IP Library › Granted Patent US 12,579,267
Granted Patent B2
US 12,579,267 · App. 18/224,628 · Granted Mar 17, 2026

Methods and systems for analyzing environment-sensitive malware with coverage-guided fuzzing

Inventors: Daniele Cono D'Elia (Teggiano, IT); Nicola Bottura (Gonzaga, IT)
Assignees: Daniele Cono D'Elia; PRISMA S.R.L.
G06F21/566G06F21/54G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,579,267
App. No.
18/224,628
Granted
Mar 17, 2026
Kind
B2
Abstract

The present invention concerns methods and systems for analyzing a software program as a potential environment-sensitive malware sample. The methods and systems described here may comprise monitoring access to environmental information, altering according to an execution policy the contents of environmental information items before retrieval by the program, recording as coverage information the internal states and the externally observable actions from the program execution, using recoded coverage information to generate in a fuzzing fashion execution policies with new contents for environmental information items, and identifying execution policies that induce previously unseen internal states and externally observable actions for the program.

Claims (55)

1 . A method for analyzing an untrusted software program for potential environment-sensitive behavior, the method comprising the use of:

an execution monitor running on an execution system, the execution system including computer hardware and operating system, environmental information items, and having interposition capabilities;

a database of sets of information including rules and execution policies, the rules defining actions to be taken by the execution monitor when interposing on requests of access from a software program to said environmental information items, the database being accessible to said execution monitor;

the following steps being performed by the execution monitor:

A generating a new execution policy by means of random, coverage-guided fuzzing-style mutations of the rules in the execution policy, wherein the random, coverage-guided fuzzing-style mutations are made on the basis of said information about the actions recorded in the external coverage information to generate modifications to the rules in the execution policy, and wherein the new execution policy is set as the current execution policy;

B starting and monitoring an execution of the untrusted software program;

C interposing on accesses requested by the untrusted software program to one or more of the environmental information items;

D altering a response of the execution system to said requested accesses by taking the actions according to the current execution policy;

E recording, as external coverage information for guiding subsequent policy generation:

information about the actions invoked by the untrusted software program and regulated by the execution monitor under the current execution policy when accessing environmental information items; and

information about possible transient and permanent changes done by the untrusted software program's execution to the execution system under the current execution policy;

F recording, as internal coverage information, information about internal program states, including code portions traversed by the untrusted software program's execution under the current execution policy, and data flows of the program, including values for input parameters when the program uses library functions or comparison instructions; and

X1 selecting an execution policy from the database with internal and external coverage information from a previous execution of step E and F, or

X2 setting an execution policy when there is no internal and external coverage information as defined in step E and F, and executing steps B-F before starting step A;

and wherein the following steps are carried out at the end of said execution of the untrusted software program:

G determining if the recorded internal and external coverage information for the current execution policy reveals novel information indicative of previously unobserved program states or actions, thereby providing feedback for adaptive policy generation compared to a plurality of prior executions of the untrusted software program;

H if step G determines no novel information, discarding the current policy, and starting again from steps X1 and X2;

I if step G determines novel information:

I1 saving said novel information into the current execution policy and updating the database by adding the current execution policy to it; and then

I2 if step E detects no transient or permanent changes, performing again steps A-I; or

I3 if step E detects transient and/or permanent changes, reporting to a user that an instance of environment-sensitive behavior has been revealed for the untrusted software program.

2 . The method of claim 1 , wherein the software program is a binary executable.

3 . The method of claim 2 , wherein dynamic binary instrumentation is used for steps B-F.

4 . The method of claim 1 , wherein accesses to environmental information items include one or more of: the invocation of operating system APIs for querying environmental information, the use of CPU instructions that provide direct access to environmental information, and direct accesses to shared-memory regions mapped in the process space of the program.

5 . The method of claim 4 , wherein the operating system APIs for querying environmental information are configured to access or check the existence of one or more of: files, processes, registry contents, hardware interfaces, timing sources, application windows, and configuration parameters of the operating system.

6 . The method of claim 5 , wherein a rule from an execution policy for an access to an environmental information item can prescribe one of: modifying the contents of the item before its retrieval by the program, denying the access, or forging a fake result for the access when it would be denied by the normal operation of the underlying execution system.

7 . The method of claim 1 , where external coverage information of step E include one or more of: attempted network communications, the creation or opening of inter-process communication objects, the creation, modification or removal of files, processes, application windows, and configuration parameters of the operating system.

