IP Library Granted Patent US 12,536,281
Granted Patent B1
US 12,536,281 · App. 19/227,656 · Granted Jan 27, 2026

Systems and methods for malware detection in portable executable files

Inventors: Chenggang Tong (Singapore, SG); Fan Liu (Singapore, SG); Yingfei Wang (Singapore, SG)
Assignee: Morgan Stanley Services Group Inc.
G06F21/56G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,536,281
App. No.
19/227,656
Granted
Jan 27, 2026
Kind
B1
Abstract

Systems and methods for detecting malware in portable executable (PE) files is provided. A PE file can be received by a server, the PE file can be decompiled into p-code, and one or more predetermined variables can be extracted from the p-code, where the one or more predetermined variables are potentially malicious. The one or more predetermined variables can be backward to its respective source and constant values found in the one or more predetermined variables can be extracted. The constant values can indicate the PE file as malware and preventing the PE file from being executed.

Claims (36)

1 . A method for detecting malware in portable executable (PE) files, the method comprising:

receiving, by a server, a PE file;

decompiling, by the server, the PE file into p-code;

extracting, by the server, one or more predetermined variables from the p-code, wherein the one or more predetermined variables are potentially malicious;

obtaining, by the server, a p-code varnode of each of the one or more predetermined variables;

tracking, by the server, the one or more predetermined variables backward to its respective source by:

i) for a p-code varnode that is not a constant value, determining which next p-code varnode to consider next based on an instruction type of the p-code varnode to track backward to arrive at a constant, and

ii) for a p-code varnode that is a constant, extracting the constant values;

determining, by the server, whether the constant values indicate the PE file as malware; and

preventing, by the server, the PE file from being executed.

2 . The method of claim 1 further comprising locating one or more API calls in the decompiled PE file, and wherein extracting the one or more predetermined variables is based on an API definition database.

3 . The method of claim 1 wherein tracking the one or more predetermined variables backward further comprises creating a data flow of all points reached during the backward tracking.

4 . The method of claim 1 further comprising parsing, by the server, the PE file to filter known malware.

5 . The method of claim 1 wherein determining which next p-code varnode to consider next based on an instruction type of the p-code varnode to track backward to arrive at a constant further comprises:

for a p-code varnode having instruction type “INDIRECT” setting the next p-code varnode to consider is the second of two input operand varnodes.

6 . The method of claim 1 wherein determining which next p-code varnode to consider next based on an instruction type of the p-code varnode to track backward to arrive at a constant further comprises:

for a p-code varnode having instruction type “INT_NEGATE”, “INT_ZEXT”, “INTSEXT”, or “CAST, COPY” setting the next p-code varnode to consider as the only input operand varnodes.

7 . The method of claim 1 wherein determining which next p-code varnode to consider next based on an instruction type of the p-code varnode to track backward to arrive at a constant further comprises:

for a p-code varnode having instruction type “INT_ADD”, “INT_SUB”, “INT_MULT”, “INT_DIV”, “INT_AND”, “INT_OR”, “INT_XOR”, or “PIECE, PTRSUB” setting the next p-code varnode to consider as two input operand varnodes.

8 . The method of claim 1 wherein determining which next p-code varnode to consider next based on an instruction type of the p-code varnode to track backward to arrive at a constant further comprises:

for a p-code varnode having instruction type “MULTIEQUAL” setting the next p-code varnode to consider as all input operand varnodes.

9 . One or more non-transitory computer-readable storage media comprising instructions that are executable to cause one or more processors to:

receive a PE file;

decompile the PE file into p-code;

extract one or more predetermined variables from the p-code, wherein the one or more predetermined variables are potentially malicious;

obtaining a p-code varnode of each of the one or more predetermined variables;

track the one or more predetermined variables backward to its respective source by:

i) for a p-code varnode that is not a constant value, determine which next p-code varnode to consider next based on an instruction type of the p-code varnode to track backward to arrive at a constant, and

ii) for a p-code varnode that is a constant, extract the constant values;

extract constant values found in the one or more predetermined variables;

determine, whether the constant values indicate the PE file as malware; and

prevent the PE file from being executed.

10 . The one or more non-transitory computer-readable storage media of claim 9 wherein the one or more processors is further configured to:

locate one or more API calls in the decompiled PE file, and wherein extracting the one or more predetermined variables is based on an API definition database.

