IP Library Granted Patent US 12,430,429
Granted Patent B2
US 12,430,429 · App. 17/572,548 · Granted Sep 30, 2025

Detection of malicious code that is obfuscated within a document file

Inventors: Benjamin Chang (Fremont, CA); Ghanashyam Satpathy (Bangalore, IN)
Assignee: Netskope, Inc.
G06F21/56G06F21/53G06N5/01G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,430,429
App. No.
17/572,548
Filed
Jan 10, 2022
Granted
Sep 30, 2025
Kind
B2
Art Unit
2436
USPC
726/24
Abstract

The technology disclosed relates to cybersecurity attacks and cloud-based security, and specifically to the detection of malicious code that is obfuscated within document files. Such malicious code can be delivered in the form of malicious macros and/or malicious OLE objects stored within document files. The technology disclosed detects obfuscated and malicious code using a trained machine learning model to predict which documents include malicious code, despite such malicious not having a known signature. The technology disclosed can thus predict which documents include malicious code lacking a known signature. Safe documents are allowed into the network. Suspicious documents are subjected to additional processing, including quarantining or sandboxing methods. Malicious documents are rejected from the network. In a further aspect, the disclosed technology combines machine learning with other network security methods, to further increase the capability of a network security system to detect malicious macros and malicious OLE files.

Claims (28)

1. A method for classifying input documents in a networked system to determine if at least one of the documents may include malicious code, comprising the steps of:

parsing a document file to separate code data from document payload data;

generating for the document file at least obfuscation features indicative of past instances of malware embedded in code using known obfuscation methods;

inputting the obfuscation features to a trained machine learning model and applying the trained machine learning model to process the document file to predict the presence of malicious code and classify the document file as to its threat level;

using a secondary malware detection engine operating to reduce false positives;

classifying the document file, based on the threat level predicted by the trained machine learning model as qualified by the secondary malware detection engine, as safe, suspicious, or malicious; and

based on the step of classifying, accepting the document file classified as safe into the networked system, or blocking the document file classified as malicious, or isolating the document file classified as suspicious for threat analysis.

2. The method of claim 1 wherein a network interface that is coupled to a network, and where receiving the document file occurs via said network interface.

3. The method of claim 1 wherein said document file is a Microsoft Office document.

4. The method of claim 1 wherein said document file is one of a Microsoft Word document, a Microsoft Excel document, or a Microsoft Power Point document.

5. The method of claim 1 wherein said document file is one of a word processing document, a spreadsheet document or a presentation document.

6. The method of claim 1 wherein the code includes a VBA macro.

7. The method of claim 1 wherein said obfuscation scoring features include macro related features, said features including at least one use of CreateObject, Shell, FileSystem, URLDownloadToFile, CallByName, or Detect Sandbox.

8. The method of claim 1 further including testing for malicious code within a document file while quarantining said document file into a sandbox.

9. A system including one or more processors coupled to memory, the memory loaded with computer instructions to classify input documents in a networked system to determine if at least one of the documents may include malicious code, the instructions, when executed on the processors, implement actions comprising:

parsing a document file to separate code data from document payload data;

generating for the document file at least obfuscation features indicative of past instances of malware embedded in code using known obfuscation methods;

inputting the obfuscation features to a trained machine learning model and applying the trained machine learning model to process the document file to predict the presence of malicious code and classify the document file as to its threat level;

using a secondary malware detection engine operating to reduce false positives;

classifying the document file, based on the threat level predicted by the trained machine learning model as qualified by the secondary malware detection engine, as safe, suspicious, or malicious; and

based on the step of classifying, accepting the document file classified as safe into the networked system, or blocking the document file classified as malicious, or isolating the document file classified as suspicious for threat analysis.

10. The system of claim 9 wherein said system further includes a network interface that is coupled to a network, and where receiving the document file occurs via said network interface.

11. The system of claim 9 wherein said document file is a Microsoft Office document.

12. The system of claim 9 wherein said document file is one of a Microsoft Word document, a Microsoft Excel document, or a Microsoft Power Point document.

