IP Library Granted Patent US 9,832,215
Granted Patent B2
US 9,832,215 · App. 14/836,984 · Granted Nov 28, 2017

Automatic content inspection system for exploit detection

Inventors: Aviv Gafni (Ramat Gan, IL); Ben Omelchenko (Tel Aviv, IL)
Assignee: Check Point Advanced Threat Prevention Ltd
H04L63/1425G06F9/45533G06F9/45558H04L63/145H04L63/1466H04L63/1483G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,832,215
App. No.
14/836,984
Granted
Nov 28, 2017
Kind
B2
Abstract

A method of inspecting content intended for a workstation to detect content that performs malicious exploits, including receiving the content for inspection at an inspection server using a processor and memory, loading a virtual machine at the inspection server with an operating system and processes for activating the content, wherein the operating system and processes are similar to those executed at the intended workstation, activating the content in the virtual machine, tracing activity of the virtual machine to form trace data by using features of the processor, wherein upon occurrence of an exception control is transferred to an analyzer that analyzes the trace data based on a context of the exception; and a notification is provided if suspicious activity is detected.

Claims (25)

1. A method of detecting potentially malicious content, comprising:

identifying content for inspection;

loading a virtual machine for activating the identified content for inspection;

the virtual machine, upon detecting an occurrence of an application processing the content on a processor, tracing activity of the processor in order to form trace data, by:

a lightweight driver providing: 1) a list of modules being executed by the virtual machine, and 2) the addresses of the memory pages used by the modules;

the lightweight driver activating an exploit detection engine (EDE) to accept a page dump of the memory pages used by the modules; and,

upon detecting an occurrence of an exception in the trace data by the EDE, the EDE transferring control to an analyzer, the analyzer detecting suspicious activity according to the trace data based on a context of the exception.

2. A method according to claim 1 , wherein identifying the content is performed by identifying attachments in email with potentially malicious file types.

3. A method according to claim 1 , wherein identifying the content is performed by identifying content in data received from a web site with potentially malicious data types.

4. A method according to claim 1 , wherein the tracing includes recording details of flow control instructions executed by a workstation associated with the processor.

5. A method according to claim 1 , wherein the accepting a page dump of the memory pages used by the modules occurs before starting to execute code from memory pages.

6. A method according to claim 1 , wherein a notification is provided upon the detecting of the suspicious activity.

7. A method according to claim 1 , wherein an inspection server which includes the processor intercepts the content before being provided to a workstation.

8. A method according to claim 1 , wherein an inspection server which includes the processor receives the content from a workstation.

9. A computer system for detecting potentially malicious content, comprising:

a storage medium for storing computer components; and,

a computerized processor for executing the computer components comprising:

a first computer component for identifying content for inspection;

a second computer component for loading a virtual machine for activating the identified content for inspection, the virtual machine upon detecting an occurrence of an application processing the content on a processor, tracing the activity of the processor in order to form trace data, by:

a lightweight driver providing: 1) a list of modules being executed by the virtual machine, and 2) the addresses of the memory pages used by the modules;

the lightweight driver activating an exploit detection engine (EDE) to accept a page dump of the memory pages used by the modules;

a third computer component for, upon detecting an occurrence of an exception in the trace data by the EDE, causing the transfer of control from the EDE to an analyzer that detects suspicious activity according to the trace data based on a context of the exception; and,

a fourth computer component for activating the analyzer for detecting suspicious activity according to the trace data based on a context of the exception.

10. The method of claim 1 , wherein the processor includes debugging features including one or more of: Branch Tree Storage (BTS), Last Branch Record (LBR), Branch Tree Message (BTM) and a Processor Trace.

11. The system of claim 9 , wherein the second computer component uses features of the processor, which include debugging features including one or more of: Branch Tree Storage (BTS), Last Branch Record (LBR), Branch Tree Message (BTM) and a Processor Trace.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2024
From: GAFNI, AVIV; OMELCHENKO, BEN
To: HYPERWISE SECURITY LTD.
Reel/Frame 069048/0463 →
CHANGE OF NAME Recorded Oct 29, 2024
From: HYPERWISE SECURITY LTD.
To: CHECK POINT ADVANCED THREAT PREVENTION LTD
Reel/Frame 069274/0066 →
MERGER Recorded Sep 11, 2024
From: CHECK POINT ADVANCED THREAT PREVENTION LTD
To: CHECK POINT SOFTWARE TECHNOLOGIES LTD.
Reel/Frame 068548/0794 →
Continuity (2)
Continuation 14333566 · Jul 17, 2014
Related Publication 20160021142A1 · Jan 21, 2016