IP Library Granted Patent US 12,380,210
Granted Patent B2
US 12,380,210 · App. 17/805,677 · Granted Aug 5, 2025

Analyzing files using a kernel mode of a virtual machine

Inventor: Ran Dubin (Habostan 2, IL)
Assignee: OPSWAT Inc.
G06F21/565G06F9/45558G06F21/53G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,380,210
App. No.
17/805,677
Granted
Aug 5, 2025
Kind
B2
Abstract

A method includes receiving, by a computerized system, a file in network traffic to an enterprise system. The computerized system identifies data associated with the file. The computerized system receives a policy based on the data associated with the file for an event of the file. The computerized system executes the file in a user mode of a virtual machine. A driver in a kernel mode of the virtual machine analyzes the event of the file based on the policy during the executing of the file. When the event violates the policy, the computerized system denies an entry of the file to the enterprise system.

Claims (44)

1. A method comprising:

receiving, by a computerized system, a file in network traffic to an enterprise system;

identifying, by the computerized system, data associated with the file;

receiving, by the computerized system, a policy based on the data associated with the file for an event of the file;

executing, by the computerized system, the file in a user mode of a virtual machine;

analyzing, by a driver in a kernel mode of the virtual machine, the event of the file based on the policy during the executing of the file, wherein the driver monitors and modifies system calls in real-time based on the policy to prevent unauthorized actions before they complete;

determining, by the driver in the kernel mode, in real-time, when the event violates the policy; and

when the event violates the policy, denying, by the computerized system, an entry of the file to the enterprise system.

2. The method of claim 1 , wherein the data associated with the file includes a file type.

3. The method of claim 1 , wherein the data associated with the file includes a target destination.

4. The method of claim 1 , further comprising, when the event is permitted by the policy, allowing, by the computerized system, the entry of the file to the enterprise system.

5. The method of claim 1 , wherein the event comprises at least one of file operations, mutex operations, registry operations, network operations, process operations, and handle operations.

6. The method of claim 1 , wherein the policy is based on a target destination.

7. The method of claim 1 , wherein the policy is based on malicious activity of the file.

8. The method of claim 1 , wherein the policy is based on an operation that can be performed by the file.

9. The method of claim 1 , further comprising:

connecting, by the computerized system, to a network traffic device outside of the enterprise system.

10. The method of claim 1 , wherein during the analyzing of the event of the file in the kernel mode during the executing of the file, the kernel mode is undetectable by the user mode.

11. A computerized system comprising:

a memory storing executable instructions; and

a processor, coupled to the memory, that performs a method by executing the instructions stored in the memory, the method comprising:

receiving, by the processor, a file in network traffic to an enterprise system;

identifying, by the processor, data associated with the file;

receiving, by the processor, a policy based on the data associated with the file for an event of the file;

executing, by the processor, the file in a user mode of a virtual machine;

analyzing, by a driver in a kernel mode of the virtual machine, the event of the file based on the policy during the executing of the file, wherein the driver monitors and modifies system calls in real-time based on the policy to prevent unauthorized actions before they complete;

determining, by the driver in the kernel mode, in real-time, when the event violates the policy; and

when the event violates the policy, denying, by the processor, an entry of the file to the enterprise system.

12. The computerized system of claim 11 , wherein when the event is permitted by the policy, allowing the entry of the file to the enterprise system.

13. The computerized system of claim 11 , wherein the event comprises at least one of file operations, mutex operations, registry operations, network operations, process operations, and handle operations.

14. The computerized system of claim 11 , wherein the policy is based on a target destination.

15. The computerized system of claim 11 , wherein the policy is based on malicious activity of the file.

16. The computerized system of claim 11 , wherein the processor connects to a network traffic device outside of the enterprise system.

17. The computerized system of claim 11 , wherein during the analyzing of the event of the file in the kernel mode during the executing of the file, the kernel mode is undetectable by the user mode.

18. A non-transitory computer-readable media embodying program instructions that, when executed by a processor, cause the processor to implement a method, comprising:

receiving a file in network traffic to an enterprise system;

identifying data associated with the file;

receiving a policy based on the data associated with the file for an event of the file;

executing the file in a user mode of a virtual machine;

analyzing, by a driver in a kernel mode of the virtual machine, the event of the file based on the policy during the executing of the file, wherein the driver monitors and modifies system calls in real-time based on the policy to prevent unauthorized actions before they complete;

determining, by the driver in the kernel mode, in real-time, when the event violates the policy; and

when the event violates the policy, denying an entry of the file to the enterprise system.

19. The non-transitory computer-readable media of claim 18 , wherein the policy is based on a target destination.

20. The non-transitory computer-readable media of claim 18 , wherein the policy is based on malicious activity of the file.

Assignments (2)
SECURITY INTEREST Recorded Dec 29, 2022
From: OPSWAT INC.
To: CITIBANK, N.A.
Reel/Frame 062236/0124 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2022
From: DUBIN, RAN
To: OPSWAT, INC.
Reel/Frame 060134/0253 →
Continuity (1)
Related Publication 20230394146A1 · Dec 7, 2023
References Cited (17)
US 8272048B2 · Cooper · 2012 [cited by examiner]
US 9148428B1 · Banga et al. · 2015 [cited by applicant]
US 9208328B2 · Russello · 2015 [cited by examiner]
US 10033747B1 · Paithane · 2018 [cited by examiner]
US 10341363B1 · Vincent et al. · 2019 [cited by applicant]
US 20150096022A1 · Vincent · 2015 [cited by examiner]
US 20160306966A1 · Srivastava · 2016 [cited by examiner]
US 20170032123A1 · Carson · 2017 [cited by examiner]
US 20190205533A1 · Diehl · 2019 [cited by examiner]
US 20190222591A1 · Kislitsin et al. · 2019 [cited by applicant]
US 20200242236A1 · Ghosh et al. · 2020 [cited by applicant]
US 20210026950A1 · Ionescu · 2021 [cited by examiner]
US 20210182388A1 · Myneni · 2021 [cited by examiner]
US 20210192043A1 · Bhary et al. · 2021 [cited by applicant]
US 20220066808A1 · Tsirkin · 2022 [cited by examiner]
“Combating Malware Innovation With Innovation”, Sndbox Technology Ltd 2018, 3 pgs, www.sndbox.com. [cited by applicant]
Kumar, Mohit., “SNDBOX: AI-Powered Online Automated Malware Analysis Platform”, Dec. 5, 2018, 12 pgs, The Hacker News. https://thehackernews.com/2018/12/sndbox-malware-analysis-tool.html. [cited by applicant]