IP Library Granted Patent US 12,602,467
Granted Patent B2
US 12,602,467 · App. 18/479,295 · Granted Apr 14, 2026

In-memory scan for threat detection with binary instrumentation backed generic unpacking, decryption, and deobfuscation

Inventors: Sandeep Paul (Bengaluru, IN); Sarthak Misraa (New Delhi, IN); Deepen Desai (San Ramon, CA)
Assignee: Zscaler, Inc.
G06F21/53G06F21/566G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,602,467
App. No.
18/479,295
Granted
Apr 14, 2026
Kind
B2
Abstract

Systems and methods for in-memory malware unpacking and deobfuscation in a sandbox include, responsive to receiving unknown content, scanning an image of the unknown content for packed, obfuscated, or encrypted code; responsive to detecting the packed, obfuscated, or encrypted code performing steps of unpacking, deobfuscating, or decrypting the packed, obfuscated, or encrypted code; executing the unpacked, deobfuscated, or decrypted code; monitoring execution of the unpacked, deobfuscated, or decrypted code; obtaining events during the scanning and the execution; and providing the obtained events to the sandbox for use in a sandbox analysis for classifying the content as one of malware and clean.

Claims (40)

1 . A non-transitory computer-readable medium having instructions stored thereon for programming one or more processors, associated with a sandbox, to perform steps of:

responsive to receiving unknown content, scanning an image of the unknown content for packed, obfuscated, or encrypted code;

responsive to detecting the packed, obfuscated, or encrypted code performing steps of:

unpacking, deobfuscating, or decrypting the packed, obfuscated, or encrypted code in memory using an in-memory unpacking and deobfuscation scanner configured to defeat anti-sandbox evasion techniques;

executing the unpacked, deobfuscated, or decrypted code;

monitoring execution of the unpacked, deobfuscated, or decrypted code including monitoring memory allocations, permission changes, spawned child process, process injections, and associated system calls;

obtaining events comprising behavioral evens, system calls, and memory events, the events including artifacts collected prior to cleanup of allocated memory regions; and

providing the obtained events to the sandbox for use in a sandbox analysis, wherein the sandbox analysis includes adjusting a malware classification score based on the obtained events to classify the unknown content as one of malware and clean.

2 . The non-transitory computer-readable medium of claim 1 , wherein the steps further include:

responsive to not detecting the packed, obfuscated, or encrypted code, performing the sandbox analysis.

3 . The non-transitory computer-readable medium of claim 1 , wherein the unpacked, deobfuscated, or decrypted code is configured to execute on a time delay to avoid the classifying by the sandbox.

4 . The non-transitory computer-readable medium of claim 1 , wherein the monitoring includes detecting any spawned child processes and capturing the associated command-line arguments.

5 . The non-transitory computer-readable medium of claim 1 , wherein the monitoring includes detecting any process injection and generating a memory dump of injected payloads.

6 . The non-transitory computer-readable medium of claim 1 , wherein the monitoring includes detecting any system calls and Application Programming Interface (API) calls.

7 . The non-transitory computer-readable medium of claim 1 , wherein the events include a plurality of behavior based events, system calls, and memory events.

8 . The non-transitory computer-readable medium of claim 1 , wherein the events include (TTP) events and behavior events.

9 . The non-transitory computer-readable medium of claim 1 , wherein the steps further include:

running one or more rules on the events; and

providing results of the one or more rules to the sandbox.

10 . The non-transitory computer-readable medium of claim 1 , wherein the adjusting the malware classification score is based on artifacts collected by the in-memory unpacking and deobfuscation scanner, the artifacts comprising freed memory regions, command in-line arguments of spawned child processes, and memory dumps of injected payloads.

11 . A method comprising steps of:

responsive to receiving unknown content, scanning an image of the unknown content for packed, obfuscated, or encrypted code;

responsive to detecting the packed, obfuscated, or encrypted code performing steps of:

unpacking, deobfuscating, or decrypting the packed, obfuscated, or encrypted code in memory using an in-memory unpacking and deobfuscation scanner configured to defeat anti-sandbox evasion techniques;

executing the unpacked, deobfuscated, or decrypted code;

monitoring execution of the unpacked, deobfuscated, or decrypted code including monitoring memory allocations, permission changes, spawned child process, process injections, and associated system calls;

obtaining events comprising behavioral evens, system calls, and memory events, the events including artifacts collected prior to cleanup of allocated memory regions; and

providing the obtained events to the sandbox for use in a sandbox analysis, wherein the sandbox analysis includes adjusting a malware classification score based on the obtained events to classify the unknown content as one of malware and clean.

