IP Library Granted Patent US 9,444,844
Granted Patent B2
US 9,444,844 · App. 14/155,835 · Granted Sep 13, 2016

Malicious mobile code runtime monitoring system and methods

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,444,844
App. No.
14/155,835
Granted
Sep 13, 2016
Kind
B2
Abstract

Protection systems and methods provide for protecting one or more personal computers (“PCs”) and/or other intermittently or persistently network accessible devices or processes from undesirable or otherwise malicious operations of Java TN applets, ActiveX™ controls, JavaScript™ scripts, Visual Basic scripts, add-ins, downloaded/uploaded programs or other “Downloadables” or “mobile code” in whole or part. A protection engine embodiment provides for monitoring information received, determining whether received information does or is likely to include executable code, and if so, causes mobile protection code (MPC) to be transferred to and rendered operable within a destination device of the received information. An MPC embodiment further provides, within a Downloadable-destination, for initiating the Downloadable, enabling malicious Downloadable operation attempts to be received by the MPC, and causing (predetermined) corresponding operations to be executed in response to the attempts.

Claims (48)

1. A method for protecting a computer from malicious downloadables, comprising:

receiving, by a first computer, an incoming downloadable, the downloadable including a security profile including a list of suspicious instructions that was attached thereto by a second computer;

extracting the security profile from the received downloadable;

comparing the security profile with a security policy to determine if the downloadable violates the security policy; and

taking an additional action related to execution of the downloadable if the downloadable violates the security policy.

2. The method of claim 1 , wherein said receiving comprises receiving from the second computer.

3. The method of claim 1 , wherein said receiving comprises receiving from a computer other than the second computer.

4. The method of claim 1 , wherein the additional action includes preventing execution of the downloadable by a third computer.

5. The method of claim 4 , wherein the third computer is the same computer as the first computer.

6. The method of claim 4 , wherein the third computer is a computer other than the first computer.

7. The method of claim 4 , wherein the third computer is a mobile computing device.

8. The method of claim 4 , wherein the third computer is an intrusion detection/ prevention device.

9. The method of claim 4 , wherein the third computer is a desktop computer.

10. The method of claim 4 , wherein the third computer is a network switch.

11. The method of claim 4 , wherein the third computer is a network firewall.

12. The method of claim 1 , wherein the security profile was attached to content of the downloadable, and wherein said extracting extracts the security profile from the downloadable content.

13. The method of claim 1 , wherein the security profile was attached to a transport protocol for the downloadable, and wherein said extracting extracts the security profile from the transport protocol.

14. A method for protecting a computer from malicious downloadables, comprising:

receiving, by a first computer, an incoming downloadable, the downloadable including a security profile including a list of suspicious instructions that was attached by a second computer;

searching for the security profile within the received downloadable and if a security profile is found,

extracting the security profile from the received downloadable;

comparing the security profile with a security policy to determine if the downloadable violates the security policy; and

taking an additional action related to execution of the downloadable if the downloadable violates the security policy.

15. A method for protecting a computer from malicious downloadables, comprising:

receiving an incoming downloadable;

deriving a security profile for the downloadable, the security profile including a list of suspicious computer operations that may be attempted by the downloadable, wherein deriving comprises inspecting the downloadable by at least one software inspection method; and

attaching the security profile to the downloadable.

16. The method of claim 15 , wherein said attaching attaches the security profile to content of the downloadable.

17. The method of claim 15 , wherein said attaching attaches the security profile to a transport protocol for the downloadable.

18. The method of claim 15 , wherein the at least one software inspection method includes a signature-based inspection method.

19. The method of claim 15 , wherein the at least one software inspection method includes a behavior-based inspection method.

20. The method of claim 15 , wherein the at least one software inspection method includes a URL-based inspection method.

21. A system for protecting a computer from malicious downloadables, comprising a first computer comprising:

a receiver for receiving an incoming downloadable, the downloadable including a security profile including a list of suspicious instructions that was appended by a second computer;

a profile extractor for extracting the security profile from the received downloadable;

a comparator for comparing the security profile with a security policy, to determine if the downloadable violates the security policy; and

a prevention module for preventing execution of the downloadable by a third computer when said comparator determines that the downloadable violates the security policy.

22. The system of claim 21 , wherein said receiver receives the incoming downloadable from the second computer.

23. The system of claim 21 , wherein said receiver receives the incoming downloadable from a computer other than the second computer.

24. The system of claim 21 , wherein the third computer is the same computer as the first computer.

25. The system of claim 21 , wherein the third computer is a computer other than the first computer.

26. The system of claim 21 , wherein said third computer is a mobile computing device.

27. The system of claim 21 , wherein said third computer is an intrusion detection/prevention device.

28. The system of claim 21 , wherein said third computer is a desktop computer.

29. The system of claim 21 , wherein said third computer is a network switch.

30. The system of claim 21 , wherein said third computer is a network firewall.

31. The system of claim 21 , wherein the security profile was attached to content of the downloadable, and wherein said profile extractor extracts the security profile from the downloadable content.

32. The system of claim 21 , wherein the security profile was attached to a transport protocol for the downloadable, and wherein said profile extractor extracts the security profile from the transport protocol.

Assignments (6)
CHANGE OF NAME Recorded Aug 18, 2020
From: FINJAN, INC.
To: FINJAN LLC
Reel/Frame 053536/0186 →
CHANGE OF ADDRESS Recorded May 20, 2015
From: FINJAN, INC.
To: FINJAN, INC.
Reel/Frame 035742/0741 →
CHANGE OF ADDRESS Recorded Apr 22, 2015
From: FINJAN, INC.
To: FINJAN, INC.
Reel/Frame 035475/0876 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2014
From: FINJAN SOFTWARE, LTD.
To: FINJAN, INC.
Reel/Frame 031976/0613 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2014
From: EDERY, YIGAL MORDECHAI; VERED, NIMROD I.; KROLL, DAVID R.
To: FINJAN SOFTWARE, INC.
Reel/Frame 032032/0351 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2014
From: TOUBOUL, SHLOMO
To: FINJAN SOFTWARE, INC.
Reel/Frame 032033/0095 →