The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Nov. 15, 2016

Filed:

Jun. 03, 2015
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

William A. Bird, Fredericton, CA;

Rory F. Bray, Rothesay, CA;

Jody D. Brownell, Charters Settlement, CA;

Ben A. Wuest, Fredericton, CA;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06F 9/54 (2006.01); G06F 21/56 (2013.01);
U.S. Cl.
CPC ...
H04L 63/1483 (2013.01); G06F 9/542 (2013.01); G06F 21/56 (2013.01); H04L 63/145 (2013.01); H04L 63/1416 (2013.01); H04L 63/1441 (2013.01); G06F 2221/2119 (2013.01); H04L 63/0281 (2013.01);
Abstract

According to one exemplary embodiment, a method for detecting malware in a network stream to at least one host computer is provided. The method may include initializing a browser profile corresponding with a first website having a first website source and a first plurality of content features. The method may include recording the first plurality of content features and a trusted source based on the first website source. The method may include scanning the network stream for a second content feature within a second plurality of content features associated with a second website. The method may include determining if the second content feature matches a first content feature. The method may include determining if the second plurality of content features is consistent with the first plurality of content features. The method may include determining if a second website source matches the trusted source. The method may include generating an alert.


Find Patent Forward Citations

Loading…