Invention Grant
- Patent Title: Detecting URL scheme hijacking
-
Application No.: US14817936Application Date: 2015-08-04
-
Publication No.: US10009374B1Publication Date: 2018-06-26
- Inventor: Rui Jing , Jinghao Li
- Applicant: Symantec Corporation
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: Holland & Hart LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/56 ; G06F21/12 ; G06F21/60 ; G06F21/62

Abstract:
A computer-implemented method for detecting malware is described. In some embodiments, the method includes identifying an application identifier of a first application paired with a universal resource locator (URL) scheme, and storing the identified pairing of the application identifier and URL scheme of the first application in a database. In some cases, the database stores URL scheme pairings of a plurality of applications. In some embodiments, the method includes identifying an application identifier of a first application paired with a universal resource locator (URL) scheme, identifying a second application as an unknown application, detecting a request to register a URL scheme pairing of the second application, querying the database based on the request to register the URL scheme pairing of the second application, and determining whether the second application is potential malware based on a result of the querying.
Information query