IP Library Granted Patent US 12,361,130
Granted Patent B2
US 12,361,130 · App. 18/301,366 · Granted Jul 15, 2025

Real-time shellcode detection and prevention

Inventors: Or Chechik (Rishon LeZion, IL); Liav Zigelbaum (Herzliya, IL); Eldar Aharoni (Holon, IL); Bar Lahav (Herzliya, IL)
Assignee: Palo Alto Networks, Inc.
G06F21/566G06F21/564
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,361,130
App. No.
18/301,366
Granted
Jul 15, 2025
Kind
B2
Abstract

Methods, storage systems and computer program products implement embodiments of the present invention for protecting a computing device, which includes a processor and a memory and is coupled to a storage device storing a set of one or more files. In embodiments of the present invention, a call to a specified function for execution by the processor is detected, and a stack trace for the call to the specified function is generated in the memory. Upon detecting, in the stack trace, a stack frame including a return address referencing a shellcode region in the memory, wherein the shellcode region includes executable code that was not loaded from any given file on the storage device, then the referenced executable code is compared to a list of malicious shellcode. Finally, a preventive action is initiated upon detecting a match between the referenced executable code and one of malicious shellcodes in the list.

Claims (39)

1. A method for protecting a computing device, which includes a processor and a memory and is coupled to a storage device storing a set of one or more files, the method comprising:

detecting, by the processor, a call to a specified function for execution by the processor;

generating, in the memory, a stack trace for the call to the specified function;

detecting, in the stack trace, a stack frame comprising a return address referencing a page in the memory containing executable code, the stack frame including a flag indicating whether the executable code was loaded from a file on the storage device;

in response to the flag indicating that the executable code was not loaded from any file on the storage device,

comparing the referenced executable code to a list of malicious shellcode; and

initiating a preventive action upon detecting a match between the referenced executable code and one of malicious shellcodes in the list.

2. The method according to claim 1 , wherein the referenced executable code executes in kernel mode.

3. The method according to claim 1 , wherein the referenced executable code executes in user mode.

4. The method according to claim 1 , wherein the shellcode comprises an application programming interface (API) hashing algorithm.

5. The method according to claim 1 , wherein the list of malicious shellcode comprises a list of signatures, and wherein comparing the referenced executable code to the list of malicious shellcode comprises extracting one or more shellcode buffers from the referenced executable code, and comparing the one or more extracted shellcode buffers to the list of signatures.

6. The method according to claim 5 , wherein a signature in the list comprises a wildcard.

7. The method according to claim 1 , wherein the specified function loads an executable library to the memory.

8. The method according to claim 1 , wherein the specified function creates a new thread in the memory.

9. The method according to claim 1 , wherein the specified function creates a new process in the memory.

10. The method according to claim 1 , wherein the specified function initiates a new connection.

11. The method according to claim 1 , wherein the specified function listens for an incoming connection.

12. The method according to claim 1 , wherein the specified function communicates with kernel drivers so as to provide a view of input data and output data.

13. The method according to claim 1 , wherein the memory comprises a set of memory pages, and wherein the specified function allocates one or more of the memory pages to a process in the memory.

14. The method according to claim 1 , wherein the memory comprises a set of memory addresses, and wherein the specified function changes a memory permission of a given memory address.

15. The method according to claim 1 , wherein the specified function retrieves a buffer from an address in the memory.

16. The method according to claim 1 , wherein the specified function writes a buffer to an address in the memory.

17. The method according to claim 1 , wherein the specified function sets a thread context of a thread in the memory.

18. The method according to claim 1 , wherein the specified function adds an asynchronous procedure call (APC) to an APC queue in a thread in the memory.

19. The method according to claim 1 , wherein the specified function injects additional executable code into a process in the memory.

20. An apparatus for protecting a computing device, comprising:

a memory; and

a processor coupled to a storage device storing a set of one or more files and configured:

to detect a call to a specified function for execution by the processor,

to generate, in the memory a stack trace for the call to the specified function,

to detect, in the stack trace, a stack frame comprising a return address referencing a page in the memory containing executable code. the stack frame including a flag indicating whether the executable code was loaded from a file on the storage device,

to compare the referenced executable code to a list of malicious shellcode, in response to the flag indicating that the executable code was not loaded from any file on the storage device, and

to initiate a preventive action upon detecting a match between the referenced executable code and one of malicious shellcodes in the list.

21. A computer software product for protecting a computing device, which includes a processor and a memory and is coupled to a storage device storing a set of one or more files, the computer software product comprising a non-transitory computer-readable medium, in which program instructions are stored, which instructions, when read by a computer, cause the computer:

to detect a call to a specified function for execution by the processor;

to generate, in the memory, a stack trace for the call to the specified function;

to detect, in the stack trace, a stack frame comprising a return address referencing a page in the memory containing executable code, the stack frame including a flag indicating whether the executable code was loaded from a file on the storage device;

to compare the referenced executable code to a list of malicious shellcode, in response to the flag indicating that the executable code was not loaded from any file on the storage device; and

