IP Library Granted Patent US 12,647,433
Granted Patent B2
US 12,647,433 · App. 18/795,848 · Granted Jun 2, 2026

Real-time prevention of malicious content via dynamic analysis

Inventors: Senthil Cheetancheri (Fremont, CA); Alex Dubrovsky (Los Altos, CA); Sachin Holagi (Fremont, CA)
Assignee: SONICWALL INC.
H04L63/1416G06F21/567H04L63/0245H04L63/1433H04L63/1441H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,433
App. No.
18/795,848
Granted
Jun 2, 2026
Kind
B2
Abstract

This disclosure is related to methods and apparatus used to for preventing malicious content from reaching a destination via a dynamic analysis engine may operate in real-time when packetized data is received. Data packets sent from a source computer may be received and be forwarded to an analysis computer that may monitor actions performed by executable program code included within the set of data packets when making determinations regarding whether the data packet set should be classified as malware. In certain instances all but a last data packet of the data packet set may also be sent to the destination computer while the analysis computer executes and monitors the program code included in the data packet set. In instances when the analysis computer identifies that the data packet set does include malware, the malware may be blocked from reaching the destination computer by not sending the last data packet to the destination computer.

Claims (52)

1 . A method for detecting malicious content, the method comprising:

receiving data at a sandbox device, wherein the data is received from a separate firewall device after the separate firewall device receives the data from a sender device, and wherein a first portion of the data being sent to a destination device while holding a second portion of the data at the separate firewall device until at least after an observation of the data at the sandbox device;

observing that a first action is performed when instructions included in the received data are executed at the sandbox device;

determining a classification of the received data based on the first action, wherein the classification is associated with malware;

sending a message to the separate firewall device regarding the classification of the received data as being associated with malware; and

performing a corrective action based on the classification of the received data as being associated with malware.

2 . The method of claim 1 , wherein the first action includes reorganizing the received data, and further comprising identifying that the first action is malicious based on the reorganization of the received data.

3 . The method of claim 1 , wherein the first action includes accessing a data storage location designated as inappropriate.

4 . The method of claim 1 , wherein the first action includes de-obfuscating a set of the instructions in the received data.

5 . The method of claim 1 , wherein the separate firewall device drops the second portion of the data based on the message.

6 . The method of claim 1 , further comprising:

identifying an attribute associated with the received data; and

storing the attribute in memory, wherein the attribute is stored in association with the received data.

7 . The method of claim 1 , further comprising:

generating a signature from the received data; and

storing the signature at a deep packet inspection data store.

8 . The method of claim 7 , further comprising:

generating a second signature from a second set of the received data;

identifying that the stored signature matches the second signature; and

classifying the second set of received data based on the stored signature matching the second signature.

9 . The method of claim 1 , wherein the first action includes intercepting a basic input/output (BIOS) instruction.

10 . The method of claim 1 , wherein the first action includes preparing to transmit data from the sandbox device.

11 . The method of claim 1 , further comprising performing a deep packet inspection (DPI) scan of the received data in parallel.

12 . The method of claim 11 , wherein determining the classification is based on the DPI scan indicating that the received data matches one or more previously identified patterns, and wherein the first action is observed while the DPI scan is performed by a multi-processor platform associated with the sandbox device.

13 . A non-transitory computer-readable storage medium having embodied thereon a program executable by a processor for implementing a method for detecting malicious content, the method comprising:

receiving data at a sandbox device, wherein the data is received from a separate firewall device after the separate firewall device receives the data from a sender device, and wherein a first portion of the data being sent to a destination device while holding a second portion of the data at the separate firewall device until at least after an observation of the data at the sandbox device;

observing that a first action is performed when instructions included in the received data are executed at the sandbox device;

determining a classification of the received data based on the first action, wherein the classification is associated with malware;

sending a message to the separate firewall device regarding the classification of the received data as being associated with malware; and

performing a corrective action based on the classification of the received data as being associated with malware.