11 . The one or more non-transitory computer-readable storage media of claim 9 wherein the tracking further causes the one or more processors to create a data flow of all points reached during the backward tracking.

12 . The one or more non-transitory computer-readable storage media of claim 9 wherein the one or more processors is further configured to parse the PE file to filter known malware.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 4, 2025
From: TONG, CHENGGANG; LIU, FAN; WANG, YINGFEI
To: MORGAN STANLEY SERVICES GROUP INC.
Reel/Frame 071312/0512 →
References Cited (43)
US 6971019B1 · Nachenberg · 2005 [cited by examiner]
US 7370360B2 · van der Made · 2008 [cited by examiner]
US 8881293B1 · Brucker · 2014 [cited by examiner]
US 9213838B2 · Lu · 2015 [cited by applicant]
US 9454659B1 · Daymont · 2016 [cited by examiner]
US 9594904B1 · Jain · 2017 [cited by applicant]
US 9792443B1 · Sheridan · 2017 [cited by examiner]
US 9870471B2 · Shen et al. · 2018 [cited by applicant]
US 10007789B2 · Kim et al. · 2018 [cited by applicant]
US 10033747B1 · Paithane et al. · 2018 [cited by applicant]
US 10083298B1 · Krishnappa · 2018 [cited by examiner]
US 10354069B2 · Gray · 2019 [cited by examiner]
US 10416970B2 · Takata et al. · 2019 [cited by applicant]
US 11354409B1 · Kenefick · 2022 [cited by applicant]
US 12050687B1 · Tong et al. · 2024 [cited by applicant]
US 20080263669A1 · Alme · 2008 [cited by applicant]
US 20090254992A1 · Schultz · 2009 [cited by examiner]
US 20120317644A1 · Kumar et al. · 2012 [cited by applicant]
US 20130185798A1 · Saunders · 2013 [cited by examiner]
US 20160057159A1 · Yin · 2016 [cited by applicant]
US 20190114417A1 · Subbarayan · 2019 [cited by applicant]
US 20190129825A1 · Bardin · 2019 [cited by examiner]
US 20190220596A1 · Lie · 2019 [cited by examiner]
US 20200250015A1 · Zhi · 2020 [cited by applicant]
US 20210141897A1 · Seifert et al. · 2021 [cited by applicant]
US 20210374241A1 · Parikh et al. · 2021 [cited by applicant]
US 20220083661A1 · Ma et al. · 2022 [cited by applicant]
US 20220129564A1 · Hecht · 2022 [cited by applicant]
US 20220300615A1 · Sahu · 2022 [cited by examiner]
US 20230367516A1 · Zhang · 2023 [cited by applicant]
US 20240007492A1 · Shen · 2024 [cited by applicant]
US 20250077201A1 · Ring · 2025 [cited by examiner]
US 20250117479A1 · Yang · 2025 [cited by examiner]
CN 107908963 · 2018 [cited by applicant]
CN 109543410 · 2019 [cited by applicant]
EP 1706833 · 2006 [cited by applicant]
WO WO2006006144 · 2006 [cited by applicant]
Mei Rui, Yan Han-Bing, Shen Yuan, Han Zhi-Hui. Application Research of Slicing Technology of Binary Executables in Malware Detection. Journal of Cyber Security. vol. 6 No. 3. May 2021. [cited by applicant]
Wenjie Guo, Jingfeng Xue, Wenheng Meng, Weijie Han, Zishu Liu, Yong Wang, Zhongjun Li. MalOSDF: An Opcode Slice-Based Malware Detection Framework Using Active and Ensemble Learning. Electronics 2024, 13, 359. [cited by applicant]
Igor Santos, Felix Brezo, Xabier Ugarte-Pedrero, Pablo G. Bringas. Opcode sequences as representation of executables for data-mining-based unknown malware detection. Information Sciences 231 (2013) 64-82. [cited by applicant]
Yulei Sui, Jingling Xue. SVF: Interprocedural Static Value-Flow Analysis in LLVM. [cited by applicant]
Saurabh Sinha, Mary Jean Harrold, Gregg Rothermel. System-Dependence-Graph-Based Slicing of Programs with Arbitrary Interprocedural Control Flow. [cited by applicant]
Chen et al., Malware Classification Using Static Disassembly and Machine Learning, arXiv:2201.07649v1, [cs.CR] dated Dec. 10, 2021, 9 pages. [cited by applicant]