12 . The method of claim 11 , wherein the steps further include:

responsive to not detecting the packed, obfuscated, or encrypted code, performing the sandbox analysis.

13 . The method of claim 11 , wherein the unpacked, deobfuscated, or decrypted code is configured to execute on a time delay to avoid the classifying by the sandbox.

14 . The method of claim 11 , wherein the monitoring includes detecting any spawned child processes and capturing the associated command-line argument.

15 . The method of claim 11 , wherein the monitoring includes detecting any process injection and generating a memory dump of injected payloads.

16 . The method of claim 11 , wherein the monitoring includes detecting any system calls and Application Programming Interface (API) calls.

17 . The method of claim 11 , wherein the events include a plurality of behavior based events, system calls, and memory events.

18 . The method of claim 11 , wherein the events include (TTP) events and behavior events.

19 . The method of claim 11 , wherein the steps further include:

running one or more rules on the events; and

providing results of the one or more rules to the sandbox.

20 . The method of claim 11 , wherein the adjusting the malware classification score is based on artifacts collected by the in-memory unpacking and deobfuscation scanner, the artifacts comprising freed memory regions, command-line arguments of spawned child processes and memory dumps of injected payloads.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2023
From: PAUL, SANDEEP; MISRAA, SARTHAK; DESAI, DEEPEN
To: ZSCALER, INC.
Reel/Frame 065092/0583 →
Priority Claims (1)
IN 202311055524 · Aug 18, 2023 · national
Continuity (3)
Continuation In Part 18302394 · Apr 18, 2023
Continuation In Part 16776868 · Jan 30, 2020
Related Publication 20240028707A1 · Jan 25, 2024
References Cited (77)
US 7062680B2 · Sirbu · 2006 [cited by applicant]
US 7181769B1 · Keanini et al. · 2007 [cited by applicant]
US 7392543B2 · Szor · 2008 [cited by applicant]
US 7894350B2 · Kailash et al. · 2011 [cited by applicant]
US 7899849B2 · Chaudry et al. · 2011 [cited by applicant]
US 8171554B2 · Elovici et al. · 2012 [cited by applicant]
US 8181245B2 · Tripathi et al. · 2012 [cited by applicant]
US 8185510B2 · Chaudry et al. · 2012 [cited by applicant]
US 8347386B2 · Mahaffey et al. · 2013 [cited by applicant]
US 8365259B2 · Chaudry et al. · 2013 [cited by applicant]
US 8402539B1 · Chen et al. · 2013 [cited by applicant]
US 8413238B1 · Sutton · 2013 [cited by applicant]
US 8413239B2 · Sutton et al. · 2013 [cited by applicant]
US 8453234B2 · Dawson et al. · 2013 [cited by applicant]
US 8464335B1 · Sinha et al. · 2013 [cited by applicant]
US 8478708B1 · Larcom · 2013 [cited by applicant]
US 8484726B1 · Sutton · 2013 [cited by applicant]
US 8510838B1 · Sun et al. · 2013 [cited by applicant]
US 8549581B1 · Kailash et al. · 2013 [cited by applicant]
US 8607066B1 · Kailash et al. · 2013 [cited by applicant]
US 8863288B1 · Savage et al. · 2014 [cited by applicant]
US 9152789B2 · Natarajan et al. · 2015 [cited by applicant]
US 9223972B1 · Vincent et al. · 2015 [cited by applicant]
US 9609015B2 · Natarajan et al. · 2017 [cited by applicant]
US 9917855B1 · Li et al. · 2018 [cited by applicant]
US 10515214B1 · Vincent · 2019 [cited by examiner]
