IP Library Granted Patent US 12,455,957
Granted Patent B2
US 12,455,957 · App. 18/672,750 · Granted Oct 28, 2025

Methods and apparatus for control and detection of malicious content using a sandbox environment

Inventors: Anup Ghosh (Centreville, VA); Scott Cosby (Alexandria, VA); Alan Keister (Oakton, VA); Benjamin Bryant (Alexandria, VA); Stephen Taylor (Washington, DC)
Assignee: Invincea, Inc.
G06F21/53G06F21/56G06F21/566G06F2221/034G06F2221/2101G06F2221/2141G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,455,957
App. No.
18/672,750
Granted
Oct 28, 2025
Kind
B2
Abstract

A non-transitory processor-readable medium storing code representing instructions to cause a processor to perform a process includes code to cause the processor to receive a set of indications of allowed behavior associated with an application. The processor is also caused to initiate an instance of the application within a sandbox environment. The processor is further caused to receive, from a monitor module associated with the sandbox environment, a set of indications of actual behavior of the instance of the application in response to initiating the instance of the application within the sandbox environment. The processor is also caused to send an indication associated with an anomalous behavior if at least one indication from the set of indications of actual behavior does not correspond to an indication from the set of indications of allowed behavior.

Claims (39)

1 . A non-transitory processor-readable medium storing code representing instructions to be executed by one or more processors, the instructions comprising code to cause the one or more processors to:

receive a file;

open, in a sandbox environment, the file using a process associated with the file;

receive a set of indications of actual behavior associated with the file;

classify an actual behavior associated with an indication of actual behavior from the set of indications of actual behavior as an anomalous behavior for the file based on the indication of actual behavior not being in a set of indications of allowed behavior for the file, the set of indications of allowed behavior for the file being based on a trust level associated with the file; and

send an indication associated with the anomalous behavior in response to identifying the anomalous behavior.

2 . The non-transitory processor-readable medium of claim 1 , wherein the file is a portable document format (PDF) file and the process is a PDF reader.

3 . The non-transitory processor-readable medium of claim 1 , wherein the indication of actual behavior is based on the process associated with the file attempting to at least one of modify a sensitive file path, modify an executable file, initiate a network connection, associate with an application, or modify a registry key.

4 . The non-transitory processor-readable medium of claim 1 , wherein the code to cause the one or more processors to receive the file includes code to cause the one or more processors to receive the file at a user device,

the code to cause the one or more processors to classify includes code to cause the one or more processors to classify the actual behavior as an anomalous behavior at an execution server different from the user device.

5 . The non-transitory processor-readable medium of claim 1 , wherein the code to cause the one or more processors to receive the file includes code to cause the one or more processors to receive the file at a user device,

the code to cause the one or more processors to classify includes code to cause the one or more processors to classify the actual behavior as an anomalous behavior at the user device.

6 . The non-transitory processor-readable medium of claim 1 , further comprising code to cause the one or more processors to:

perform a remedial action on at least one of the sandbox environment, the file or the process.

7 . A method, comprising:

receiving, via a network, an indication that a user device has received a potentially malicious process;

initiating, by sending a signal to an execution server via the network, a sandbox environment at the execution server,

sending a signal to the execution server to execute the potentially malicious process in the sandbox environment;

receiving, via the network, a set of indications of actual behavior of the potentially malicious process from the sandbox environment;

classifying an actual behavior associated with an indication of actual behavior from the set of indications of actual behavior as an anomalous behavior for the potentially malicious process based on the indication of actual behavior not being in a set of indications of allowed behavior for the potentially malicious process, the set of indications of allowed behavior for the potentially malicious process being based on a trust level associated with the potentially malicious process; and

sending an indication associated with the anomalous behavior in response to identifying the anomalous behavior.

8 . The method of claim 7 , wherein the set of indications of actual behavior is generated based on the user device interacting with the potentially malicious process via the network.

9 . The method of claim 7 , wherein the user device is from a plurality of user devices and the sandbox environment is from a plurality of sandbox environments at the execution server, each sandbox environment from the plurality of sandbox environments being associated with a user device from the plurality of user devices.

10 . The method of claim 7 , wherein the actual behavior includes the potentially malicious process attempting to at least one of modify a sensitive file path, modify an executable file, initiate a network connection, associate with an application, or modify a registry key.

11 . The method of claim 7 , further comprising:

performing a remedial action based on the indication associated with the anomalous behavior, the remedial action including at least one of terminating the potentially malicious process, restarting the potentially malicious process, terminating the sandbox environment, or restarting the sandbox environment.

