IP Library › Granted Patent US 11,681,801
Granted Patent B2
US 11,681,801 · App. 16/531,314 · Granted Jun 20, 2023

Malicious code purification in graphics files

Inventors: Yevgeni Gehtman (Modi'in, IL); Maxim Futerman (Ashdod, IL)
Assignee: Dell Products L.P.
G06F21/564G06F21/565G06F21/568G06T1/0021
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,681,801
App. No.
16/531,314
Filed
Aug 5, 2019
Granted
Jun 20, 2023
Kind
B2
Art Unit
2438
USPC
726/23
Abstract

An information handling system improves detection of steganography data embedded in a graphics file by parsing the portable network graphics file to determine a location of a graphics file signature in the graphics file, and determining whether there is data embedded in the graphics file before the graphics signature. The embedded data may then be removed from the graphics file.

Claims (48)

1. A method, comprising:

parsing, by a processor, a graphics file to determine a location of a graphics file signature in the graphics file;

determining, by the processor, whether there is embedded data at a location in the graphics file that is after the determined location of the graphics file signature;

in response to the determining that there is embedded data after the graphics file signature, removing, by the processor, the embedded data from the graphics file;

subsequent to the removing the embedded data from the graphics file, setting a flag to indicate that the embedded data in the graphics file has been removed;

determining a hash of the embedded data after removing the embedded data from the graphics file; and

based on the hash, alerting a malware detection system of a possible malware infection.

2. The method of claim 1 , wherein the graphics file comprises a portable network graphics (PNG) file, and wherein the graphics file signature comprises hexadecimal values comprising “00 00 00 00 49 45 4E 44 AE 42 60 82”.

3. The method of claim 1 , further comprising determining, by a processor, to scan the graphics file for potential steganographic content, wherein the determining includes determining whether at least one of a plurality of steganographic criteria is satisfied, wherein the plurality of steganographic criteria includes at least one of:

a field associated with the graphics file indicates that the graphics file has been modified after the graphics file has been downloaded;

a field associated with the graphics file indicates that the graphics file has been modified after the graphics file has been replicated;

a field associated with the graphics file indicates that the graphics file has been modified after the graphics file has been backed up; or

a field associated with the graphics file indicates that the graphics file has been modified after the graphics file has been restored.

4. An information handling system comprising:

a processor; and

a memory having code stored thereon that, when executed by the processor, performs a method comprising:

parsing, by the processor, a graphics file to determine a location of a graphics file signature in the graphics file;

determining, by the processor, whether there is embedded data at a location in the graphics file that is after the determined location of the graphics file signature;

in response to the determining that there is embedded data after the graphics file signature, removing, by the processor, the embedded data from the graphics file;

subsequent to the removing the embedded data from the graphics file, setting a flag to indicate that the embedded data in the graphics file has been removed;

determining a hash of the embedded data after removing the embedded data from the graphics file; and

based on the hash, alerting a malware detection system of a possible malware infection.

5. The information handling system of claim 4 , wherein the graphics file comprises a portable network graphics (PNG) file, and wherein the graphics file signature comprises hexadecimal values comprising “00 00 00 00 49 45 4E 44 AE 42 60 82”.

6. A non-transitory computer-readable medium including code for performing a method, the method comprising:

parsing, by a processor, a graphics file to determine a location of a graphics file signature in the graphics file;

determining, by the processor, whether there is embedded data at a location in the graphics file that is after the determined location of the graphics file signature;

in response to the determining that there is embedded data after the graphics file signature, removing, by the processor, the embedded data from the graphics file;

subsequent to the removing the embedded data from the graphics file, setting a flag to indicate that the embedded data in the graphics file has been removed;

determining a hash of the embedded data after removing the embedded data from the graphics file; and

based on the hash, alerting a malware detection system of a possible malware infection.

7. The non-transitory computer-readable medium of claim 6 , wherein the graphics file comprises a portable network graphics (PNG) file, and wherein the graphics file signature comprises hexadecimal values comprising “00 00 00 00 49 45 4E 44 AE 42 60 82”.

8. The method of claim 1 , wherein the step of parsing, by the processor, a graphics file to determine the location of a graphics file signature in the graphics file comprises parsing, by the processor, the graphics file to determine a location of a post-fix graphics file signature, and wherein the step of determining, by the processor, whether there is embedded data in the graphics file after the graphics file signature comprises determining whether there is embedded data in the graphics file after the post-fix graphics file signature.

9. The method of claim 8 , wherein the step of parsing, by the processor, a graphics file to determine the location of a graphics file signature in the graphics file comprises parsing, by the processor, the graphics file to determine a location of a post-fix graphics file signature, and wherein the step of determining whether there is embedded data in the graphics file after a post-fix graphics file signature comprises determining whether there is embedded data in the graphics file after the post-fix graphics file signature at an end of a body of the graphics file.

10. The information handling system of claim 4 , wherein the memory further comprises code stored thereon that, when executed by the processor, performs a method comprising:

determining, by a processor, to scan the graphics file for potential steganographic content, wherein the determining whether to analyze the graphics file for potential steganography includes determining whether at least one of a plurality of steganographic criteria is satisfied.

11. The information handling system of claim 10 , wherein the plurality of steganographic criteria includes at least one of:

a field associated with the graphics file indicates that the graphics file has been modified after the graphics file has been downloaded;

a field associated with the graphics file indicates that the graphics file has been modified after the graphics file has been replicated;

a field associated with the graphics file indicates that the graphics file has been modified after the graphics file has been backed up; or

a field associated with the graphics file indicates that the graphics file has been modified after the graphics file has been restored.

12. The information handling system of claim 4 , wherein the step of determining whether there is embedded data in the graphics file after the graphics file signature comprises determining whether there is embedded data in the graphics file after a post-fix graphics file signature at an end of a body of the graphics file.

13. The non-transitory computer-readable medium of claim 6 , further comprising code for performing: determining to scan the graphics file for potential steganographic content, wherein the determining includes determining whether at least one of a plurality of steganographic criteria is satisfied.

14. The non-transitory computer-readable medium of claim 13 , wherein the plurality of steganographic criteria includes at least one of:

a field associated with the graphics file indicates that the graphics file has been modified after the graphics file has been downloaded;

a field associated with the graphics file indicates that the graphics file has been modified after the graphics file has been replicated;

a field associated with the graphics file indicates that the graphics file has been modified after the graphics file has been backed up; or

a field associated with the graphics file indicates that the graphics file has been modified after the graphics file has been restored.

15. The non-transitory computer-readable medium of claim 6 , wherein the step of determining whether there is embedded data in the graphics file after the graphics file signature comprises determining whether there is embedded data in the graphics file after a post-fix graphics file signature at an end of a body of the graphics file.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (051302/0528) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.); SECUREWORKS CORP.
Reel/Frame 060438/0593 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST AT REEL 051449 FRAME 0728 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
Reel/Frame 058002/0010 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Dec 31, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 051449/0728 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Dec 16, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 051302/0528 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2019
From: GEHTMAN, YEVGENI; FUTERMAN, MAXIM
To: DELL PRODUCTS L.P.
Reel/Frame 049956/0466 →
Continuity (2)
Continuation In Part 16246955 · Jan 14, 2019
Related Publication 20200226255A1 · Jul 16, 2020
Cited By (1)
US 12,743,517