14 . The non-transitory computer-readable storage medium of claim 13 , wherein the first action includes reorganizing the received data, and further comprising instructions executable to identify that the first action is malicious based on the reorganization of the received data.

15 . The non-transitory computer-readable storage medium of claim 13 , wherein the first action includes accessing a data storage location designated as inappropriate.

16 . The non-transitory computer-readable storage medium of claim 13 , further comprising instructions executable to direct the separate firewall device to drop the second portion of the data based on the message.

17 . The method of claim 13 , further comprising instructions executable to:

identify an attribute associated with the received data; and

store the attribute in memory, wherein the attribute is stored in association with the received data.

18 . The method of claim 13 , further comprising instructions executable to:

generate a signature from the received data; and

store the signature at a deep packet inspection data store.

19 . The non-transitory computer-readable storage medium of claim 13 , wherein the first action includes intercepting a basic input/output (BIOS) instruction.

20 . A system for detecting malicious content, the system comprising:

a separate firewall device that:

receives a data set sent from a sender device, wherein the data set is directed to a destination device,

sends the data set for analysis,

sends a first portion of the data set to the destination device, and

holds a second portion of the data set; and

a sandbox device separate from the separate firewall device, wherein the sandbox device:

receives the data set from the separate firewall device,

observes that a first action is performed when instructions included in the first data set are executed,

determines a classification of the received data based on the first action, wherein the classification is associated with malware,

sends a message to the separate firewall device regarding the classification of the received data as being associated with malware, and

performs a corrective action based on the classification of the received data as being associated with malware.

