IP Library › Granted Patent US 9,860,270
Granted Patent B2
US 9,860,270 · App. 15/192,129 · Granted Jan 2, 2018

System and method for determining web pages modified with malicious code

Inventors: Vladimir A. Kuskov (Moscow, RU); Alexander A. Romanenko (Moscow, RU); Oleg V. Kupreev (Moscow, RU)
Assignee: AO KASPERSKY LAB
H04L63/145G06F17/3089G06F21/56G06F21/566H04L63/1416H04L63/1425H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,860,270
App. No.
15/192,129
Granted
Jan 2, 2018
Kind
B2
Abstract

Disclosed are a system and method for determining web pages modified with malicious code. An example method includes: intercepting an attempt to access a website; selecting, by a processor, one or more malicious software configuration files based on the intercepting of the attempt to access the website; creating a verification web page based on one or more code fragments from the selected one or more malicious software configuration files; opening the verification web page; and determining, by the processor, whether malicious code has been injected into the opened verification web page.

Claims (54)

1. A method for determining modified web pages, the method comprising:

intercepting an attempt to access a website;

selecting, by a processor, one or more malicious software configuration files based on the intercepting of the attempt to access the website;

creating a verification web page based on one or more code fragments from the selected one or more malicious software configuration files;

opening the verification web page; and

determining, by the processor, whether malicious code has been injected into the opened verification web page.

2. The method of claim 1 , wherein the opening of the verification web page comprises:

opening the verification web page without displaying the verification web page on a display.

3. The method of claim 1 , wherein the selecting one or more malicious software configuration files based on the intercepting of the attempt to access the website comprises:

selecting, by the processor, one or more malicious software configuration files based on identification of a uniform resource locator (URL) associated with the website.

4. The method of claim 1 , wherein the determining whether malicious code has been injected into the opened verification web page comprises:

Identifying, by the processor, one or more modifications to the verification web page;

executing code associated with the one or more modifications in a protected environment, emulator, or virtual machine to determine whether the code associated with the one or more modifications is malicious.

5. The method of claim 1 , wherein determining whether malicious code has been injected into the opened verification web page comprises:

determining an initial state of the verification web page prior to opening the verification web page;

determining an opened state of the verification web page after opening the verification web page; and

comparing the initial state to the opened state to identify injection of malicious code into the opened verification web page.

6. The method of claim 1 , wherein the creating of the verification web page based on the one or more code fragments from the selected one or more malicious software configuration files comprises:

selecting a plurality of the code fragments from the one or more malicious software configuration files based on one or more criteria.

7. The method of claim 6 , wherein the one or more criteria include a maximum number of web pages associated with the verification web page, a maximum size of the verification web page, or a maximum length of a uniform resource locator (URL) associated with opening the verification web page.

8. A system for determining modified web pages, the system comprising:

a memory; and

at least one hardware processor coupled to the memory and configured to:

intercept an attempt to access a website;

select one or more malicious software configuration files based on the intercepting of the attempt to access the website;

create a verification web page based on one or more code fragments from the selected one or more malicious software configuration files;

open the verification web page; and

determine whether malicious code has been injected into the opened verification web page.

9. The system of claim 8 , wherein the at least one hardware processor is configured to open the verification web page by opening the verification web page without displaying the verification web page on a display.

10. The system of claim 8 , wherein the at least one hardware processor is configured to select one or more malicious software configuration files based on the interception of the attempt to access the website by selecting one or more malicious software configuration files based on identification of a uniform resource locator (URL) associated with the website.

11. The system of claim 8 , wherein the at least one hardware processor is configured to determine whether malicious code has been injected into the opened verification web page by identifying one or more modifications to the verification web page and executing code associated with the one or more modifications in a protected environment, emulator, or virtual machine to determine whether the code associated with the one or more modifications is malicious.

12. The system of claim 8 , wherein the at least one hardware processor is configured to determine whether malicious code has been injected into the opened verification web page by:

determining an initial state of the verification web page prior to opening the verification web page;

determining an opened state of the verification web page after opening the verification web page; and

comparing the initial state to the opened state to identify injection of malicious code into the opened verification web page.

13. The system of claim 8 , wherein the at least one hardware processor is configured to create the verification web page based on the one or more code fragments from the selected one or more malicious software configuration files by selecting a plurality of the code fragments from the one or more malicious software configuration files based on one or more criteria.

14. The system of claim 13 , wherein the one or more criteria include a maximum number of web pages associated with the verification web page, a maximum size of the verification web page, or a maximum length of a uniform resource locator (URL) associated with opening the verification web page.

15. A non-transitory computer-readable medium storing computer-executable instructions for determining modified web pages, comprising instructions for:

intercepting an attempt to access a website;

selecting one or more malicious software configuration files based on the intercepting of the attempt to access the website;

creating a verification web page based on one or more code fragments from the selected one or more malicious software configuration files;

opening the verification web page; and

determining whether malicious code has been injected into the opened verification web page.

16. The computer-readable medium of claim 15 , wherein the instructions for opening the verification web page includes instructions for opening the verification web page without displaying the verification web page on a display.

17. The computer-readable medium of claim 15 , wherein the instructions for selecting one or more malicious software configuration files based on the interception of the attempt to access the website includes instructions for selecting one or more malicious software configuration files based on identification of a uniform resource locator (URL) associated with the website.

18. The computer-readable medium of claim 15 , wherein the code to determine whether malicious code has been injected into the opened verification web page includes instructions for:

identify one or more modifications to the verification web page; and

executing code associated with the one or more modifications in a protected environment, emulator, or virtual machine to determine whether the code associated with the one or more modifications is malicious.

19. The computer-readable medium of claim 15 , wherein the instructions for determining whether malicious code has been injected into the opened verification web page includes instructions for:

determining an initial state of the verification web page prior to opening the verification web page;

determining an opened state of the verification web page after opening the verification web page; and

comparing the initial state to the opened state to identify injection of malicious code into the opened verification web page.

20. The computer-readable medium of claim 15 , wherein the instructions for creating the verification web page based on the one or more code fragments from the selected one or more malicious software configuration files includes instructions for selecting a plurality of the code fragments from the one or more malicious software configuration files based on one or more criteria.

21. The computer-readable medium of claim 20 , wherein the one or more criteria include a maximum number of web pages associated with the verification web page, a maximum size of the verification web page, or a maximum length of a uniform resource locator (URL) associated with opening the verification web page.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2016
From: KUSKOV, VLADIMIR A.; ROMANENKO, ALEXANDER A.; KUPREEV, OLEG V.
To: AO KASPERSKY LAB
Reel/Frame 039005/0211 →
Priority Claims (1)
RU 2015125971 · Jun 30, 2015 · national
Continuity (2)
Continuation 14834853 · Aug 25, 2015
Related Publication 20170006046A1 · Jan 5, 2017