Systems and methods for malware detection and scanning

US9344446B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9344446-B2
Application numberUS-201414480289-A
CountryUS
Kind codeB2
Filing dateSep 8, 2014
Priority dateDec 30, 2010
Publication dateMay 17, 2016
Grant dateMay 17, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods are provided for malware scanning and detection in a computing system. In one exemplary embodiment, the method includes launching, in a computing device of the computing system, a virtual machine, and launching, in the virtual machine of the computing device, an internet browser. The method also includes requesting, by the internet browser, data from a web page, and performing, using one or more analysis tools, analysis on the web page. In the method, performing analysis on the web page includes performing monitoring and recording of system application programming interface (API) calls, and creating software objects associated with the web page. The method also includes performing antivirus scanning of the software objects, de-obfuscating JavaScript associated with the software objects, and correlating data associated with the performed analysis to determine if the web page is a malicious web page.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method operating in a computing device, the method comprising: receiving, at a controller in the computing device, a malware scan request transmitted from a remote controller device via a network, the malware scan request comprising a type and version of an internet browser and one or more parameters, the one or more parameters comprising target uniform resource identifiers (URIs), uniform resource locators (URLs), and/or uniform resource names (URNs) used to identify web pages upon which malware scanning is to be performed, the computing device storing a plurality of virtual machines, wherein at least two of the plurality of virtual machines are within a same domain or a same netblock; launching, by the controller, the plurality of virtual machines in the computing device, in response to the received malware scan request; instructing, by the controller, each of the plurality of virtual machines of the computing device to: launch an internet browser of the type and version, request data from a web server hosting a web page over the network via the internet browser, wherein at least one of the plurality of virtual machines that are within the same domain or the same netblock is rate-limited; and perform, in the virtual machine of the computing device, analysis on the web page using one or more analysis tools; and receiving, from each of the plurality of virtual machines, results of the performed analysis; and storing, in a storage, the results of the performed analysis for malware analysis. 2. The computer-implemented method of claim 1 , wherein performing the analysis includes: monitoring and recording of system application programming interface (API) calls, creating software objects associated with the web page, performing antivirus scanning of the software objects, and de-obfuscating code associated with the software objects; and correlating data associated with the analysis that is performed to determine if the web page is a malicious web page. 3. The computer-implemented method of claim 1 , further comprising: routing, by the controller, traffic from each of the virtual machines through at least one proxy computing device in the network. 4. The computer-implemented method of claim 1 , further including: creating, by the controller, packet capture (pcap) files; and storing the pcap files in a storage. 5. The computer-implemented method of claim 1 , further including: comparing at least one of uniform resource identifier (URI), universal resource locator (URL) data, or uniform resource number (URN) data associated with the web page against one or more lists. 6. The computer-implemented method of claim 1 , wherein potential malware includes one or more of obfuscated executable code and potential cross-site scripting attacks. 7. The computer-implemented method of claim 1 , further including: matching a pattern of the web page with one or more other patterns known to be indicative of malware. 8. The computer-implemented method of claim 1 , wherein the one or more parameters in the malware scan request includes a number of virtual machines to visit the web page, and wherein launching a plurality of virtual machines includes: launching the plurality of virtual machines based on the number of virtual machines included in the malware scan request. 9. A computing device for scanning and detection, the device comprising: at least one memory to store data and instructions; and at least one processor to access memory and to execute instructions to: receive, at a virtual machine controller in the computing device, a malware scan request transmitted from a remote controller device via a network, the malware scan request comprising a type and version of an internet browser and one or more parameters, the one or more parameters comprising target uniform resource identifiers (URIs), uniform resource locators (URLs), and/or uniform resource names (URNs) used to identify web pages upon which malware scanning is to be performed, wherein at least two of the plurality of virtual machines are within a same domain or a same netblock; launch, by the virtual machine controller, a plurality of virtual machines in the computing device, in response to the received malware scan request; instruct, by the virtual machine controller, each of the plurality of virtual machines of the computing device to: launch an internet browser of the type and version, request data from a web server hosting a web page over the network via the internet browser, wherein at least one of the plurality of virtual machines that are within the same domain or the same netblock is rate-limited; and perform, in the virtual machine of the computing device, analysis on the web page using one or more analysis tools; receive, from each of the plurality of virtual machines, results of the performed analysis; and store, in a storage, the results of the performed analysis for malware analysis. 10. The computing device of claim 9 , wherein performing the analysis includes: monitoring and recording of system application programming interface (API) calls, creating software objects associated with the web page, performing antivirus scanning of the software objects, and de-obfuscating code associated with the software objects; and correlating data associated with the analysis that is performed to determine if the web page is a malicious web page. 11. The computing device of claim 9 , wherein the processor is further to: route, by the virtual machine controller, traffic from each of the virtual machines through at least one proxy computing device in the network. 12. The computing device of claim 9 , wherein the processor is further to: create, by the virtual machine controller, packet capture (pcap) files; and store the pcap files in a storage. 13. The computing device of claim 9 , wherein the processor is further to: compare, by the virtual machine controller, at least one of uniform resource identifier (URI), universal resource locator (URL) data, or uniform resource number (URN) data associated with the web page against one or more lists. 14. The computing device of claim 9 , wherein potential malware includes one or more of obfuscated executable code and potential cross-site scripting attacks. 15. The computing device of claim 9 , wherein the processor is further to: match a pattern of the web page with one or more other patterns known to be indicative of malware. 16. The computing device of claim 9 , wherein the one or more parameters in the malware scan request includes a number of virtual machines to visit the web page, and wherein launching a plurality of virtual machines includes: launching the plurality of virtual machines based on the number of virtual machines included in the malware scan request. 17. A non-transitory computer-readable medium containing instructions that, when executed by a computing device, cause the computing device to perform a method to: receive, at a virtual machine controller in the computing device, a malware scan request comprising a type and version of an internet browser and one or more parameters, the one or more parameters comprising target uniform resource identifiers (URIs), uniform resource locators (URLs), and/or uniform resource names (URNs) used to identify web pages upon which malware scanning is to be performed, wherein at least two of the plurality of virtual machines are within a same domain or a same netblock; launch, by the virtual machine controller, a plurality of virtual mach

Assignees

Inventors

Classifications

  • Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks · CPC title

  • G06F21/566Primary

    Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities · CPC title

  • using deception as countermeasure, e.g. honeypots, honeynets, decoys or entrapment · CPC title

  • service impersonation, e.g. phishing, pharming or web spoofing (detection of rogue wireless access points H04W12/12) · CPC title

  • Hypervisors; Virtual machine monitors · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9344446B2 cover?
Systems and methods are provided for malware scanning and detection in a computing system. In one exemplary embodiment, the method includes launching, in a computing device of the computing system, a virtual machine, and launching, in the virtual machine of the computing device, an internet browser. The method also includes requesting, by the internet browser, data from a web page, and performi…
Who is the assignee on this patent?
Verisign Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/566. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue May 17 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).