13. The system of claim 9 wherein said document file is one of a word processing document, a spreadsheet document or a presentation document.

14. The system of claim 9 wherein the code includes a VBA macro.

15. The system of claim 9 wherein said obfuscation scoring features include macro related features, said features including at least one use of CreateObject, Shell, FileSystem, URLDownloadToFile, CallByName, or Detect Sandbox.

16. The system of claim 9 further including testing for malicious code within a document file while quarantining said document file into a sandbox.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2022
From: CHANG, BENJAMIN; SATPATHY, GHANASHYAM
To: NETSKOPE, INC.
Reel/Frame 058612/0715 →
Continuity (2)
Continuation 17184478 · Feb 24, 2021
Related Publication 20220269782A1 · Aug 25, 2022
References Cited (178)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 5960170A · Chen et al. · 1999 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8813222B1 · Codreanu et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9438613B1 · Paithane et al. · 2016 [cited by applicant]
US 9690933B1 · Singh et al. · 2017 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 10009370B1 · Douglas et al. · 2018 [cited by applicant]
US 10050998B1 · Singh · 2018 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10192059B2 · Grafi · 2019 [cited by examiner]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10521587B1 · Agranonik · 2019 [cited by examiner]
US 10581874B1 · Khalid et al. · 2020 [cited by applicant]
US 10805314B2 · Jakobsson et al. · 2020 [cited by applicant]
US 10817607B1 · M et al. · 2020 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 10878091B2 · Usui · 2020 [cited by examiner]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11038916B1 · Cao · 2021 [cited by examiner]
US 11184379B1 · Kjar · 2021 [cited by examiner]
US 11222112B1 · Satpathy et al. · 2022 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 11829467B2 · Bhary · 2023 [cited by examiner]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-LeMair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20100064369A1 · Stolfo · 2010 [cited by examiner]
US 20100162400A1 · Feeney et al. · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20120216280A1 · Zorn · 2012 [cited by examiner]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130160127A1 · Jeong et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140331324A1 · Stolfo et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20150261955A1 · Huang et al. · 2015 [cited by applicant]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20180060580A1 · Zhao · 2018 [cited by examiner]
US 20180152470A1 · Lu · 2018 [cited by examiner]
US 20180218155A1 · Grafi · 2018 [cited by examiner]
US 20190007436A1 · Dods · 2019 [cited by examiner]
US 20190114539A1 · Chistyakov · 2019 [cited by examiner]
US 20190222591A1 · Kislitsin et al. · 2019 [cited by applicant]
US 20190236273A1 · Saxe · 2019 [cited by examiner]
US 20200012789A1 · Usui et al. · 2020 [cited by applicant]
US 20200042708A1 · Usui et al. · 2020 [cited by applicant]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20200057853A1 · Zhao · 2020 [cited by examiner]
US 20200089880A1 · De Los Santos Vilchez et al. · 2020 [cited by applicant]
US 20200233962A1 · Chantry · 2020 [cited by examiner]
US 20200250309A1 · Harang · 2020 [cited by applicant]
US 20200334353A1 · Kosarev · 2020 [cited by examiner]
US 20200396190A1 · Pickman et al. · 2020 [cited by applicant]
US 20200412740A1 · Goutal et al. · 2020 [cited by applicant]
US 20210058395A1 · Jakobsson · 2021 [cited by applicant]
US 20210141897A1 · Seifert · 2021 [cited by examiner]
US 20210173928A1 · Grafi · 2021 [cited by examiner]
US 20220083661A1 · Ma · 2022 [cited by examiner]
US 20240070276A1 · Gray · 2024 [cited by examiner]
EP 1063833A2 · 2000 [cited by applicant]
WO 2018159010A1 · 2018 [cited by applicant]
Xun Lu; De-obfuscation and detection of malicious PDF files with high accuracy; IEEE; Year:2013; pp. 4890-4899. [cited by examiner]
Netskope, “Data Loss Prevention and Monitoring in the Cloud”, Nov. 2014, 18 pages. [cited by applicant]
