IP Library Granted Patent US 9,438,622
Granted Patent B1
US 9,438,622 · App. 14/673,292 · Granted Sep 6, 2016

Systems and methods for analyzing malicious PDF network content

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,438,622
App. No.
14/673,292
Granted
Sep 6, 2016
Kind
B1
Abstract

Systems and methods for analyzing malicious PDF network content are provided herein. According to some embodiments, a PDF parser examines a body portion of a PDF document received over a network and intended for a digital device and determines if one or more suspicious characteristics indicative of malicious network content are included in the examined body portion of the PDF document. The examined body portion of the PDF document is lesser in size than an entirety of the body portion of the PDF document. When the portion of the body section of the PDF document is determined to include one or more suspicious characteristics indicative of malicious network content, the PDF document is provided to one or more virtual machines associated with the digital device to verify the inclusion of malicious network content in the portion of the body section of the PDF document. Such verification comprises execution of a PDF reader application by the one or more virtual machines to process the portion of the body section of the PDF document and monitor behavior of the PDF document so as to determine if the portion of the body section of the PDF document includes malicious network content.

Claims (49)

1. A system comprising:

a processor; and

a memory device coupled to the processor, the memory device comprises a portable document format (PDF) parser that, when executed by the processor, examines one or more portions of a PDF document to determine if one or more suspicious characteristics indicative of malicious network content are included in the one or more examined portions of the PDF document, wherein the one or more examined portions of the PDF document comprise less than an entirety of the PDF document, and

one or more virtual machines to receive the PDF document in response to the one or more examined portions of the PDF document being determined to include one or more suspicious characteristics indicative of malicious network content, the one or more virtual machines to process at least the one or more examined portions of the PDF document so as to determine whether the PDF document includes malicious network content.

2. The system of claim 1 , wherein a determination by the PDF parser if the one or more suspicious characteristics indicative of malicious network content are included in the one or more examined portions of the PDF document, comprises:

determining a score associated with the one or more suspicious characteristics for the PDF document, the score indicative of a probability that the PDF document includes malicious network content; and

identifying the PDF document as suspicious if the score satisfies a threshold value.

3. The system of claim 1 , wherein a body portion of the PDF document is examined and the entirety of the PDF document is not examined prior to providing the PDF document to the one or more virtual machines.

4. The system of claim 3 , wherein at least one of a header, a cross-reference table, or a trailer of the PDF document is not examined prior to providing the PDF document to the one or more virtual machines.

5. The system of claim 1 wherein the PDF parser, when executed by the processor, examines the PDF document by at least applying heuristics to determine if at least one suspicious characteristic indicative of malicious network content is included in the PDF document.

6. The system of claim 1 , wherein the memory further comprises a module that, when executed by the processor, prevents the delivery of the PDF document verified to include malicious network content to a web browser application from which the delivery was requested.

7. The system of claim 1 , wherein an examination of the one or more portions of the PDF document by the PDF parser, when executed by the processor, further comprises:

examining at least one of a header section or a body section of the PDF document; and

when the body section or the header section of the PDF document is determined to include one or more suspicious characteristics indicative of malicious network content, providing the PDF document to the one or more virtual machines associated with the digital device to verify the inclusion of malicious network content in the PDF document.

8. The system of claim 1 , wherein the one or more virtual machines includes two or more augmented finite state machines, the two or more augmented finite state machines each including a configuration that includes at least one set of operating system instructions, at least one set of web browser instructions, and at least one set of PDF reader instructions, the configuration of each of the two or more augmented finite state machines being different from one another.

9. The system of claim 1 , wherein the examining of the one or more portions of the PDF document by the PDF parser further comprises:

examining one or more of a header section, a body section, a trailer section, or a cross-reference table section of the PDF document; and

providing the PDF document to the one or more virtual machines associated with the digital device to verify the inclusion of malicious network content in the PDF document when one or more of the body section, the header section, the trailer section or the cross-reference table section of the PDF document is determined to include one or more suspicious characteristics indicative of malicious network content.

10. The system of claim 1 further comprising a data access component communicatively coupled to the processor, the data access component to intercept at least the PDF document before the PDF parser examines the one or more portions of the PDF document.

11. The system of claim 10 , wherein the one or more portions of the PDF document comprises a body section of the PDF document.

12. The system of claim 1 , wherein the one or more virtual machines are configured based on at least data associated with the PDF document in response to the one or more examined portions of the PDF document being determined to include one or more suspicious characteristics indicative of malicious network content.

13. The system of claim 12 , wherein the one or more virtual machines are configured based on one or more PDF specification version numbers of the PDF document.

14. The system of claim 13 , wherein a PDF specification version number of the one or more PDF specification version numbers is used to identify a PDF reader application version to be run in a virtual machine of the one or more virtual machines.

15. The system of claim 1 , wherein the one or more examined portions of the PDF document comprises a body section and a header section of the PDF document.

