IP Library Granted Patent US 12,001,554
Granted Patent B2
US 12,001,554 · App. 17/505,327 · Granted Jun 4, 2024

Just in time memory analysis for malware detection

Inventors: Soumyadipta Das (Milpitas, CA); Alex Dubrovsky (Milpitas, CA); Igor Korsunsky (Milpitas, CA)
Assignee: SonicWALL Inc.
G06F21/566G06F2221/034G06F2221/2125
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,001,554
App. No.
17/505,327
Granted
Jun 4, 2024
Kind
B2
Abstract

Methods and apparatus consistent with the present disclosure may use instrumentation code that remains transparent to an application program that the instrumentation code has been injected into. In certain instances, data sets that include executable code may be received via packetized communications or be received via other means, such as, receiving a file from a data store. The present technique allows a processor executing instrumentation code to monitor actions performed by the program code included in a received data set. Malware may be detected by scanning suspect program code with a malware scanner, malware may be detected by identifying suspicious actions performed by a set of program code, or malware may be detected by a combination of such techniques.

Claims (42)

1. A method for analyzing computer data, the method comprising:

allowing instructions of a set of computer data to be executed by a processor;

monitoring actions performed by the execution of the instructions of the set of computer data, the monitoring performed by the processor executing a set of instrumentation code instructions;

pausing execution of the instructions of the computer data based on an identification that the monitored actions include writing data to a memory;

identifying that the monitored actions correspond to an access pattern of the memory that includes allocating a portion of the memory and includes invocation of an operating system program function, wherein the data written to the memory is written to a newly allocated memory portion;

comparing a signature generated from the data written to the allocated memory portion of the memory to a malware signature generated from previously identified malicious code; and

performing a corrective action based on an identification that the generated signature matches the malware signature.

2. The method of claim 1 , further comprising identifying that the monitored actions include de-obfuscating the data written to the allocated memory portion of the memory.

3. The method of claim 1 , further comprising generating the signature by scanning the data written to the allocated memory portion of the memory with a deep packet inspection (DPI) scanner.

4. The method of claim 1 , further comprising identifying that the monitored actions include unpacking of the data from the set of computer data before the data is written to the allocated memory portion of the memory.

5. The method of claim 1 , further comprising identifying that the monitored actions include marking the data written to the allocated memory portion of the memory as executable.

6. The method of claim 1 , further comprising:

identifying that a first action of the monitored actions corresponds to a first memory access state;

identifying that a second action of the monitored actions corresponds to a second memory access state;

identifying that the execution of the instructions of set of computer data has performed a suspicious behavior, the identification based on the first action occurring before the second action and based on a rule that identifies that the signature should be generated when the first memory access state occurs before the second memory access state; and

generating the signature according to the rule.

7. A non-transitory computer-readable storage medium having embodied thereon a program executable by a processor for implementing a method for analyzing computer data, the method comprising:

allowing instructions of a set of computer data to be executed by a processor;

monitoring actions performed by the execution of the instructions of the set of computer data, the monitoring performed by the processor executing a set of instrumentation code instructions;

pausing execution of the instructions of the computer data based on an identification that the monitored actions include writing data to a memory;

identifying that the monitored actions correspond to an access pattern of the memory that includes allocating a portion of the memory and includes invocation of an operating system program function, wherein the data written to the memory is written to a newly allocated memory portion;

comparing a signature generated from the data written to the allocated memory portion to a malware signature generated from previously identified malicious code; and

performing a corrective action based on an identification that the generated signature matches the malware signature.

8. The non-transitory computer-readable storage medium of claim 7 , the program further executable to identify that the monitored actions include de-obfuscating the data written to the allocated memory portion.

9. The non-transitory computer-readable storage medium of claim 7 , the program further executable to generate the signature by scanning the data written to the allocated memory portion with a deep packet inspection (DPI) scanner.

10. The non-transitory computer-readable storage medium of claim 7 , the program further executable to identify that the monitored actions include unpacking of the data from the set of computer data before the data is written to the allocated memory portion.

11. The non-transitory computer-readable storage medium of claim 7 , the program further executable to identify that the monitored actions include marking the data written to the allocated memory portion as executable.

12. The non-transitory computer-readable storage medium of claim 7 , the program further executable to:

identify that a first action of the monitored actions corresponds to a first memory access state;

identify that a second action of the monitored actions corresponds to a second memory access state;

identify that the execution of the instructions of set of computer data has performed a suspicious behavior, the identification based on the first action occurring before the second action and based on a rule that identifies that the signature should be generated when the first memory access state occurs before the second memory access state; and

generate the signature according to the rule.

13. An apparatus for analyzing computer data, the apparatus comprising:

a memory; and

a processor that executes instructions out of the memory to:

execute instructions of a set of computer data;

monitor actions performed by the execution of the instructions of the set of computer data, the monitoring performed by the processor executing a set of instrumentation code instructions, pause execution of the instructions of the computer data based on an identification that the monitored actions include writing data to the memory,

identify that the monitored actions correspond to an access pattern of the memory that includes allocating a portion of the memory and includes invocation of an operating system program function, wherein the data written to the memory is written to a newly allocated memory portion,

compare a signature generated from the data written to the allocated memory portion to a malware signature generated from previously identified malicious code, and

perform a corrective action based on an identification that the generated signature matches the malware signature.

14. The apparatus of claim 13 , wherein the execution of the set of instrumentation code instructions allow the processor to identify that the monitored actions include de-obfuscating the data written to the allocated memory portion.

15. The apparatus of claim 13 , further comprising instructions of a set of deep packet inspection (DPI) program code, wherein execution of the instructions of the set of DPI program code generate the signature.

Assignments (2)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071758/0159 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2021
From: DAS, SOUMYADIPTA; DUBROVSKY, ALEX; KORSUNSKY, IGOR
To: SONICWALL, INC
Reel/Frame 058507/0512 →
Continuity (2)
Continuation 15783793 · Oct 13, 2017
Related Publication 20220035919A1 · Feb 3, 2022
Cited By (3)
US 12,639,438 US 12,647,433 US 12,717,914