12 . A non-transitory processor-readable medium storing code representing instructions to be executed by one or more processors, the instructions comprising code to cause the one or more processors to:

receive, via a network, an indication that a user device has received a file;

initiate, by sending a signal to an execution server via the network, a sandbox environment at the execution server,

send a signal to the execution server to open the file in the sandbox environment using a process associated with the file;

receive, from the sandbox environment via the network, a set of indications of actual behavior associated with the file;

classify an actual behavior associated with an indication of actual behavior from the set of indications of actual behavior as an anomalous behavior for the file based on the indication of actual behavior not being in a set of indications of allowed behavior for the file, the set of indications of allowed behavior for the file being based on a trust level associated with the file; and

send an indication associated with the anomalous behavior in response to identifying the anomalous behavior.

13 . The non-transitory processor-readable medium of claim 12 , wherein the file is a portable document format (PDF) file and the process is a PDF reader.

14 . The non-transitory processor-readable medium of claim 12 , wherein the set of indications of actual behavior is generated based on the user device interacting with the file via the network.

15 . The non-transitory processor-readable medium of claim 12 , wherein the user device is from a plurality of user devices and the sandbox environment is from a plurality of sandbox environments at the execution server, each sandbox environment from the plurality of sandbox environments being associated with a user device from the plurality of user devices.

16 . The non-transitory processor-readable medium of claim 12 , wherein the actual behavior includes the process associated with the file attempting to at least one of modify a sensitive file path, modify an executable file, initiate a network connection, associate with an application, or modify a registry key.

17 . The non-transitory processor-readable medium of claim 12 , further comprising code to cause the one or more processors to:

