IP Library › Granted Patent US 11,200,316
Granted Patent B2
US 11,200,316 · App. 16/246,955 · Granted Dec 14, 2021

System and method for malicious code purification of portable network graphics files

Inventors: Yevgeni Gehtman (Modi'in, IL); Maxim Futerman (Ashdod, IL)
Assignee: Dell Products L.P.
G06F21/563G06F21/565G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,200,316
App. No.
16/246,955
Filed
Jan 14, 2019
Granted
Dec 14, 2021
Kind
B2
Art Unit
2491
USPC
726/23
Abstract

An information handling system improves detection of steganography data embedded in a portable network graphics file by parsing the portable network graphics file to determine a location of a portable network graphics signature in the portable network graphics file, and determining whether there is data embedded in the portable network graphics file before the portable network graphics signature. The embedded data may then be removed from the portable network graphics file.

Claims (33)

1. A method to improve detection of steganography data embedded in a portable network graphics file, the method comprising:

detecting, by a hardware processor, the portable network graphics file; parsing the portable network graphics file to determine whether first eight bytes of the portable network graphics file in a header of the portable network graphics file is a portable network graphics signature: in response to determining that the first eight bytes of the header of the portable network graphics file is not the portable network graphics signature, determining a location of the portable network graphics signature; and

if there is embedded data before the location of the portable network graphics signature, then removing the embedded data from the portable network graphics file; and

subsequent to the removing of the embedded data from the portable network graphics file, setting a flag to indicate that the embedded data in the portable network graphics file has been removed.

2. The method of claim 1 , further comprising outputting results to a display device.

3. The method of claim 1 , further comprising determining whether to analyze the portable network graphics file for potential steganography.

4. The method of claim 3 , wherein the determining whether to analyze the portable network graphics file for potential steganography includes determining whether at least one of a plurality of stenographic criteria is satisfied.

5. The method of claim 4 , wherein one of the stenographic criteria is satisfied when a field associated with the portable network graphics file indicates that the portable network graphics file has been modified after the portable network graphics file has been downloaded.

6. The method of claim 4 , wherein one of the stenographic criteria is satisfied when a field associated with the portable network graphics file indicates that the portable network graphics file has been modified after the portable network graphics file has been backed up.

7. The method of claim 4 , wherein one of the stenographic criteria is satisfied when a field associated with the portable network graphics file indicates that the portable network graphics file has been modified after the portable network graphics file has been replicated.

8. The method of claim 4 , wherein one of the stenographic criteria is satisfied when a field associated with the portable network graphics file indicates that the portable network graphics file has been modified after the portable network graphics file has been restored.

9. An information handling system comprising:

a plurality of processors; and

a memory having code stored thereon that, when executed by one of the processors, performs a method including:

detecting a portable network graphics file;

parsing the portable network graphics file to determine whether first eight bytes of a header of the portable network graphics file is a portable network graphics signature;

in response to determining that the first eight bytes of the header of the portable network graphics file is not the portable network graphics signature, determining a location of the portable network graphics signature;

if there is embedded data before the location of the portable network graphic signature, removing the embedded data from the portable network graphics file; and

subsequent to the removing of the embedded data from the portable network graphics file, setting a flag to indicate that the embedded data in the portable network graphics file has been removed.

10. The information handling system of claim 9 , wherein the memory having code stored thereon, when executed by one of the processors, performs the method further comprising outputting results to a display device.

11. The information handling system of claim 9 , wherein the memory having code stored thereon, when executed by one of the processors, performs the method further comprising determining whether to analyze the portable network graphics file for potential steganography.

12. The information handling system of claim 11 , wherein the memory having code stored thereon, when executed by one of the processors, performs the method wherein the determining whether to analyze the portable network graphics file for potential steganography includes determining whether at least one of a plurality of stenographic criteria is satisfied.

13. The information handling system of claim 12 , wherein the memory having code stored thereon, when executed by one of the processors, performs the method wherein one of the stenographic criteria is satisfied when a field associated with the portable network graphics file indicates that the portable network graphics file has been modified after the portable network graphics file has been downloaded.

14. The information handling system of claim 12 , wherein the memory having code stored thereon, when executed by one of the processors, performs the method wherein one of the stenographic criteria is satisfied when a field associated with the portable network graphics file indicates that the portable network graphics file has been modified after the portable network graphics file has been backed up.

15. The information handling system of claim 12 , wherein the memory having code stored thereon, when executed by one of the processors, performs the method wherein one of the stenographic criteria is satisfied when a field associated with the portable network graphics file indicates that the portable network graphics file has been modified after the portable network graphics file has been replicated.

16. A non-transitory computer-readable medium including code for performing a method, the method comprising:

detecting a portable network graphics file;

parsing the portable network graphics file to determine whether first eight bytes of a header in the portable network graphics file is a portable network graphics signature;

in response to determining that the first eight bytes in the header of the portable network graphics file is not the portable network graphics signature, determining a location of the portable network graphics signature;

if there is embedded data before the location of the portable network graphics signature, then removing the embedded data from the portable network graphics file; and

subsequent to the removing of the embedded data in the portable network graphics file before the portable network graphics signature, setting a flag to indicate that the embedded data in the portable network graphics file is removed.

17. The non-transitory computer-readable medium of claim 16 , including code for performing the method, the method further comprising determining whether to analyze the portable network graphics file for potential steganography.

18. The non-transitory computer-readable medium of claim 16 , including code for performing the method, the method further comprising setting a flag to indicate that the embedded data in the portable network graphics file has been removed.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: GEHTMAN, YEVGENI; FUTERMAN, MAXIM
To: DELL PRODUCTS, LP
Reel/Frame 049548/0918 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
Continuity (1)
Related Publication 20200226254A1 · Jul 16, 2020
Cited By (1)
US 12,743,517