IP Library › Granted Patent US 12,423,414
Granted Patent B2
US 12,423,414 · App. 18/109,733 · Granted Sep 23, 2025

MAYA: a hardware-based cyber-deception framework to combat malware

Inventors: Guru Prasadh V. Venkataramani (Fairfax, VA); Preet Derasari (Alexandria, VA); Kailash Gogineni (Alexandria, VA)
Assignee: The George Washington University
G06F21/54G06F21/564G06F21/568
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,423,414
App. No.
18/109,733
Granted
Sep 23, 2025
Kind
B2
Abstract

A hardware framework for cyber-deception operations provides flexibility in formulating counterattacks and leverages hardware support for efficiency. Hardware-assisted deception primitives are provided at kernel crossing boundaries to privileged system features that propel the security defenses to dynamically manipulate the malware execution and present a deceptive view of the system state to the attackers. Malware may be in the form of various attack vectors including ransomware, infostealers, buffer overflow, and side-channels.

Claims (43)

1. A cyber-deception system comprising:

a hardware processor is configured to:

intercept a system call; and

select at least one subroutine amongst a plurality of subroutines based on the intercepted system call;

the hardware processor having a subroutine, wherein the subroutine is configured to implement, based on the system call, at least one deception strategy amongst a plurality of deception strategies, wherein the at least one deception strategy is implemented by executing one or more instructions of the selected at least one subroutine; and

the hardware processor executes pre-runtime setup instructions to allow a system administrator to directly populate tactics into a deception table through a user interface, wherein the hardware processor further includes exception synthesis instructions to translate the tactics from the deception table entries into an exception subroutine, wherein one or more honey quivers are synthesized based on the tactic specified.

2. The cyber-deception system of claim 1 , the hardware processor further configured to:

execute one or more instructions of the intercepted system call; and

return at least one result of the executed one or more instructions of the intercepted system call.

3. The cyber-deception system of claim 1 , wherein the intercepted system call is determined to have originated from a malicious actor.

4. The cyber-deception system of claim 1 , wherein the intercepted system call includes at least one attack vector including data integrity corruption, ransomware, privilege escalation, infostealers, buffer overflow exploits, privacy leakage, side-channels, or a combination thereof.

5. The cyber-deception system of claim 1 , wherein the at least one deception strategy is at least one of a diversion strategy, a fabrication strategy, and an exhaustion strategy.

6. The cyber-deception system of claim 1 , wherein the selected at least one subroutine invokes at least one exception.

7. The cyber-deception system of claim 1 , wherein the at least one deception strategy is selected using a random number generator.

8. The cyber-deception system of claim 1 , wherein the deception table is populated with one or more deception strategy entries received from the hardware processor used against malware types.

9. The cyber-deception system of claim 1 , wherein the at least one subroutine is selected based on a number of the intercepted system call.

10. A deception trigger device, comprising:

a hardware processor; and

a memory coupled to the hardware processor, the memory having instructions stored thereon that when executed by the hardware processor implement:

receiving a system call associated with an attacker, the system call having a system call number;

reading the system call number of the received system call;

recording the system call number in a register;

invoking a system call-specific subroutine amongst a plurality of system call-specific subroutines, based on the system call number of the received system call; and

implementing at least one deception strategy by executing the invoked system call-specific subroutine, wherein the at least one deception strategy includes one or more deception primitive data types include kernel boundaries to intercept malware system service requests and to enforce the at least one deception strategy at the hardware processor, wherein a system administrator, through a user interface, directly retrieves the appropriate format for a specified tactic comprising the deception primitive and mode from a deception table supported by a disclosed hardware.

11. The deception trigger device of claim 10 , wherein, in response to the one or more deception primitives specifying at least one return-time manipulation of target fields, a system return tracker flag is set to 1.

12. The deception trigger device of claim 11 , wherein the at least one deception strategy is invoked for a system return when the system return tracker flag is set to 1 by the received system call.

13. The deception trigger device of claim 12 , wherein the at least one deception strategy invoked for the system return uses the recorded number in the register and the system return tracker flag value to index a subroutine for return-time deception.

14. A deception trigger device, comprising:

a hardware processor; and

a memory coupled to the hardware processor, the memory having instructions stored thereon that when executed by the hardware processor implement:

receiving a system call associated with an attacker, the system call having a system call number;

reading the system call number of the received system call;

recording the system call number in a register;

invoking a system call-specific subroutine amongst a plurality of system call-specific subroutines, based on the system call number of the received system call; and

implementing at least one deception strategy by executing the invoked system call-specific subroutine, wherein the at least one deception strategy includes a return-time deception, wherein a hardware-assisted random number generator triggers a random selection of an index to dynamically activates a deception tactic with one of an exception subroutine each time for each of the system call-specific subroutines, wherein at least one deception subroutine is executed during time of return for the received system call.

