IP Library Granted Patent US 12,625,961
Granted Patent B2
US 12,625,961 · App. 18/789,764 · Granted May 12, 2026

Malicious direct syscall call detection

Inventors: Or Chechik (Rishon LeZion, IL); Ofir Ozer (Tel Aviv, IL); Ori Damari (Ramat Gan, IL); Yuval Zan (Givatayim, IL)
Assignee: Palo Alto Networks, Inc.
G06F21/566G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,625,961
App. No.
18/789,764
Granted
May 12, 2026
Kind
B2
Abstract

Methods, storage systems and computer program products implement embodiments of the present invention for protecting a computer by first deploying in a memory of the computer a hooked version of a syscall used by an operating system kernel of the computer A notification of a call to the hooked version of the syscall from a user mode of the computer is received from the hooked version of the syscall, the notification including a return address in the memory and a set of features extracted from the call. The return address and the received features are analyzed so as to classify the call as benign or malicious, and an alert is generated for the computer upon classifying the new call as malicious.

Claims (43)

1 . A method for protecting a computer, comprising:

deploying in a memory of the computer a hooked version of a syscall used by an operating system kernel of the computer;

receiving, from the hooked version of the syscall, a notification of a call to the hooked version of the syscall from a user mode of the computer, the notification comprising a return address in the memory and a set of features extracted from the call;

analyzing the return address and the received features so as to classify the call as benign or malicious; and

generating, for the computer, an alert upon classifying the new call as malicious,

wherein classifying the call as malicious comprises classifying the call as a direct call, and

wherein the call comprises a new call, and wherein the features further comprise additional features from previous direct calls to the hooked version of the syscall by execution entities executing in the memory of the computer and additional computers, wherein the new call and previous calls were conveyed during multiple days, and wherein one or more organizations comprise the computers.

2 . The method according to claim 1 , wherein analyzing the return address comprises identifying the return address as belonging to a specified block in a user-mode segment of the memory.

3 . The method according to claim 2 , wherein the specified block is not allocated to a specified DLL.

4 . The method according to claim 1 , wherein a given feature comprises a mapped block in the memory comprising the execution entities, wherein analyzing the features comprises identifying a number of distinct execution entities that generated the direct calls from the mapped block, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

5 . The method according to claim 1 , wherein a given feature comprises a mapped block in the memory comprising the execution entities, wherein analyzing the features comprises identifying a number of distinct days when any of the computers having the given feature, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

6 . The method according to claim 1 , and further comprising defining a key comprising first and second features, the first feature comprising a given execution entity that conveyed one or more of the direct calls, and the second feature comprising a mapped block in the memory comprising an execution entity that generated one or more of the direct calls, wherein analyzing the features comprises identifying a number of distinct computers having the key, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

7 . The method according to claim 1 , and further comprising defining a key comprising first and second features, the first feature comprising a given execution entity that conveyed one or more of the direct calls, and the second feature comprising a mapped block in the memory comprising an execution entity that generated one or more of the direct calls, wherein analyzing the features comprises identifying a number of distinct days when any of the computers have the key, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

8 . The method according to claim 1 , and further comprising defining a key comprising first and second features, the first feature comprising a given execution entity that conveyed one or more of the direct calls, and the second feature comprising a mapped block in the memory comprising an execution entity that generated one or more of the direct calls, wherein analyzing the features comprises identifying a number of distinct organizations comprising the computers having the key, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

9 . The method according to claim 1 , and further comprising defining a key comprising first and second features, the first feature comprising a given execution entity that conveyed one or more of the direct calls, and the second feature comprising the hooked version of the syscall, wherein analyzing the features comprises identifying a number of distinct memory blocks comprising the key, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

10 . The method according to claim 1 , and further comprising defining a key comprising first and second features, the first feature comprising a process that conveyed one or more of the direct calls, and the second feature comprising the hooked version of the syscall, wherein analyzing the features comprises identifying a number of distinct computers comprising the key, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

11 . The method according to claim 1 , and further comprising defining a key comprising first and second features, the first feature comprising a given execution entity that conveyed one or more of the direct calls, and the second feature comprising the hooked version of the syscall, wherein analyzing the features comprises identifying a number of distinct days when any of the computers have the key, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

12 . The method according to claim 1 , wherein one or more of the computers execute shellcodes comprising respective shellcode headers.

