IP Library Granted Patent US 11,550,912
Granted Patent B2
US 11,550,912 · App. 16/903,060 · Granted Jan 10, 2023

Detection of exploitative program code

Inventors: Soumyadipta Das (Bangalore, IN); Sai Sravan Kumar Ganachari (Bangalore, IN); Yao He (San Jose, CA); Aleksandr Dubrovsky (Los Altos, CA)
Assignee: SONICWALL INC.
G06F21/563G06F21/566G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,550,912
App. No.
16/903,060
Granted
Jan 10, 2023
Kind
B2
Abstract

The present disclosure is directed to monitoring internal process memory of a computer at a time with program code executes. Methods and apparatus consistent with the present disclosure monitor the operation of program code with the intent of detecting whether received program inputs may exploit vulnerabilities that may exist in the program code at runtime. By detecting suspicious activity or malicious code that may affect internal process memory at run-time, methods and apparatus described herein identify suspected malware based on suspicious actions performed as program code executes. Runtime exploit detection may detect certain anomalous activities or chain of events in a potentially vulnerable application during execution. These events may be detected using instrumentation code when a regular code execution path of an application is deviated from.

Claims (33)

1. A method for analyzing data, the method comprising:

storing environmental data that associates a mapping of memory addresses with sets of executable program code;

identifying that execution of instructions included in data packets received at a computer results in the environmental data being accessed, wherein the identification further includes identifying that a memory address accessed by the execution of the instructions was previously written to by an initial instruction included in the data packets; and

classifying the instructions received at the computer as suspicious based on the environmental data being accessed.

2. The method of claim 1 , further comprising identifying that the execution of the instructions results in the accessing of a dynamic linked library (DLL).

3. The method of claim 1 , further comprising identifying that the execution of the instructions results in the accessing of an operating system function that accesses a memory based on the mapping of memory addresses of the stored environmental data.

4. The method of claim 1 , further comprising identifying that the execution of the instructions results in data associated with the sets of executable program code being overwritten.

5. The method of claim 1 , further comprising identifying that the execution of the instructions results in the accessing of application program interface data.

6. The method of claim 1 , further comprising identifying that the instructions included in the data packets are being executed out of a temporary directory.

7. The method of claim 1 , further comprising identifying that data included in the data packets are de-obfuscated before the instructions included in the data packets are executed.

8. A non-transitory computer-readable storage medium having embodied thereon a program executable by a processor for implementing a method for analyzing data, the method comprising:

storing environmental data that associates a mapping of memory addresses with sets of executable program code;

identifying that execution of instructions included in received data packets results in the environmental data being accessed, wherein the identification further includes identifying that a memory address accessed by the execution of the instructions was previously written to by an initial instruction included in the data packets; and

classifying the instructions included in received data packets as suspicious based on the environmental data being accessed.

9. The non-transitory computer-readable storage medium of claim 8 , the program further executable to identify that the execution of the instructions results in the accessing of a dynamic linked library (DLL).

10. The non-transitory computer-readable storage medium of claim 8 , further executable to identify that the execution of the instructions results in the accessing of an operating system function that accesses a memory based on the mapping of memory addresses of the stored environmental data.

11. The non-transitory computer-readable storage medium of claim 8 , further executable to identify that the execution of the instructions results in data associated with the sets of executable program code being overwritten.

12. The non-transitory computer-readable storage medium of claim 8 , further executable to identify that the execution of the instructions results in the accessing of application program interface data.

13. The non-transitory computer-readable storage medium of claim 8 , further executable to identify that the instructions included in the data packets are being executed out of a temporary directory.

14. The non-transitory computer-readable storage medium of claim 8 , further executable to identify that data included in the data packets are de-obfuscated before the instructions included in the data packets are executed.

15. A system for analyzing data, the system comprising a computer that includes:

a memory that stores environmental data that associates a mapping of memory addresses with sets of executable program code; and

a processor that executes instructions out of the memory to:

identify that execution of instructions included in data packets received via a computer network results in the environmental data being accessed, wherein the identification further includes identifying that a memory address previously accessed by the execution of the instructions was previously written to by an initial instruction included in the data packets, and

classify the instructions received at the computer as suspicious based on the environmental data being accessed.

16. The system of claim 15 , further comprising a firewall that initially receives the data packets and that sends the data packets to the computer via the computer network.

17. The system of claim 15 , wherein the processor identifies that the execution of the instructions results in the accessing of a dynamic linked library (DLL).

18. The system of claim 15 , wherein the processor identifies that at the execution of the instructions results in the accessing of an operating system function that accesses a memory based on the mapping of memory addresses of the stored environmental data.

19. The system of claim 15 , wherein the processor identifies that the execution of the instructions results in data associated with the sets of executable program code being overwritten.

20. A method for analyzing data, the method comprising:

storing environmental data that associates a mapping of memory addresses with sets of executable program code;

identifying that execution of instructions included in data packets received at a computer results in the environmental data being accessed, wherein the identification further includes identifying that the instructions included in the data packets are being executed out of a temporary directory; and

classifying the instructions received at the computer as suspicious based on the environmental data being accessed.

Assignments (2)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071758/0159 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2020
From: DAS, SOUMYADIPTA; GANACHARI, SAI SRAVAN KUMAR; HE, YAO; DUBROVSKY, ALEKSANDR
To: SONICWALL INC.
Reel/Frame 053409/0265 →
Continuity (2)
Continuation 15858785 · Dec 29, 2017
Related Publication 20200380127A1 · Dec 3, 2020
Cited By (3)
US 12,639,438 US 12,647,433 US 12,717,914