Assignments (2)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071758/0159 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2024
From: CHEETANCHERI, SENTHIL; DUBROVSKY, ALEX; HOLAGI, SACHIN
To: SONICWALL INC.
Reel/Frame 068907/0208 →
Continuity (4)
Continuation 17949796 · Sep 21, 2022
Continuation 17128639 · Dec 21, 2020
Continuation 15671445 · Aug 8, 2017
Related Publication 20250030708A1 · Jan 23, 2025
References Cited (162)
US 6154844A · Touboul et al. · 2000 [cited by applicant]
US 6804780B1 · Touboul · 2004 [cited by applicant]
US 6965968B1 · Touboul · 2005 [cited by applicant]
US 7058822B2 · Edery et al. · 2006 [cited by applicant]
US 7260845B2 · Kedma et al. · 2007 [cited by applicant]
US 7523502B1 · Kennedy et al. · 2009 [cited by applicant]
US 7613926B2 · Edery et al. · 2009 [cited by applicant]
US 7647633B2 · Edery et al. · 2010 [cited by applicant]
US 7934103B2 · Kidron · 2011 [cited by applicant]
US 7962959B1 · Batenin · 2011 [cited by applicant]
US 7971255B1 · Kc et al. · 2011 [cited by applicant]
US 7975305B2 · Rubin et al. · 2011 [cited by applicant]
US 8104089B1 · Guo et al. · 2012 [cited by applicant]
US 8141154B2 · Gruzman et al. · 2012 [cited by applicant]
US 8146151B2 · Hulten et al. · 2012 [cited by applicant]
US 8225408B2 · Rubin et al. · 2012 [cited by applicant]
US 8276202B1 · Dubrovsky et al. · 2012 [cited by applicant]
US 8307432B1 · Feng · 2012 [cited by applicant]
US 8327137B1 · Erb · 2012 [cited by examiner]
US 8413235B1 · Chen et al. · 2013 [cited by applicant]
US 8539578B1 · Zhou et al. · 2013 [cited by applicant]
US 8595829B1 · Kane · 2013 [cited by applicant]
US 8645923B1 · Satish et al. · 2014 [cited by applicant]
US 8677494B2 · Edery et al. · 2014 [cited by applicant]
US 8832836B2 · Thomas et al. · 2014 [cited by applicant]
US 8893278B1 · Chechik · 2014 [cited by examiner]
US 8910238B2 · Lukacs et al. · 2014 [cited by applicant]
US 9141794B1 · Soubramanien et al. · 2015 [cited by applicant]
US 9202048B2 · Sallam · 2015 [cited by applicant]
US 9336386B1 · Qu · 2016 [cited by applicant]
US 9355247B1 · Thioux et al. · 2016 [cited by applicant]
US 9411953B1 · Kane et al. · 2016 [cited by applicant]
US 9430646B1 · Mushtaq · 2016 [cited by examiner]
US 9516055B1 · Liu · 2016 [cited by applicant]
US 9836604B2 · Coronado et al. · 2017 [cited by applicant]
US 9882929B1 · Ettema · 2018 [cited by examiner]
US 9990497B2 · Spernow et al. · 2018 [cited by applicant]
US 10210329B1 · Malik et al. · 2019 [cited by applicant]
US 10515213B2 · Stepan et al. · 2019 [cited by applicant]
US 10685110B2 · Das · 2020 [cited by applicant]
US 10873589B2 · Cheetancheri · 2020 [cited by applicant]
US 10902122B2 · Das · 2021 [cited by applicant]
US 11151252B2 · Das · 2021 [cited by applicant]
US 11232201B2 · Das · 2022 [cited by applicant]
US 11550912B2 · Das · 2023 [cited by applicant]
US 11558405B2 · Cheetancheri · 2023 [cited by applicant]
US 11797677B2 · Dubrovsky et al. · 2023 [cited by applicant]
US 12001554B2 · Das et al. · 2024 [cited by applicant]
US 12058154B2 · Cheetancheri et al. · 2024 [cited by applicant]
US 12079340B2 · Dubrovsky et al. · 2024 [cited by applicant]
US 12130919B2 · Das · 2024 [cited by applicant]
US 20020009079A1 · Jungck et al. · 2002 [cited by applicant]
US 20030033542A1 · Goseva-Popstojanova et al. · 2003 [cited by applicant]
US 20030140248A1 · Izatt · 2003 [cited by applicant]
US 20060155865A1 · Brandt · 2006 [cited by examiner]
US 20060224724A1 · Marinescu · 2006 [cited by examiner]
US 20070050848A1 · Khalid · 2007 [cited by applicant]
US 20070157203A1 · Lim · 2007 [cited by applicant]
US 20070256127A1 · Kraemer et al. · 2007 [cited by applicant]
US 20070261112A1 · Todd et al. · 2007 [cited by applicant]
US 20080016339A1 · Shukla · 2008 [cited by applicant]
US 20090070876A1 · Kim et al. · 2009 [cited by applicant]
