IP Library Granted Patent US 12,074,887
Granted Patent B1
US 12,074,887 · App. 16/231,089 · Granted Aug 27, 2024

System and method for selectively processing content after identification and removal of malicious content

Inventor: Muhammad Zain ul abadin Gardezi (Milpitas, CA)
Assignee: Musarubra US LLC
H04L63/1416G06F9/54H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,074,887
App. No.
16/231,089
Granted
Aug 27, 2024
Kind
B1
Abstract

A system and method directed toward the deployment of one or more security plug-ins for software components (e.g., applications) that analyze incoming content and selectively prevent malicious portions of the content from being processed by the applications without limiting the processing and/or rendering of the legitimate (non-malicious) portions of the incoming content is described. Each of the security plug-ins is communicatively coupled to a published interface of a software component, such as an application. The security plug-in includes logic to (i) gain access to content received by the software component prior to processing of the content by the software component, (ii) parse the content into separate segments, (iii) analyze each content segment to determine whether the content segment is malicious or non-malicious, and (iv) permit rendering of one or more non-malicious content segments while preventing processing of one or more malicious content segments.

Claims (39)

1. An endpoint device, comprising:

one or more hardware processors; and

a memory coupled to the one or more hardware processors, the memory comprises

management logic,

a plurality of software components, and

a plurality of security plug-ins corresponding to the plurality of software components stored within the endpoint device, the plurality of security plug-ins comprise a first security plug-in communicatively coupled to an interface of a first software component of the plurality of software components and a second security plug-in communicatively coupled to an interface of a second software component of the plurality of software components,

wherein the first security plug-in of the plurality of security plug-ins including logic configured to gain access to a first type of content that includes web page content and the second security plug-in including logic configured to gain access to a second type of content that is different from the first type of content,

wherein both of the first security plug-in and the second security plug-in are configured to (i) parse received content, being the first type of content or the second type of content, into a plurality of content segments, wherein each content segment of the plurality of content segments is lesser in size than the received content and pertaining to a different category of content for analysis, wherein each content segment of the plurality of content segments has at least one of a plurality of segment types, wherein the plurality of segment types at least comprise an executable segment type and a non-executable segment type, (ii) locally analyze each content segment of the plurality of content segments, using one or more different threat detection rules pertaining to at least one of the plurality of segment types, and determine whether each content segment of the plurality of content segments is malicious or non-malicious, and (iii) permit rendering of one or more non-malicious content segments of the plurality of content segments by performing a remediation operation by at least replacing each malicious content segment corresponding to a displayable image with an advertisement image obtained from a data store including advertisement images that are updated as part of a service to which advertisers can subscribe, and by preventing further processing of one or more malicious content segments of the plurality of content segments,

wherein the management logic is configured to coordinate collective operability of the plurality of security plug-ins based on reported threat information to render a verdict for at least one content segment of the plurality of content segments.

2. The endpoint device of claim 1 , wherein at least the first security plug-in is configured to gain access to the received content via an application programming interface (API) provided by the software component.

3. The endpoint device of claim 1 , wherein at least the first security plug-in is configured to gain access to the received content via one or more operating system interfaces.

4. The endpoint device of claim 2 , wherein at least the first software component corresponds to a web browser application.

5. The endpoint device of claim 2 , wherein at least the first software component corresponds to a word processing application.

6. The endpoint device of claim 1 , wherein the first security plug-in is configured to analyze a first content segment and determine whether the first content segment is malicious or non-malicious by at least (i) identifying a type of content segment being analyzed and (ii) comparing information within the first content segment to regular expressions being part of threat detection rules associated with the type of content segment identified.

7. The endpoint device of claim 1 , wherein the advertisement image corresponds to a paid advertisement obtained from the data store that is periodically or aperiodically uploaded with substitute content segments.

8. The endpoint device of claim 7 , wherein the substitute content segments maintained within the data store are updated by the service to which advertisers subscribe.

9. The endpoint device of claim 1 , wherein each content segment corresponds to a JavaScript® block.

10. The endpoint device of claim 1 , wherein the memory further comprising:

notification logic configured to issue an alert provided to display control logic, wherein the alert is superimposed over an area of a web page.

