IP Library › Granted Patent US 10,673,892
Granted Patent B2
US 10,673,892 · App. 15/392,414 · Granted Jun 2, 2020

Detection of malware features in a content item

Inventors: Niels Provos (Mountain View, CA); Yunkai Zhou (Los Altos, CA); Clayton W. Bavor, Jr. (Palo Alto, CA); Eric L. Davis (Menlo Park, CA); Mark Palatucci (Pittsburgh, PA); Kamal P. Nigam (Pittsburgh, PA); Christopher K. Monson (Swissvale, PA); Panayiotis Mavrommatis (Mountain View, CA); Rachel Nakauchi (Yelm, WA)
Assignee: Google LLC
H04L63/145G06F21/564G06F21/577G06N20/00H04L43/0876H04L67/02G06F2221/2119
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,673,892
App. No.
15/392,414
Granted
Jun 2, 2020
Kind
B2
Abstract

Intrusion features of a landing page associated with sponsored content are identified. A feature score for the landing page based on the identified intrusion features is generated, and if the feature score for the landing page exceeds a feature threshold, the landing page is classified as a candidate landing page. A sponsor account associated with the candidate landing page can be suspended, or sponsored content associated with the candidate landing page can be suspended.

Claims (37)

1. A computer-implemented method comprising:

identifying, by one or more processors, a landing page of a sponsored content item that is available for presentation on a website;

evaluating features of the landing page using a first malware detection process;

determining, by the one or more processors, that the landing page is a malware candidate based on the evaluation performed using the first malware detection process reveals that the landing page has one or more malware characteristics;

evaluating, by the one or more processors, the malware candidate using a different malware detection process that performs evaluations that are beyond those performed by the first malware detection process, including:

simulating selection of the sponsored content item that is linked to the landing page; and

evaluating one or more additional pages that differ from the landing page and that are in a redirect chain followed in response to the simulated selection of the sponsored content item for characteristics of malware;

flagging, by the one or more processors, the sponsored content item as malware when the different malware detection process detects malware in the one or more additional pages that are in the redirect chain; and

preventing, by the one or more processors, the sponsored content item from being served while the sponsored content item is flagged as malware.

2. The method of claim 1 , wherein evaluating features of the landing page comprises evaluating iFrame features, URL features, or script features.

3. The method of claim 1 , wherein simulating selection of the sponsored content item comprises simulating the selection using a virtual machine, and wherein the virtual machine is further configured to:

monitor usage of system files by the sponsored content item; and

monitor processes created by the sponsored content item.

4. A system comprising:

one or more computers and one or more storage devices storing instructions that, when executed by the one or more computers, cause the one or more computers to perform operations comprising:

identifying a landing page of a sponsored content item that is available for presentation on a website;

evaluating features of the landing page using a first malware detection process;

determining that the landing page is a malware candidate based on the evaluation performed using the first malware detection process reveals that the landing page has one or more malware characteristics;

evaluating the malware candidate using a different malware detection process that performs evaluations that are beyond those performed by the first malware detection process, including:

simulating selection of the sponsored content item that is linked to the landing page; and

evaluating one or more additional pages that differ from the landing page and that are in a redirect chain followed in response to the simulated selection of the sponsored content item for characteristics of malware;

flagging the sponsored content item as malware when the different malware detection process detects malware in the one or more additional pages that are in the redirect chain; and

preventing the sponsored content item from being served while the sponsored content item is flagged as malware.

5. The system of claim 4 , wherein evaluating features of the landing page comprises evaluating iFrame features, URL features, or script features.

6. The system of claim 4 , wherein simulating selection of the sponsored content item comprises simulating the selection using a virtual machine, and wherein the virtual machine is further configured to:

monitor usage of system files by the sponsored content item; and

monitor processes created by the sponsored content item.

7. A non-transitory computer-readable medium storing software comprising instructions executable by one or more computers which, upon such execution, cause the one or more computers to perform operations comprising:

identifying a landing page of a sponsored content item that is available for presentation on a website;

evaluating features of the landing page using a first malware detection process;

determining that the landing page is a malware candidate based on the evaluation performed using the first malware detection process reveals that the landing page has one or more malware characteristics;

evaluating the malware candidate using a different malware detection process that performs evaluations that are beyond those performed by the first malware detection process, including:

simulating selection of the sponsored content item that is linked to the landing page; and

evaluating one or more additional pages that differ from the landing page and that are in a redirect chain followed in response to the simulated selection of the sponsored content item for characteristics of malware;

flagging the sponsored content item as malware when the different malware detection process detects malware in the one or more additional pages that are in the redirect chain; and

preventing the sponsored content item from being served while the sponsored content item is flagged as malware.

8. The medium of claim 7 , wherein evaluating features of the landing page comprises evaluating iFrame features, URL features, or script features.

Assignments (2)
CHANGE OF NAME Recorded Oct 5, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044129/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2016
From: PROVOS, NIELS; ZHOU, YUNKAI; BAVOR, CLAYTON W., JR.; DAVIS, ERIC L.; PALATUCCI, MARK; NIGAM, KAMAL P.; MONSON, CHRISTOPHER K.; MAVROMMATIS, PANAYIOTIS; NAKAUCHI, RACHEL
To: GOOGLE INC.
Reel/Frame 040787/0543 →
Continuity (4)
Continuation 13587025 · Aug 16, 2012
Continuation 13230544 · Sep 12, 2011
Continuation 11868321 · Oct 5, 2007
Related Publication 20170111375A1 · Apr 20, 2017