IP Library › Granted Patent US 12,524,540
Granted Patent B2
US 12,524,540 · App. 18/141,093 · Granted Jan 13, 2026

Malicious pattern extraction via fuzzing

Inventors: Zhibin Zhang (Santa Clara, CA); Bo Qu (Saratoga, CA); Tao Yan (San Jose, CA); ChienHua Lu (San Jose, CA)
Assignee: Palo Alto Networks, Inc.
G06F21/564G06F21/566G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,524,540
App. No.
18/141,093
Granted
Jan 13, 2026
Kind
B2
Abstract

Various techniques for malicious pattern extraction via fuzzing are disclosed. In some embodiments, a system/process/computer program product for malicious pattern extraction via fuzzing includes receiving a malicious sample (e.g., the malicious sample can be an executable file, such as a binary, script, etc., or a file that includes content for inputting into an application, such as for an office productivity suite or another application); mutating the malicious sample using fuzzing; and generating a signature based on a critical path (e.g., a malware signature can be automatically generated by a cloud security service for detection of the malicious sample, and the cloud security service can distribute the malware signature to a plurality of firewalls and/or other security entities to subscribers of a security service).

Claims (45)

1 . A system, comprising:

a processor configured to:

receive a malicious sample;

mutate the malicious sample using fuzzing to obtain a critical path, comprising to:

modify the malicious sample to identify mutation targets for fuzzing;

determine that a different behavior of the modified malicious sample is observed based on an execution flow of the modified malicious sample;

in response to a determination that the different behavior of the modified malicious sample is observed, store the observed different behavior of the modified malicious sample; and

detect the critical path for the malicious sample based on the stored the observed different behavior;

generate a signature based on the critical path; and

distribute the signature to a security service for detection of the malicious sample; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system of claim 1 , wherein the signature is a malware signature that is automatically generated.

3 . The system of claim 1 , wherein the signature is a malware signature that is automatically generated by a cloud security service for detection of the malicious sample.

4 . The system of claim 1 , wherein the signature is a malware signature that is automatically generated by a cloud security service for detection of the malicious sample, and wherein the cloud security service distributes the malware signature to subscribers of a security service.

5 . The system of claim 1 , wherein the signature is a malware signature that is automatically generated by a cloud security service for detection of the malicious sample, and wherein the cloud security service distributes the malware signature to subscribers of a security service for an intrusion detection system (IDS) and/or an intrusion prevention system (IPS).

6 . The system of claim 1 , wherein the signature is a malware signature that is automatically generated by a cloud security service for detection of the malicious sample, and wherein the cloud security service distributes the malware signature to a plurality of firewalls to subscribers of a security service.

7 . The system of claim 1 , wherein the malicious sample is associated with an executable file or a file that includes content for inputting into an application.

8 . The system of claim 1 , wherein the signature is verified to check for false positives.

9 . The system of claim 1 , wherein the processor is further configured to:

analyze execution flow of the malicious sample to identify mutation targets for fuzzing.

10 . A method, comprising:

receiving a malicious sample;

mutating the malicious sample using fuzzing to obtain a critical path, comprising:

modifying the malicious sample to identify mutation targets for fuzzing;

determining that a different behavior of the modified malicious sample is observed based on an execution flow of the modified malicious sample;

in response to a determination that the different behavior of the modified malicious sample is observed, storing the observed different behavior of the modified malicious sample; and

detecting the critical path for the malicious sample based on the stored the observed different behavior;

generating a signature based on the critical path; and

distributing the signature to a security service for detection of the malicious sample.

11 . The method of claim 10 , wherein the signature is a malware signature that is automatically generated.

12 . The method of claim 10 , wherein the signature is a malware signature that is automatically generated by a cloud security service for detection of the malicious sample.

13 . The method of claim 10 , wherein the signature is a malware signature that is automatically generated by a cloud security service for detection of the malicious sample, and wherein the cloud security service distributes the malware signature to subscribers of a security service.

