IP Library › Granted Patent US 12,585,768
Granted Patent B2
US 12,585,768 · App. 18/747,589 · Granted Mar 24, 2026

Systems and methods for tracking execution flows for automated malware detection

Inventors: Igor Seletskiy (Palo Alto, CA); Serhii Brazhnyk (Odessa, UA); Arsenii Pastushenko (Kyiv, UA)
Assignee: Cloud Linux Software, Inc.
G06F21/56G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,585,768
App. No.
18/747,589
Granted
Mar 24, 2026
Kind
B2
Abstract

Disclosed herein are systems and methods for detecting malware in scripts. A method includes: monitoring, at a first computing device, an execution flow of at least one portion of a script; computing a fingerprint that represents the execution flow; determining whether the fingerprint is present in a local fingerprint database that includes a plurality of entries for known scripts; in response to determining that the fingerprint is not present in the local fingerprint database, transmitting the fingerprint to a central database server including a universal fingerprint database; in response to receiving an indication that the fingerprint is not present in the universal fingerprint database, scanning the at least one portion of the script for malware; and blocking the script in response to determining that the at least one portion of the script includes malware based on the scanning.

Claims (70)

1 . A method for detecting malware in scripts, the method comprising:

monitoring, at a first computing device, an execution flow of at least one portion of a script;

computing a fingerprint that represents the execution flow;

determining whether the fingerprint is present in a local fingerprint database that comprises a plurality of entries for known scripts;

in response to determining that the fingerprint is not present in the local fingerprint database, transmitting the fingerprint to a central database server comprising a universal fingerprint database;

in response to receiving an indication that the fingerprint is not present in the universal fingerprint database, scanning the at least one portion of the script for malware;

blocking the at least one portion of the script in response to determining that the at least one portion of the script comprises malware based on the scanning:

determining whether the at least one portion of the script associated with the fingerprint has a different version with a fingerprint in the local fingerprint database;

in response to determining that the at least one portion of the script has the different version, determining whether the different version is a latest version of the at least one portion of the script; and

in response to determining that the different version is not the latest version, identifying the fingerprint as a candidate fingerprint for inclusion in the universal fingerprint database and transmitting the fingerprint to the central database server.

2 . The method of claim 1 , wherein the central database server is configured to:

receive candidate fingerprints from a plurality of computing devices;

identify a subset of the candidate fingerprints to include in the universal fingerprint database; and

update the universal fingerprint database to include the subset.

3 . The method of claim 2 , wherein identifying the subset of candidate fingerprints comprises for each respective candidate fingerprint, including the respective candidate fingerprint in the subset when:

determining that more than a first threshold number of the plurality of computing devices reported a respective execution flow associated with the respective candidate fingerprint; or

determining that more than a second threshold number and less than a third threshold number of the plurality of computing devices reported the respective execution flow associated with the respective candidate fingerprint, with a total number of reports of the respective execution flow being more than the first threshold number.

4 . The method of claim 2 , wherein the central database server is further configured to:

store the candidate fingerprints in a temporary data store;

copying the subset into the universal fingerprint database; and

clearing the temporary data store after a threshold period of time.

5 . The method of claim 1 , wherein an entry in the universal fingerprint database indicates one or more of: (1) a script name, (2) script version, (3) script fingerprint, (4) date when the entry was added to the universal fingerprint database, (5) a Boolean flag indicative of whether the script version is closed.

6 . The method of claim 5 , wherein the script version is identified as closed when there are at least two newer versions of a given script in the universal fingerprint database or when there are no new execution flows for the script version reported during a threshold period of time.

7 . The method of claim 1 , wherein the script is a plugin.

8 . The method of claim 1 , wherein computing the fingerprint comprises:

identifying a segment of the execution flow; and

computing the fingerprint of the segment.

9 . The method of claim 8 , wherein identifying the segment comprises:

identifying, in the execution flow, a function that is in a predetermined set of functions of interest;

determining a chain of functions preceding the function in the execution flow; and

including the chain of functions and the function in the segment.

10 . The method of claim 9 , wherein the function is one of:

(1) an operation that accesses an address external to the first computing device;

(2) an operation that performs string manipulation.