to initiate a preventive action upon detecting a match between the referenced executable code and one of malicious shellcodes in the list.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2024
From: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
To: PALO ALTO NETWORKS INC.
Reel/Frame 068823/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2023
From: CHECHIK, OR; ZIGELBAUM, LIAV; AHARONI, ELDAR; LAHAV, BAR
To: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
Reel/Frame 063341/0807 →
Continuity (1)
Related Publication 20240346145A1 · Oct 17, 2024
References Cited (56)
US 8205257B1 · Satish et al. · 2012 [cited by applicant]
US 8646076B1 · Lim · 2014 [cited by examiner]
US 8990944B1 · Singh et al. · 2015 [cited by applicant]
US 9659182B1 · Roundy · 2017 [cited by examiner]
US 10193918B1 · Patton et al. · 2019 [cited by applicant]
US 10503904B1 · Singh et al. · 2019 [cited by applicant]
US 10860718B2 · Seetharamaiah · 2020 [cited by examiner]
US 11216559B1 · Gu · 2022 [cited by examiner]
US 11409868B2 · Reid · 2022 [cited by examiner]
US 11520886B2 · Levy et al. · 2022 [cited by applicant]
US 11886585B1 · Davis · 2024 [cited by examiner]
US 11934801B2 · Rahmani · 2024 [cited by examiner]
US 20040049693A1 · Douglas · 2004 [cited by examiner]
US 20140115652A1 · Kapoor et al. · 2014 [cited by applicant]
US 20150215335A1 · Giuliani et al. · 2015 [cited by applicant]
US 20160055337A1 · El-Moussa · 2016 [cited by examiner]
US 20160232347A1 · Badishi · 2016 [cited by examiner]
US 20170180421A1 · Shieh et al. · 2017 [cited by applicant]
US 20180115577A1 · Shukla et al. · 2018 [cited by applicant]
US 20180189490A1 · Maciejak et al. · 2018 [cited by applicant]
US 20180191779A1 · Shieh et al. · 2018 [cited by applicant]
US 20180211038A1 · Breiman et al. · 2018 [cited by applicant]
US 20180248896A1 · Challita et al. · 2018 [cited by applicant]
US 20190087572A1 · Ellam et al. · 2019 [cited by applicant]
US 20190109870A1 · Bedhapudi et al. · 2019 [cited by applicant]
US 20190121978A1 · Kraemer et al. · 2019 [cited by applicant]
US 20190318090A1 · Sandoval et al. · 2019 [cited by applicant]
US 20190325133A1 · Goodridge et al. · 2019 [cited by applicant]
US 20190347418A1 · Strogov et al. · 2019 [cited by applicant]
US 20200089876A1 · Aharoni et al. · 2020 [cited by applicant]
US 20200106808A1 · Schutz et al. · 2020 [cited by applicant]
US 20200183820A1 · Hebert et al. · 2020 [cited by applicant]
US 20200204589A1 · Strogov et al. · 2020 [cited by applicant]
US 20200342100A1 · Goldstein · 2020 [cited by examiner]
US 20210152595A1 · Hansen et al. · 2021 [cited by applicant]
US 20220284095A1 · Ahmed · 2022 [cited by examiner]
US 20230084691A1 · Levy et al. · 2023 [cited by applicant]
WO 2022109664A1 · 2022 [cited by applicant]
WO 2022248920A1 · 2022 [cited by applicant]
WO 2023133582A1 · 2023 [cited by applicant]
International Application # PCT/IB2024/051414 Search Report dated Apr. 17, 2024. [cited by applicant]
U.S. Appl. No. 17/979,004 Office Action dated Jan. 19, 2024. [cited by applicant]
Palo Alto Networks, “Cortex XDR,” Datasheet, pp. 1-9, year 2023. [cited by applicant]
Blackberry, “Threat Spotlight: Petya-Like Ransomware is Nasty Wiper”, pp. 1-22, Nov. 7, 2017, as downloaded from https://blogs.blackberry.com/en/2017/07/threat-spotlight-petya-like-ransomware-is-nasty-wiper. [cited by applicant]
AU Application # 2021319159 Office Action dated May 25, 2023. [cited by applicant]
Cristalli et al., “Trusted Execution Path for Protecting Java Applications Against Deserialization of Untrusted Data,” Proceedings, International Conference, ICB 2007—Advances in Biometrics, Springer Nature Switzerland … [cited by applicant]
Wikipedia, “Java Remote Method Invocation,” pp. 1-4, last edited Dec. 26, 2020. [cited by applicant]
Wikipedia, “Metasploit Project,” pp. 1-7, last edited Jun. 7, 2022. [cited by applicant]
CYNET, “Cobalt Strike: White Hat Hacker Powerhouse in the Wrong Hands,” pp. 1-6, last updated Jun. 27, 2022, as downloaded from https://web.archive.org/web/20220627023847/https://www.cynet.com/network-attacks/cobalt-str… [cited by applicant]
Shah, “Analyzing CVE-2017-9791: Apache StrutsVulnerability Can Lead to Remote Code Execution,”, McAfee, pp. 1-7, Jul. 19, 2017, as downloaded from https://www.mcafee.com/blogs/other-blogs/mcafee-labs/analyzing-cve-2017-… [cited by applicant]
Frohoff, “A Proof-of-Concept Tool for Generating Payloads that Exploit unsafe Java Object Deserialization,” github.com, pp. 1-3, Jul. 16, 2022, as downloaded from https://github.com/frohoff/ysoserial. [cited by applicant]
Wikipedia, “Return-oriented Programming,” pp. 1-6, last edited Mar. 31, 2020, as downloaded from https://web.archive.org/web/20200403142512/https://en.wikipedia.org/wiki/Return-oriented_programming. [cited by applicant]
McNab, “Network Security Assessment”, 2nd edition, Chapter 16 (Exploitation Frameworks), pp. 393-414, Oct. 2007. [cited by applicant]
Balakrishnan, “Understanding Java Agents,” Tutorial, pp. 1-8, Jul. 6, 2020, as downloaded from https://dzone.com/articles/java-agent-1. [cited by applicant]
Wikipedia, “Java Virtual Machine,” pp. 1-8, last update Oct. 25, 2022. [cited by applicant]
International Application # PCT/US2025/016969 Search Report dated Apr. 22, 2025. [cited by applicant]