11. A non-transitory computer readable medium including management logic and a plurality of security plug-ins communicatively coupled to a software component and, upon execution, performing operations comprising:

gaining access, by each security plug-in of the plurality of security plug-ins, to a different type of content in which a first security plug-in is configured to gain access to a first type of content that includes web page content and a second security plug-in is configured to gain access to a second type of content that includes a non-executable and is different from the first type of content;

parsing, by both the first security plug-in and the second security plug-in, received content, being the first type of content or the second content, into a plurality of content segments, wherein each content segment of the plurality of content segments is lesser in size than the received content, wherein each content segment of the plurality of content segments has at least one of a plurality of segment types, wherein the plurality of segment types at least comprise an executable segment type and a non-executable segment type;

locally analyzing, by the first security plug-in and the second security plug-in, each content segment of the plurality of content segments, using one or more different threat detection rules pertaining to at least one of the plurality of segment types, and determine whether each content segment of the plurality of content segments is malicious or non-malicious; and

permitting, by the first security plug-in and the second security plug-in, a rendering of one or more non-malicious content segments of the plurality of content segments by performing a remediation operation by at least replacing each malicious content segment corresponding to a displayable image with an advertisement image obtained from a data store including advertisement images that are updated as part of a service to which advertisers can subscribe, and by preventing further processing of one or more malicious content segments of the plurality of content segments,

wherein the management logic is configured to coordinate collective operability of the plurality of security plug-ins based on reported threat information to render a verdict for at least one content segment of the plurality of content segments.

12. The non-transitory computer readable medium of claim 11 , wherein the first security plug-in, upon execution by a processor, is configured to gain access to the content via an application programming interface (API) provided by the software component.

13. The non-transitory computer readable medium of claim 11 , wherein the first security plug-in, upon execution by the processor, to gain access to the received first type of content via one or more operating system interfaces.

14. The non-transitory computer readable medium of claim 12 , wherein the software component corresponds to a web browser application.

15. The non-transitory computer readable medium of claim 12 , wherein the software component corresponds to a word processing application.

16. The non-transitory computer readable medium of claim 11 , wherein the first security plug-in, upon execution by the processor, is configured to analyze a first content segment and determine whether the first content segment is malicious or non-malicious by at least (i) identifying a type of content segment being analyzed and (ii) comparing information within the first content segment to regular expressions being part of threat detection rules associated with the type of content segment identified.

17. The non-transitory computer readable medium of claim 11 , wherein the advertisement image corresponds to a paid advertisement that is obtained from the data store and the data store is periodically or aperiodically uploaded with substitute content segments.

18. The non-transitory computer readable medium of claim 11 , wherein the first security plug-in, upon execution by the processor, is configured to permit processing of the one or more non-malicious content segments by performing a second remediation operation by removing linking capability for each malicious content segment.

19. The non-transitory computer readable medium of claim 11 , wherein each content segment corresponds to a JavaScript® block.

20. A method for modifying a web page by a plurality of security plug-ins that are deployed within an endpoint device and each configured to detect and remove one or more malicious content segments directed to a cyberattack within a web page and rendering of the modified web page, comprising:

gaining access, by each security plug-in of the plurality of security plug-ins, to a different type of content in which a first security plug-in is configured to gain access to a first type of content that includes web page content and a second security plug-in is configured to gain access to a second type of content that includes a non-executable and is different from the first type of content;

parsing, by both the first security plug-in and the second security plug-in, received content, being the first type of content or the second content, into a plurality of content segments, wherein each content segment of the plurality of content segments is lesser in size than the received content, wherein each content segment of the plurality of content segments has at least one of a plurality of segment types, wherein the plurality of segment types at least comprise an executable segment type and a non-executable segment type;

locally analyzing, by the first security plug-in and the second security plug-in, each content segment of the plurality of content segments, using one or more different threat detection rules pertaining to at least one of the plurality of segment types, and determine whether each content segment of the plurality of content segments is malicious or non-malicious; and

permitting, by the first security plug-in and the second security plug-in, a rendering of one or more non-malicious content segments of the plurality of content segments by performing a remediation operation by at least replacing each malicious content segment corresponding to a displayable image with an advertisement image obtained from a data store including advertisement images that are updated as part of a service to which advertisers can subscribe, and by preventing further processing of one or more malicious content segments of the plurality of content segments,

wherein management logic within the endpoint device is configured to coordinate collective operability of the plurality of security plug-ins based on reported threat information to render a verdict for at least one content segment of the plurality of content segments.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
MERGER Recorded Jul 23, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068055/0665 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063114/0766 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063114/0701 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2019
From: GARDEZI, MUHAMMAD ZAIN UL ABADIN
To: FIREEYE, INC.
Reel/Frame 047935/0513 →