11 . A system for detecting malware in scripts, the system comprising:

at least one memory; and

at least one hardware processor communicatively coupled with the at least one memory and configured, individually or in combination, to:

monitor, at a first computing device, an execution flow of at least one portion of a script;

compute a fingerprint that represents the execution flow;

determine whether the fingerprint is present in a local fingerprint database that comprises a plurality of entries for known scripts;

in response to determining that the fingerprint is not present in the local fingerprint database, transmit the fingerprint to a central database server comprising a universal fingerprint database;

in response to receiving an indication that the fingerprint is not present in the universal fingerprint database, scan the at least one portion of the script for malware;

block the at least one portion of the script in response to determining that the script comprises malware based on the scanning;

determine whether the at least one portion of the script associated with the fingerprint has a different version with a fingerprint in the local fingerprint database;

in response to determining that the at least one portion of the script has the different version, determine whether the different version is a latest version of the at least one portion of the script; and

in response to determining that the different version is not the latest version, identify the fingerprint as a candidate fingerprint for inclusion in the universal fingerprint database and transmitting the fingerprint to the central database server.

12 . The system of claim 11 , wherein the central database server is configured to:

receive candidate fingerprints from a plurality of computing devices;

identify a subset of the candidate fingerprints to include in the universal fingerprint database; and

update the universal fingerprint database to include the subset.

13 . The system of claim 12 , wherein the at least one hardware processor is further configured to identify the subset of candidate fingerprints by, for each respective candidate fingerprint, including the respective candidate fingerprint in the subset when:

determining that more than a first threshold number of the plurality of computing devices reported a respective execution flow associated with the respective candidate fingerprint; or

determining that more than a second threshold number and less than a third threshold number of the plurality of computing devices reported the respective execution flow associated with the respective candidate fingerprint, with a total number of reports of the respective execution flow being more than the first threshold number.

14 . The system of claim 12 , wherein the central database server is further configured to:

store the candidate fingerprints in a temporary data store;

copying the subset into the universal fingerprint database; and

clearing the temporary data store after a threshold period of time.

15 . The system of claim 11 , wherein an entry in the universal fingerprint database indicates one or more of: (1) a script name, (2) script version, (3) script fingerprint, (4) date when the entry was added to the universal fingerprint database, (5) a Boolean flag indicative of whether the script version is closed.

16 . The system of claim 15 , wherein the script version is identified as closed when there are at least two newer versions of a given script in the universal fingerprint database or when there are no new execution flows for the script version reported during a threshold period of time.

17 . The system of claim 11 , wherein the script is a plugin.

18 . A non-transitory computer readable medium storing thereon computer executable instructions for detecting malware in scripts, including instructions for:

monitoring, at a first computing device, an execution flow of at least one portion of a script;

computing a fingerprint that represents the execution flow;

determining whether the fingerprint is present in a local fingerprint database that comprises a plurality of entries for known scripts;

in response to determining that the fingerprint is not present in the local fingerprint database, transmitting the fingerprint to a central database server comprising a universal fingerprint database;

in response to receiving an indication that the fingerprint is not present in the universal fingerprint database, scanning the at least one portion of the script for malware;

blocking the at least one portion of the script in response to determining that the script comprises malware based on the scanning;

determining whether the at least one portion of the script associated with the fingerprint has a different version with a fingerprint in the local fingerprint database;

in response to determining that the at least one portion of the script has the different version, determining whether the different version is a latest version of the at least one portion of the script; and

in response to determining that the different version is not the latest version, identifying the fingerprint as a candidate fingerprint for inclusion in the universal fingerprint database and transmitting the fingerprint to the central database server.

