IP Library Granted Patent US 11,100,226
Granted Patent B1
US 11,100,226 · App. 15/945,694 · Granted Aug 24, 2021

Systems and methods for identifying a malicious user interface

Inventors: Vinith Raj (Los Angeles, CA); Mohit Jha (Torrance, CA)
Assignee: NortonLifeLock Inc.
G06F21/566G06F21/44G06F21/554G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,100,226
App. No.
15/945,694
Granted
Aug 24, 2021
Kind
B1
Abstract

The disclosed computer-implemented method for identifying a malicious user interface may include (1) detecting, at a computing device, a launch of a user interface (UI), (2) gathering characteristics of the UI including a UI image, (3) identifying the UI is not permissible by comparing the UI image to a whitelist including permissible UI images, and (4) performing, when the UI image is not permissible, a security action. Various other methods, systems, and computer-readable media are also disclosed.

Claims (67)

1. A computer-implemented method for identifying a malicious user interface, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

detecting, at the computing device, a launch of a user interface (UI);

gathering characteristics of the UI including a UI image, wherein the UI Image is displayed on a video display device coupled to the computing device;

identifying, by the computing device, the UI is not permissible by automatically comparing the UI image displayed on the video display device to a whitelist including permissible UI images; and

performing, when the UI image is not permissible, a security action.

2. The computer-implemented method of claim 1 , wherein the characteristics further comprise a trust rating of a process that launched the UI, a language of the UI, and an authentication identifier; wherein the identifying further comprises comparing the trust rating of the process that launched the UI, the language of the UI, and the authentication identifier to the whitelist to identify a mismatch; and further comprising:

performing the security action when there is a mismatch.

3. The computer-implemented method of claim 1 , wherein the characteristics further comprise a language of the UI and further comprising:

gathering operating system (OS) characteristics including an OS language;

comparing the OS language to the language of the UI to identify a mismatch; and

performing the security action when there is a mismatch.

4. The computer-implemented method of claim 1 , wherein the characteristics further comprise text displayed by the UI and an identification of a process that launched the UI, and further comprising:

comparing the text displayed by the UI to the identification of the process that launched the UI to identify a mismatch; and

performing the security action when there is a mismatch.

5. The computer-implemented method of claim 1 , further comprising:

identifying the UI is a child window of a parent window;

identifying a process that launched the child window;

identifying a process that launched the parent window;

comparing the process that launched the child window to the process that launched the parent window to identify a mismatch; and

performing the security action when there is a mismatch.

6. The computer-implemented method of claim 1 , wherein the security action comprises preventing data entry into the UI and displaying a warning on the video display device.

7. The computer-implemented method of claim 1 , wherein the security action comprises displaying, on the video display device, a pop-up box indicating that the UI is potentially malicious.

8. A system for identifying a malicious user interface, the system comprising:

a detecting module, stored in a memory, that detects a launch of a user interface (UI);

a gathering module, stored in the memory, that gathers characteristics of the UI including a UI image, wherein the UI Image is displayed on a video display device;

an identifying module, stored in the memory, that identifies the UI is not permissible by automatically comparing the UI image displayed on the video display device to a whitelist including permissible UI images;

a performing module, stored in the memory, that performs a security action when the UI image is not permissible; and

at least one physical processor that executes the detecting module, the gathering module, the identifying module, and the performing module.

9. The system of claim 8 , wherein the characteristics further comprise a trust rating of a process that launched the UI, a language of the UI, and an authentication identifier; wherein the identifying further comprises comparing the trust rating of the process that launched the UI, the language of the UI, and the authentication identifier to the whitelist to identify a mismatch; and further comprising:

a second performing module, stored in the memory, that performs the security action when there is a mismatch.

10. The system of claim 8 , wherein the characteristics further comprise a language of the UI and further comprising:

a second gathering module, stored in the memory, that gathers operating system (OS) characteristics including an OS language;

a comparing module, stored in the memory, that compares the OS language to the language of the UI to identify a mismatch; and

a second performing module, stored in the memory, that performs the security action when there is a mismatch.

11. The system of claim 8 , wherein the characteristics further comprise text displayed by the UI and an identification of a process that launched the UI, and further comprising:

a comparing module, stored in the memory, that compares the text displayed by the UI to the identification of the process that launched the UI to identify a mismatch; and

a second performing module, stored in the memory, that performs the security action when there is a mismatch.

12. The system of claim 8 , further comprising:

a first identifying module, stored in the memory, that identifies the UI is a child window of a parent window;

a second identifying module, stored in the memory, that identifies a process that launched the child window;

a third identifying module, stored in the memory, that identifies a process that launched the parent window;

a comparing module, stored in the memory, that compares the process that launched the child window to the process that launched the parent window to identify a mismatch; and

a second performing module, stored in the memory, that performs the security action when there is a mismatch.

13. The system of claim 8 , wherein the security action comprises preventing data entry into the UI and displaying a warning on the video display device.

14. The system of claim 8 , wherein the security action comprises displaying, on the video display device, a pop-up box indicating that the UI is potentially malicious.

15. A non-transitory computer-readable medium comprising one or more computer-executable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

detect, at the computing device, a launch of a user interface (UI);

gather characteristics of the UI including a UI image, wherein the UI Image is displayed on a video display device coupled to the computing device;

identify, by the computing device, the UI is not permissible by automatically comparing the UI image displayed on the video display device to a whitelist including permissible UI images; and

perform, when the UI image is not permissible, a security action.

16. The non-transitory computer-readable medium of claim 15 , wherein the characteristics further comprise a trust rating of a process that launched the UI, a language of the UI, and an authentication identifier; wherein the identifying further comprises comparing the trust rating of the process that launched the UI, the language of the UI, and the authentication identifier to the whitelist to identify a mismatch; and further comprising one or more computer-executable instructions that, when executed by the at least one processor of the computing device, cause the computing device to:

perform the security action when there is a mismatch.

17. The non-transitory computer-readable medium of claim 15 , wherein the characteristics further comprise a language of the UI and further comprising one or more computer-executable instructions that, when executed by the at least one processor of the computing device, cause the computing device to:

gather operating system (OS) characteristics including an OS language;

compare the OS language to the language of the UI to identify a mismatch; and

perform the security action when there is a mismatch.

18. The non-transitory computer-readable medium of claim 15 , wherein the characteristics further comprise text displayed by the UI and an identification of a process that launched the UI, and further comprising one or more computer-executable instructions that, when executed by the at least one processor of the computing device, cause the computing device to:

compare the text displayed by the UI to the identification of the process that launched the UI to identify a mismatch; and

perform the security action when there is a mismatch.

19. The non-transitory computer-readable medium of claim 15 , further comprising one or more computer-executable instructions that, when executed by the at least one processor of the computing device, cause the computing device to:

identify the UI is a child window of a parent window;

identify a process that launched the child window;

identify a process that launched the parent window;

compare the process that launched the child window to the process that launched the parent window to identify a mismatch; and

perform the security action when there is a mismatch.

20. The non-transitory computer-readable medium of claim 15 , wherein the security action comprises preventing data entry into the UI and displaying a warning on the video display device.

21. The computer-implemented method of claim 1 , wherein the UI image is a video image displayed by the UI.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Feb 14, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051935/0228 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2018
From: RAJ, VINITH; JHA, MOHIT
To: SYMANTEC CORPORATION
Reel/Frame 045440/0311 →