perform a remedial action based on the indication associated with the anomalous behavior, the remedial action including at least one of terminating the process associated with the file, restarting the process associated with the file, terminating the sandbox environment, or restarting the sandbox environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2024
From: GHOSH, ANUP K.; COSBY, SCOTT; KEISTER, ALAN; BRYANT, BENJAMIN; TAYLOR, STEPHEN
To: INVINCEA, INC.
Reel/Frame 067518/0478 →
Continuity (8)
Continuation 17211412 · Mar 24, 2021
Continuation 16671664 · Nov 1, 2019
Continuation 16018720 · Jun 26, 2018
Continuation 15359004 · Nov 22, 2016
Continuation 14797847 · Jul 13, 2015
Continuation 13690452 · Nov 30, 2012
Provisional Application 61566162 · Dec 2, 2011
Related Publication 20240320323A1 · Sep 26, 2024
References Cited (323)
US 5297269A · Donaldson et al. · 1994 [cited by applicant]
US 5394555A · Hunter et al. · 1995 [cited by applicant]
US 5696822A · Nachenberg · 1997 [cited by applicant]
US 5842002A · Schnurer et al. · 1998 [cited by applicant]
US 5854916A · Nachenberg · 1998 [cited by applicant]
US 5895467A · Ubell et al. · 1999 [cited by applicant]
US 5974549A · Golan · 1999 [cited by applicant]
US 6067410A · Nachenberg · 2000 [cited by applicant]
US 6157721A · Shear et al. · 2000 [cited by applicant]
US 6211871B1 · Himmel et al. · 2001 [cited by applicant]
US 6377959B1 · Carlson · 2002 [cited by applicant]
US 6397242B1 · Devine et al. · 2002 [cited by applicant]
US 6496847B1 · Bugnion et al. · 2002 [cited by applicant]
US 6584495B1 · Bisset et al. · 2003 [cited by applicant]
US 6718482B2 · Sato et al. · 2004 [cited by applicant]
US 6832120B1 · Frank et al. · 2004 [cited by applicant]
US 6845464B2 · Gold · 2005 [cited by applicant]
US 6859889B2 · Matsuura et al. · 2005 [cited by applicant]
US 6880110B2 · Largman et al. · 2005 [cited by applicant]
US 6883098B1 · Roman et al. · 2005 [cited by applicant]
US 6944785B2 · Gadir et al. · 2005 [cited by applicant]
US 7058822B2 · Edery et al. · 2006 [cited by applicant]
US 7086090B1 · Dawson, Jr. et al. · 2006 [cited by applicant]
US 7096381B2 · Largman et al. · 2006 [cited by applicant]
US 7100075B2 · Largman et al. · 2006 [cited by applicant]
US 7111201B2 · Largman et al. · 2006 [cited by applicant]
US 7137034B2 · Largman et al. · 2006 [cited by applicant]
US 7363264B1 · Doughty et al. · 2008 [cited by applicant]
US 7392541B2 · Largman et al. · 2008 [cited by applicant]
US 7536598B2 · Largman et al. · 2009 [cited by applicant]
US 7552479B1 · Conover et al. · 2009 [cited by applicant]
US 7571353B2 · Largman et al. · 2009 [cited by applicant]
US 7577871B2 · Largman et al. · 2009 [cited by applicant]
US 7584503B1 · Palmer et al. · 2009 [cited by applicant]
US 7633864B2 · Johnson et al. · 2009 [cited by applicant]
US 7693991B2 · Greenlee et al. · 2010 [cited by applicant]
US 7698744B2 · Fanton et al. · 2010 [cited by applicant]
US 7788699B2 · Largman et al. · 2010 [cited by applicant]
US 7836303B2 · Levy et al. · 2010 [cited by applicant]
US 7840801B2 · Berger et al. · 2010 [cited by applicant]
US 7849360B2 · Largman et al. · 2010 [cited by applicant]
US 7873635B2 · Wang et al. · 2011 [cited by applicant]
US 7899867B1 · Sherstinsky et al. · 2011 [cited by applicant]
US 7904797B2 · Wong et al. · 2011 [cited by applicant]
US 7941813B1 · Protassov et al. · 2011 [cited by applicant]
US 7979889B2 · Gladstone et al. · 2011 [cited by applicant]
US 8001606B1 · Spertus · 2011 [cited by applicant]
US 8078740B2 · Franco et al. · 2011 [cited by applicant]
US 8196205B2 · Gribble et al. · 2012 [cited by applicant]
US 8234640B1 · Fitzgerald et al. · 2012 [cited by applicant]
US 8290763B1 · Zhang · 2012 [cited by applicant]
US 8356352B1 · Wawda et al. · 2013 [cited by applicant]
US 8370931B1 · Chien et al. · 2013 [cited by applicant]
US 8401982B1 · Satish et al. · 2013 [cited by applicant]
US 8447880B2 · Johnson et al. · 2013 [cited by applicant]
US 8468600B1 · Kaskel et al. · 2013 [cited by applicant]
US 8479286B2 · Dalcher et al. · 2013 [cited by applicant]
US 8572735B2 · Ghosh et al. · 2013 [cited by applicant]
US 8578345B1 · Kennedy et al. · 2013 [cited by applicant]
US 8621458B2 · Traut et al. · 2013 [cited by applicant]
US 8694797B2 · Challener et al. · 2014 [cited by applicant]
US 8719924B1 · Williamson et al. · 2014 [cited by applicant]
US 8775369B2 · Largman et al. · 2014 [cited by applicant]
US 8776038B2 · Larimore et al. · 2014 [cited by applicant]