13 . The method according to claim 12 , wherein a given feature comprises a given execution entity that one or more of the computers executed from any of the shellcodes, and that conveyed one or more of the direct calls, wherein analyzing the features comprises identifying a number of distinct computers having the given feature, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

14 . The method according to claim 12 , wherein a given feature comprises a given execution entity that one or more of the computers executed from any of the shellcodes, and that conveyed one or more of the direct calls, wherein analyzing the features comprises identifying a number of distinct days when any of the computers have the given feature, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

15 . The method according to claim 12 , wherein a given feature comprises a given execution entity that one or more of the computers executed from any of the shellcodes, and that conveyed one or more of the direct calls, wherein analyzing the features comprises identifying a number of distinct shellcode headers having execution entities identical to the given feature, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

16 . The method according to claim 12 , and further comprising defining a key comprising first and second features, the first feature comprising a given execution entity that one or more of the computers executed from any of the shellcodes, and the second feature a given shellcode header for a given shellcode that spawned a given execution entity, wherein analyzing the features comprises identifying a number of distinct computers having the key, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

17 . The method according to claim 12 , and further comprising defining a key comprising first and second features, the first feature comprising a given execution entity that one or more of the computers executed from any of the shellcodes, and the second feature a given shellcode header for a given shellcode that spawned a given execution entity, wherein analyzing the features comprises identifying a number of distinct days when any of the computers have the key, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

18 . The method according to claim 12 , and further comprising defining a key comprising first and second features, the first feature comprising a given execution entity that one or more of the computers executed from any of the shellcodes, and the second feature a given shellcode header for a given shellcode that spawned a given execution entity, wherein analyzing the features comprises identifying a number of distinct organizations comprising the computers having the key, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

19 . The method according to claim 12 , and further comprising defining a key comprising first and second features, the first feature comprising the hooked version of the syscall, and the second feature a given shellcode header for a given shellcode that spawned a given execution entity, wherein analyzing the features comprises identifying a number of distinct computers having the key, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

20 . The method according to claim 12 , and further comprising defining a key comprising first and second features, the first feature comprising the hooked version of the syscall, and the second feature a given shellcode header for a given shellcode that spawned a given execution entity, wherein analyzing the features comprises identifying a number of distinct days when any of the computers in a given organization have the key, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

21 . The method according to claim 12 , and further comprising defining a key comprising first and second features, the first feature comprising the hooked version of the syscall, and the second feature a given shellcode header for a given shellcode that spawned a given execution entity, wherein analyzing the features comprises identifying a number of distinct execution entities having the key, and wherein classifying the new call as malicious comprises identifying that identified number is less than a specified threshold.

22 . A security server, comprising:

a memory; and

a processor configured:

to deploy, in the memory, a hooked version of a syscall used by an operating system kernel of a computer,

to receive, from the computer, a notification of a call to a hooked version of the syscall from a user mode of the second computer, the notification comprising a return address in the memory and a set of features extracted from the call,

to analyze the return address and the received features so as to classify the call as benign or malicious, and

to generate, for the computer, an alert upon classifying the new call as malicious,

wherein classifying the call as malicious comprises classifying the call as a direct call, and

wherein the call comprises a new call, and wherein the features further comprise additional features from previous direct calls to the hooked version of the syscall by execution entities executing in the memory of the computer and additional computers, wherein the new call and previous calls were conveyed during multiple days, and wherein one or more organizations comprise the computers.

23 . A computer software product for protecting a computer, the computer software product comprising a non-transitory computer-readable medium, in which program instructions are stored, which instructions, when read by the computer, cause the computer:

to deploy in a memory of the computer a hooked version of a syscall used by an operating system kernel of the computer;

to receive, from the hooked version of the syscall, a notification of a call to the hooked version of the syscall from a user mode of the computer, the notification comprising a return address in the memory and a set of features extracted from the call;

to analyze the return address and the received features so as to classify the call as benign or malicious; and

to generate, for the computer, an alert upon classifying the new call as malicious,

wherein classifying the call as malicious comprises classifying the call as a direct call, and

