IP Library Granted Patent US 9,553,882
Granted Patent B2
US 9,553,882 · App. 14/480,041 · Granted Jan 24, 2017

Correlation of advertising content to malicious software

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,553,882
App. No.
14/480,041
Granted
Jan 24, 2017
Kind
B2
Abstract

Technologies are generally described for systems, methods and devices effective to analyze a file. In some examples, a processor may receive the file. The file may include content and instructions. The content may include data executable by a browser. The processor may analyze the instructions. The processor may identify an internet protocol (IP) address in the instructions based on the analysis. The processor may compare the identified IP address with a list of IP addresses associated with an attack. The processor may generate an alert based on the comparison.

Claims (27)

1. A method to analyze a file, the method comprising, by a processor: receiving the file from a first internet protocol (IP) address, wherein the file includes content and instructions, wherein the file further includes an advertisement from an advertising network and the content includes data executable by a browser; analyzing the instructions; identifying a second internet protocol (IP) address in the instructions based on the analysis, where the second IP address is different from the first IP address; comparing the second IP address with a list of IP addresses experiencing an attack; generating an alert based on the comparison, sending the generated alert to the advertising network.

2. The method of claim 1 , wherein the attack includes a distributed denial of service (DDoS) attack.

3. The method of claim 1 , wherein the content includes an advertisement.

4. The method of claim 1 , wherein the analyzing is performed by execution of the file with the browser to determine the second IP address requested by the executed file.

5. The method of claim 1 , wherein the processor is associated with the advertising network and the alert includes an identification of the advertisement, the method further comprises:

quarantining, by the processor, the identified advertisement.

6. The method of claim 5 , further comprising identifying, by the advertising network, a provider of the advertisement.

7. The method of claim 1 , wherein the attack includes a distributed denial of service (DDoS) attack and the alert includes an identification of the advertisement, the method further comprises:

quarantining, by the advertising network, the identified advertisement; and

identifying, by the advertising network, a provider of the advertisement.

8. The method of claim 1 , wherein:

the attack includes a distributed denial of service (DDoS) attack and the alert includes an identification of the advertisement;

the analyzing is performed by execution of the file with the browser to determine the second IP address requested by the executed file; and the method further comprises:

quarantining, by the advertising network, the identified advertisement; and

identifying, by the advertising network, a provider of the advertisement.

9. A system configured to analyze a file, the system comprising: a processor configured to communicate with a memory, the memory including first instructions, wherein the processor is configured to: receive the file from a first internet protocol (IP) address, wherein the file includes content and second instructions, wherein the file further includes an advertisement from an advertising network, wherein the content includes data executable by a browser; analyze the second instructions; identify a second internet protocol (IP) address in the second instructions based on the analysis, where the second IP address is different from the first IP address, compare the second IP address with a list of IP addresses experiencing an attack; generate an alert based on the comparison, and send the alert to the advertising network.

10. The system of claim 9 , wherein the attack includes a distributed denial of service (DDoS) attack.

11. The system of claim 9 , wherein the content includes an advertisement.

12. The system of claim 9 , wherein the content includes an advertisement from an advertising network.

13. The system of claim 9 , wherein the analysis is performed by execution of the file with the browser to determine the second IP address requested by the executed file.

14. The system of claim 9 , wherein the processor is a monitoring processor, and the system further comprises:

an advertising network processor, wherein the advertising network processor is configured to be in communication with the monitoring processor;

the monitoring processor is further configured to send the alert to the advertising network processor, wherein the alert includes an identification of the file; and

the advertising network processor is further configured to quarantine the file.

15. The system of claim 14 , wherein the advertising network processor is further configured to identify a provider of the advertisement.

16. A method to analyze a file, the method comprising, by a processor: receiving the file, wherein the file is received from an advertising network and the processor is associated with the advertising network; wherein the file includes content and instructions, wherein the content includes data executable by a browser to display an advertisement; executing the file; analyzing an amount of resources used by the instructions on the processor during the execution of the file; generating an alert based on the analysis, and sending the alert to the advertising network.

17. The method of claim 16 , further comprising quarantining, by the processor, the identified advertisement.

Assignments (4)
SECURITY INTEREST Recorded Jan 29, 2019
From: EMPIRE TECHNOLOGY DEVELOPMENT LLC
To: CRESTLINE DIRECT FINANCE, L.P.
Reel/Frame 048373/0217 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2014
From: MARGALIT, MORDEHAI
To: MORDEHAI MARGALIT HOLDINGS LTD.
Reel/Frame 033691/0825 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2014
From: MORDEHAI MARGALIT HOLDINGS LTD.
To: EMPIRE TECHNOLOGY DEVELOPMENT LLC
Reel/Frame 033691/0896 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2014
From: DABIJA, VLAD GRIGORE
To: EMPIRE TECHNOLOGY DEVELOPMENT LLC
Reel/Frame 033691/0984 →