IP Library Granted Patent US 12,483,570
Granted Patent B2
US 12,483,570 · App. 17/969,462 · Granted Nov 25, 2025

Malware traffic analyzer with direct malware detonation

Inventor: Cirlig Constantin Gabriel (London, GB)
Assignee: HUMAN SECURITY, INC.
H04L63/1425G06F8/61
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,483,570
App. No.
17/969,462
Granted
Nov 25, 2025
Kind
B2
Abstract

Systems, methods, apparatuses, and computer program products for analyzing malware traffic with direct malware detonation. The method may include, retrieving a data package from a source database. The method may also include invoking an auto tester to generate an indicator on the data package. The method may further include installing, in response to the invocation, the data package on a user equipment. In addition, the method may include triggering malicious behavior on the user equipment. Further, the method may include implementing an emulation of at least one user event on the data package during the malicious behavior. The method may also include extracting a uniform resource locator, a header, or a request body generated by the user equipment.

Claims (60)

1 . A method, comprising:

retrieving a data package from a source database;

invoking an auto tester to generate indicators of compromise corresponding to types of malicious behavior on the data package;

triggering the malicious behavior on a user equipment by installing, in response to the invocation, the data package on the user equipment;

implementing an emulation of at least one user event on the data package during the malicious behavior; and

extracting a uniform resource locator, a header, or a request body generated by the user equipment,

wherein the malicious behavior comprises at least one of

setting a clock of the auto tester for a future date;

rebooting the user equipment;

turning on or off a screen of the user equipment; or

activating an idle mode of the user equipment.

2 . The method according to claim 1 , wherein the auto tester is invoked based on an available user equipment instance.

3 . The method according to claim 1 , further comprising:

correlating traffic associated with the user equipment by initiating a packet analyzer and a proxy,

wherein the proxy is configured to capture incoming and outgoing data from the data package installed on the user equipment, and

wherein the packet analyzer is configured to intercept and display traffic captured by the proxy.

4 . The method according to claim 3 , further comprising:

applying a filter to the packet analyzer and the proxy.

5 . The method according to claim 3 , further comprising:

routing a request from the user equipment through the packet analyzer first, and then through the proxy.

6 . A dynamic malware traffic analyzer system, comprising:

a simple storage service comprising at least one data package;

a service connector connected to the simple storage service, wherein the service connector is configured to download the at least one data package from the simple storage service;

a device organizer configured to

retrieve and process the at least one data package stored at the service connector,

invoke an auto tester to generate indicators of compromise corresponding to types of malicious behavior on the data package, and

trigger the malicious behavior on a user equipment by installing, in response to the invocation, the data package on the user equipment; and

at least one user equipment in communication with the device organizer,

wherein the malicious behavior comprises at least one of

setting a clock of the auto tester for a future date;

rebooting the user equipment;

turning on or off a screen of the user equipment; or

activating an idle mode of the user equipment.

7 . The dynamic malware traffic analyzer system according to claim 6 , wherein the device organizer is configured to implement an emulation of at least one user event on the at least one data package.

8 . The dynamic malware traffic analyzer system according to claim 6 ,

wherein the device organizer comprises

a proxy configured to capture ingoing and outgoing data from the at least one data package, and

a packet analyzer configured to intercept and display traffic captured by the proxy.

9 . The dynamic malware traffic analyzer system according to claim 6 , further comprising:

an elastic search server configured to store, search, and analyze.

10 . A non-transitory computer readable medium encoded with a computer program, the computer program comprising computer executable code, which, when executed by a processor, causes the processor to:

retrieve a data package from a source database;

invoke an auto tester to generate indicators of compromise corresponding to types of malicious behavior on the data package;

trigger the malicious behavior on a user equipment by installing, in response to the invocation, the data package on a user equipment;

implement an emulation of at least one user event on the data package during the malicious behavior; and

extract a uniform resource locator, a header, or a request body generated by the user equipment,

wherein the malicious behavior comprises at least one of

setting a clock of the auto tester for a future date;

rebooting the user equipment;

turning on or off a screen of the user equipment; or

activating an idle mode of the user equipment.

11 . The computer program according to claim 10 , wherein the auto tester is invoked based on an available user equipment instance.

12 . The computer program according to claim 10 , wherein computer program comprising computer executable code, which, when executed by a processor, further causes the processor to:

correlate traffic associated with the user equipment by initiating a packet analyzer and a proxy,

wherein the proxy is configured to capture ingoing and outgoing data from the data package installed on the user equipment, and

wherein the packet analyzer is configured to intercept and display traffic captured by the proxy.

13 . The computer program according to claim 12 , wherein computer program comprising computer executable code, which, when executed by a processor, further causes the processor to:

apply a filter to the packet analyzer and the proxy.

14 . The computer program according to claim 12 , wherein computer program comprising computer executable code, which, when executed by a processor, further causes the processor to:

route a request from the user equipment through the packet analyzer first, and then through the proxy.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2025
From: ALTER DOMUS (US) LLC
To: HUMAN SECURITY, INC.; SINGULARITY BUYER LLC
Reel/Frame 071935/0384 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2025
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY
To: HUMAN SECURITY, INC.; SINGULARITY BUYER LLC; PERIMETERX, INC.
Reel/Frame 071935/0486 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 25, 2025
From: HUMAN SECURITY, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 072253/0310 →
SUPPLEMENT NO. 1 TO INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 9, 2023
From: HUMAN SECURITY, INC.; PERIMETERX, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 065532/0512 →
FIRST AMENDMENT TO INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: HUMAN SECURITY, INC.; SINGULARITY BUYER LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 063906/0041 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2022
From: GABRIEL, CIRLIG CONSTANTIN
To: HUMAN SECURITY, INC.
Reel/Frame 061479/0946 →
Continuity (2)
Related Publication 20240137374A1 · Apr 25, 2024
Related Publication 20240236123A9 · Jul 11, 2024
References Cited (16)
US 8434151B1 · Franklin · 2013 [cited by examiner]
US 9195829B1 · Goradia · 2015 [cited by examiner]
US 9489516B1 · Lu · 2016 [cited by examiner]
US 10397255B1 · Bhalotra · 2019 [cited by examiner]
US 10846405B1 · Ciubotariu · 2020 [cited by examiner]
US 10956573B2 · Zheng · 2021 [cited by examiner]
US 11943248B1 · McGregory · 2024 [cited by examiner]
US 20140223566A1 · Zaitsev · 2014 [cited by examiner]
US 20160283716A1 · Momot · 2016 [cited by examiner]
US 20200104511A1 · Stolfo · 2020 [cited by examiner]
US 20210099476A1 · Montgomery · 2021 [cited by examiner]
US 20210200872A1 · Cannings · 2021 [cited by examiner]
US 20240281531A1 · Taylor · 2024 [cited by examiner]
US 20240303344A1 · Chiscariu · 2024 [cited by examiner]
US 20250077682A1 · Guttridge · 2025 [cited by examiner]
US 20250181724A1 · Lanson · 2025 [cited by examiner]