IP Library › Granted Patent US 12,341,811
Granted Patent B2
US 12,341,811 · App. 17/486,731 · Granted Jun 24, 2025

Detecting malicious behavior using an accomplice model

Inventors: Adam Hunt (El Cerrito, CA); Joseph Linn (Emeryville, CA); Nick Goodman (San Mateo, CA); Elias Manousos (San Francisco, CA); Chris Kiernan (San Francisco, CA); David Pon (Sunnyvale, CA); Jonas Edgeworth (San Francisco, CA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/1483G06F16/24578G06F16/951G06F16/955H04L63/0236H04L63/101G06F21/56H04L63/14H04L63/1433H04L63/1441H04L63/168H04L67/02H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,341,811
App. No.
17/486,731
Filed
Sep 27, 2021
Granted
Jun 24, 2025
Kind
B2
Examiner
DO, KHANG D
Art Unit
2492
USPC
726/22
Abstract

The present disclosure generally relates to web page analysis, and more particularly to detecting malicious behavior using an accomplice model. In certain embodiments, the accomplice model may determine that a URI is associated with malicious behavior based upon the URI being associated with an attribute determined to be related to malicious behavior. Examples of an attribute include a host system, a domain, or an element of a document used to render the web page. Examples of an element of a document used to render the web page may include an active/dynamic element (e.g., a function, a script, etc.) or an inactive/static element (e.g., a string, a number, a frame, a tracking username, a social networking username, etc.).

Claims (74)

1. A method, comprising:

creating a uniform resource identifier (URI) list, which includes a plurality of URIs that are used to render a web page;

identifying an attribute associated with the web page;

identifying a number of web pages that are rendered and that cause a first URI associated with the attribute to be called without calling a second URI that is determined to be malicious;

calculating a score for the attribute based at least on the number of the web pages that are rendered and that cause the first URI associated with the attribute to be called without calling the second URI that is determined to be malicious;

classifying the attribute as malicious based at least on the score;

determining that an identified URI in the URI list is associated with the attribute; and

as a result of determining that the identified URI in the URI list is associated with the attribute, performing the following operations:

creating a blacklist incident for the identified URI; and

performing a security action with regard to the identified URI.

2. The method of claim 1 , further comprising:

using a statistical model to assign a plurality of reputation scores to the plurality of URIs in the URI list;

wherein the blacklist incident is created for the identified URI further as a result of a reputation score assigned to the identified URI exceeding a threshold value.

3. The method of claim 1 , wherein performing a security action comprises:

informing a user that the identified URI is malicious.

4. The method of claim 1 , wherein performing a security action comprises:

sending the identified URI to a system that removes code that causes the identified URI to be called.

5. The method of claim 1 , further comprising:

identifying indirect connections from one-time-use hosts that redirect to the web page.

6. The method of claim 1 , wherein creating the blacklist incident comprises:

adding the blacklist incident to a blacklist sequence that is segmented based on profiles of blacklist incidents.

7. The method of claim 1 , wherein creating the blacklist incident comprises:

adding the blacklist incident to a blacklist sequence; and

wherein the method further comprises:

identifying a social media username that is malicious by identifying blacklisted URIs in the blacklist sequence that are associated with the social media username.

8. The method of claim 1 , further comprising:

applying an exponential decay factor to the reputation score assigned to the identified URI, the exponential decay factor based at least on an amount of time since a host or domain associated with the identified URI was blacklisted.

9. The method of claim 1 , further comprising:

applying an exponential decay factor to the reputation score assigned to the identified URI, the exponential decay factor based at least on an amount of time since a blacklisted host or domain associated with the identified URI was crawled.

10. A system comprising:

a memory; and

one or more processors coupled to the memory, the one or more processors configured to:

create a uniform resource identifier (URI) list, which includes a plurality of URIs that are used to render a web page;

identify an attribute associated with the web page;

identify a number of web pages that are rendered and that cause a first URI associated with the attribute to be called without calling a second URI that is determined to be malicious;

calculate a score for the attribute based at least on the number of the web pages that are rendered and that cause the first URI associated with the attribute to be called without calling the second URI that is determined to be malicious;

classify the attribute as malicious based at least on the score;

determine that an identified URI in the URI list is associated with the attribute; and

as a result of a determination that the identified URI in the URI list is associated with the attribute:

create a blacklist incident for the identified URI; and

perform a security action with regard to the identified URI.

11. The system of claim 10 , wherein the one or more processors are further configured to:

use a statistical model to assign a plurality of reputation scores to the plurality of URIs in the URI list; and

wherein the one or more processors are configured to:

create the blacklist incident for the identified URI further as a result of a reputation score assigned to the identified URI exceeding a threshold value.

12. The system of claim 10 , wherein the one or more processors are configured to:

inform a user that the identified URI is malicious.

13. The system of claim 10 , wherein the one or more processors are configured to:

send the identified URI to a system that removes code that causes the identified URI to be called.

14. The system of claim 10 , wherein the one or more processors are further configured to:

identify indirect connections from one-time-use hosts that redirect to the web page.

15. The system of claim 10 , wherein the one or more processors are configured to:

add the blacklist incident to a blacklist sequence that is segmented based on profiles of blacklist incidents.

