IP Library Granted Patent US 9,830,453
Granted Patent B1
US 9,830,453 · App. 14/929,155 · Granted Nov 28, 2017

Detection of code modification

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,830,453
App. No.
14/929,155
Granted
Nov 28, 2017
Kind
B1
Abstract

A system for detecting unusual code operating in a browser agent comprises a processor and a memory. The processor is to: determine that a block of code is running on a web page; parse the block of code into a parsed template; obtain indicia associated with the block of code; and determine that the parsed template is unusual based at least in part on the parsed template and the indicia. The memory is coupled with the processor and is configured to provide the processor with instructions.

Claims (55)

1. A system for detecting unusual code operating in a browser, comprising:

a processor to:

determine that a block of code is running on a web page;

parse the block of code into a parsed template;

obtain indicia associated with the block of code; and

determine that the parsed template is unusual based at least in part on the parsed template and the indicia, comprising to:

determine whether a misconfiguration issue exists, comprising to:

determine whether a number of reports for a script associated with the block of code is equal to or exceeds a minimum count threshold, the minimum count threshold being 100; and

in response to a determination that the number of reports for a script associated with the block of code is equal to or exceeds the minimum count threshold:

 determine whether a portion of IPs with the block of code is equal to or exceeds a minimum percent of users, the minimum percent of users being 50 percent:

 in response to a determination that the portion of IPs with the block of code is greater than or equal to the minimum percent of users:

 determine whether the script is not a known malware script; and

 in response to a determination that the script is not a known malware script, determine that a script misconfiguration exists; and

 in response to a determination that the portion of IPs with the block of code is less than the minimum percent of users, omit determining that the script misconfiguration exists; and

a memory coupled with the processor, wherein the memory is configured to provide the processor with instructions.

2. The system as in claim 1 , wherein the block of code is hashed.

3. The system as in claim 1 , wherein the parsed template is hashed.

4. The system as in claim 3 , wherein an identifier is generated from hashing the parsed template.

5. The system as in claim 1 , wherein the parsed template includes a substitute for a literal in the code.

6. The system as in claim 1 , wherein the parsed template includes substitutes for data structures constructed entirely out of literals.

7. The system as in claim 1 , wherein one of the indicia associated with the block of code comprises a count of occurrence of the block of code.

8. The system as in claim 1 , wherein one of the indicia associated with the block of code comprises a count of occurrence of the parsed template.

9. The system as in claim 1 , wherein one of the indicia associated with the block of code comprises the portion of IPs with the block of code.

10. The system as in claim 1 , wherein the indicia are augmented using CSPs to determine whether a web page is running malicious code.

11. The system as in claim 1 , wherein the processor is to receive instructions.

12. The system as in claim 11 , wherein the instructions comprise instructions to monitor.

13. The system as in claim 11 , wherein the instructions comprise instructions to filter.

14. The system as in claim 11 , wherein the instructions comprise instructions to delete.

15. The system as in claim 11 , wherein the instructions comprise instructions to quarantine.

16. A method for detecting unusual code operating in a browser agent, comprising:

determining, using a processor, that a block of code is running on a web page;

parsing the block of code into a parsed template;

obtaining indicia associated with the block of code; and

determining that the parsed template is unusual based at least in part on the parsed template and the indicia, comprising:

determining whether a misconfiguration issue exists, comprising:

determining whether a number of reports for a script associated with the block of code is equal to or exceeds a minimum count threshold, the minimum count threshold being 100; and

in response to a determination that the number of reports for a script associated with the block of code is equal to or exceeds the minimum count threshold:

determining whether a portion of IPs with the block of code is equal to or exceeds a minimum percent of users, the minimum percent of users being 50 percent;

in response to a determination that the portion of IPs with the block of code is greater than or equal to the minimum percent of users:

 determining whether the script is not a known malware script; and

 in response to a determination that the script is not a known malware script, determining that a script misconfiguration exists; and

in response to a determination that the portion of IPs with the block of code is less than the minimum percent of users, omitting determining that the script misconfiguration exists.

17. A computer program product for detecting unusual code operating in a browser agent, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

determining, using a processor, that a block of code is running on a web page;

parsing the block of code into a parsed template;

obtaining indicia associated with the block of code; and

determining that the parsed template is unusual based at least in part on the parsed template and the indicia, comprising:

determining whether a misconfiguration issue exists, comprising:

determining whether a number of reports for a script associated with the block of code is equal to or exceeds a minimum count threshold, the minimum count threshold being 100; and

in response to a determination that the number of reports for a script associated with the block of code is equal to or exceeds the minimum count threshold:

determining whether a portion of IPs with the block of code is equal to or exceeds a minimum percent of users, the minimum percent of users being 50 percent;

in response to a determination that the portion of IPs with the block of code is greater than or equal to the minimum percent of users:

 determining whether the script is not a known malware script; and

 in response to a determination that the script is not a known malware script, determining that a script misconfiguration exists; and

in response to a determination that the portion of IPs with the block of code is less than the minimum percent of users, omitting determining that the script misconfiguration exists.

Assignments (5)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2019
From: TCELL.IO, INC.
To: RAPID7, INC.
Reel/Frame 048163/0538 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2016
From: FEIERTAG, MICHAEL; HELD, GARRETT; LIVINGSTON, BLAKE
To: TCELL.IO, INC.
Reel/Frame 037611/0664 →