8 . The method of claim 1 , wherein random, coverage-guided fuzzing-style mutations over the current execution policy can make one or more of the following: adding rules, deleting an existing rule, and modifying an existing rule in its data manipulation criteria.

9 . The method of claim 8 , wherein added and/or deleted and/or modified rules are based on the information about the actions invoked by the software program and regulated by the execution monitor of step E.

10 . The method of claim 9 , wherein added and/or deleted, and/or modified rules are additionally based on the internal coverage information, wherein the internal coverage information of step F includes the data flows from the software program as recorded when the program executes a code that compares strings or other byte sequences, wherein said code is a standard library function or one or more comparison instructions in the code of the untrusted software program.

11 . The method of claim 1 , wherein the information about transient and permanent changes of step E include one or more of: creation, modification or removal of files, processes, application windows, and configuration parameters of the operating system, where applicable, network communications attempts, and the creation or opening of temporary objects such as mutexes and other inter-process communication objects.

12 . A system comprising:

a processor; and

a memory communicatively coupled to the processor, the memory including:

an untrusted software program;

an execution monitor;

a database of execution policies;

wherein the execution monitor is configured to perform the following steps:

A generating a new execution policy by means of random, coverage-guided fuzzing-style mutations of the rules in the execution policy, wherein the random, coverage-guided fuzzing-style mutations are made on the basis of said information about the actions recorded in the external coverage information to generate modifications to the rules in the execution policy, and wherein the new execution policy is set as the current execution policy;

B starting and monitoring an execution of the untrusted software program;

C interposing on accesses requested by the untrusted software program to one or more of the environmental information items;

D altering a response of the execution system to said requested accesses by taking the actions according to the current execution policy;

E recording, as external coverage information for guiding subsequent policy generation: information about the actions invoked by the untrusted software program and regulated by the execution monitor under the current execution policy when accessing environmental information items; and

information about possible transient and permanent changes done by the untrusted software program's execution to the execution system under the current execution policy;

F recording, as internal coverage information, information about internal program states, including code portions traversed by the untrusted software program's execution under the current execution policy, and data flows of the program, including values for input parameters when the program uses library functions or comparison instructions; and

X1 selecting an execution policy from the database with internal and external coverage information from a previous execution of step E and F, or

X2 setting an execution policy when there is no internal and external coverage information as defined in step E and F, and executing steps B-F before starting step A;

and wherein the following steps are carried out at the end of said execution of the untrusted software program:

G determining if the recorded internal and external coverage information for the current execution policy reveals novel information indicative of previously unobserved program states or actions, thereby providing feedback for adaptive policy generation compared to a plurality of prior executions of the untrusted software program;

H if step G determines no novel information, discarding the current policy, and starting again from steps X1 and X2;

I if step G determines novel information:

I1 saving said novel information into the current execution policy and updating the database by adding the current execution policy to it; and then

I2 if step E detects no transient or permanent changes, performing again steps A-I; or

I3 if step E detects transient and/or permanent changes, reporting to a user that an instance of environment-sensitive behavior has been revealed for the untrusted software program.

13 . The method of claim 11 , wherein the temporary objects are mutexes and other inter-process communication objects.

