IP Library › Granted Patent US 12,244,624
Granted Patent B2
US 12,244,624 · App. 18/380,339 · Granted Mar 4, 2025

Malware detection at endpoint devices

Inventor: Ricardo Varanda (Reading, GB)
Assignee: Bank of America Corporation
H04L63/1425H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,624
App. No.
18/380,339
Granted
Mar 4, 2025
Kind
B2
Abstract

Aspects of the disclosure relate to malware detection at endpoint devices. A computing platform may send rule information to a browser extension including a set of rules defining reportable behavior of network traffic associated with a website. Subsequently, the computing platform may receive report information including an identification of a loaded web page associated with the website that exhibits the reportable behavior defined by at least one rule of the set of rules and an indication of which rules of the set of rules have been met. Based on receiving the report information, the computing platform may assign a risk score for the identified loaded web page. Thereafter, the computing platform may determine that the risk score is above a predetermined threshold, and in response, the computing platform may send commands to the browser extension directing the browser extension to close the identified loaded web page.

Claims (48)

1. A computing platform, comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

send, via the communication interface, to a browser extension on a computing device, rule information including a set of rules defining reportable behavior of network traffic associated with a website;

receive, via the communication interface, from the browser extension on the computing device, report information, wherein the report information includes an identification of a loaded web page associated with the website that exhibits the reportable behavior defined by at least one rule of the set of rules in the rule information, an indication that the loaded web page associated with the website is transmitting information using an insecure security protocol, and an indication of which rules of the set of rules have been met;

based on receiving the report information, assign a risk score for the identified loaded web page, wherein the risk score is assigned based on points that are allocated to the reportable behavior exhibited by the website associated with the identified loaded web page;

determine that the risk score is above a predetermined threshold, wherein the predetermined threshold is adjusted for the identified loaded web page; and

in response to determining that the risk score is above the predetermined threshold, send, via the communication interface, to the browser extension on the computing device, one or more commands directing the browser extension on the computing device to close the identified loaded web page.

2. The computing platform of claim 1 , wherein assigning the risk score for the identified loaded web page comprises evaluating a combination of rules of the set of rules indicated as being met.

3. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

cause the browser extension on the computing device to monitor the network traffic to and from the website.

4. The computing platform of claim 1 , wherein receiving the report information from the browser extension on the computing device comprises receiving information indicating that the loaded web page associated with the website exhibits a similarity to a known or suspected malicious behavior defined as a reportable behavior by the set of rules.

5. The computing platform of claim 1 , wherein receiving the report information from the browser extension on the computing device comprises receiving information indicating that the loaded web page associated with the website is connecting to a server in a high-risk country or area.

6. The computing platform of claim 1 , wherein receiving the report information from the browser extension on the computing device comprises receiving information indicating that the loaded web page associated with the website is sending data to an unexpected or unknown destination.

7. The computing platform of claim 1 , wherein receiving the report information from the browser extension on the computing device comprises receiving information indicating that the loaded web page associated with the website is sending data over hypertext transfer protocol (HTTP).

8. The computing platform of claim 1 , wherein receiving the report information from the browser extension on the computing device comprises receiving information indicating that the loaded web page associated with the website is setting cookies with wildcard domains.

9. The computing platform of claim 1 , wherein receiving the report information from the browser extension on the computing device comprises receiving information indicating that the loaded web page associated with the website is using unsafe keywords.

10. The computing platform of claim 1 , wherein receiving the report information from the browser extension on the computing device comprises receiving information indicating that the loaded web page associated with the website is using known vulnerable third-party libraries.

11. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

cause the browser extension on the computing device to load the rule information upon startup of a browser.

12. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

add a rule to or remove a rule from the rule information including the set of rules defining reportable behavior of network traffic associated with the website; and

update the rule information based on the addition or removal of the rule.

13. A method, comprising:

at a computing platform comprising at least one processor, a communication interface, and memory:

sending, by the at least one processor, via the communication interface, to a browser extension on a computing device, rule information including a set of rules defining reportable behavior of network traffic associated with a website;

receiving, by the at least one processor, via the communication interface, from the browser extension on the computing device, report information, wherein the report information includes an identification of a loaded web page associated with the website that exhibits the reportable behavior defined by at least one rule of the set of rules in the rule information, an indication that the loaded web page associated with the website is transmitting information using an insecure security protocol, and an indication of which rules of the set of rules have been met;

based on receiving the report information, assigning, by the at least one processor, a risk score for the identified loaded web page, wherein the risk score is assigned based on points that are allocated to the reportable behavior exhibited by the website associated with the identified loaded web page;

determining, by the at least one processor, that the risk score is above a predetermined threshold, wherein the predetermined threshold is adjusted for the identified loaded web page; and

in response to determining that the risk score is above the predetermined threshold, sending, by the at least one processor, via the communication interface, to the browser extension on the computing device, one or more commands directing the browser extension on the computing device to close the identified loaded web page.

14. The method of claim 13 , wherein assigning the risk score for the identified loaded web page comprises evaluating a combination of rules of the set of rules indicated as being met.

15. The method of claim 13 , further comprising:

causing, by the at least one processor, the browser extension on the computing device to monitor the network traffic to and from the website.

