IP Library › Granted Patent US 12,455,961
Granted Patent B2
US 12,455,961 · App. 18/120,807 · Granted Oct 28, 2025

Detecting potential malware in host memory

Inventors: Nir Rosen (Pardes Hana-Karkur, IL); Katya Egert-Berg (Tel Aviv, IL); Rami Ailabouni (Eilabun, IL); Ohad Peres (Tel Aviv, IL); Elad Haimovich (Kiryat Bialik, IL); Vadim Gechman (Hulda, IL); Haim Elisha, V (Ashkelon, IL); Adi Peled (Kefar Saba, IL); Chen Rozenbaum (Beer Yakov, IL); Ahmad Saleh (Nazareth, IL); Shie Mannor (Haifa, IL)
Assignee: Mellanox Technologies, Ltd.
G06F21/554G06F21/52G06F21/566G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,455,961
App. No.
18/120,807
Filed
Mar 13, 2023
Granted
Oct 28, 2025
Kind
B2
Art Unit
2407
USPC
726/23
Abstract

Apparatuses, systems, and techniques of using one or more circuits (e.g., of a network interface) to obtain assembly code for one or more machine code segments loaded and/or injected into a process, and determine whether the assembly code is likely to perform at least one unauthorized task.

Claims (43)

1. A method comprising:

obtaining, by a network interface, one or more machine code segments at least one of loaded or injected into a process;

using a data structure to identify a region of memory used by the process to store the one or more machine code segments;

obtaining, by the network interface, assembly code for the one or more machine code segments stored in the region of memory; and

determining, by the network interface, whether the assembly code is likely to perform at least one unauthorized task.

2. The method of claim 1 , wherein determining whether the assembly code is likely to perform the at least one unauthorized task comprises using artificial intelligence to classify the assembly code as potentially being malware or as not being malware.

3. The method of claim 2 , wherein the artificial intelligence comprises at least one machine learning model that is used to classify the assembly code.

4. The method of claim 3 , wherein the at least one machine learning model comprises at least one of a Natural Language Processing (“NLP”) model or a Graph Neural Network (“GNN”).

5. The method of claim 1 , further comprising:

causing, by the network interface, information to be displayed when the assembly code is classified as potentially being malware.

6. The method of claim 1 , further comprising:

identifying, by the network interface, the process based at least in part on contents of at least one memory region associated with the process.

7. The method of claim 1 , further comprising:

identifying, by the network interface, the process by detecting at least one suspicious machine code segment at least one of loaded or injected into the process.

8. The method of claim 7 , wherein the network interface uses at least one heuristic to detect the at least one suspicious machine code segment at least one of loaded or injected into the process.

9. A system comprising:

at least one host processor to perform a process;

a host memory to store one or more machine code segments at least one of loaded or injected into the process; and

one or more circuits connected to the host memory to use a data structure to identify a region of the host memory used by the process to store the one or more machine code segments, obtain assembly code for the one or more machine code segments stored in the region of the host memory, and determine whether the assembly code is likely to perform at least one unauthorized task.

10. The system of claim 9 , wherein determining whether the assembly code is likely to perform the at least one unauthorized task comprises using artificial intelligence to classify the assembly code as potentially being malicious or as not being malicious.

11. The system of claim 10 , wherein the artificial intelligence comprises at least one machine learning model that is used to classify the assembly code.

12. The system of claim 11 , wherein the at least one machine learning model comprises at least one of a Natural Language Processing (“NLP”) model or a Graph Neural Network (“GNN”).

13. The system of claim 9 , wherein the one or more circuits are to cause information to be displayed when the assembly code is classified as potentially being malicious.

14. The system of claim 9 , wherein the one or more circuits are to identify the process based at least in part on contents of at least one memory region associated with the process.

15. The system of claim 9 , wherein the one or more circuits are to identify the process by detecting at least one suspicious machine code segment at least one of loaded or injected into the process.

16. The system of claim 15 , wherein the one or more circuits are to use at least one heuristic to detect the at least one suspicious machine code segment at least one of loaded or injected into the process.

17. The system of claim 9 , further comprising:

a host computing system comprising the at least one host processor and the host memory; and

a network interface comprising the one or more circuits.

18. The system of claim 9 , wherein the one or more circuits are at least one of out-of-band or agentless with respect to the at least one host processor.

19. A processor comprising:

one or more circuits to use a data structure to identify a region of memory used by a process to store one or more machine code segments, obtain assembly code by disassembling one or more machine code segments stored in the region of memory, and determine whether the assembly code is likely to perform at least one unauthorized task.

20. The processor of claim 19 , wherein determining whether the assembly code is likely to perform the at least one unauthorized task comprises using artificial intelligence to classify the assembly code as potentially being malicious or as not being malicious.

21. The processor of claim 20 , wherein the artificial intelligence comprises at least one machine learning model that is used to classify the assembly code.

22. The processor of claim 21 , wherein the at least one machine learning model comprises at least one of a Natural Language Processing (“NLP”) model or a Graph Neural Network (“GNN”).

23. The processor of claim 19 , wherein the one or more circuits are to cause information to be displayed when the assembly code is classified as potentially being malicious.

24. The processor of claim 19 , wherein the one or more circuits are to:

identify the process based at least in part on contents of the region of memory used by the process; and

obtain the one or more machine code segments which were at least one of loaded or injected into the process.

25. The processor of claim 24 , wherein the one or more circuits are to identify the process by detecting at least one suspicious machine code segment at least one of loaded or injected into the process.

