IP Library › Granted Patent US 11,785,028
Granted Patent B1
US 11,785,028 · App. 17/878,030 · Granted Oct 10, 2023

Dynamic analysis for detecting harmful content

Inventors: Aleksandr Sevcenko (Vilnius, LT); Mantas Briliauskas (Vilnius, LT)
Assignee: UAB 360 IT
H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,785,028
App. No.
17/878,030
Granted
Oct 10, 2023
Kind
B1
Abstract

A method including receiving, by a user device, harmful patterns indicating characteristics of harmful traits included in affected data known to include malicious content and clean patterns indicating characteristics of clean traits included in clean data known to be free of the malicious content; receiving, by the user device, a first portion of given data; determining, by the user device, a pattern associated with traits included in the first portion of the given data; determining, by the user device, whether the first portion of the given data includes the malicious content based at least in part on comparing the determined pattern with the harmful patterns and the clean patterns; and selectively receiving, by the user device, a second portion of the given data based at least in part on determining whether the first portion of the given data includes the malicious content is disclosed. Various other aspects are contemplated.

Claims (42)

1. A method, comprising:

receiving, by a user device, harmful patterns indicating characteristics of harmful traits included in affected data known to include malicious content and clean patterns indicating characteristics of clean traits included in clean data known to be free of the malicious content;

receiving, by the user device, a first portion of given data;

determining, by the user device, a pattern associated with traits included in the first portion of the given data;

determining, by the user device, whether the first portion of the given data includes the malicious content based at least in part on comparing the determined pattern with the harmful patterns and the clean patterns; and

selectively receiving, by the user device, a second portion of the given data based at least in part on determining whether the first portion of the given data includes the malicious content, wherein

selectively receiving the second portion of the given data includes selecting to receive the second portion of the given data based at least in part on determining that the first portion of the given data fails to include the malicious content.

2. The method of claim 1 , wherein a trait includes a function associated with a software code or an alphanumeric string associated with a communication.

3. The method of claim 1 , wherein selectively receiving the second portion of the given data includes selecting to refrain from receiving the second portion of the given data based at least in part on determining that the first portion of the given data includes the malicious content.

4. The method of claim 1 , further comprising:

determining a size of the first portion of the given data to be received.

5. The method of claim 1 , wherein determining the pattern includes determining the pattern that indicates a particular arrangement of one or more traits included in the first portion of the given data.

6. The method of claim 1 , wherein determining whether the first portion of the given data includes the malicious content includes utilizing a machine learning model to compare the determined pattern with the harmful patterns and the clean patterns.

7. The method of claim 1 , further comprising:

refraining from executing or rendering a received portion of the given data until all portions of the given data are received and determined to fail to include the malicious content.

8. A user device, comprising:

a memory; and

a processor communicatively coupled with the memory, the memory and the processor being configured to:

receive harmful patterns indicating characteristics of harmful traits included in affected data known to include malicious content and clean patterns indicating characteristics of clean traits included in clean data known to be free of the malicious content;

receive a first portion of given data;

determine a pattern associated with traits included in the first portion of the given data;

determine whether the first portion of the given data includes the malicious content based at least in part on comparing the determined pattern with the harmful patterns and the clean patterns; and

selectively receive a second portion of the given data based at least in part on determining whether the first portion of the given data includes the malicious content, wherein

to selectively receive the second portion of the given data, the memory and the processor are configured to select to receive the second portion of the given data based at least in part on determining that the first portion of the given data fails to include the malicious content.

9. The infrastructure device of claim 8 , wherein a trait includes a function associated with a software code or an alphanumeric string associated with a communication.

10. The infrastructure device of claim 8 , wherein, to selectively receive the second portion of the given data, the memory and the processor are configured to select to refrain from receiving the second portion of the given data based at least in part on determining that the first portion of the given data includes the malicious content.

11. The infrastructure device of claim 8 , the memory and the processor are configured to determine a size of the first portion of the given data to be received.

12. The infrastructure device of claim 8 , wherein, to determine the pattern, the memory and the processor are configured to determine the pattern that indicates a particular arrangement of one or more traits included in the first portion of the given data.

13. The infrastructure device of claim 8 , wherein, to determine whether the first portion of the given data includes the malicious content, the memory and the processor are configured to utilize a machine learning model to compare the determined pattern with the harmful patterns and the clean patterns.

14. The infrastructure device of claim 8 , wherein the memory and the processor are configured to refrain from executing or rendering a received portion of the given data until all portions of the given data are received and determined to fail to include the malicious content.

15. A non-transitory computer-readable medium configured to store instructions, which when executed by a processor associated with a user device, configure the processor to:

receive harmful patterns indicating characteristics of harmful traits included in affected data known to include malicious content and clean patterns indicating characteristics of clean traits included in clean data known to be free of the malicious content;

receive a first portion of given data;

determine a pattern associated with traits included in the first portion of the given data;

determine whether the first portion of the given data includes the malicious content based at least in part on comparing the determined pattern with the harmful patterns and the clean patterns; and

selectively receive a second portion of the given data based at least in part on determining whether the first portion of the given data includes the malicious content, wherein

to selectively receive the second portion of the given data, the processor is configured to select to receive the second portion of the given data based at least in part on determining that the first portion of the given data fails to include the malicious content.

16. The non-transitory computer-readable medium of claim 15 , wherein a trait includes a function associated with a software code or an alphanumeric string associated with a communication.

17. The non-transitory computer-readable medium of claim 15 , wherein, to selectively receive the second portion of the given data, the processor is configured to select to refrain from receiving the second portion of the given data based at least in part on determining that the first portion of the given data includes the malicious content.

18. The non-transitory computer-readable medium of claim 15 , the processor is configured to determine a size of the first portion of the given data to be received.

19. The non-transitory computer-readable medium of claim 15 , wherein, to determine the pattern, the processor is configured to determine the pattern that indicates a particular arrangement of one or more traits included in the first portion of the given data.

20. The non-transitory computer-readable medium of claim 15 , wherein, to determine whether the first portion of the given data includes the malicious content, the processor is configured to utilize a machine learning model to compare the determined pattern with the harmful patterns and the clean patterns.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 3, 2022
From: SEVCENKO, ALEKSANDR; BRILIAUSKAS, MANTAS
To: UAB 360 IT
Reel/Frame 060704/0927 →
Cited By (1)
US 12,425,432