IP Library Granted Patent US 12,579,262
Granted Patent B2
US 12,579,262 · App. 18/686,631 · Granted Mar 17, 2026

Systems and methods for neutralizing malicious code with nested executuion contexts

Inventor: Avihay Cohen (Tel-Aviv, IL)
Assignee: SERAPHIC ALGORITHMS LTD.
G06F21/554G06F8/65G06F21/128G06F21/54G06F9/45529G06F9/54G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,579,262
App. No.
18/686,631
Granted
Mar 17, 2026
Kind
B2
Abstract

A non-transitory computer readable medium contains instructions that when executed cause one or more processors to perform cybersecurity operations that include detecting an interpreter-based application configured to exhibit native functionality and to generate a plurality of execution contexts following receipt of an original input code. An interpreter-based cybersecurity agent is injected within the detected interpreter-based application, which is itself configured for execution by the interpreter-based application prior to execution of the original input code. Exposed APIs are patched using the injected interpreter-based cybersecurity agent to cause patched APIs to exhibit non-native functionality in order to thwart exploitations.

Claims (35)

1 . A non-transitory computer-readable medium containing instructions executable by at least one processor to perform operations for neutralizing malicious code, the operations comprising:

accessing an interpreter-based application associated with a first execution context having at least one first-execution-context exposed API;

executing a first intercepting code prior to execution of first-execution-context input code, the first intercepting code being configured to patch the at least one first-execution-context exposed API;

determining whether the first-execution-context input code generates a second execution context having at least one second-execution-context exposed API; and

executing a second intercepting code prior to execution of second-execution-context input code, the second intercepting code being configured to patch the at least one second-execution-context exposed API.

2 . The non-transitory computer-readable medium of claim 1 , wherein the first-execution-context input code is the same as the second-execution-context input code.

3 . The non-transitory computer-readable medium of claim 1 , wherein the first-execution-context input code is different from the second-execution-context input code.

4 . The non-transitory computer-readable medium of claim 1 , wherein the first intercepting code is the same as the second intercepting code.

5 . The non-transitory computer-readable medium of claim 1 , wherein the first intercepting code is different from the second intercepting code.

6 . The non-transitory computer-readable medium of claim 1 , wherein the second execution context is nested within the first execution context.

7 . The non-transitory computer-readable medium of claim 1 , wherein the first execution context is represented by a top frame and the second execution context is associated with the top frame.

8 . The non-transitory computer-readable medium of claim 1 , wherein the first execution context and the second execution context are associated with separate computing processes.

9 . The non-transitory computer-readable medium of claim 1 , wherein the first execution context and the second execution context are associated with a same computing process.

10 . The non-transitory computer-readable medium of claim 1 , wherein at least one of executing the first intercepting code prior to execution of the first-execution-context input code or executing the second intercepting code prior to execution of the second-execution-context input code includes using at least one JavaScript agent.

11 . The non-transitory computer-readable medium of claim 1 , wherein:

the operations further comprise determining that the first execution context is associated with a first source differing from a second source associated with the second execution context; and

the execution of the second intercepting code is based on the determination that the first execution context is associated with the first source differing from the second source associated with the second execution context.

12 . A method for neutralizing malicious code, the method comprising:

accessing an interpreter-based application associated with a first execution context having at least one first-execution-context exposed API;

executing a first intercepting code prior to execution of first-execution-context input code, the first intercepting code being configured to patch the at least one first-execution-context exposed API;

determining whether the first-execution-context input code generates a second execution context having at least one second-execution-context exposed API; and

executing a second intercepting code prior to execution of second-execution-context input code, the second intercepting code being configured to patch the at least one second-execution-context exposed API.

13 . The method of claim 12 , wherein the first-execution-context input code is the same as the second-execution-context input code or the first intercepting code is the same as the second intercepting code.

14 . The method of claim 12 , wherein the first-execution-context input code is different from the second-execution-context input code or the first intercepting code is different from the second intercepting code.

15 . The method of claim 12 , wherein the second execution context is nested within the first execution context.

16 . The method of claim 12 , wherein the first execution context is represented by a top frame and the second execution context is associated with the top frame.

17 . The method of claim 12 , wherein the first execution context and the second execution context are associated with separate computing processes.

18 . The method of claim 12 , wherein the first execution context and the second execution context are associated with a same computing process.

19 . A cyber security system for neutralizing malicious code, the system comprising:

at least one processor configured to:

access an interpreter-based application associated with a first execution context having at least one first-execution-context exposed API;

execute a first intercepting code prior to execution of first-execution-context input code, the first intercepting code being configured to patch the at least one first-execution-context exposed API;

determine whether the first-execution-context input code generates a second execution context having at least one second-execution-context exposed API; and

execute a second intercepting code prior to execution of second-execution-context input code, the second intercepting code being configured to patch the at least one second-execution-context exposed API.

20 . The cyber security system of claim 19 , wherein the second execution context is nested within the first execution context.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Jun 25, 2026
From: HSBC BANK PLC
To: SERAPHIC ALGORITHMS LTD
Reel/Frame 075079/0275 →
SECURITY INTEREST Recorded May 12, 2025
From: SERAPHIC ALGORITHMS LTD
To: HSBC BANK PLC
Reel/Frame 071088/0637 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2024
From: COHEN, AVIHAY
To: SERAPHIC ALGORITHMS LTD.
Reel/Frame 066568/0693 →
Continuity (3)
Continuation In Part PCTIL2021051062 · Aug 31, 2021
Provisional Application 63072581 · Aug 31, 2020
Related Publication 20240419784A1 · Dec 19, 2024
References Cited (16)
US 9438625B1 · Yang · 2016 [cited by applicant]
US 12321791B1 · Jones · 2025 [cited by examiner]
US 20150163248A1 · Epstein · 2015 [cited by applicant]
US 20180205705A1 · Kupferschmied et al. · 2018 [cited by applicant]
US 20180336348A1 · Ng · 2018 [cited by examiner]
US 20190095616A1 · Drapeau et al. · 2019 [cited by applicant]
US 20190318090A1 · Sandoval · 2019 [cited by examiner]
US 20200159998A1 · Cohavi · 2020 [cited by examiner]
US 20210026969A1 · Hod et al. · 2021 [cited by applicant]
US 20210029170A1 · Gupta et al. · 2021 [cited by applicant]
WO 2018006241A1 · 2018 [cited by applicant]
Sachin, Vijetha, et al. “Surfguard JavaScript Instrumentation-based Defense against Drive-by downloads”, Recent Advances in Computing and Software Systems (RACESS), 2012 International Conference on, IEEE, Apr. 25, 2012,… [cited by applicant]
Mandal, Debasish, “Browser Exploits? Grab 'em by the Collar?”, Oct. 26, 2017, pp. 1-68. [cited by applicant]
Extended European Search Report in European Patent Application No. 22863711.2-1218/4396711 PCT/IB2022051699 dated Apr. 24, 2025 (9 pages). [cited by applicant]
International Search Report issued in PCT/IB22/51699 dated May 13, 2022 (2 pages). [cited by applicant]
Written Opinion of the International Searching Authority issued in PCT/IB22/51699 dated May 13, 2022 (12 pages). [cited by applicant]