifying the web content at protocol level to remove the malware threat from the web content;

assembling, by the protection agent, a modified version of the web page, wherein the modified web page is assembled using the modified web content, and wherein the modified version of the web page does not comprise the malware threat; and

providing, by the protection agent, the modified version of the web page to the web browser application on the remote computer for rendering and display.

2. The method of claim 1 , further comprising supplementing, by the protection agent, the web content with indicators regarding a vulnerability of one or more links within the web content.

3. The method of claim 1 , wherein an analysis to identify a malware threat within the web content includes one or more of a URL (Uniform Resource Locator) analysis, an IP (Internet Protocol) analysis, an image analysis, and a script/HTML analysis.

4. The method of claim 1 , further comprising determining, by the protection agent, whether a request for the web content from the web browser application is a first request.

5. The method of claim 1 , further comprising performing one or more of pre-process data decryption, de-chunking and decompressing.

6. The method of claim 1 , wherein a protocol-level analysis is utilized to identify the malware threat within the web content.

7. The method of claim 3 , further comprising performing cloud verification of the web content, wherein cloud verification determines one or more malware vulnerabilities based on an aggregation of the analyses.

8. The method of claim 1 , further comprising allocating memory for caching the web content.

9. A content analysis and malware prevention system comprising:

at least one processor; and

memory encoding computer executable instructions that, when executed by the at least one processor, perform a method comprising:

intercepting a request from a web browser;

determining whether the request is associated with known malicious content;

when the request is associated with known malicious content, blocking, by a protection agent, the request; and

when the request is not associated with known malicious content:

sending the request to one or more web servers;

receiving web content from one or more web servers, wherein web content comprises data for assembling a web page;

identifying a malware threat within the web content;

in response to identifying the malware threat, modifying the web content, wherein modifying the web content comprises modifying the web at protocol level to remove the malware threat from the web content;

assembling a modified version of the web page, wherein the modified web page is assembled using the modified web content, and wherein the modified version of the web page does not comprise the malware threat; and

providing the modified version of the web page to a web browser application on the remote computer for rendering and display.

10. The system of claim 9 , wherein the method further comprises supplementing the web content with indicators regarding a vulnerability of one or more links within the web content.

11. The system of claim 9 , wherein the method further comprises identifying the malware threat within the web content by performing one or more of a URL (Uniform Resource Locator) analysis, an IP (Internet Protocol) analysis, an image analysis, and a script/HTML analysis.

12. The system of claim 9 , wherein the method further comprises determining whether a request for the web content from the web browser application is a first request.

13. The system of claim 9 , wherein the method further comprises performing one or more of pre-process data decryption, de-chunking, and decompressing.

14. The system of claim 9 , wherein the method further comprises identifying the malware threat utilizing a protocol-level analysis.

15. The system of claim 9 , wherein the method further comprises caching the web content in allocated memory.

16. The method of claim 1 , wherein the malware threat comprises a Uniform Resource Locator (URL).

17. The system of claim 9 , wherein the method further comprises determining if a malware threat comprises a Uniform Resource Locator (URL).

18. The method of claim 1 , wherein sending the request to one or more web servers comprises iteratively sending a plurality of requests to the one or more web servers.

19. The method of claim 1 , further comprising processing the web content prior to identifying the malware threat within the web content.

20. The system of claim 9 , wherein sending the request to one or more web servers comprises iteratively sending a plurality of requests to the one or more web servers.

Assignments (9)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS RECORDED AT R/F 048723/0612 Recorded Dec 26, 2019
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: WEBROOT INC.
Reel/Frame 051418/0714 →
SECURITY INTEREST Recorded Mar 28, 2019
From: WEBROOT INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 048723/0612 →
RELEASE OF SECURITY INTEREST Recorded Mar 22, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: WEBROOT INC.
Reel/Frame 050454/0102 →
SECURITY INTEREST Recorded Jan 6, 2015
From: WEBROOT INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 034742/0085 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 22, 2014
From: MCCLOY, HARRY MURPHEY, III; ADAMS, ROBERT EDWARD
To: WEBROOT INC.
Reel/Frame 034009/0378 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2012
From: JAROCH, JOE
To: WEBROOT INC.
Reel/Frame 029067/0845 →
Continuity (2)
Provisional Application 61542693 · Oct 3, 2011
Related Publication 20130086681A1 · Apr 4, 2013
Cited By (23)
US 12,197,383 US 12,206,698 US 12,210,479 US 12,235,962 US 12,244,626 US 12,259,967 US 12,261,822 US 12,261,884 US 12,282,549 US 12,301,539 US 12,341,814 US 12,363,151 US 12,412,413 US 12,418,565 US 12,423,078 US 12,432,253 US 12,437,068 US 12,450,351 US 12,452,273 US 12,468,810 US 12,579,268 US 12,598,206 US 12,664,258