US 8793787B2 · Ismael et al. · 2014 [cited by applicant]
US 8839422B2 · Ghosh et al. · 2014 [cited by applicant]
US 8856782B2 · Ghosh et al. · 2014 [cited by applicant]
US 8856937B1 · Wuest et al. · 2014 [cited by applicant]
US 8881282B1 · Aziz et al. · 2014 [cited by applicant]
US 8881284B1 · Gabriel · 2014 [cited by applicant]
US 9081959B2 · Ghosh et al. · 2015 [cited by applicant]
US 9098698B2 · Ghosh et al. · 2015 [cited by applicant]
US 9111089B1 · Bhatia et al. · 2015 [cited by applicant]
US 9117075B1 · Yeh · 2015 [cited by applicant]
US 9436822B2 · Ghosh et al. · 2016 [cited by applicant]
US 9519779B2 · Ghosh et al. · 2016 [cited by applicant]
US 9602524B2 · Ghosh et al. · 2017 [cited by applicant]
US 9846588B2 · Ghosh et al. · 2017 [cited by applicant]
US 9871812B2 · Ghosh et al. · 2018 [cited by applicant]
US 10043001B2 · Ghosh et al. · 2018 [cited by applicant]
US 10120998B2 · Ghosh et al. · 2018 [cited by applicant]
US 10187417B2 · Ghosh et al. · 2019 [cited by applicant]
US 10467406B2 · Ghosh et al. · 2019 [cited by applicant]
US 10567414B2 · Ghosh et al. · 2020 [cited by applicant]
US 10956184B2 · Ghosh et al. · 2021 [cited by applicant]
US 10984097B2 · Ghosh et al. · 2021 [cited by applicant]
US 11310252B2 · Ghosh et al. · 2022 [cited by applicant]
US 11411992B2 · N · 2022 [cited by applicant]
US 12019734B2 · Ghosh et al. · 2024 [cited by applicant]
US 20020004799A1 · Gorelik et al. · 2002 [cited by applicant]
US 20020013802A1 · Mori et al. · 2002 [cited by applicant]
US 20020138701A1 · Suzuoki et al. · 2002 [cited by applicant]
US 20020169987A1 · Meushaw et al. · 2002 [cited by applicant]
US 20030023895A1 · Sinha et al. · 2003 [cited by applicant]
US 20030105882A1 · Ali et al. · 2003 [cited by applicant]
US 20040008652A1 · Tanzella et al. · 2004 [cited by applicant]
US 20040025158A1 · Traut · 2004 [cited by applicant]
US 20040064735A1 · Frazier et al. · 2004 [cited by applicant]
US 20040093372A1 · Chen et al. · 2004 [cited by applicant]
US 20040123117A1 · Berger · 2004 [cited by applicant]
US 20050086500A1 · Albornoz · 2005 [cited by applicant]
US 20050138370A1 · Goud et al. · 2005 [cited by applicant]
US 20050160133A1 · Greenlee et al. · 2005 [cited by applicant]
US 20050267856A1 · Woollen · 2005 [cited by applicant]
US 20060021029A1 · Brickell et al. · 2006 [cited by applicant]
US 20060021031A1 · Leahy et al. · 2006 [cited by applicant]
US 20060136720A1 · Armstrong et al. · 2006 [cited by applicant]
US 20060168156A1 · Bae et al. · 2006 [cited by applicant]
US 20060195899A1 · Ben-Shachar et al. · 2006 [cited by applicant]
US 20060206904A1 · Watkins et al. · 2006 [cited by applicant]
US 20060271661A1 · Qi et al. · 2006 [cited by applicant]
US 20060277433A1 · Largman et al. · 2006 [cited by applicant]
US 20060294519A1 · Hattori et al. · 2006 [cited by applicant]
US 20070044151A1 · Whitmore · 2007 [cited by applicant]
US 20070079307A1 · Dhawan et al. · 2007 [cited by applicant]
US 20070106993A1 · Largman et al. · 2007 [cited by applicant]
US 20070107058A1 · Schuba et al. · 2007 [cited by applicant]
US 20070157312A1 · Joubert et al. · 2007 [cited by applicant]
US 20070174915A1 · Gribble et al. · 2007 [cited by applicant]
US 20070192866A1 · Sagoo et al. · 2007 [cited by applicant]
US 20070208822A1 · Wang et al. · 2007 [cited by applicant]
US 20070226773A1 · Pouliot · 2007 [cited by applicant]
US 20070240212A1 · Matalytski · 2007 [cited by applicant]
US 20070250833A1 · Araujo et al. · 2007 [cited by applicant]
US 20070250928A1 · Boney · 2007 [cited by applicant]
US 20070271610A1 · Grobman · 2007 [cited by applicant]
US 20070289019A1 · Lowrey · 2007 [cited by applicant]
US 20080010683A1 · Baddour et al. · 2008 [cited by applicant]
US 20080016339A1 · Shukla · 2008 [cited by applicant]
US 20080016568A1 · Szor et al. · 2008 [cited by applicant]
US 20080059556A1 · Greenspan et al. · 2008 [cited by applicant]
US 20080082976A1 · Steinwagner et al. · 2008 [cited by applicant]
US 20080098465A1 · Ramakrishna et al. · 2008 [cited by applicant]
US 20080127292A1 · Cooper et al. · 2008 [cited by applicant]
US 20080127348A1 · Largman et al. · 2008 [cited by applicant]
US 20080141266A1 · Hunt et al. · 2008 [cited by applicant]
US 20080175246A1 · Kunhappan et al. · 2008 [cited by applicant]
US 20080215852A1 · Largman et al. · 2008 [cited by applicant]
US 20080235764A1 · Cohen et al. · 2008 [cited by applicant]
US 20080244743A1 · Largman et al. · 2008 [cited by applicant]
US 20080244747A1 · Gleichauf et al. · 2008 [cited by applicant]