wherein the call comprises a new call, and wherein the features further comprise additional features from previous direct calls to the hooked version of the syscall by execution entities executing in the memory of the computer and additional computers, wherein the new call and previous calls were conveyed during multiple days, and wherein one or more organizations comprise the computers.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2024
From: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
To: PALO ALTO NETWORKS INC.
Reel/Frame 068823/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2024
From: CHECHIK, OR; OZER, OFIR; DAMARI, ORI; ZAN, YUVAL
To: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
Reel/Frame 068131/0469 →
Continuity (1)
Related Publication 20260037628A1 · Feb 5, 2026
References Cited (99)
US H2196H · Tester · 2007 [cited by examiner]
US 7950057B1 · Kennedy et al. · 2011 [cited by applicant]
US 8205257B1 · Satish et al. · 2012 [cited by applicant]
US 8539578B1 · Zhou et al. · 2013 [cited by applicant]
US 8601584B1 · Lu et al. · 2013 [cited by applicant]
US 8640235B2 · Repasi · 2014 [cited by examiner]
US 8646076B1 · Lim et al. · 2014 [cited by applicant]
US 8990944B1 · Singh et al. · 2015 [cited by applicant]
US 9256552B2 · Epstein · 2016 [cited by applicant]
US 9659182B1 · Roundy et al. · 2017 [cited by applicant]
US 10193918B1 · Patton et al. · 2019 [cited by applicant]
US 10409981B2 · Iyengar · 2019 [cited by examiner]
US 10503904B1 · Singh et al. · 2019 [cited by applicant]
US 10860718B2 · Seetharamaiah et al. · 2020 [cited by applicant]
US 11216559B1 · Gu et al. · 2022 [cited by applicant]
US 11409868B2 · Reid et al. · 2022 [cited by applicant]
US 11520886B2 · Levy et al. · 2022 [cited by applicant]
US 11886585B1 · Davis · 2024 [cited by applicant]
US 11934801B2 · Rahmani et al. · 2024 [cited by applicant]
US 12223044B1 · Jung · 2025 [cited by examiner]
US 20040049693A1 · Douglas · 2004 [cited by applicant]
US 20050091558A1 · Chess · 2005 [cited by examiner]
US 20060005200A1 · Vega et al. · 2006 [cited by applicant]
US 20060143707A1 · Song · 2006 [cited by examiner]
US 20080040800A1 · Park · 2008 [cited by examiner]
US 20090049550A1 · Shevchenko · 2009 [cited by applicant]
US 20120047515A1 · Kanetomo · 2012 [cited by applicant]
US 20120255004A1 · Salam · 2012 [cited by applicant]
US 20130227680A1 · Pavlyushchik · 2013 [cited by applicant]
US 20140115652A1 · Kapoor et al. · 2014 [cited by applicant]
US 20150199514A1 · Tosa et al. · 2015 [cited by applicant]
US 20150213260A1 · Park · 2015 [cited by applicant]
US 20150215335A1 · Giuliani · 2015 [cited by examiner]
US 20160055337A1 · El-Moussa · 2016 [cited by applicant]
US 20160232347A1 · Badishi · 2016 [cited by applicant]
US 20170180421A1 · Shieh et al. · 2017 [cited by applicant]
US 20180068115A1 · Golovkin et al. · 2018 [cited by applicant]
US 20180115577A1 · Shukla et al. · 2018 [cited by applicant]
US 20180189490A1 · Maciejak et al. · 2018 [cited by applicant]
US 20180191779A1 · Shieh et al. · 2018 [cited by applicant]
US 20180211038A1 · Breiman et al. · 2018 [cited by applicant]
US 20180248896A1 · Challita et al. · 2018 [cited by applicant]
US 20190087572A1 · Ellam et al. · 2019 [cited by applicant]
US 20190109870A1 · Bedhapudi et al. · 2019 [cited by applicant]
US 20190121978A1 · Kraemer et al. · 2019 [cited by applicant]
US 20190138727A1 · Dontov et al. · 2019 [cited by applicant]
US 20190318090A1 · Sandoval · 2019 [cited by examiner]
US 20190325133A1 · Goodridge et al. · 2019 [cited by applicant]
US 20190347418A1 · Strogov et al. · 2019 [cited by applicant]
US 20200089876A1 · Aharoni et al. · 2020 [cited by applicant]
US 20200106808A1 · Schutz et al. · 2020 [cited by applicant]
US 20200183820A1 · Hebert et al. · 2020 [cited by applicant]
US 20200204589A1 · Strogov et al. · 2020 [cited by applicant]
US 20200342100A1 · Goldstein et al. · 2020 [cited by applicant]
US 20210152595A1 · Hansen et al. · 2021 [cited by applicant]
US 20220222338A1 · Gupta · 2022 [cited by applicant]
US 20220284095A1 · Ahmed · 2022 [cited by applicant]
US 20230084691A1 · Levy et al. · 2023 [cited by applicant]
CN 115033879A · 2022 [cited by examiner]
JP 2010509654A · 2010 [cited by applicant]
JP 2015141718A · 2015 [cited by applicant]