US 20100024033A1 · Kang et al. · 2010 [cited by applicant]
US 20100185876A1 · Kim · 2010 [cited by applicant]
US 20100269171A1 · Raz · 2010 [cited by examiner]
US 20110047620A1 · Mahaffey et al. · 2011 [cited by applicant]
US 20110078794A1 · Manni et al. · 2011 [cited by applicant]
US 20110277033A1 · Ramchetty et al. · 2011 [cited by applicant]
US 20110302656A1 · El-Moussa · 2011 [cited by applicant]
US 20120266243A1 · Turkulainen · 2012 [cited by applicant]
US 20130007884A1 · Franklin et al. · 2013 [cited by applicant]
US 20130080625A1 · Morinaga et al. · 2013 [cited by applicant]
US 20130091584A1 · Liebmann et al. · 2013 [cited by applicant]
US 20130276056A1 · Epstein · 2013 [cited by applicant]
US 20140115652A1 · Kapoor · 2014 [cited by applicant]
US 20140181976A1 · Snow et al. · 2014 [cited by applicant]
US 20140208426A1 · Natarajan et al. · 2014 [cited by applicant]
US 20140215621A1 · Xaypanya et al. · 2014 [cited by applicant]
US 20150089651A1 · Mirski et al. · 2015 [cited by applicant]
US 20150096018A1 · Mircescu · 2015 [cited by applicant]
US 20150096022A1 · Vincent et al. · 2015 [cited by applicant]
US 20150227742A1 · Pereira · 2015 [cited by applicant]
US 20160098560A1 · Friedrichs et al. · 2016 [cited by applicant]
US 20160099963A1 · Mahaffey et al. · 2016 [cited by applicant]
US 20160110542A1 · Shanbhogue et al. · 2016 [cited by applicant]
US 20160357958A1 · Guidry · 2016 [cited by applicant]
US 20160378640A1 · Hron · 2016 [cited by applicant]
US 20170171240A1 · Arzi et al. · 2017 [cited by applicant]
US 20170289176A1 · Chen et al. · 2017 [cited by applicant]
US 20170329621A1 · Beckett · 2017 [cited by applicant]
US 20180018459A1 · Zhang et al. · 2018 [cited by applicant]
US 20180052720A1 · Ionescu et al. · 2018 [cited by applicant]
US 20180288097A1 · Poornachandran · 2018 [cited by applicant]
US 20190052651A1 · Cheetancheri · 2019 [cited by applicant]
US 20190065740A1 · van Riel et al. · 2019 [cited by applicant]
US 20190087572A1 · Ellam · 2019 [cited by applicant]
US 20190114421A1 · Das et al. · 2019 [cited by applicant]
US 20190205537A1 · Das et al. · 2019 [cited by applicant]
US 20190236275A1 · Das et al. · 2019 [cited by applicant]
US 20190342313A1 · Watkiss et al. · 2019 [cited by applicant]
US 20190347413A1 · Dubrovsky et al. · 2019 [cited by applicant]
US 20190354680A1 · De Lima, Jr. et al. · 2019 [cited by applicant]
US 20200380127A1 · Das · 2020 [cited by applicant]
US 20210185062A1 · Cheetancheri · 2021 [cited by applicant]
US 20220035919A1 · Das · 2022 [cited by applicant]
US 20220222343A1 · Dubrovsky et al. · 2022 [cited by applicant]
US 20230020421A1 · Cheetancheri · 2023 [cited by applicant]
US 20230222214A1 · Das et al. · 2023 [cited by applicant]
US 20240012907A1 · Dubrovsky et al. · 2024 [cited by applicant]
US 20240370561A1 · Das et al. · 2024 [cited by applicant]
US 20240427889A1 · Dubrovsky et al. · 2024 [cited by applicant]
US 20250124128A1 · Das et al. · 2025 [cited by applicant]
CA 3017941 · 2017 [cited by applicant]
EP 3665573 · 2020 [cited by applicant]
EP 3732571 · 2020 [cited by applicant]
EP 4177779 · 2023 [cited by applicant]
EP 242036424 · 2024 [cited by applicant]
EP 4474993 · 2024 [cited by applicant]
GB 2553033 · 2018 [cited by applicant]
WO WO2019032702 · 2019 [cited by applicant]
WO WO2019075388 · 2019 [cited by applicant]
WO WO2019133637 · 2019 [cited by applicant]
WO WO2019222261 · 2019 [cited by applicant]
Nethercote, Nicholas; “Dynamic binary analysis and instrumentation”, Technical Report, UCAM-CL-TR-606, ISSN 1476-2986, Nov. 2004. [cited by applicant]
Software Instrumentation, Wiley Encyclopedia of Computer Science and Engineering, edited by Benjamin Wah. Copyright 2008 John Wiley & Sons, Inc. [cited by applicant]
