发明名称 Identifying and Assessing Malicious Resources
摘要 Methods, systems, and computer-readable media for analyzing and indicating network resources as potentially malicious are disclosed. Some aspects of the disclosure provide ways for threat-analyzing individuals and/or organizations to transmit information about potentially malicious resources in a safe manner. Users or computing devices may transmit non-resolvable “de-fanged” resource identifiers, which lessens the likelihood that the receiving computing device will download malicious data or applications from the resource. Some aspects disclosed herein provide ways to correctly and accurately “re-fang” the resource identifier for threat analysis of the resource, for example by selecting one or more re-fangers to apply and applying the re-fangers to the identifier. Data may be retrieved from the resource (for example via a headless or non-interactive browser), and the resource and/or resource identifier may be categorized as malicious. Indications of a resource as malicious may be transmitted to other computing devices to reduce or eliminate malicious activity.
申请公布号 US2016381047(A1) 申请公布日期 2016.12.29
申请号 US201514748493 申请日期 2015.06.24
申请人 Bank of America Corporation 发明人 D'Aveta Robert;Camacho Chris
分类号 H04L29/06;G06F17/30;H04L29/08 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method comprising: receiving, at a computing device and via a user interface, a string of text comprising a de-fanged uniform resource locator; converting, by the computing device, the de-fanged uniform resource locator into a resolvable uniform resource locator; retrieving, by the computing device, data from a network location identified by the resolvable uniform resource locator, wherein retrieving the data comprises instantiating a headless browser and rendering the data via the headless browser, resulting in rendered data; categorizing, by the computing device, based on the rendered data, the location as a malicious location; generating, by the computing device, one or more notifications based on the categorizing; and transmitting, by the computing device, the one or more notifications to another device to update a record stored at the another device and associated with the network location to include information indicating that the network location is malicious.
地址 Charlotte NC US