System and method for selectively processing content after identification and removal of malicious content
A system and method directed toward the deployment of one or more security plug-ins for software components (e.g., applications) that analyze incoming content and selectively prevent malicious portions of the content from being processed by the applications without limiting the processing and/or rendering of the legitimate (non-malicious) portions of the incoming content is described. Each of the security plug-ins is communicatively coupled to a published interface of a software component, such as an application. The security plug-in includes logic to (i) gain access to content received by the software component prior to processing of the content by the software component, (ii) parse the content into separate segments, (iii) analyze each content segment to determine whether the content segment is malicious or non-malicious, and (iv) permit rendering of one or more non-malicious content segments while preventing processing of one or more malicious content segments.
1. An endpoint device, comprising:
one or more hardware processors; and
a memory coupled to the one or more hardware processors, the memory comprises
management logic,
a plurality of software components, and
a plurality of security plug-ins corresponding to the plurality of software components stored within the endpoint device, the plurality of security plug-ins comprise a first security plug-in communicatively coupled to an interface of a first software component of the plurality of software components and a second security plug-in communicatively coupled to an interface of a second software component of the plurality of software components,
wherein the first security plug-in of the plurality of security plug-ins including logic configured to gain access to a first type of content that includes web page content and the second security plug-in including logic configured to gain access to a second type of content that is different from the first type of content,
wherein both of the first security plug-in and the second security plug-in are configured to (i) parse received content, being the first type of content or the second type of content, into a plurality of content segments, wherein each content segment of the plurality of content segments is lesser in size than the received content and pertaining to a different category of content for analysis, wherein each content segment of the plurality of content segments has at least one of a plurality of segment types, wherein the plurality of segment types at least comprise an executable segment type and a non-executable segment type, (ii) locally analyze each content segment of the plurality of content segments, using one or more different threat detection rules pertaining to at least one of the plurality of segment types, and determine whether each content segment of the plurality of content segments is malicious or non-malicious, and (iii) permit rendering of one or more non-malicious content segments of the plurality of content segments by performing a remediation operation by at least replacing each malicious content segment corresponding to a displayable image with an advertisement image obtained from a data store including advertisement images that are updated as part of a service to which advertisers can subscribe, and by preventing further processing of one or more malicious content segments of the plurality of content segments,
wherein the management logic is configured to coordinate collective operability of the plurality of security plug-ins based on reported threat information to render a verdict for at least one content segment of the plurality of content segments.
2. The endpoint device of claim 1 , wherein at least the first security plug-in is configured to gain access to the received content via an application programming interface (API) provided by the software component.
3. The endpoint device of claim 1 , wherein at least the first security plug-in is configured to gain access to the received content via one or more operating system interfaces.
4. The endpoint device of claim 2 , wherein at least the first software component corresponds to a web browser application.
5. The endpoint device of claim 2 , wherein at least the first software component corresponds to a word processing application.
6. The endpoint device of claim 1 , wherein the first security plug-in is configured to analyze a first content segment and determine whether the first content segment is malicious or non-malicious by at least (i) identifying a type of content segment being analyzed and (ii) comparing information within the first content segment to regular expressions being part of threat detection rules associated with the type of content segment identified.
7. The endpoint device of claim 1 , wherein the advertisement image corresponds to a paid advertisement obtained from the data store that is periodically or aperiodically uploaded with substitute content segments.
8. The endpoint device of claim 7 , wherein the substitute content segments maintained within the data store are updated by the service to which advertisers subscribe.
9. The endpoint device of claim 1 , wherein each content segment corresponds to a JavaScript® block.
10. The endpoint device of claim 1 , wherein the memory further comprising:
notification logic configured to issue an alert provided to display control logic, wherein the alert is superimposed over an area of a web page.