15. A deception trigger device, comprising:

a hardware processor; and

a memory coupled to the hardware processor, the memory having instructions stored thereon that when executed by the hardware processor implement:

receiving a system call associated with an attacker, the system call having a system call number;

reading the system call number of the received system call;

recording the system call number in a register;

invoking a system call-specific subroutine amongst a plurality of system call-specific subroutines, based on the system call number of the received system call; and

implementing at least one deception strategy by executing the invoked system call-specific subroutine, wherein the at least one deception strategy includes a deception tactic received from triggering a hardware-assisted random number generator to randomly select an index and dynamically activates a deception tactic with one of a respective honey quivers an exception subroutine each time for each of the system call-specific subroutines, to provide useless bytes to the attacker by scrambling a read buffer using a SCRAMBLE RETURN primitive, which randomizes each byte value in REG mode of operation wherein the scrambling is an iterative loop based on the value held in a RDX register.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2024
From: VENKATARAMANI, GURU PRASADH V.; DERASARI, PREET; GOGINENI, KAILASH
To: THE GEORGE WASHINGTON UNIVERSITY
Reel/Frame 069651/0773 →
Continuity (2)
Provisional Application 63309833 · Feb 14, 2022
Related Publication 20240095341A1 · Mar 21, 2024
References Cited (24)
US 10230745B2 · Singh · 2019 [cited by examiner]
US 11062028B2 · Lamay · 2021 [cited by examiner]
US 11651081B1 · Powers · 2023 [cited by examiner]
US 20040153574A1 · Cohen · 2004 [cited by examiner]
US 20140250524A1 · Meyers · 2014 [cited by examiner]
US 20180041536A1 · Berlin · 2018 [cited by examiner]
US 20190166098A1 · Trama · 2019 [cited by examiner]
US 20190384692A1 · Liu · 2019 [cited by examiner]
US 20210089647A1 · Suwad · 2021 [cited by examiner]
US 20230221986A1 · O'Connell · 2023 [cited by examiner]
US 20250030733A1 · Kahlhofer et al. · 2025 [cited by applicant]
US 20250039236A1 · Ignatius et al. · 2025 [cited by applicant]
CN 109416721A · 2019 [cited by examiner]
WO WO2020125839A1 · 2020 [cited by examiner]
P. Derasari et al., “MAYAVI: A Cyber-Deception Hardware for Memory Load-Stores”, In Proceedings of the Great Lakes Symposium on VLSI 2023 (GLSVLSI '23), Jun. 5-7, 2023, Knoxville, TN, USA. ACM, New York, NY, USA, pp. 56… [cited by applicant]
P. Derasari et al., “MAYALOK: A Cyber-Deception Hardware Using Runtime Instruction Infusion”, 2023 IEEE 34th International Conference on Application-specific Systems, Architectures and Processors (ASAP), pp. 33-40, http… [cited by applicant]
P. Derasari et al., “MAYA: Hardware Enhanced Customizable Defenses at the User-Kernel Interface”, 2024 International Symposium on Secure and Private Execution Environment Design (SEED), pp. 50-61, https://ieeexplore.iee… [cited by applicant]
P. Derasari et al., “EPIC: Efficient and Proactive Instruction-Level Cyberdefense”, GLSVLSI '24, Jun. 12-14, 2024, Clearwater, FL, USA, pp. 407-414, https://dl.acm.org/doi/abs/10.1145/3649476.3658749, 7 pages. [cited by applicant]
M. S. I. Sajid et al., “SODA: A System for Cyber Deception Orchestration and Automation”, ACSAC '21, Dec. 6- 10, 2021, Virtual Event, USA, pp. 675-689, https://dl.acm.org/doi/abs/10.1145/3485832.3485918, 15 pages. [cited by applicant]
A. Aly et al., “Real-time multi-class threat detection and adaptive deception in Kubernetes environments”, Nature Portfolio, Scientific Reports, 158924, 2025, https://www.nature.com/articles/s41598-025-91606-8, 14 pages. [cited by applicant]
M. Couillard et al., “DRACO: Production Network Deployment and Evaluation of Deceptive Defense As-a-Service”, 2024 IEEE International Conference on Big Data (Big Data), pp. 2606-2615, https://ieeexplore.ieee.org/abstrac… [cited by applicant]
L. Sharma et al., “RISC-V Based Secure Processor Architecture for Return Address Protection”, 2025 38th International Conference on VLSI Design and 2025 24th International Conference on Embedded Systems (VLSID), pp. 481… [cited by applicant]
Y. Song et al., “Interstellar: Fully Partitioned and Efficient Security Monitoring Hardware Near a Processor Core for Protecting Systems against Attacks on Privileged Software,” CCS '24, Oct. 14-18, 2024, Salt Lake City… [cited by applicant]
J-S. Huang et al., “Time Machine: An Efficient and Backend-Migratable Architecture for Defending Against Ransomware in the Hypervisor”, CCSW'24, Oct. 14-18, 2024, Salt Lake City, UT, USA., pp. 66-79, https://dl.acm.org/… [cited by applicant]