US 10565376B1 · Jung · 2020 [cited by examiner]
US 10628586B1 · Jung · 2020 [cited by examiner]
US 10671726B1 · Paithane et al. · 2020 [cited by applicant]
US 10893059B1 · Aziz et al. · 2021 [cited by applicant]
US 11184379B1 · Kjar · 2021 [cited by examiner]
US 11562071B2 · Jung · 2023 [cited by examiner]
US 12223044B1 · Jung · 2025 [cited by examiner]
US 20050188272A1 · Bodorin et al. · 2005 [cited by applicant]
US 20060075500A1 · Bertman et al. · 2006 [cited by applicant]
US 20070266421A1 · Vaidya et al. · 2007 [cited by applicant]
US 20080098478A1 · Vaidya et al. · 2008 [cited by applicant]
US 20100031353A1 · Thomas et al. · 2010 [cited by applicant]
US 20100095277A1 · Cheng et al. · 2010 [cited by applicant]
US 20120079596A1 · Thomas · 2012 [cited by examiner]
US 20120304244A1 · Xie et al. · 2012 [cited by applicant]
US 20130091571A1 · Lu et al. · 2013 [cited by applicant]
US 20130239214A1 · Klein et al. · 2013 [cited by applicant]
US 20130291087A1 · Kailash et al. · 2013 [cited by applicant]
US 20130305357A1 · Ayyagari et al. · 2013 [cited by applicant]
US 20130333032A1 · Delatorre et al. · 2013 [cited by applicant]
US 20130347094A1 · Bettini et al. · 2013 [cited by applicant]
US 20140090059A1 · Wang et al. · 2014 [cited by applicant]
US 20140208426A1 · Natarajan et al. · 2014 [cited by applicant]
US 20150096022A1 · Vincent et al. · 2015 [cited by applicant]
US 20150319182A1 · Natarajan et al. · 2015 [cited by applicant]
US 20170083703A1 · Abbasi et al. · 2017 [cited by applicant]
US 20180046799A1 · Kohavi et al. · 2018 [cited by applicant]
US 20180285567A1 · Raman · 2018 [cited by examiner]
US 20190005226A1 · Boutnaru · 2019 [cited by examiner]
US 20190114421A1 · Das · 2019 [cited by examiner]
US 20190250937A1 · Thomas · 2019 [cited by examiner]
US 20190347413A1 · Dubrovsky · 2019 [cited by examiner]
US 20200012793A1 · Avraham · 2020 [cited by examiner]
US 20200175152A1 · Xu et al. · 2020 [cited by applicant]
US 20200311268A1 · Kostyushko et al. · 2020 [cited by applicant]
US 20200329071A1 · Dani · 2020 [cited by examiner]
US 20200342100A1 · Goldstein · 2020 [cited by examiner]
US 20200394299A1 · Urias et al. · 2020 [cited by applicant]
US 20210117544A1 · Kurtz · 2021 [cited by examiner]
US 20210192043A1 · Bhary et al. · 2021 [cited by applicant]
US 20210200870A1 · Yavo · 2021 [cited by examiner]
US 20220261481A1 · Fitzgerald · 2022 [cited by examiner]
US 20220414209A1 · Strogov · 2022 [cited by examiner]
US 20230325501A1 · Chhetri · 2023 [cited by examiner]
US 20230367877A1 · Chaudhari · 2023 [cited by examiner]
US 20230418943A1 · Han · 2023 [cited by examiner]
US 20250030704A1 · Kim · 2025 [cited by examiner]
Elovici et al., “Applying Machine Learning Techniques for Detection of Malicious Code in Network Traffic,” KI 2007, LNAI 4667, pp. 44-50. [cited by applicant]
Overton, Anti-Malware Tools: Intrusion Detection Systems, IBM, Apr. 30, 2005-May 3, 2005, pp. 1-22. [cited by applicant]
Van Randwyk et al., “Farm: An Automated Malware Analysis Environment”, Security Technology, 2008, ICCST 2008, 42nd Annual IEEE International Carnahan Conference on IEEE, 2008, pp. 1-5. [cited by applicant]
Xie et al., “iPanda: A Comprehensive Malware Analysis Tool”, Information Networking (ICOIN), 2013 International Conference on IEEE, 2013, pp. 1-6. [cited by applicant]