IP Library Granted Patent US 10,523,694
Granted Patent B2
US 10,523,694 · App. 15/592,211 · Granted Dec 31, 2019

System and method for interception of malicious files

Inventors: Maor Hizkiev (Tel-Aviv, IL); Liron Barak (Rishon Lezion, IL); Alex Livshiz (Rishon Lezion, IL); Ran Regenstreif (Tel-Aviv, IL)
Assignee: BITDAM LTD
H04L63/1425G06F21/53G06F21/566H04L63/1441G06F2221/033G06F2221/2101G06F2221/2115
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,523,694
App. No.
15/592,211
Granted
Dec 31, 2019
Kind
B2
Abstract

A system and method for interception of malicious files, the system comprising an agent component planted in a mail server; a protection server configured to communicate with the agent component, the protection server comprising a hardware processor configured to execute code instructions for: fetching by the agent component a file received at the mail server; generating a file execution record of at least a list of tuple addresses used by the fetched file; verifying validity of the tuple address types; and indicating that a file is suspicious in case a tuple address is not valid.

Claims (32)

1. A system for interception of malicious files, the system comprising:

an agent component planted in a mail server;

a protection server configured to communicate with the agent component, the protection server comprising a hardware processor configured to execute code instructions for:

fetching by the agent component a file received at the mail server;

generating a file execution record of at least a list of tuple addresses used by the fetched file;

verifying validity of the tuple address types; and

indicating that a file is suspicious in case a tuple address is not valid,

wherein the verifying further includes verifying that a tuple address and/or a function pointed to matches a tuple address and/or a function name stored in a database, and

wherein a tuple address is comprised of: TO-address and FROM-address.

2. The system of claim 1 , wherein the generation of the file execution record is by executing the fetched file and recording the list of tuple addresses used by the fetched file.

3. The system of claim 2 , wherein the generation of the file execution record is further by parsing of text included in the file code.

4. The system of claim 1 , wherein the file execution record includes a module name and/or address, and wherein the processor is configured to execute code instructions for comparing the module name and/or address to names and/or addresses stored in a database.

5. The system of claim 4 , wherein the processor is configured to execute code instructions for identifying to which module a tuple address belongs and adjusting the tuple address according to an address offset of the module.

6. The system of claim 4 , wherein the processor is configured to execute code instructions for preventing storage of a module in a same memory space as a previously unloaded module, by marking the memory space of the unloaded module as occupied.

7. The system of claim 1 , wherein the file execution record includes a process count value, and wherein the processor is configured to execute code instructions for comparing the process count value to values stored in a database.

8. The system of claim 1 , wherein the processor is configured to execute code instructions for calculating an address of a call corresponding to a return instruction.

9. The system of claim 8 , wherein the processor is configured to execute code instructions for executing the return instruction and monitoring whether the address reached after the return instruction is executed is the expected location pointed to by a corresponding tuple address.

10. A method for interception of malicious files, the method comprising:

communicate with an agent component planted in a mail server agent component to fetch a file received at the mail server;

generating a file execution record of at least a list of tuple addresses used by the fetched file;

verifying validity of the tuple address types; and

indicating that a file is suspicious in case a tuple address is not valid

wherein the verifying further includes verifying that a tuple address and/or a function pointed to matches a tuple address and/or a function name stored in a database

wherein a tuple address is comprised of: TO-address and FROM-address.

11. The method of claim 10 , wherein the generation of the file execution record is by executing the fetched file and recording the list of tuple addresses used by the fetched file.

12. The method of claim 11 , wherein the generation of the file execution record is further by parsing of text included in the file code.

13. The method of claim 10 , wherein the file execution record includes a module name and/or address, and the method comprising comparing the module name and/or address to names and/or addresses stored in a database.

14. The method of claim 13 , wherein the method comprising identifying to which module a tuple address belongs and adjusting the tuple address according to an address offset of the module.

15. The method of claim 13 , wherein the method comprising preventing storage of a module in a same memory space as a previously unloaded module, by marking the memory space of the unloaded module as occupied.

16. The method of claim 10 , wherein the file execution record includes a process count value, and wherein the method comprising comparing the process count value to values stored in a database.

17. The method of claim 10 , wherein the method comprising calculating an address of a call corresponding to a return instruction.

18. The method of claim 17 , wherein the method comprising executing the return instruction and monitoring whether the address reached after the return instruction is executed is the expected location pointed to by a corresponding tuple address.

Assignments (2)
CHANGE OF NAME Recorded Oct 27, 2023
From: DATTO, INC.
To: DATTO, LLC
Reel/Frame 065385/0256 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 11, 2017
From: HIZKIEV, MAOR; BARAK, LIRON; LIVSHIZ, ALEX; REGENSTREIF, RAN
To: BITDAM LTD
Reel/Frame 042332/0991 →
Continuity (1)
Related Publication 20180332059A1 · Nov 15, 2018