“Repave the Cloud-Data Breach Collision Course,” netSkope, Inc., 2014, 6 pgs. [cited by applicant]
“Netskope Introspection,” netSkope, Inc., 2015, 3 pgs. [cited by applicant]
“Cloud Data Loss Prevention Reference Architecture”, Sep. 2015, Netskope, WP-88-1, 2 pages. [cited by applicant]
“The Netskope Active Platform Enabling Safe Migration to the Cloud”, Apr. 2015, DS-1-8, Netskope, Inc., 6 pages. [cited by applicant]
“The Netskope Advantage: Three “Must-Have” Requirements for Cloud Access Security Brokers”, Jul. 2015, WP-12-2, 4 pages. [cited by applicant]
“Netskope The 15 Critical CASB Use Cases”, Netskope, Inc., EB-141-1, 19 pages. [cited by applicant]
Cheng et al., “Cloud Security For Dummies, Netskope Special Edition,” John Wiley & Sons, Inc. 2015. [cited by applicant]
Daniel Gibert; A Hierarchical Convolutional Neural Network for Malware Classification; IEEE:2019;; pp. 1-8. [cited by applicant]
U.S. Appl. No. 17/184,502—Nonfinal Office Action dated Jun. 2, 2021, 25 pages. [cited by applicant]
Netskope Active Cloud DLP, netSkope, Inc., 2015, 4 pgs. [cited by applicant]
Netskope Cloud Confidence Index, netSkope, Inc., 2015, 2 pgs. [cited by applicant]
U.S. Appl. No. 17/184,502, filed Feb. 24, 2021, Pending. [cited by applicant]
U.S. Appl. No. 17/184,478—Nonfinal Office Action dated Apr. 29, 2021, 19 pages. [cited by applicant]
U.S. Appl. No. 17/184,478—Response to Nonfinal Office Action dated Apr. 29, 2021, filed Jul. 29, 2021, 15 pages. [cited by applicant]
U.S. Appl. No. 17/184,478—Notice of Allowance dated Sep. 1, 2021, 18 pages. [cited by applicant]
U.S. Appl. No. 17/184,502 Final Office Action dated Oct. 5, 2021, 22 pgs. [cited by applicant]
Canzanese, Dangerous Docs: Surge in Cloud-delivered Malicious Office Documents, NetSkope, Inc., Sep. 30, 2020 (www.netskope.com/blog/dangerous-docs-surge-in-cloud-delivered-malicious-office-documents). [cited by applicant]
Canzanese, Beware of Google Docs Spam, NetSkope, Inc. (www.netskope.com/blog/beware-of-google-docs-spam). [cited by applicant]
U.S. Appl. No. 17/184,502—Final Office Action dated Oct. 5, 2021, 22 pages. [cited by applicant]
U.S. Appl. No. 17/184,502—Response to Final Office Action dated Oct. 5, 2021, field Nov. 30, 2021, 9 pages. [cited by applicant]
Netskope, “The 5 Steps to Cloud Confidence,” netSkope Inc., 2014, 11 pgs. [cited by applicant]
PCT/US2022/017778—International Search Report and Written Opinion dated Jun. 13, 2022, 9 pages. [cited by applicant]
JP2023-551122—First Office Action with machine translation dated Jan. 30, 2024, 6 pages. [cited by applicant]
JP2023-551122—Response to First Office Action with machine translation filed Apr. 5, 2024, 12 pages. [cited by applicant]
JP2023-551122—Notice of Allowance with machine translation dated Apr. 23, 2024, 5 pages. [cited by applicant]
Douzi et al., “Advanced Phishing Filter Using Autoencoder and Denoising Autoencoder”, BDIOT '17: Proceedings of the International Conference on Big Data and Internet of Things, 2017, pp. 125-129. [cited by applicant]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff “Ending Clear Text Protocols,” Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Newton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
Mccullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al., “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., “Farsite: Federated, available, and reliable storage for an incompletely trusted environment,” SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al., Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html#:˜:text=mode of communication.-, What are the different email protoc… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” TechTarget, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?Offer=ab… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1, Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet, FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/10.1007/978-3-319-61… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al., “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&P 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management For Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]