16. The system of claim 10 , wherein the one or more processors are configured to:

create the blacklist incident by adding the blacklist incident to a blacklist sequence; and

identify a social media username that is malicious by identifying blacklisted URIs in the blacklist sequence that are associated with the social media username.

17. The system of claim 10 , wherein the one or more processors are further configured to:

apply an exponential decay factor to the reputation score assigned to the identified URI, the exponential decay factor based at least on an amount of time since a host or domain associated with the identified URI was blacklisted.

18. The system of claim 10 , wherein the one or more processors are further configured to:

apply an exponential decay factor to the reputation score assigned to the identified URI, the exponential decay factor based at least on an amount of time since a blacklisted host or domain associated with the identified URI was crawled.

19. A computer program product comprising a non-transitory computer-readable storage medium having instructions recorded thereon for enabling a processor-based system to perform operations, the operations comprising:

creating a uniform resource identifier (URI) list, which includes a plurality of URIs that are used to render a web page;

identifying an attribute associated with the web page;

identifying a number of web pages that are rendered and that cause a first URI associated with the attribute to be called without calling a second URI that is determined to be malicious;

calculating a score for the attribute based at least on the number of the web pages that are rendered and that cause the first URI associated with the attribute to be called without calling the second URI that is determined to be malicious;

classifying the attribute as malicious based at least on the score;

determining that an identified URI in the URI list is associated with the attribute; and

as a result of determining that the identified URI in the URI list is associated with the attribute:

creating a blacklist incident for the identified URI; and

performing a security action with regard to the identified URI.

20. The computer program product of claim 19 , wherein the operations further comprise:

applying an exponential decay factor to the reputation score assigned to the identified URI, the exponential decay factor based at least on at least one of:

an amount of time since a host or domain associated with the identified URI was blacklisted; or

an amount of time since a blacklisted host or domain associated with the identified URI was crawled.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2021
From: HUNT, ADAM; LINN, JOSEPH; GOODMAN, NICK; MANOUSOS, ELIAS; KIERNAN, CHRIS; PON, DAVID; EDGEWORTH, JONAS
To: RISKIQ, INC.
Reel/Frame 057614/0845 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2021
From: RISKIQ, INC.
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 057614/0917 →
Continuity (4)
Continuation 16709898 · Dec 10, 2019
Continuation 15803736 · Nov 3, 2017
Provisional Application 62417228 · Nov 3, 2016
Related Publication 20220014552A1 · Jan 13, 2022
References Cited (41)
US 8468597B1 · Warner · 2013 [cited by examiner]
US 8826426B1 · Dubey · 2014 [cited by examiner]
US 8850567B1 · Hsieh · 2014 [cited by examiner]
US 9413774B1 · Liu · 2016 [cited by examiner]
US 9838407B1 · Oprea · 2017 [cited by examiner]
US 10057279B1 · Balduzzi · 2018 [cited by examiner]
US 20050086206A1 · Balasubramanian · 2005 [cited by examiner]
US 20060075494A1 · Bertman · 2006 [cited by examiner]
US 20070078936A1 · Quinlan · 2007 [cited by examiner]
US 20080010683A1 · Baddour · 2008 [cited by examiner]
US 20080082662A1 · Dandliker · 2008 [cited by examiner]
US 20080133540A1 · Hubbard · 2008 [cited by examiner]
US 20080256622A1 · Neystadt · 2008 [cited by examiner]
US 20080301116A1 · Wang · 2008 [cited by examiner]
US 20090012946A1 · Tsunokawa · 2009 [cited by examiner]
US 20090182818A1 · Krywaniuk · 2009 [cited by examiner]
US 20090300768A1 · Krishnamurthy · 2009 [cited by examiner]
US 20100235915A1 · Memon · 2010 [cited by examiner]
US 20100251371A1 · Brown · 2010 [cited by examiner]
US 20110078309A1 · Bloch · 2011 [cited by examiner]
US 20110271329A1 · Hulten · 2011 [cited by examiner]
US 20110289582A1 · Kejriwal · 2011 [cited by examiner]
US 20120072407A1 · Shyamsunder · 2012 [cited by examiner]
US 20120101808A1 · Duong-Van · 2012 [cited by examiner]
US 20120102545A1 · Carter, III · 2012 [cited by examiner]
US 20120317642A1 · Royal · 2012 [cited by examiner]
US 20130179421A1 · Jeong · 2013 [cited by examiner]
US 20140283078A1 · Redfoot · 2014 [cited by examiner]
US 20140337973A1 · Foster · 2014 [cited by examiner]
US 20150007312A1 · Pidathala · 2015 [cited by examiner]
US 20150172311A1 · Freedman · 2015 [cited by examiner]
US 20150244728A1 · Tao · 2015 [cited by examiner]
US 20150244738A1 · Lu · 2015 [cited by examiner]
US 20150339580A1 · Riabov · 2015 [cited by examiner]
US 20150350232A1 · Liu · 2015 [cited by examiner]
US 20160036833A1 · Ardeli · 2016 [cited by examiner]
US 20160380977A1 · Bean · 2016 [cited by examiner]
US 20170104782A1 · Folco · 2017 [cited by examiner]
US 20170149821A1 · Li · 2017 [cited by examiner]
US 20170195353A1 · Taylor · 2017 [cited by examiner]
US 20170353434A1 · Al-Saber · 2017 [cited by examiner]