KR 20090088198A · 2009 [cited by examiner]
KR 20100078081A · 2010 [cited by examiner]
KR 20120031745A · 2012 [cited by examiner]
KR 20120126667A · 2012 [cited by examiner]
RU 2012113963A · 2013 [cited by examiner]
WO 2008056944A1 · 2008 [cited by applicant]
WO 2022109664A1 · 2022 [cited by applicant]
WO 2022248920A1 · 2022 [cited by applicant]
WO 2023133582A1 · 2023 [cited by applicant]
1 International Application # PCT/US2025/016969 Search Report dated Apr. 22, 2025. [cited by applicant]
Blackberry, “Threat Spotlight: Petya-Like Ransomware is Nasty Wiper”, pp. 1-22, Nov. 7, 2017, as downloaded from https://blogs.blackberry.com/en/2017/07/threat-spotlight-petya-like-ransomware-is-nasty-wiper. [cited by applicant]
Wikipedia, “Java Virtual Machine,” pp. 1-8, last update Oct. 25, 2022. [cited by applicant]
Cristalli et al., “Trusted Execution Path for Protecting Java Applications Against Deserialization of Untrusted Data,” Proceedings, International Conference, ICB 2007—Advances in Biometrics, Springer Nature Switzerland … [cited by applicant]
Wikipedia, “Java Remote Method Invocation,” pp. 1-4, last edited Dec. 26, 2020. [cited by applicant]
Wikipedia, “Metasploit Project,” pp. 1-7, last edited Jun. 7, 2022. [cited by applicant]
Cynet, “Cobalt Strike: White Hat Hacker Powerhouse in the Wrong Hands,” pp. 1-6, last updated Jun. 27, 2022, as downloaded from https://web.archive.org/web/20220627023847/https://www.cynet.com/network-attacks/cobalt-str… [cited by applicant]
Shah, “Analyzing CVE-2017-9791: Apache Struts Vulnerability Can Lead to Remote Code Execution,”, McAfee, pp. 1-7, Jul. 19, 2017, as downloaded from https://www.mcafee.com/blogs/other-blogs/mcafee-labs/analyzing-cve-2017… [cited by applicant]
Frohoff, “A Proof-of-Concept Tool for Generating Payloads that Exploit unsafe Java Object Deserialization,” github.com, pp. 1-3, Jul. 16, 2022, as downloaded from https://github.com/frohoff/ysoserial. [cited by applicant]
Wikipedia, “Return-oriented Programming,” pp. 1-6, last edited Mar. 31, 2020, as downloaded from https://web.archive.org/web/20200403142512/https://en.wikipedia.org/wiki/Return-oriented_programming. [cited by applicant]
Mcnab, “Network Security Assessment”, 2nd edition, Chapter 16 (Exploitation Frameworks), pp. 393-414, Oct. 2007. [cited by applicant]
Balakrishnan, “Understanding Java Agents,” Tutorial, pp. 1-8, Jul. 6, 2020, as downloaded from https://dzone.com/articles/java-agent-1. [cited by applicant]
Wilson, “Windows Inline Function Hooking,” Blog Entry, LRQA Nettitude, pp. 1-11, Mar. 18, 2015, as downloaded from https://blog.nettitude.com/uk/windows-inline-function-hooking. [cited by applicant]
Palo Alto Networks, “Cortex XDR,” Datasheet, pp. 1-9, year 2023. [cited by applicant]
U.S. Appl. No. 17/979,004 Office Action dated Jun. 6, 2024. [cited by applicant]
Chechik et al., U.S. Appl. No. 18/301,366, filed Apr. 17, 2023. [cited by applicant]
Chechik et al., U.S. Appl. No. 18/676,573, filed May 29, 2024. [cited by applicant]
Aharoni et al., U.S. Appl. No. 18/779,134, filed Jul. 22, 2024. [cited by applicant]
U.S. Appl. No. 17/979,004 Office Action dated Sep. 6, 2024. [cited by applicant]
AU Application # 2021447019 Office Action dated Sep. 16, 2024. [cited by applicant]
Bauman et al, “Renewable Just-In-Time Control-Flow Integrity”, Proceedings of the 26th International Symposium On Research in Attacks, Intrusions and Defenses, Oct. 16, 2023 (Oct. 16, 2023), pp. 580-594, https://dl.acm.… [cited by applicant]
PCT International Search Report and Written Opinion for international application No. PCT/US2025/035110, dated Oct. 8, 2025. [cited by applicant]
Non-final Office Action, U.S. Appl. No. 18/676,573, dated Aug. 27, 2025. [cited by applicant]
Notice of References Cited, U.S. Appl. No. 18/676,573, dated Aug. 27, 2025. [cited by applicant]
Final Office Action, U.S. Appl. No. 18/676,573, dated Dec. 3, 2025. [cited by applicant]
JP Office Action, Patent Application No. 2023-572867 dated Jan. 7, 2025. [cited by applicant]
JP Notice of Allowance, JP Patent Application No. 2023-572867 dated Mar. 4, 2025. [cited by applicant]
Notice of References Cited, U.S. Appl. No. 18/779,134, dated Oct. 23, 2025. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 18/779,134, dated Oct. 23, 2025. [cited by applicant]