26. The processor of claim 25 , wherein the one or more circuits are to use at least one heuristic to detect the at least one suspicious machine code segment.

27. The processor of claim 19 , wherein the one or more circuits are at least one of out-of-band or agentless with respect to at least one host processor when the at least one host processor executes the one or more machine code segments.

28. The processor of claim 19 , wherein at least a portion of the processor is comprised in at least one of a network interface or a data processing unit (“DPU”).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2023
From: ROSEN, NIR; EGERT-BERG, KATYA; AILABOUNI, RAMI; PERES, OHAD; HAIMOVICH, ELAD; GECHMAN, VADIM; ELISHA, HAIM; PELED, ADI; ROZENBAUM, CHEN; SALEH, AHMAD; MANNOR, SHIE
To: MELLANOX TECHNOLOGIES, LTD.
Reel/Frame 062965/0480 →
Continuity (2)
Provisional Application 63406465 · Sep 14, 2022
Related Publication 20240086527A1 · Mar 14, 2024
References Cited (35)
US 7971255B1 · Kc et al. · 2011 [cited by applicant]
US 8510596B1 · Gupta · 2013 [cited by examiner]
US 9588829B2 · Turbin · 2017 [cited by examiner]
US 10817606B1 · Vincent · 2020 [cited by examiner]
US 11042637B1 · Davis · 2021 [cited by examiner]
US 12118078B2 · Gechman et al. · 2024 [cited by applicant]
US 12160437B2 · Gechman et al. · 2024 [cited by applicant]
US 12169563B2 · Gechman et al. · 2024 [cited by applicant]
US 12261881B2 · Gechman et al. · 2025 [cited by applicant]
US 20030033536A1 · Pak · 2003 [cited by examiner]
US 20200074080A1 · Srinivasagopalan · 2020 [cited by examiner]
US 20200104498A1 · Smith et al. · 2020 [cited by applicant]
US 20230161879A1 · Koo · 2023 [cited by examiner]
US 20240045662A1 · Jain · 2024 [cited by examiner]
US 20240086536A1 · Rosen · 2024 [cited by examiner]
CN 114707150A · 2022 [cited by examiner]
CN 117828597A · 2024 [cited by examiner]
CN 117992956A · 2024 [cited by examiner]
Rigger et al, An Analysis of x86-64 Inline Assembly in C Programs, VEE '18, pp. 1-16 (Year: 2018). [cited by examiner]
David et al., “Neural Reverse Engineering of Stripped Binaries using Augmented Control Flow Graphs, ” Proceedings of the ACM on Programming Languages, 4(225): 2020, 28 pages. [cited by applicant]
IEEE, “IEEE Standard 754-2008 (Revision of IEEE Standard 754-1985): IEEE Standard for Floating-Point Arithmetic,” Aug. 29, 2008, 70 pages. [cited by applicant]
IEEE, “IEEE Standard for 802.3,” IEEE Standard for Ethernetn, IEEE Computer Society, Dec. 28, 2012, 634 pages. [cited by applicant]
Li et al., “PalmTree: Learning an Assembly Language Model for Instruction Embedding,” Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, 2021, 16 pages. [cited by applicant]
U.S. Appl. No. 17/864,303, “Ransomware Detection in Memory of a Data Processing Unit Using Machine Learning Detection Models, ” filed Jul. 13, 2022. [cited by applicant]
U.S. Appl. No. 17/864,306, “Malicious Activity Detection in Memory of a Data Processing Unit Using Machine Learning Detection Models,” filed Jul. 13, 2022. [cited by applicant]
U.S. Appl. No. 17/864,310, “Malicious Uniform Resource Locator (URL) Detection in Memory of a Data Processing Unit Using Machine Learning Detection Models,” filed Jul. 13, 2022. [cited by applicant]
U.S. Appl. No. 17/864,312, “Malicious Domain Generation Algorithm (DGA) Detection in Memory of a Data Processing Unit Using Machine Learning Detection Models,” filed Jul. 13, 2022. [cited by applicant]
Wikipedia, “IEEE 802.11,” Wikipedia the Free Encyclopedia, https://en.wikipedia.org/wiki/IEEE_802.11, most recent edit Sep. 20, 2020 [retrieved Sep. 22, 2020], 15 pages. [cited by applicant]
Wikipedia, “IEEE 802.5,” Wikepedia the Free Encyclopedia, https://en.wikipedia.org/wiki/Token_Ring, Jan. 14, 2020, 12 pages. [cited by applicant]
Block et al., “Windows Memory Forensics: Detecting (Un)Intentionally Hidden Injected Code by Examining Page Table Entries,” Digital Investigation, 2019, 10 pages. [cited by applicant]
Downing et al., “DeepReflect: Discovering Malicious Functionality through Binary Reconstruction,” USENIX Security Symposium, Aug. 2021, 19 pages. [cited by applicant]
Jholgui, “Yara-Rules/Rules,” retrieved from https://github.com/Yara-Rules/rules/blob/master/malware/APT_Cobalt.yar, 2019, 1 page. [cited by applicant]
Pelissier et al., “Yara-Rules/Rules,” GitHub, retrieved from https://github.com/Yara-Rules/rules/blob/master/crypto/crypto_signatures.yar, 2021, 31 pages. [cited by applicant]
Shipp et al., “InQuest/Awesome-yara,” GitHub, retrieved from https://github.com/InQuest/awesome-yara, 2020, 18 pages. [cited by applicant]
Yara, “Yara in a Nutshell,” retrieved from https://virustotal.github.io/yara/, 2016, pages. [cited by applicant]