11. A non-transitory computer readable medium including management logic and a plurality of security plug-ins communicatively coupled to a software component and, upon execution, performing operations comprising:
gaining access, by each security plug-in of the plurality of security plug-ins, to a different type of content in which a first security plug-in is configured to gain access to a first type of content that includes web page content and a second security plug-in is configured to gain access to a second type of content that includes a non-executable and is different from the first type of content;
parsing, by both the first security plug-in and the second security plug-in, received content, being the first type of content or the second content, into a plurality of content segments, wherein each content segment of the plurality of content segments is lesser in size than the received content, wherein each content segment of the plurality of content segments has at least one of a plurality of segment types, wherein the plurality of segment types at least comprise an executable segment type and a non-executable segment type;
locally analyzing, by the first security plug-in and the second security plug-in, each content segment of the plurality of content segments, using one or more different threat detection rules pertaining to at least one of the plurality of segment types, and determine whether each content segment of the plurality of content segments is malicious or non-malicious; and
permitting, by the first security plug-in and the second security plug-in, a rendering of one or more non-malicious content segments of the plurality of content segments by performing a remediation operation by at least replacing each malicious content segment corresponding to a displayable image with an advertisement image obtained from a data store including advertisement images that are updated as part of a service to which advertisers can subscribe, and by preventing further processing of one or more malicious content segments of the plurality of content segments,
wherein the management logic is configured to coordinate collective operability of the plurality of security plug-ins based on reported threat information to render a verdict for at least one content segment of the plurality of content segments.
12. The non-transitory computer readable medium of claim 11 , wherein the first security plug-in, upon execution by a processor, is configured to gain access to the content via an application programming interface (API) provided by the software component.
13. The non-transitory computer readable medium of claim 11 , wherein the first security plug-in, upon execution by the processor, to gain access to the received first type of content via one or more operating system interfaces.
14. The non-transitory computer readable medium of claim 12 , wherein the software component corresponds to a web browser application.
15. The non-transitory computer readable medium of claim 12 , wherein the software component corresponds to a word processing application.
16. The non-transitory computer readable medium of claim 11 , wherein the first security plug-in, upon execution by the processor, is configured to analyze a first content segment and determine whether the first content segment is malicious or non-malicious by at least (i) identifying a type of content segment being analyzed and (ii) comparing information within the first content segment to regular expressions being part of threat detection rules associated with the type of content segment identified.
17. The non-transitory computer readable medium of claim 11 , wherein the advertisement image corresponds to a paid advertisement that is obtained from the data store and the data store is periodically or aperiodically uploaded with substitute content segments.
18. The non-transitory computer readable medium of claim 11 , wherein the first security plug-in, upon execution by the processor, is configured to permit processing of the one or more non-malicious content segments by performing a second remediation operation by removing linking capability for each malicious content segment.
19. The non-transitory computer readable medium of claim 11 , wherein each content segment corresponds to a JavaScript® block.
20. A method for modifying a web page by a plurality of security plug-ins that are deployed within an endpoint device and each configured to detect and remove one or more malicious content segments directed to a cyberattack within a web page and rendering of the modified web page, comprising:
gaining access, by each security plug-in of the plurality of security plug-ins, to a different type of content in which a first security plug-in is configured to gain access to a first type of content that includes web page content and a second security plug-in is configured to gain access to a second type of content that includes a non-executable and is different from the first type of content;
parsing, by both the first security plug-in and the second security plug-in, received content, being the first type of content or the second content, into a plurality of content segments, wherein each content segment of the plurality of content segments is lesser in size than the received content, wherein each content segment of the plurality of content segments has at least one of a plurality of segment types, wherein the plurality of segment types at least comprise an executable segment type and a non-executable segment type;
locally analyzing, by the first security plug-in and the second security plug-in, each content segment of the plurality of content segments, using one or more different threat detection rules pertaining to at least one of the plurality of segment types, and determine whether each content segment of the plurality of content segments is malicious or non-malicious; and
permitting, by the first security plug-in and the second security plug-in, a rendering of one or more non-malicious content segments of the plurality of content segments by performing a remediation operation by at least replacing each malicious content segment corresponding to a displayable image with an advertisement image obtained from a data store including advertisement images that are updated as part of a service to which advertisers can subscribe, and by preventing further processing of one or more malicious content segments of the plurality of content segments,
wherein management logic within the endpoint device is configured to coordinate collective operability of the plurality of security plug-ins based on reported threat information to render a verdict for at least one content segment of the plurality of content segments.