US 20080271019A1 · Stratton et al. · 2008 [cited by applicant]
US 20080271025A1 · Gross et al. · 2008 [cited by applicant]
US 20080320594A1 · Jiang · 2008 [cited by applicant]
US 20090025009A1 · Brunswig et al. · 2009 [cited by applicant]
US 20090034423A1 · Coon et al. · 2009 [cited by applicant]
US 20090044265A1 · Ghosh et al. · 2009 [cited by applicant]
US 20090055693A1 · Budko et al. · 2009 [cited by applicant]
US 20090113423A1 · Hiltgen et al. · 2009 [cited by applicant]
US 20090125902A1 · Ghosh et al. · 2009 [cited by applicant]
US 20090125974A1 · Zhang et al. · 2009 [cited by applicant]
US 20090158430A1 · Borders · 2009 [cited by applicant]
US 20090158432A1 · Zheng et al. · 2009 [cited by applicant]
US 20090172662A1 · Liu · 2009 [cited by applicant]
US 20090241190A1 · Todd et al. · 2009 [cited by applicant]
US 20090254572A1 · Redlich et al. · 2009 [cited by applicant]
US 20090282477A1 · Chen et al. · 2009 [cited by applicant]
US 20090300599A1 · Piotrowski · 2009 [cited by applicant]
US 20090300739A1 · Nice et al. · 2009 [cited by applicant]
US 20090328008A1 · Mital et al. · 2009 [cited by applicant]
US 20100005531A1 · Largman et al. · 2010 [cited by applicant]
US 20100037235A1 · Larimore et al. · 2010 [cited by applicant]
US 20100064039A9 · Ginter et al. · 2010 [cited by applicant]
US 20100115621A1 · Staniford et al. · 2010 [cited by applicant]
US 20100122342A1 · El-Moussa et al. · 2010 [cited by applicant]
US 20100122343A1 · Ghosh et al. · 2010 [cited by applicant]
US 20100125903A1 · Devarajan et al. · 2010 [cited by applicant]
US 20100132011A1 · Morris et al. · 2010 [cited by applicant]
US 20100138639A1 · Shah et al. · 2010 [cited by applicant]
US 20100146523A1 · Brigaut et al. · 2010 [cited by applicant]
US 20100192011A1 · Largman et al. · 2010 [cited by applicant]
US 20100223613A1 · Schneider · 2010 [cited by applicant]
US 20100235830A1 · Shukla et al. · 2010 [cited by applicant]
US 20100306850A1 · Barile et al. · 2010 [cited by applicant]
US 20100325357A1 · Reddy et al. · 2010 [cited by applicant]
US 20110004749A1 · Bennetts et al. · 2011 [cited by applicant]
US 20110047613A1 · Walsh · 2011 [cited by applicant]
US 20110047620A1 · Mahaffey et al. · 2011 [cited by applicant]
US 20110083180A1 · Mashevsky et al. · 2011 [cited by applicant]
US 20110099620A1 · Stavrou et al. · 2011 [cited by applicant]
US 20110145923A1 · Largman et al. · 2011 [cited by applicant]
US 20110145926A1 · Dalcher et al. · 2011 [cited by applicant]
US 20110154431A1 · Walsh · 2011 [cited by applicant]
US 20110167492A1 · Ghosh et al. · 2011 [cited by applicant]
US 20110191851A1 · Largman et al. · 2011 [cited by applicant]
US 20120079596A1 · Thomas · 2012 [cited by examiner]
US 20120151211A1 · Kreiner et al. · 2012 [cited by applicant]
US 20120297457A1 · Schulte et al. · 2012 [cited by applicant]
US 20120304244A1 · Xie et al. · 2012 [cited by applicant]
US 20120317645A1 · Fortier · 2012 [cited by examiner]
US 20120331441A1 · Adamson · 2012 [cited by applicant]
US 20120331553A1 · Aziz et al. · 2012 [cited by applicant]
US 20130042294A1 · Colvin et al. · 2013 [cited by applicant]
US 20130097659A1 · Das · 2013 [cited by examiner]
US 20130117006A1 · Varghese et al. · 2013 [cited by applicant]
US 20130145463A1 · Ghosh et al. · 2013 [cited by applicant]
US 20150212842A1 · Ghosh et al. · 2015 [cited by applicant]
US 20150324586A1 · Ghosh et al. · 2015 [cited by applicant]
US 20160019391A1 · Ghosh et al. · 2016 [cited by applicant]
US 20160182540A1 · Ghosh et al. · 2016 [cited by applicant]
US 20170200004A1 · Ghosh et al. · 2017 [cited by applicant]
US 20170206348A1 · Ghosh et al. · 2017 [cited by applicant]
US 20170302692A1 · Ghosh et al. · 2017 [cited by applicant]
US 20180046479A1 · Ghosh et al. · 2018 [cited by applicant]
US 20180103053A1 · Ghosh et al. · 2018 [cited by applicant]
US 20180314823A1 · Ghosh et al. · 2018 [cited by applicant]
US 20190158523A1 · Ghosh et al. · 2019 [cited by applicant]
US 20200242236A1 · Ghosh et al. · 2020 [cited by applicant]
US 20200267173A1 · Ghosh et al. · 2020 [cited by applicant]
US 20210209225A1 · Ghosh et al. · 2021 [cited by applicant]
WO WO0221274A1 · 2002 [cited by applicant]
WO WO03067435A2 · 2003 [cited by applicant]
WO WO2005074433A2 · 2005 [cited by applicant]
WO WO2005074434A2 · 2005 [cited by applicant]
WO WO2005116804A2 · 2005 [cited by applicant]
WO WO2007048062A2 · 2007 [cited by applicant]
WO WO2008027563A2 · 2008 [cited by applicant]
WO WO2008027564A2 · 2008 [cited by applicant]