“XOR Cipher—Wikipedia”, Mar. 19, 2017, XP055758581, Retrieved from the Internet: URL:https://en.wikipedia.org/w/index.php?title=XOR_cipher&oldid=771112755 [retrieved on Dec. 9, 2020]. [cited by applicant]
SNWL-153EP European Application No. 18844091.1 Extended European Search Report dated Jan. 19, 2021. [cited by applicant]
SNWL-153EPDVA European Application No. 22208411.3 Extended European Search Report dated Mar. 21, 2023. [cited by applicant]
SNWL-155EP European Application No. 18894474.8 Extended European Search Report dated Aug. 3, 2021. [cited by applicant]
PCT Application No. PCT/US2018/045814 International Preliminary Report on Patentability dated Feb. 11, 2020; 8 pages. [cited by applicant]
PCT Application No. PCT/US2018/045814 International Search Report and Written Opinion dated Oct. 19, 2018; 9 pages. [cited by applicant]
PCT Application No. PCT/US2018/055694 International Preliminary Report on Patentability dated Apr. 14, 2020; 7 pages. [cited by applicant]
PCT Application No. PCT/US2018/055694 International Search Report and Written Opinion dated Feb. 11, 2019; 8 pages. [cited by applicant]
PCT Application No. PCT/US2018/067541 International Preliminary Report on Patentability dated Jun. 30, 2020; 7 pages. [cited by applicant]
PCT Application No. PCT/US2018/067541 International Search Report and Written Opinion dated Mar. 27, 2019; 7 pages. [cited by applicant]
PCT Application No. PCT/US2019/032283 International Preliminary Report on Patentability dated Nov. 17, 2020; 9 pages. [cited by applicant]
PCT Application No. PCT/US2019/032283 International Search Report and Written Opinion dated Sep. 12, 2019; 10 pages. [cited by applicant]
European Application No. 22208411.3, First Examination Report dated Jun. 30, 2025. [cited by applicant]
Parsons, Christopher; Chapter One: Deep Packet Inspection and Its Predecessors, Feb. 6, 2012: Version 3.5. [cited by applicant]
European Application No. 24203642.4, Extended European Search Report dated Dec. 11, 2024. [cited by applicant]
U.S. Appl. No. 15/783,793, Office Action dated Apr. 16, 2020. [cited by applicant]
U.S. Appl. No. 15/671,445 Office Action mailed May 14, 2020. [cited by applicant]
U.S. Appl. No. 15/671,445 Final Office Action mailed Aug. 15, 2019. [cited by applicant]
U.S. Appl. No. 15/671,445 Office Action mailed Feb. 25, 2019. [cited by applicant]
U.S. Appl. No. 17/949,796 Office Action mailed Sep. 14, 2023. [cited by applicant]
U.S. Appl. No. 15/783,793 Office Action mailed Feb. 22, 2021. [cited by applicant]
U.S. Appl. No. 15/783,793 Final Office Action mailed Oct. 14, 2020. [cited by applicant]
U.S. Appl. No. 15/783,793 Office Action mailed Apr. 16, 2019. [cited by applicant]
U.S. Appl. No. 15/783,793 Final Office Action mailed Dec. 11, 2019. [cited by applicant]
U.S. Appl. No. 15/783,793 Office Action mailed Jun. 28, 2019. [cited by applicant]
U.S. Appl. No. 17/505,327 Office Action mailed Aug. 16, 2023. [cited by applicant]
U.S. Appl. No. 15/858,785 Office Action mailed Sep. 6, 2019. [cited by applicant]
U.S. Appl. No. 16/903,060 Office Action mailed May 12, 2022. [cited by applicant]
U.S. Appl. No. 18/095,340 dated Jan. 5, 2024. [cited by applicant]
U.S. Appl. No. 15/890,192 Office Action mailed Jun. 11, 2020. [cited by applicant]
U.S. Appl. No. 15/890,192 Final Office Action mailed Jan. 21, 2020. [cited by applicant]
U.S. Appl. No. 15/890,192 Office Action mailed Oct. 4, 2019. [cited by applicant]
U.S. Appl. No. 16/055,958 Office Action mailed Mar. 25, 2021. [cited by applicant]
U.S. Appl. No. 16/055,958 Final Office Action mailed Oct. 9, 2020. [cited by applicant]
U.S. Appl. No. 16/055,958 Office Action mailed Apr. 21, 2020. [cited by applicant]
U.S. Appl. No. 17/584, 152 Office Action mailed Feb. 16, 2023. [cited by applicant]
EPO Article 94(3) EPC mailed in EP Application No. 22208411.3 on Mar. 6, 2026, 7 pages. [cited by applicant]