14 . The method of claim 10 , wherein the signature is a malware signature that is automatically generated by a cloud security service for detection of the malicious sample, and wherein the cloud security service distributes the malware signature to subscribers of a security service for an intrusion detection system (IDS) and/or an intrusion prevention system (IPS).

15 . The method of claim 10 , wherein the signature is a malware signature that is automatically generated by a cloud security service for detection of the malicious sample, and wherein the cloud security service distributes the malware signature to a plurality of firewalls to subscribers of a security service.

16 . The method of claim 10 , wherein the malicious sample is associated with an executable file or a file that includes content for inputting into an application.

17 . A computer program product embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

receiving a malicious sample;

mutating the malicious sample using fuzzing to obtain a critical path, comprising:

modifying the malicious sample to identify mutation targets for fuzzing;

determining that a different behavior of the modified malicious sample is observed based on an execution flow of the modified malicious sample;

in response to a determination that the different behavior of the modified malicious sample is observed, storing the observed different behavior of the modified malicious sample; and

detecting the critical path for the malicious sample based on the stored the observed different behavior;

generating a signature based on the critical path; and

distributing the signature to a security service for detection of the malicious sample.

18 . The computer program product recited in claim 17 , wherein the signature is a malware signature that is automatically generated.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2023
From: ZHANG, ZHIBIN; QU, BO; YAN, TAO; LU, CHIENHUA
To: PALO ALTO NETWORKS, INC.
Reel/Frame 064247/0329 →
Continuity (1)
Related Publication 20240362327A1 · Oct 31, 2024
References Cited (22)
US 8261366B2 · Shuster · 2012 [cited by applicant]
US 8407789B1 · Mears · 2013 [cited by applicant]
US 8448245B2 · Banerjee · 2013 [cited by applicant]
US 8499283B2 · Mony · 2013 [cited by applicant]
US 8997219B2 · Staniford · 2015 [cited by applicant]
US 10783247B1 · Steinfadt · 2020 [cited by examiner]
US 20060064755A1 · Azadet · 2006 [cited by examiner]
US 20110247072A1 · Staniford · 2011 [cited by applicant]
US 20110289582A1 · Kejriwal · 2011 [cited by applicant]
US 20120084859A1 · Radinsky · 2012 [cited by applicant]
US 20130097705A1 · Montoro · 2013 [cited by applicant]
US 20130145466A1 · Richard · 2013 [cited by applicant]
US 20190065746A1 · Alsulami · 2019 [cited by examiner]
US 20240259347A1 · Grover · 2024 [cited by examiner]
EP 4254869A2 · 2023 [cited by examiner]
Babu et al., “Adaptive Ordering of Pipelined Stream Filters”, 2014. [cited by applicant]
Dynamorio, Existing DynamoRIO-Based Tools, downloaded Apr. 27, 2023. [cited by applicant]
Jarle Kittilsen, “Detecting malicious PDF documents”, master thesis for Department of Computer Science and Media Technology, Gjøvik University College, Norway; Jan. 12, 2011. [cited by applicant]
Laskov et al., 2011, Static Detection of Malicious JavaScript-Bearing PDF Documents, In Proceedings of the 27th Annual Computer Security Applications Conference (ACSAC '11). ACM, New York, NY, USA, 373-382. D01=10.1145/… [cited by applicant]
Paul Baccas, Finding Rules for Heuristic Detection of Malicious PDFS: with Analysis of Embedded Exploit Code, Virus Bulletin Conference, Sep. 2010. [cited by applicant]
Tao et al., A Novel Framework for Learning to Detect Malicious Web Pages, 2010 International Forum on Information Technology and Applications, IEEE 2010. [cited by applicant]
Wikipedia, How to get a Backtrace with WinDbg—The Document Foundation Wiki, downloaded Apr. 27, 2023. [cited by applicant]