WO WO2008092031A2 · 2008 [cited by applicant]
WO WO2013082437A1 · 2013 [cited by applicant]
Adabala, S., et al., “From virtualized resources to virtual computing grids: the In-VIGO system”, Future Generation Computer Systems (Nov. 11, 2003); 14 pages. [cited by applicant]
Arbaugh, W. A., et al., “Automated Recovery in a Secure Bootstrap Process”, University of Pennsylvania, Distributed Systems Laboratory (Aug. 1, 1997); 17 pages. [cited by applicant]
[Author Unknown] “Capture Communication Protocol Draft”, Victoria University of Wellington, New Zealand (Sep. 22, 2007); 40 pages. [cited by applicant]
[Author Unknown] “Capture-HPC Client Honeypot/Honeyclient”, Victoria University of Wellington, New Zealand (Sep. 2, 2008) [online] https://projects.honeynet.org/capture-hpc (Access Date: Nov. 20, 2015); 1 page. [cited by applicant]
[Author Unknown] “Change History for WikiStart”, WikiStart (history) Capture-HPC [online] https://projects.honeynet.org/capture-hpc/wiki/WikiStart?action=history (Access Date: Nov. 20, 2015); 1 page. [cited by applicant]
[Author Unknown] “CollaborateComm 2008 Conference Program (preliminary)”, Orlando, Florida, USA (Nov. 2008) [online] http://collaboratecom.org/2008/program.php (Access Date: Nov. 20, 2015); 5 pages. [cited by applicant]
[Author Unknown] “CollaborateComm 2008 Registration Policy”, Orlando, Florida, USA (Nov. 13-16, 2008); 3 pages. [cited by applicant]
[Author Unknown] “CollaborateComm 2008 Selected Publications Table of Contents”, Orlando, Florida, USA (Nov. 13-16, 2008); 12 pages. [cited by applicant]
[Author Unknown, Date Unknown] “Shutdown”, Microsoft Windows XP [online] https://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/enus/shutdown.mspx?mfr=true, (Access Date: Feb. 23, 2016); 2 pages. [cited by applicant]
[Author Unknown] “Solstice DiskSuite 4.2.1 Reference Guide”, Sun Microsystems, Inc. (Feb. 2000); 195 pages. [cited by applicant]
[Author Unknown] “Software for the Secure Management and deployment of Java”, Digitivity, Inc. (Aug. 6, 1998) [online] http://www.digitivity.com/html/body_products.html (Access Date: Dec. 10, 2015); 5 pages. [cited by applicant]
[Author Unknown] “Timeline”, Timeline-Capture HPC (Apr. 15, 2008) [online] https://projects.honeynet.org/capturehpc/timeline?from=20080415T13%3A53%3A08Z&precision=second (Access Date: Feb. 15, 2016); 4 pages. [cited by applicant]
[Author Unknown] “Timeline”, Timeline-Capture HPC (Nov. 13, 2008) [online] https://projects.honeynet.org/capture-hpc/timeline?from=20081113T21%3A15%3A49Z&precision=second (Access Date: Nov. 20, 2015); 2 pages. [cited by applicant]
Bressoud, T. C. et al., “Hypervisor-Based Fault-Tolerance”, ACM Transactions on Computer Systems (Feb. 1996); 14(1): 80-107. [cited by applicant]
Bressoud, T. C., “TFT: A Software System for Application-Transparent Fault Tolerance”, Digest of Papers, Twenty-Eighth Annual International Symposium on Fault-Tolerant Computing, IEEE (1998); 11 pages. [cited by applicant]
Chiueh, T., et al., “Spout: a transparent distributed execution engine for Java applets”, Computer Science Department, State University of New York at Stony Brook, Proceedings 20th IEEE International Conference on Distr… [cited by applicant]
Czajkowski, G., “Application Isolation in the Java Virtual Machine”, Sun Microsystems Laboratories, Proceedings of the 15th ACM SIGPLAN Conference on Object-oriented Programming, Systems, Languages, and Applications (Oc… [cited by applicant]
Dehni, T., et al., “Intelligent Networks and the HP OpenCall Technology”, Article 6, Hewlett-Packard Journal (Aug. 1997); pp. 1-14. [cited by applicant]
Dinaburg, A., et al., “Ether: Malware analysis via hardware virtualization extensions”, CCS'08, Alexandria, Virginia, USA, 15th ACM Conference 2008 (Oct. 27-31, 2008); pp. 51-62. [cited by applicant]
Final Office Action for U.S. Appl. No. 12/037,412, mailed Apr. 23, 2012, 20 pages. [cited by applicant]
Fritzinger, J. S., et al., “Java security”, Sun Microsystems, Inc. (1996); 7 pages. [cited by applicant]
Hines, M., “‘Virtual sandboxing’ provides safe security testing”, Computerworld (Aug. 9, 2007) [online] http://www.computerworld/com/s/article/9029885/Virtual_Sandboxin _ . . . (Access Date: Apr. 7, 2011); 3 pages. [cited by applicant]
Huang, Y., et al., “Efficiently tracking application interactions using lightweight virtualization”, VMSEC'08, Fairfax, Virginia, USA (Oct. 31, 2008); 9 pages. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2012/067311, mailed Mar. 12, 2013, 7 pages. [cited by applicant]