16. The system of claim 1 , wherein a header of the PDF document is examined and the entirety of the PDF document is not examined prior to providing the PDF document to the one or more virtual machines.

17. A non-transitory computer readable storage medium storing software that, upon execution by a processor, detects malware within a portable document format (PDF) document, the non-transitory computer readable storage medium comprising:

a portable document format (PDF) parser that, when executed by the processor, examines one or more portions of the PDF document to determine if one or more suspicious characteristics indicative of malicious network content are included in the one or more examined portions of the PDF document, wherein the one or more examined portions of the PDF document comprise less than an entirety of the PDF document, and

one or more virtual machines to receive the PDF document in response to the one or more examined portions of the PDF document being determined to include one or more suspicious characteristics indicative of malicious network content, the one or more virtual machines to process at least the one or more examined portions of the PDF document so as to determine whether the PDF document includes malicious network content.

18. The non-transitory computer readable storage medium of claim 17 , wherein a determination by the PDF parser if the one or more suspicious characteristics indicative of malicious network content are included in the one or more examined portions of the PDF document, comprises:

determining a score associated with the one or more suspicious characteristics for the PDF document, the score indicative of a probability that the PDF document includes malicious network content; and

identifying the PDF document as suspicious if the score satisfies a threshold value.

19. The non-transitory computer readable storage medium of claim 17 , wherein the PDF parser examines a body portion of the PDF document and the entirety of the PDF document is not examined prior to providing the PDF document to the one or more virtual machines.

20. The non-transitory computer readable storage medium of claim 19 , wherein at least one of a header, a cross-reference table, or a trailer of the PDF document is not examined prior to providing the PDF document to the one or more virtual machines.

21. The non-transitory computer readable storage medium of claim 17 wherein the PDF parser, when executed by the processor, examines the PDF document by at least applying heuristics to determine if at least one suspicious characteristic indicative of malicious network content is included in the PDF document.

22. The non-transitory computer readable storage medium of claim 17 , wherein the memory further comprises a module that, when executed by the processor, prevents the delivery of the PDF document verified to include malicious network content to a web browser application from which the delivery was requested.

23. The non-transitory computer readable storage medium of claim 17 , wherein an examination of the one or more portions of the PDF document by the PDF parser, when executed by the processor, further comprises:

examining at least one of a header section or a body section of the PDF document; and

when the body section or the header section of the PDF document is determined to include one or more suspicious characteristics indicative of malicious network content, providing the PDF document to the one or more virtual machines associated with the digital device to verify the inclusion of malicious network content in the PDF document.

24. The non-transitory computer readable storage medium of claim 17 , wherein the one or more virtual machines includes two or more augmented finite state machines, the two or more augmented finite state machines each including a configuration that includes at least one set of operating system instructions, at least one set of web browser instructions, and at least one set of PDF reader instructions, the configuration of each of the two or more augmented finite state machines being different from one another.

25. The non-transitory computer readable storage medium of claim 17 , wherein the examining of the one or more portions of the PDF document by the PDF parser further comprises:

examining one or more of a header section, a body section, a trailer section, or a cross-reference table section of the PDF document; and

providing the PDF document to the one or more virtual machines associated with the digital device to verify the inclusion of malicious network content in the PDF document when one or more of the body section, the header section, the trailer section or the cross-reference table section of the PDF document is determined to include one or more suspicious characteristics indicative of malicious network content.

26. The non-transitory computer readable storage medium of claim 17 further comprising a data access component communicatively coupled to the processor, the data access component to intercept at least the PDF document before the PDF parser examines the one or more portions of the PDF document.

27. The non-transitory computer readable storage medium of claim 26 , wherein the one or more portions of the PDF document comprises a body section of the PDF document.

28. The non-transitory computer readable storage medium of claim 17 , wherein the one or more virtual machines are configured based on at least data associated with the PDF document in response to the one or more examined portions of the PDF document being determined to include one or more suspicious characteristics indicative of malicious network content.

29. The non-transitory computer readable storage medium of claim 28 , wherein the one or more virtual machines are configured based on one or more PDF specification version numbers of the PDF document.

30. The non-transitory computer readable storage medium of claim 29 , wherein a PDF specification version number of the one or more PDF specification version numbers is used to identify a specific PDF reader application version to be run in a virtual machine of the one or more virtual machines.

31. The non-transitory computer readable storage medium of claim 17 , wherein the one or more examined portions of the PDF document comprises a body section and a header section of the PDF document.

32. The non-transitory computer readable storage medium of claim 17 , wherein the PDF parser examines a header of the PDF document and the entirety of the PDF document is not examined prior to providing the PDF document to the one or more virtual machines.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063113/0150 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063113/0140 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2016
From: STANIFORD, STUART GRESLEY; AZIZ, ASHAR
To: FIREEYE, INC.
Reel/Frame 039203/0460 →