IP Library Granted Patent US 10,554,682
Granted Patent B2
US 10,554,682 · App. 15/382,903 · Granted Feb 4, 2020

Detecting and removing injected elements from content interfaces

Inventors: Ohad Greenshpan (Ra'anana, IL); Chemi Katz (Ra'anana, IL)
Assignee: Namogoo Technologies Ltd.
H04L63/1441G06Q30/0277
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,554,682
App. No.
15/382,903
Granted
Feb 4, 2020
Kind
B2
Abstract

Systems and methods are disclosed for detecting and removing injected elements from content interfaces. In one implementation, a processing device receives a content interface from a content provider, processes the content interface to identify elements of the interface that may not have been received from the content provider, compares the content interface with corresponding reference interfaces to identify elements of the content interface that are not present in the reference interfaces, processes the identified elements to determine how the identified elements affect a rendering of the content interface on the device, and modifies a rendering of the content interface on the device based on the manner in which the identified elements affect the rendering of the content interface on the device.

Claims (29)

1. A method comprising:

receiving a webpage associated with a content provider, wherein the webpage comprises a plurality of content elements;

comparing, by a processing device, the webpage loaded by the device with one or more reference webpages originating from the content provider to detect a first malware element of the plurality of content elements of the webpage loaded by the device that is not present in the one or more reference webpages, wherein the first malware element is loaded after expiration of a time interval subsequent to a loading of one or more other content elements of the webpage; and

modifying a first parameter of code associated with the first malware element to interrupt a display of the first malware element via the webpage on the device, wherein at least a portion of the code associated with the first malware element is maintained.

2. The method of claim 1 , further comprising identifying the first malware element is capable of being injected by a third-party service into the webpage.

3. The method of claim 1 , further comprising identifying the first malware element was previously injected into another webpage by a third-party service.

4. The method of claim 1 , further comprising identifying the first malware element is capable of being injected by a third-party service and not present in the one or more corresponding reference interfaces.

5. The method of claim 4 , further comprising comparing a first attribute of the first malware element with one or more attributes of one or more elements from the one or more reference webpages, wherein the first attribute comprises at least one of: a position of the first malware element, a size of the first malware element, or a shape of the first malware element.

6. The method of claim 1 , further comprising identifying the first malware element comprises one or more source domains that are not included in a set of valid source domains.

7. The method of claim 1 , further comprising determining the first malware element overlays one or more content elements of the webpage.

8. The method of claim 1 , further comprising identifying a removal of one or more content elements of the webpage.

9. The method of claim 1 , further comprising identifying a removal of one or more content elements of the webpage after expiration of a time interval.

10. The method of claim 1 , wherein the first parameter comprises one or more coordinates pertaining to an orientation of the first malware element.

11. The method of claim 1 , further comprising removing one or more parameters of the first malware element.

12. The method of claim 1 , further comprising replacing a content element of the webpage with a substitute content element.

13. The method of claim 1 , further comprising generating a content element that encapsulates the first malware element.

14. The method of claim 13 , wherein the content element comprises an invisibility attribute.

15. The method of claim 1 , further comprising determining the first malware element is listening for one or more inputs to be provided in relation to the webpage.

16. The method of claim 15 , further comprising modifying the webpage to process an input prior to processing of the input by the first malware element.

17. A system comprising:

a memory; and

a processing device, coupled to the memory, to:

receive a webpage associated with a content provider, wherein the webpage comprises a plurality of elements;

compare the webpage loaded by the device with one or more corresponding reference webpages originating from the content provider to detect a first malware element of the plurality of elements of the webpage loaded by the device that is not present in the one or more corresponding reference webpages, wherein an element of the plurality of elements is removed after expiration of a time interval; and

modify a first parameter of code associated with the first malware element to interrupt a display of the first malware element via the webpage on the device, wherein at least a portion of the code associated with the first malware element is maintained.

18. A non-transitory computer readable medium having instructions stored thereon that, when executed by a processing device, cause the processing device to:

receive a webpage associated with a content provider, wherein the webpage comprises a plurality of elements;

compare the webpage loaded by the device with one or more corresponding reference webpages originating from the content provider to detect a first malware element of the plurality of elements of the webpage loaded by the device that is not present in the one or more corresponding reference webpages, wherein an element of the plurality of elements is removed after expiration of a time interval; and

modify a first parameter of code associated with the first malware element to interrupt a display of the first malware element via the webpage on the device, wherein at least a portion of the code associated with the first malware element is maintained.

Assignments (3)
SECURITY INTEREST Recorded Jan 12, 2022
From: NAMOGOO TECHNOLOGIES LTD.
To: SILICON VALLEY BANK
Reel/Frame 058635/0407 →
SECURITY INTEREST Recorded Jun 17, 2021
From: NAMOGOO TECHNOLOGIES LTD.
To: SILICON VALLEY BANK
Reel/Frame 056576/0036 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2016
From: GREENSHPAN, OHAD; KATZ, CHEMI
To: NAMOGOO TECHNOLOGIES LTD.
Reel/Frame 040752/0809 →
Continuity (3)
Provisional Application 62031284 · Jul 31, 2014
Provisional Application 62031285 · Jul 31, 2014
Related Publication 20180219910A1 · Aug 2, 2018