Jajodia, S., et al., “Application-Level Isolation to Cope With Malicious Database Users”, Proceedings 14th Annual Computer Security Applications Conference (Dec. 1998); 11 pages. [cited by applicant]
Jiang, X., et al., “Stealthy Malware Detection Through VMM-Based “Out-of-the-Box” Semantic View Reconstruction”, CCS'07, Alexandria, Virginia USA, Proceedings of the 14th ACM Conference (Oct. 29-Nov. 2, 2007); pp. 128-1… [cited by applicant]
Jmunro, “Virtual Machines & VMware, Part 1”, ExtremeTech (Dec. 21, 2001) [online] http://www.extremetech.com/computing/72186-virtual-machines-vmware-part-I (Access Date: May 20, 2015); 21 pages. [cited by applicant]
Jmunro, “Virtual Machines & VMware, Part II”, ExtremeTech (Dec. 28, 2001) [online] http://www.extremetech.com/computing/72268-virtual-machines-vmware-part-ii (Access Date: May 20, 2015); 35 pages. [cited by applicant]
Jonback, M., et al., “Open architecture in the Core of Axe”, Ericsson Review (2001); 1: 24-31. [cited by applicant]
King, S. T., et al., “SubVirt: Implementing malware with virtual machines”, Proceedings of the 2006 IEEE Symposium on Security and Privacy (S&P'06) (2006); 14 pages. [cited by applicant]
Lee, J-S., et al., “A Generic Virus Detection Agent on the Internet”, Proceedings of the Thirtieth Annual Hawaii International Conference on System Sciences (1997); 10 pages. [cited by applicant]
Liu, P., et al., “Intrusion Confinement by Isolation in Information Systems”, Department of Information Systems, University of Maryland, Baltimore County, the MITRE Corporation, Center for Secure Information Systems, an… [cited by applicant]
Malkhi, D., et al., “Secure Execution of Java Applets using a Remote Playground”, AT&T Labs Research, IEEE Transactions on Software Engineering (Dec. 2000); 26(12): 1197-1209. [cited by applicant]
Morales, J. A., et al., “Building malware infection trees”, Malicious and Unwanted Software (Malware) 2011 6th International Conference on Malicious and Unwanted Software, IEEE (Oct. 2011); pp. 50-57. [cited by applicant]
Moshchuk, A., et al., “SpyProxy: Execution-based Detection of Malicious Web Content”, Proceedings of 16th USENIX Security Symposium on USENIX Security Symposium (Aug. 6-10, 2007); 16 pages. [cited by applicant]
Nachenberg, C., “Understanding and Managing Polymorphic Viruses”, The Symantec Enterprise Papers (1996); 16 pages. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/211,412 dated Sep. 8, 2023, 19 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 14/480,657, mailed Apr. 25, 2016, 10 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 15/249,975, mailed Jul. 3, 2018, 10 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 15/795,977, mailed Nov. 16, 2020, 9 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/018,720, mailed Jun. 27, 2019, 9 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/250,006, mailed Oct. 2, 2019, 10 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/671,664, mailed Jan. 6, 2021, 9 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/211,412 dated Feb. 7, 2024, 7 pages. [cited by applicant]
Office Action for U.S. Appl. No. 12/037,412, mailed Aug. 16, 2013, 22 pages. [cited by applicant]
Office Action for U.S. Appl. No. 12/037,412, mailed Oct. 27, 2011, 20 pages. [cited by applicant]
Office Action for U.S. Appl. No. 12/059,454, mailed Feb. 2, 2011, 12 pages. [cited by applicant]
Office Action for U.S. Appl. No. 12/059,454, mailed Oct. 12, 2011, 13 pages. [cited by applicant]
Office Action for U.S. Appl. No. 12/558,841, mailed Apr. 3, 2012, 20 pages. [cited by applicant]
Office Action for U.S. Appl. No. 12/558,841, mailed Jan. 30, 2013, 21 pages. [cited by applicant]
Office Action for U.S. Appl. No. 12/558,841, mailed Jan. 9, 2014, 22 pages. [cited by applicant]
Office Action for U.S. Appl. No. 12/558,841, mailed Sep. 30, 2014, 23 pages. [cited by applicant]
Office Action for U.S. Appl. No. 12/757,675, mailed Aug. 2, 2012, 21 pages. [cited by applicant]
Office Action for U.S. Appl. No. 12/757,675, mailed May 15, 2013, 20 pages. [cited by applicant]
Office Action for U.S. Appl. No. 12/827,203, mailed Apr. 17, 2014, 8 pages. [cited by applicant]
Office Action for U.S. Appl. No. 12/827,203, mailed Jan. 15, 2013, 17 pages. [cited by applicant]
Office Action for U.S. Appl. No. 13/296,319, mailed Dec. 17, 2012, 9 pages. [cited by applicant]
Office Action for U.S. Appl. No. 13/296,319, mailed Sep. 5, 2013, 10 pages. [cited by applicant]