Continuity (3)
Continuation In Part 17550093 · Dec 14, 2021
Continuation In Part 17389523 · Jul 30, 2021
Related Publication 20240338441A1 · Oct 10, 2024
References Cited (67)
US 7624443B2 · Kramer · 2009 [cited by examiner]
US 8201244B2 · Sun · 2012 [cited by examiner]
US 8332946B1 · Boisjolie · 2012 [cited by examiner]
US 9178904B1 · Gangadharan · 2015 [cited by examiner]
US 9413721B2 · Morris · 2016 [cited by examiner]
US 9762399B2 · Ghose · 2017 [cited by examiner]
US 9813443B1 · Subramanian · 2017 [cited by examiner]
US 10044750B2 · Livshits · 2018 [cited by examiner]
US 10491627B1 · Su · 2019 [cited by examiner]
US 11574053B1 · Chen · 2023 [cited by examiner]
US 12069083B2 · Hawthorn · 2024 [cited by examiner]
US 20050137976A1 · Anderson · 2005 [cited by examiner]
US 20060095971A1 · Costea · 2006 [cited by examiner]
US 20070271301A1 · Klive · 2007 [cited by examiner]
US 20080127336A1 · Sun · 2008 [cited by examiner]
US 20080162265A1 · Sundaresan · 2008 [cited by examiner]
US 20090044024A1 · Oberheide · 2009 [cited by examiner]
US 20090089879A1 · Wang · 2009 [cited by examiner]
US 20100095380A1 · Fossen · 2010 [cited by examiner]
US 20100180344A1 · Malyshev · 2010 [cited by examiner]
US 20110083176A1 · Martynenko · 2011 [cited by examiner]
US 20110154495A1 · Stranne · 2011 [cited by examiner]
US 20110197177A1 · Mony · 2011 [cited by examiner]
US 20110239294A1 · Kim · 2011 [cited by examiner]
US 20110307955A1 · Kaplan · 2011 [cited by examiner]
US 20120102569A1 · Turbin · 2012 [cited by examiner]
US 20120159564A1 · Spektor · 2012 [cited by examiner]
US 20120260340A1 · Morris · 2012 [cited by examiner]
US 20120266244A1 · Green · 2012 [cited by examiner]
US 20120297488A1 · Kapoor · 2012 [cited by examiner]
US 20120304244A1 · Xie · 2012 [cited by examiner]
US 20130111547A1 · Kraemer · 2013 [cited by examiner]
US 20140115323A1 · Fanton · 2014 [cited by examiner]
US 20140130161A1 · Golovanov · 2014 [cited by examiner]
US 20140317732A1 · Beaufrere · 2014 [cited by examiner]
US 20150007315A1 · Rivera · 2015 [cited by examiner]
US 20150067839A1 · Wardman · 2015 [cited by examiner]
US 20150096018A1 · Mircescu · 2015 [cited by examiner]
US 20150363598A1 · Xu · 2015 [cited by examiner]
US 20160094572A1 · Tyagi · 2016 [cited by examiner]
US 20160119148A1 · Ghose · 2016 [cited by examiner]
US 20160267271A1 · Prasad · 2016 [cited by examiner]
US 20160359875A1 · Kim · 2016 [cited by examiner]
US 20170041338A1 · Martini · 2017 [cited by examiner]
US 20170329968A1 · Wachdorf · 2017 [cited by examiner]
US 20180025157A1 · Titonis · 2018 [cited by examiner]
US 20180096149A1 · Morkovský · 2018 [cited by examiner]
US 20180205554A1 · Blinn · 2018 [cited by examiner]
US 20180211041A1 · Davis · 2018 [cited by examiner]
US 20180255081A1 · Xiao · 2018 [cited by examiner]
US 20180300480A1 · Sawhney · 2018 [cited by examiner]
US 20190065744A1 · Gaustad · 2019 [cited by examiner]
US 20190377877A1 · Johns · 2019 [cited by examiner]
US 20200137126A1 · Yawalkar · 2020 [cited by examiner]
US 20200213087A1 · Mazzarella · 2020 [cited by examiner]
US 20210064748A1 · Gordeychik · 2021 [cited by examiner]
US 20210117544A1 · Kurtz · 2021 [cited by examiner]
US 20210157915A1 · Pizano · 2021 [cited by examiner]
US 20210173926A1 · Slipenchuk · 2021 [cited by examiner]
US 20210232680A1 · Hecht · 2021 [cited by examiner]
US 20230022279A1 · Vasilenko · 2023 [cited by examiner]
S. Cesare, Y. Xiang and W. Zhou, “Control Flow-Based Malware VariantDetection,” in IEEE Transactions on Dependable and Secure Computing, vol. 11, No. 4, pp. 307-317, Jul.-Aug. 2014, doi: 10.1109/TDSC.2013.40. (Year: 201… [cited by examiner]
E. B. Karbab, M. Debbabi, S. Alrabaee and D. Mouheb, “DySign: dynamic fingerprinting for the automatic detection of android malware,” 2016 11th International Conference on Malicious and Unwanted Software (Malware), Faja… [cited by examiner]
Mitropoulos, Dimitris, et al. “How to train your browser: Preventing XSS attacks using contextual script fingerprints.” ACM Transactions on Privacy and Security (TOPS) 19.1 (2016): 1-31. (Year: 2016). [cited by examiner]
Y.-J. Park, Z. Zhang and S. Chen, “Run-Time Detection of Malwares via Dynamic Control-Flow Inspection,” 2009 20th IEEE International Conference on Application-specific Systems, Architectures and Processors, Boston, MA, … [cited by examiner]
Wrench, P., and Barry Irwin. “Detecting derivative malware samples using deobfuscation-assisted similarity analysis.” SAIEE Africa Research Journal 107.2 (2016): 65-77. (Year: 2016). [cited by examiner]
Q. Zhang, H. Chen and J. Sun, “An execution-flow based method for detecting Cross-site Scripting attacks,” The 2nd International Conference on Software Engineering and Data Mining, Chengdu, China, 2010, pp. 160-165. (Ye… [cited by examiner]