16. The method of claim 13 , wherein receiving the report information from the browser extension on the computing device comprises receiving information indicating that the loaded web page associated with the website exhibits a similarity to a known or suspected malicious behavior defined as a reportable behavior by the set of rules.

17. The method of claim 13 , further comprising:

adding or removing, by the at least one processor, a rule to or from the rule information including the set of rules defining reportable behavior of network traffic associated with the website; and

updating the rule information based on the adding or removing of the rule.

18. The method of claim 13 , further comprising:

causing, by the at least one processor, the browser extension on the computing device to load the rule information upon startup of a browser.

19. One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to:

send, via the communication interface, to a browser extension on a computing device, rule information including a set of rules defining reportable behavior of network traffic associated with a website;

receive, via the communication interface, from the browser extension on the computing device, report information, wherein the report information includes an identification of a loaded web page associated with the website that exhibits the reportable behavior defined by at least one rule of the set of rules in the rule information, an indication that the loaded web page associated with the website is transmitting information using an unencrypted security protocol, and an indication of which rules of the set of rules have been met;

based on receiving the report information, assign a risk score for the identified loaded web page, wherein the risk score is assigned based on points that are allocated to the reportable behavior exhibited by the website associated with the identified loaded web page;

determine that the risk score is above a predetermined threshold, wherein the predetermined threshold is adjusted for the identified loaded web page; and

in response to determining that the risk score is above the predetermined threshold, send, via the communication interface, to the browser extension on the computing device, one or more commands directing the browser extension on the computing device to close the identified loaded web page.

20. The one or more non-transitory computer-readable media of claim 19 , further including instructions that, when executed, cause the computing platform to:

cause the browser extension on the computing device to monitor the network traffic to and from the website.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2023
From: VARANDA, RICARDO
To: BANK OF AMERICA CORPORATION
Reel/Frame 065232/0737 →
Continuity (2)
Continuation 17141685 · Jan 5, 2021
Related Publication 20240039942A1 · Feb 1, 2024
References Cited (37)
US 8656465B1 · Fong-Jones · 2014 [cited by examiner]
US 9465789B1 · Chen · 2016 [cited by examiner]
US 11288359B1 · Caldwell · 2022 [cited by examiner]
US 11301560B2 · Prakash · 2022 [cited by examiner]
US 20090064337A1 · Chien · 2009 [cited by examiner]
US 20090077383A1 · de Monseignat et al. · 2009 [cited by applicant]
US 20100049975A1 · Parno et al. · 2010 [cited by applicant]
US 20110093952A1 · Kumar et al. · 2011 [cited by applicant]
US 20120131438A1 · Li · 2012 [cited by examiner]
US 20130061323A1 · Liske · 2013 [cited by applicant]
US 20130247030A1 · Kay et al. · 2013 [cited by applicant]
US 20140020053A1 · Kay et al. · 2014 [cited by applicant]
US 20140053267A1 · Klein et al. · 2014 [cited by applicant]
US 20140201528A1 · Krig · 2014 [cited by examiner]
US 20150007250A1 · Dicato, Jr. et al. · 2015 [cited by applicant]
US 20150067853A1 · Amrutkar et al. · 2015 [cited by applicant]
US 20170006046A1 · Kuskov et al. · 2017 [cited by applicant]
US 20170091450A1 · Turgeman · 2017 [cited by applicant]
US 20170093839A1 · Whiteside et al. · 2017 [cited by applicant]
US 20170257393A1 · De Barros et al. · 2017 [cited by applicant]
US 20170270300A1 · Reddington · 2017 [cited by applicant]
US 20170293755A1 · Kargman et al. · 2017 [cited by applicant]
US 20180375896A1 · Wang et al. · 2018 [cited by applicant]
US 20200034530A1 · Zasadzinski · 2020 [cited by examiner]
US 20200092333A1 · Sebesta · 2020 [cited by examiner]
US 20200137039A1 · Whiteside et al. · 2020 [cited by applicant]
US 20200137110A1 · Tyler et al. · 2020 [cited by applicant]
US 20200151325A1 · Chen et al. · 2020 [cited by applicant]
US 20200159525A1 · Bhalla · 2020 [cited by examiner]
US 20200218433A1 · Batchelder et al. · 2020 [cited by applicant]
US 20200218434A1 · Batchelder et al. · 2020 [cited by applicant]
US 20200342103A1 · Luo et al. · 2020 [cited by applicant]
US 20200356661A1 · Stoletny et al. · 2020 [cited by applicant]
US 20200389469A1 · Litichever et al. · 2020 [cited by applicant]
US 20200404019A1 · Drake · 2020 [cited by applicant]
Obaidat et al., “Web Browser Extension User-Script XSS Vulnerabilities,” 2020 IEEE Intl Conf on Dependable, Autonomic and Secure Computing, Intl Conf on Pervasive Intelligence and Computing, Intl Conf on Cloud and Big D… [cited by examiner]
Rodrigues et al., “Securing Instant Messages With Hardware-Based Cryptography and Authentication in Browser Extension,” IEEE Access Year: 2020 | vol. 8 | Journal Article | Publisher: IEEE. [cited by examiner]