IP Library Granted Patent US 10,944,785
Granted Patent B2
US 10,944,785 · App. 16/391,714 · Granted Mar 9, 2021

Systems and methods for detecting the injection of malicious elements into benign content

Inventor: Mark Haffenden (Reading, GB)
Assignee: Forcepoint LLC
H04L63/1466H04L9/0643H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,944,785
App. No.
16/391,714
Granted
Mar 9, 2021
Kind
B2
Abstract

A method, system, and computer-usable medium are disclosed for include receiving a first version of content from a resource, generating a first lightweight fingerprint for the first version of the content, receiving a second version of the content from the same resource, generating a second lightweight fingerprint for the second version of the content, comparing the first lightweight fingerprint to the second lightweight fingerprint to determine changes to a non-injectable section of the content and potentially-injected sections of the content between the first version and the second version, and determining the content to include potentially malicious elements responsive to determining that the non-injectable section of the content have remained substantially static between the first version and the second version and determining that potentially-injected sections of the content has substantially changed between the first version and the second version.

Claims (57)

1. A computer-implementable method comprising:

receiving a first version of content from a resource;

generating a first lightweight fingerprint for the first version of the content;

receiving a second version of the content from the same resource;

generating a second lightweight fingerprint for the second version of the content;

comparing the first lightweight fingerprint to the second lightweight fingerprint to determine changes to a non-injectable section of the content and potentially-injected sections of the content between the first version and the second version; and

determining the content to include potentially malicious elements responsive to determining that the non-injectable section of the content has remained substantially static between the first version and the second version and determining that potentially-injected sections of the content have substantially changed between the first version and the second version.

2. The computer-implementable method of claim 1 , further comprising taking remedial action responsive to determining the content to include potentially malicious elements.

3. The computer-implementable method of claim 1 , further comprising determining a low likelihood of potentially malicious elements responsive to one of:

a first condition comprising determining that potentially-injected sections of the content have remained substantially static between the first version and the second version; and

a second condition comprising determining that the non-injectable section of the content has substantially changed between the first version and the second version.

4. The computer-implementable method of claim 1 , wherein generating a lightweight fingerprint comprising one of the first lightweight fingerprint and the second lightweight fingerprint comprises:

partitioning content into a plurality of sections including an outline section associated with non-injectable content of the content and at least one potentially-injectable section wherein each of the at least one potentially-injectable section is associated with a potentially-injectable element of the content;

generating respective individual fingerprints for each of the outline section and the at least one potentially-injectable section; and

combining the respective individual fingerprints to form the lightweight fingerprint.

5. The computer-implementable method of claim 4 , wherein generating an individual fingerprint for one of the outline section and an embedded script section of the at least one potentially-injectable section comprises generating a winnowing hash for the outline section.

6. The computer-implementable method of claim 4 , wherein generating an individual fingerprint for one of an external script section and an iframe section of the at least one potentially-injectable section comprises generating a two-part fingerprint comprising a host name and a final file name.

7. The computer-implementable method of claim 1 , wherein the content comprises a HyperText Markup Language file for rendering a web page.

8. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

receiving a first version of content from a resource;

generating a first lightweight fingerprint for the first version of the content;

receiving a second version of the content from the same resource;

generating a second lightweight fingerprint for the second version of the content;

comparing the first lightweight fingerprint to the second lightweight fingerprint to determine changes to a non-injectable section of the content and potentially-injected sections of the content between the first version and the second version; and

determining the content to include potentially malicious elements responsive to determining that the non-injectable section of the content has remained substantially static between the first version and the second version and determining that potentially-injected sections of the content have substantially changed between the first version and the second version.

9. The system of claim 8 , the instructions further configured for taking remedial action responsive to determining the content to include potentially malicious elements.

10. The system of claim 8 , the instructions further configured for determining a low likelihood of potentially malicious elements responsive to one of:

a first condition comprising determining that potentially-injected sections of the content have remained substantially static between the first version and the second version; and

a second condition comprising determining that the non-injectable section of the content has substantially changed between the first version and the second version.

11. The system of claim 8 , wherein generating a lightweight fingerprint comprising one of the first lightweight fingerprint and the second lightweight fingerprint comprises:

partitioning content into a plurality of sections including an outline section associated with non-injectable content of the content and at least one potentially-injectable section wherein each of the at least one potentially-injectable section is associated with a potentially-injectable element of the content;

generating respective individual fingerprints for each of the outline section and the at least one potentially-injectable section; and

combining the respective individual fingerprints to form the lightweight fingerprint.

12. The system of claim 11 , wherein generating an individual fingerprint for one of the outline section and an embedded script section of the at least one potentially-injectable section comprises generating a winnowing hash for the outline section.

13. The system of claim 11 , wherein generating an individual fingerprint for one of an external script section and an iframe section of the at least one potentially-injectable section comprises generating a two-part fingerprint comprising a host name and a final file name.

14. The system of claim 8 , wherein the content comprises a HyperText Markup Language file for rendering a web page.

15. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

receiving a first version of content from a resource;

generating a first lightweight fingerprint for the first version of the content;

receiving a second version of the content from the same resource;

generating a second lightweight fingerprint for the second version of the content;

comparing the first lightweight fingerprint to the second lightweight fingerprint to determine changes to a non-injectable section of the content and potentially-injected sections of the content between the first version and the second version; and

determining the content to include potentially malicious elements responsive to determining that the non-injectable section of the content has remained substantially static between the first version and the second version and determining that potentially-injected sections of the content have substantially changed between the first version and the second version.

16. The storage medium of claim 15 , the instructions further configured for taking remedial action responsive to determining the content to include potentially malicious elements.

17. The storage medium of claim 15 , the instructions further configured for determining a low likelihood of potentially malicious elements responsive to one of:

a first condition comprising determining that potentially-injected sections of the content have remained substantially static between the first version and the second version; and

a second condition comprising determining that the non-injectable section of the content has substantially changed between the first version and the second version.

18. The storage medium of claim 15 , wherein generating a lightweight fingerprint comprising one of the first lightweight fingerprint and the second lightweight fingerprint comprises:

partitioning content into a plurality of sections including an outline section associated with non-injectable content of the content and at least one potentially-injectable section wherein each of the at least one potentially-injectable section is associated with a potentially-injectable element of the content;

generating respective individual fingerprints for each of the outline section and the at least one potentially-injectable section; and

combining the respective individual fingerprints to form the lightweight fingerprint.

19. The storage medium of claim 18 , wherein generating an individual fingerprint for one of the outline section and an embedded script section of the at least one potentially-injectable section comprises generating a winnowing hash for the outline section.

20. The storage medium of claim 18 , wherein generating an individual fingerprint for one of an external script section and an iframe section of the at least one potentially-injectable section comprises generating a two-part fingerprint comprising a host name and a final file name.

21. The storage medium of claim 15 , wherein the content comprises a HyperText Markup Language file for rendering a web page.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0207 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 27, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 052045/0482 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2019
From: HAFFENDEN, MARK
To: FORCEPOINT LLC
Reel/Frame 048980/0501 →
Continuity (1)
Related Publication 20200344258A1 · Oct 29, 2020