Office Action for U.S. Appl. No. 13/690,452, mailed Jan. 30, 2015, 21 pages. [cited by applicant]
Office Action for U.S. Appl. No. 13/690,452, mailed Jun. 12, 2014, 16 pages. [cited by applicant]
Office Action for U.S. Appl. No. 13/690,452, mailed Nov. 8, 2013, 12 pages. [cited by applicant]
Office Action for U.S. Appl. No. 14/480,657, mailed Sep. 21, 2015, 24 pages. [cited by applicant]
Office Action for U.S. Appl. No. 14/482,786, mailed Jan. 21, 2016, 20 pages. [cited by applicant]
Office Action for U.S. Appl. No. 14/482,786, mailed Mar. 9, 2017, 14 pages. [cited by applicant]
Office Action for U.S. Appl. No. 14/482,786, mailed Oct. 25, 2016, 16 pages. [cited by applicant]
Office Action for U.S. Appl. No. 14/797,847, mailed May 17, 2016, 31 pages. [cited by applicant]
Office Action for U.S. Appl. No. 14/797,847, mailed Nov. 23, 2015, 22 pages. [cited by applicant]
Office Action for U.S. Appl. No. 14/808,681, mailed Jun. 15, 2016, 22 pages. [cited by applicant]
Office Action for U.S. Appl. No. 15/249,975, mailed Dec. 4, 2017, 14 pages. [cited by applicant]
Office Action for U.S. Appl. No. 15/249,975, mailed Jul. 28, 2017, 13 pages. [cited by applicant]
Office Action for U.S. Appl. No. 15/359,004, mailed Jul. 11, 2017, 27 pages. [cited by applicant]
Office Action for U.S. Appl. No. 15/795,977, mailed May 29, 2019, 39 pages. [cited by applicant]
Office Action for U.S. Appl. No. 15/795,977, mailed Oct. 4, 2019, 36 pages. [cited by applicant]
Office Action for U.S. Appl. No. 15/841,913, mailed Mar. 14, 2018, 9 pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/018,720, mailed Feb. 26, 2019, 8 pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/250,006, mailed Jun. 26, 2019, 9 pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/671,664, mailed Sep. 4, 2020, 8 pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/789,973, mailed Oct. 13, 2021, 7 pages. [cited by applicant]
Peterson, D. S., et al., “A Flexible Containment Mechanism for Executing Untrusted Code”, Department of Computer Science, University of California (2002); pp. 207-225. [cited by applicant]
Riden, J., “Know you Enemy: Malicious Web Servers”, The Honeynet Project (Aug. 9, 2007) [online] http://www.honeypot.org/papers/mws (Access Date: Feb. 22, 2016); 1 page. [cited by applicant]
Royal, P., et al., “PolyUnpack: Automating the Hidden-Code Extraction of Unpack-Executing Malware”, Proceedings of the 22nd Annual Computer Security Application Conference (ACSAC '06) (2006); 10 pages. [cited by applicant]
Sapuntzakis, C., et al., “Virtual Appliances for Deploying and Maintaining Software”, Computer Systems Laboratory, Stanford University (2003); 15 pages. [cited by applicant]
Seifert, C., et al., “About Capture Honeypot/Honeyclient”, The Honeynet Project, Victoria University of Wellington, New Zealand (2006) [online] https://projects.honeynet.org/capture-hpc (Access Date: Sep. 22, 2008); 3 p… [cited by applicant]
Sekar, R., et al.,“A Specification-Based Approach for Building Survivable Systems”, 21st National Information Systems Security Conference Proceedings: Papers, Hyatt Regency, Crystal City, Virginia (Oct. 6-9, 1998); 12 p… [cited by applicant]
Sugerman, J., et al., “Virtualizing I/O Devices on VMware Workstation's Hosted Virtual Machine Monitor”, Proceedings of the 2001 USENIX Annual Technical Conference, Boston, Massachusetts, USA (Jun. 25-30, 2001); 15 page… [cited by applicant]
Ugurlu, O. S., “Stealth Sandbox Analysis of Malware”, A Thesis Submitted to the Department of Computer Engineering and the Institute of Engineering and Science of Bilkent University in Partial Fulfillment of the Require… [cited by applicant]
U.S. Appl. No. 61/221,749, filed Jun. 30, 2009. [cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]
Wang, J., et al., “SafeFox: a Safe Lightweight Virtual Browsing Environment”, Proceedings of the 43rd Hawaii International Conference on System Sciences (2010); 10 pages. [cited by applicant]
Wang, J., et al., “Web Canary: A Virtualized Web Browser to Support Large-Scale Silent Collaboration in Detecting Malicious Web Sites”, ICST Institute for Computer Sciences, Social-Informatics and Telecommunications Eng… [cited by applicant]
Xia, Z., et al., “Secure Semantic Expansion based Search over Encrypted Cloud Data supporting Similarity Ranking”, Journal of Cloud Computing: Advances, Systems and Applications (2014); 3(8): 1-11. [cited by applicant]
Zeltser, L., “Reverse Engineering Malware”, www.zeltser.com (May 2001); 31 pages. [cited by applicant]