跳到主体内容

Kaspersky Lab Has Patented Technology that Detects Man-in-the-Browser Attacks

2016年9月14日

Kaspersky Lab has announced that it has been awarded a new patent from the United States, for a technology that counteracts the tricks of financial cybercriminals. The new technology detects the implementation of HTML code into a page opened by a client’s browser (Man-in-the-Browser attack).

Kaspersky Lab has announced that it has been awarded a new patent from the United States, for a technology that counteracts the tricks of financial cybercriminals. The new technology detects the implementation of HTML code into a page opened by a client’s browser (Man-in-the-Browser attack).

The technology is based on the use of special "scanning" web pages, which are integrated with a specific HTML code, to encourage malware to reveal its functions.

The creators of financial malware often modify HTML code for the websites of banks. When a client tries to open the necessary page, the malicious program detects this activity and modifies the design of various elements of the web pages (firstly, the input field), and then steals the authentication data entered, or changes the account numbers, to redirect where money is transferred.

Kaspersky Lab experts have developed a kind of ‘trap’- a banking page which has the hallmarks of different financial institution sites (the fragments of HTML code specific to the web pages of banks and payment systems). This technology is already widely used in Kaspersky Fraud Prevention Clientless Malware Detection, which was developed to prevent attempts to access customer bank accounts from infected devices. Once such a web page is opened from an infected device, the malicious program utilizing the Man-in-the-Browser technique will recognize it as the bank's website and try to make changes that will be immediately detected by the system.

"Considering the fact that Man-in-the-Browser technology is implemented by many families of banking trojans, our technology can be used in solutions to protect online banking, as an indicator of infection. If an attempt is made to embed HTML code, it’s highly likely that the user device is infected. Having detected such an attempt, the bank can block the transaction in time to protect its customer’s money from theft. We can also help the users affected by fraud to eliminate the consequences of infection with our specialist Kaspersky Fraud Prevention for Endpoints solution”, said Denis Gorchakov, senior fraud analyst at Kaspersky Fraud Prevention.

More details about Kaspersky Fraud Prevention Clientless Malware Detection are available here
Currently, Kaspersky Lab’s portfolio includes 450 patents issued in Russia, the US, the EU and China. In addition to that, over 320 patent applications are currently under consideration by the patent authorities in these countries.
The description of the technology and patent can be found on the USPTO website.

Kaspersky Lab Has Patented Technology that Detects Man-in-the-Browser Attacks

Kaspersky Lab has announced that it has been awarded a new patent from the United States, for a technology that counteracts the tricks of financial cybercriminals. The new technology detects the implementation of HTML code into a page opened by a client’s browser (Man-in-the-Browser attack).
Kaspersky logo

关于卡巴斯基

卡巴斯基是一家成立于1997年的全球网络安全和数字隐私公司。卡巴斯基以“网络免疫”理念引领行业创新,致力于保护消费者、企业、关键基础设施和政府机构免受网络威胁,迄今为止已保护超过 10 亿台设备。

卡巴斯基秉持“Cybersecurity True to Business”的理念,专注于交付明确成果、保障营收、减轻团队负担并避免业务中断。卡巴斯基深厚的威胁情报和安全专业知识不断转化为创新解决方案和服务,服务于从小型企业到大型集团等各种规模的组织,将成熟的 AI 驱动型保护技术与简洁高效的管理和专家支持相结合。

卡巴斯基的解决方案经独立测试认可,深受全球数百万个人用户及近 20 万家企业的信赖,帮助客户更早识别威胁、更快速响应,以更强的信心与自由空间开展业务,保护对客户至关重要的资产。了解更多详情,请访问 www.kaspersky.com.cn

相关文章 企业新闻