IP Library Granted Patent US 12,505,201
Granted Patent B2
US 12,505,201 · App. 18/302,394 · Granted Dec 23, 2025

Exploit detection in a cloud-based sandbox

Inventors: Nirmal Singh Bhary (Chandigarh, IN); Tarun Dewan (Punjab, IN); Rajdeepsinh Dodia (Chandigarh, IN); Chiragkumar Kantibhai Prajapati (Bengaluru, IN)
Assignee: Zscaler, Inc.
G06F21/53G06F21/552G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,201
App. No.
18/302,394
Granted
Dec 23, 2025
Kind
B2
Abstract

Computer-implemented systems and methods include receiving unknown content in a cloud-based sandbox; performing an analysis of the unknown content in the cloud-based sandbox; obtaining events based on the analysis; running one or more exploit detection rules on the events; and providing a score based on a result of the one or more rules. The systems and methods can include classifying the unknown content as malware or clean based on the score. The analysis can include a static analysis and a dynamic analysis, with the events generated based thereon.

Claims (39)

1 . A non-transitory computer-readable medium having instructions stored thereon for programming a processor to perform steps of:

receiving unknown content comprising one of executable files, dynamic link libraries (DLLs), scripts, or macros in documents executable by one or more processors in a cloud-based sandbox having hardware infrastructure configured to isolate execution of the unknown content;

performing an analysis of the unknown content in the cloud-based sandbox;

obtaining events based on the analysis;

running one or more exploit detection rules on the events, wherein the exploit detection rules comprise dynamically generated signatures created during execution of the unknown content based on observed runtime behaviors including at least one of memory injection, remote process injection, or process hollowing indicative of exploits; and

providing a score based on a result of the one or more rules.

2 . The non-transitory computer-readable medium of claim 1 , wherein the steps further include classifying the unknown content as malware or clean based on the score.

3 . The non-transitory computer-readable medium of claim 1 , wherein the events include data containing lists of all queried windows and paths of all opened files.

4 . The non-transitory computer-readable medium of claim 3 , wherein the events include an Application Programing Interface (API) count threshold flag to specify a maximum number of API calls to be listed.

5 . The non-transitory computer-readable medium of claim 1 , wherein the steps include specifying an event name or Application Programing Interface (API) name along with one or more event fields to obtain specified data.

6 . The non-transitory computer-readable medium of claim 1 , wherein the exploit detection rules include checking for a file type, and if any processes have called an Application Programing Interface (API) with a parameter containing a specified string.

7 . The non-transitory computer-readable medium of claim 1 , wherein the events include data which provides information about files opened by a target process.

8 . An apparatus comprising:

a network interface;

a data store;

a processor communicatively coupled to the network interface and the data store; and

memory storing instructions that, when executed, cause the processor to:

receive unknown content comprising one of executable files, dynamic link libraries (DLLs), scripts, or macros in documents executable by one or more processors in a cloud-based sandbox having hardware infrastructure configured to isolate execution of the unknown content;

perform an analysis of the unknown content in the cloud-based sandbox;

obtain events based on the analysis;

run one or more exploit detection rules on the events, wherein the exploit detection rules comprise dynamically generated signatures created during execution of the unknown content based on observed runtime behaviors including at least one of memory injection, remote process injection, or process hollowing indicative of exploits; and

provide a score based on a result of the one or more rules.

9 . The apparatus of claim 8 , wherein the steps further include classifying the unknown content as malware or clean based on the score.

10 . The apparatus of claim 8 , wherein the events include data containing lists of all queried windows and paths of all opened files.

11 . The apparatus of claim 10 , wherein the events include an Application Programing Interface (API) count threshold flag to specify a maximum number of API calls to be listed.

12 . The apparatus of claim 8 , wherein the steps include specifying an event name or Application Programing Interface (API) name along with one or more event fields to obtain specified data.

13 . The apparatus of claim 8 , wherein the exploit detection rules include checking for a file type, and if any processes have called an Application Programing Interface (API) with a parameter containing a specified string.

14 . The apparatus of claim 8 , wherein the events include data which provides information about files opened by a target process.

15 . A computer-implemented method comprising:

receiving unknown content comprising one of executable files, dynamic link libraries (DLLs), scripts, or macros in documents executable by one or more processors in a cloud-based sandbox having hardware infrastructure configured to isolate execution of the unknown content;

performing an analysis of the unknown content in the cloud-based sandbox;

obtaining events based on the analysis;

running one or more exploit detection rules on the events, wherein the exploit detection rules comprise dynamically generated signatures created during execution of the unknown content based on observed runtime behaviors including at least one of memory injection; remote process injection, or process hollowing indicative of exploits; and

providing a score based on a result of the one or more rules.

16 . The computer-implemented method of claim 15 , wherein the steps further include classifying the unknown content as malware or clean based on the score.

17 . The computer-implemented method of claim 15 , wherein the events include data containing lists of all queried windows and paths of all opened files.

18 . The computer-implemented method of claim 17 , wherein the events include an Application Programing Interface (API) count threshold flag to specify a maximum number of API calls to be listed.

19 . The computer-implemented method of claim 15 , wherein the exploit detection rules include checking for a file type, and if any processes have called an Application Programing Interface (API) with a parameter containing a specified string.

20 . The computer-implemented method of claim 15 , wherein the events include data which provides information about files opened by a target process.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2023
From: BHARY, NIRMAL SINGH; DEWAN, TARUN; DODIA, RAJDEEPSINH; PRAJAPATI, CHIRAGKUMAR KANTIBHAI
To: ZSCALER, INC.
Reel/Frame 063360/0284 →
Priority Claims (1)
IN 202311014402 · Mar 3, 2023 · national
Continuity (2)
Continuation In Part 16776868 · Jan 30, 2020
Related Publication 20230259612A1 · Aug 17, 2023
References Cited (16)
US 8756693B2 · Dube · 2014 [cited by examiner]
US 9152789B2 · Natarajan et al. · 2015 [cited by applicant]
US 9609015B2 · Natarajan et al. · 2017 [cited by applicant]
US 9916443B1 · Qu · 2018 [cited by examiner]
US 9917855B1 · Li · 2018 [cited by examiner]
US 10628586B1 · Jung · 2020 [cited by examiner]
US 10671726B1 · Paithane · 2020 [cited by examiner]
US 20140208426A1 · Natarajan · 2014 [cited by examiner]
US 20150319182A1 · Natarajan · 2015 [cited by examiner]
US 20160014084A1 · Hansen · 2016 [cited by examiner]
US 20170083703A1 · Abbasi · 2017 [cited by examiner]
US 20200175152A1 · Xu · 2020 [cited by examiner]
US 20200311268A1 · Kostyushko · 2020 [cited by examiner]
US 20200394299A1 · Urias · 2020 [cited by examiner]
US 20210099483A1 · Shukla · 2021 [cited by examiner]
US 20210192043A1 · Bhary et al. · 2021 [cited by applicant]