Assignments (2)
CHANGE OF APPLICANTS ADDRESS FROM VIA MARIO BIANCHINI 51, ROMA, ITALY 00142 TO VIA MOSCA 45, ROMA, ITALY 00142 Recorded Jan 22, 2026
From: PRISMA S.R.L.
To: PRISMA S.R.L.
Reel/Frame 074476/0581 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2023
From: D'ELIA, DANIELE CONO; BOTTURA, NICOLA
To: PRISMA S.R.L.; D'ELIA, DANIELE CONO
Reel/Frame 064336/0020 →
Priority Claims (1)
IT 102022000015966 · Jul 28, 2022 · national
Continuity (1)
Related Publication 20240045961A1 · Feb 8, 2024
References Cited (31)
US 9361459B2 · Kolbitsch et al. · 2016 [cited by applicant]
US 9900324B1 · Barua et al. · 2018 [cited by applicant]
US 10311235B2 · Bobritsky et al. · 2019 [cited by applicant]
US 10546128B2 · Gu et al. · 2020 [cited by applicant]
US 10735441B2 · Anderson et al. · 2020 [cited by applicant]
US 10747872B1 · Ha et al. · 2020 [cited by applicant]
US 20140317745A1 · Kolbitsch · 2014 [cited by examiner]
US 20150007325A1 · Eliseev · 2015 [cited by examiner]
US 20160259939A1 · Bobritsky et al. · 2016 [cited by applicant]
US 20210211438A1 · Trim et al. · 2021 [cited by applicant]
US 20210374241A1 · Parikh et al. · 2021 [cited by applicant]
US 20230281322A1 · Powers · 2023 [cited by examiner]
Fuzzingbook 2022, The Fuzzing Book. 2022 edition, CISPA Helmholtz Center for Information Security. [cited by applicant]
Banescu et al., Chapter Five—a Tutorial on Software Obfuscation, Advances in Computers, 2018, pp. 283-353, vol. 108, Elsevier. [cited by applicant]
Lengyel et al., Scalability, fidelity and stealth in the DRAKVUF dynamic malware analysis system, ACSAC '14: Proceedings of the 30th Annual Computer Security Applications Conference, Dec. 2014, pp. 386-395, ACM. [cited by applicant]
Oyama Y., How does Malware Use RDTSC? A Study on Operations Executed by Malware with CPU Cycle Measurement, in Detection of Intrusions and Malware, and Vulnerability Assessment, 16th International Conference, DIMVA 2019… [cited by applicant]
Xu et al., GoldenEye: Efficiently and Effectively Unveiling Malware's Targeted Environment, in Research in Attacks, Intrusions and Defenses, 17th International Symposium, RAID 2014, Gothenburg, Sweden, Sep. 17-19, 2014,… [cited by applicant]
Aschermann et al., REDQUEEN: Fuzzing with Input-to-State Correspondence, Network and Distributed Systems Security (NDSS), Symposium 2019, Feb. 24-27, 2019, pp. 1-15, San Diego, CA, US, Internet Society. [cited by applicant]
Baldoni et al., A Survey of Symbolic Execution Techniques, ACM Computing Surveys, published online May 23, 2018, pp. 1-39, Article No. 50, vol. 51, Issue 3, ACM Journals. [cited by applicant]
Brengel et al., Detecting Hardware-Assisted Virtualization, in Detection of Intrusions and Malware, and Vulnerability Assessment, 13th International Conference DIMVA 2016, San Sebastian, Spain, Jul. 7-8, 2016, Proceedin… [cited by applicant]
Cavallaro et al., On the Limits of Information Flow Techniques for Malware Analysis and Containment, in Detection of Intrusions and Malware, and Vulnerability Assessment, 5th International Conference, DIMVA 2008, Paris,… [cited by applicant]
D'Elia et al., On the Dissection of Evasive Malware, IEEE Transactions on Information Forensics and Security, 2020, pp. 2750-2765, vol. 15, IEEE. [cited by applicant]
Dinaburg et al., Ether: malware analysis via hardware virtualization extensions, CCS '08: Proceedings of the 15th ACM conference on Computer and communications security, Oct. 2008, pp. 51-62, ACM. [cited by applicant]
Garfinkel et al., Compatibility is not transparency: VMM detection myths and realities, Proceedings of HOTOS'07: 11th 11th Workshop on Hot Topics in Operating Systems, May 7-9, 2005, San Diego, CA, US, 2007, Article No.… [cited by applicant]
Jung et al., Winnie: Fuzzing Windows Applications with Harness Synthesis and Fast Cloning, Network and Distributed Systems Security (NDSS) Symposium 2021, Feb. 21-25, 2021, Internet Society. [cited by applicant]
Maffia et al., Longitudinal Study of the Prevalence of Malware Evasive Techniques, Dec. 21, 2021, arXiv technical report https://arxiv.org/abs/2112.11289. [cited by applicant]
Ollivier et al., How to Kill Symbolic Deobfuscation for Free (or: Unleashing the Potential of Path-Oriented Protections), ACSAC '19: Dec. 9-13, 2019, San Juan, PR, US, pp. 177-189, ACM. [cited by applicant]
Pham et al., Smart Greybox Fuzzing, Transactions on Software Engineering, 2019, pp. 1980-1997, vol. 47, Issue 9, IEEE. [cited by applicant]
Polino et al., Measuring and Defeating Anti-Instrumentation-Equipped Malware, in Detection of Intrusions and Malware, and Vulnerability Assessment, 14th International Conference, DIMVA 2017, Bonn, Germany, Jul. 6-7, 201… [cited by applicant]
Sentinelone, SFG: Furtim Malware Analysis. https://www.sentinelone.com/blog/sfg-furtims-parent/. [cited by applicant]
Peng et al., X-Force: Force-Executing Binary Programs for Security Applications, Proceedings of the 2014 USENIX Security symposium, pp. 829-844, USENIX Association. [cited by applicant]