IP Library Granted Patent US 9,648,032
Granted Patent B2
US 9,648,032 · App. 15/062,455 · Granted May 9, 2017

System and method for blocking execution of scripts

Inventors: Vasily A. Davydov (Moscow, RU); Anton M. Ivanov (Moscow, RU); Roman Y. Gavrilchenko (Moscow, RU); Dmitry V. Vinogradov (Moscow, RU)
Assignee: AO Kaspersky Lab
H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,648,032
App. No.
15/062,455
Granted
May 9, 2017
Kind
B2
Abstract

Disclosed are exemplary aspects of systems and methods for blocking execution of scripts. An exemplary method comprises: intercepting a request for a script from a client to a server; generating a bytecode of the intercepted script; computing a hash sum of the generated bytecode; determining a degree of similarity between the hash sum of the bytecode and a plurality of hash sums of malicious and clean scripts stored in a database; identifying a similar hash sum from the database whose degree of similarity with the hash sum of the bytecode is within a threshold of similarity; determining a coefficient of trust of the similar hash sum; determining whether the requested script is malicious based on the degree of similarity and the coefficient of trust of the similar hash sum; and blocking the execution of the malicious script on the client.

Claims (52)

1. A method for blocking execution of malicious scripts, the method comprising:

intercepting, by a processor of a client, a script requested by the client from a server by providing, on the client, a driver configured to intercept network script requests by rerouting at least one transmission channel of the script from the client to the driver;

generating, by the processor, a bytecode of the intercepted script;

computing, by the processor, a hash sum of the generated bytecode;

determining, by the processor, a degree of similarity between the hash sum of the bytecode and a plurality of hash sums of malicious and clean scripts stored in a database;

identifying, by the processor, a similar hash sum from the database whose degree of similarity with the hash sum of the bytecode is within a threshold of similarity;

determining, by the processor, a coefficient of trust of the similar hash sum;

determining, by the processor, whether the requested script is malicious based on the degree of similarity and the coefficient of trust of the similar hash sum; and

blocking, by the processor, the execution of the malicious script on the client.

2. The method of claim 1 , wherein the bytecode includes at least one opcode of the script.

3. The method of claim 1 , wherein generating a bytecode of the script includes:

identifying script commands responsible for functions of writing of data to disk, working with objects of file system and execution of programs;

grouping the identified script commands into a plurality of functional groups based on their identified functions;

assigning a binary value to each functional group; and

generating the bytecode from the binary values.

4. The method of claim 1 , wherein a hash sum includes a fuzzy hash.

5. The method of claim 1 , wherein searching for matching hash sums includes fuzzy searching.

6. A system for blocking execution of malicious scripts, the system comprising:

a hardware processor of a client configured to:

intercept a script requested by the client from a server by providing, on the client, a driver configured to intercept network script requests by rerouting at least one transmission channel of the script from the client to the driver;

generate a bytecode of the intercepted script;

compute a hash sum of the generated bytecode;

determine a degree of similarity between the hash sum of the bytecode and a plurality of hash sums of malicious and clean scripts stored in a database;

identify a similar hash sum from the database whose degree of similarity with the hash sum of the bytecode is within a threshold of similarity;

determine a coefficient of trust of the similar hash sum;

determine whether the requested script is malicious based on the degree of similarity and the coefficient of trust of the similar hash sum; and

block the execution of the malicious script on the client.

7. The system of claim 6 , wherein the bytecode includes at least one opcode of the script.

8. The system of claim 6 , wherein generating a bytecode of the script includes:

identify script commands responsible for functions of writing of data to disk, working with objects of file system and execution of programs;

group the identified script commands into a plurality of functional groups based on their identified functions;

assign a binary value to each functional group; and

generate the bytecode from the binary values.

9. The system of claim 6 , wherein a hash sum includes a fuzzy hash.

10. The system of claim 6 , wherein searching for matching hash sums includes fuzzy searching.

11. A non-transitory computer readable medium storing computer executable instructions for blocking execution of malicious scripts, including instructions for:

intercepting a script requested by a client from a server by providing, on the client, a driver configured to intercept network script requests by rerouting at least one transmission channel of the script from the client to the driver;

generating a bytecode of the intercepted script;

computing a hash sum of the generated bytecode;

determining a degree of similarity between the hash sum of the bytecode and a plurality of hash sums of malicious and clean scripts stored in a database;

identifying a similar hash sum from the database whose degree of similarity with the hash sum of the bytecode is within a threshold of similarity;

determining a coefficient of trust of the similar hash sum;

determining whether the requested script is malicious based on the degree of similarity and the coefficient of trust of the similar hash sum; and

blocking the execution of the malicious script on the client.

12. The non-transitory computer readable medium of claim 11 , wherein the bytecode includes at least one opcode of the script.

13. The non-transitory computer readable medium of claim 11 , wherein generating a bytecode of the script includes:

identifying script commands responsible for functions of writing of data to disk, working with objects of file system and execution of programs;

grouping the identified script commands into a plurality of functional groups based on their identified functions;

assigning a binary value to each functional group; and

generating the bytecode from the binary values.

14. The non-transitory computer readable medium of claim 11 , wherein a hash sum includes a fuzzy hash.

15. The non-transitory computer readable medium of claim 11 , wherein searching for matching hash sums includes fuzzy searching.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2016
From: DAVYDOV, VASILY A.; IVANOV, ANTON M.; GAVRILCHENKO, ROMAN Y.; VINOGRADOV, DMITRY V.
To: AO KASPERSKY LAB
Reel/Frame 037909/0058 →
Priority Claims (1)
RU 2015141537 · Sep 30, 2015 · national
Continuity (1)
Related Publication 20170093893A1 · Mar 30, 2017