Invention Grant
- Patent Title: Normalizing and detecting inserted malicious code
-
Application No.: US14722270Application Date: 2015-05-27
-
Publication No.: US09721098B2Publication Date: 2017-08-01
- Inventor: Ela Avrahami , Ziv Eli , Daniel Moore
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee Address: US NY Armonk
- Agency: Garg Law Firm, PLLC
- Agent Rakesh Garg; Jeffrey S. LaBaw
- Main IPC: G06F21/56
- IPC: G06F21/56 ; H04L29/06 ; G06F21/51

Abstract:
A method, system, and computer program product for detecting malicious code insertion in data are provided in the illustrative embodiments. At an application executing using a processor and a memory in a data processing system, a script that has been inserted in a mix of code and content is detected. A content-related portion is removed from the script to form a remaining script structure, the content-related portion referring to the content in the mix. From the remaining script structure, a code construct is selected and replaced with an alphanumeric string to form a normalized construct. Whether the normalized construct matches, within a tolerance, a second normalized construct in a corpus of normalized scripts is determined. Responsive to the normalized construct matching the second normalized construct within the tolerance, a conclusion is drawn that the script is malicious.
Public/Granted literature
- US20160173507A1 NORMALIZING AND DETECTING INSERTED MALICIOUS CODE Public/Granted day:2016-06-16
Information query