IP Library › Granted Patent US 12,632,549
Granted Patent B2
US 12,632,549 · App. 18/673,304 · Granted May 19, 2026

Detecting malware by modifying executable code

Inventor: Joshua Aaron Mason (Oklahoma City, OK)
Assignee: Google LLC
G06F21/563
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,549
App. No.
18/673,304
Granted
May 19, 2026
Kind
B2
Abstract

A method for detecting malware by modifying executable code includes identifying executable code that includes branch instructions. The method includes determining whether any of the branch instructions of the executable code mask maliciousness of the executable code. The determining includes modifying first one or more of the branch instructions of the executable code, causing execution of the executable code with the modified first one or more branch instructions in a first testing environment, and evaluating a result of the execution of the executable code with the modified first one or more branch instructions. The result can indicate whether the executable code is malicious. The method includes, responsive to determining that the branch instructions of the executable code mask the maliciousness of the executable code, performing one or more preventative actions with respect to the executable code.

Claims (64)

1 . A method, comprising:

identifying executable code comprising branch instructions;

determining whether any of the branch instructions of the executable code mask maliciousness of the executable code, wherein the determining comprises:

modifying first one or more of the branch instructions of the executable code to alter execution behavior of the executable code,

causing execution of the executable code with the modified first one or more branch instructions in a first testing environment, and

evaluating a result of the execution of the executable code with the modified first one or more branch instructions, the result indicating whether the executable code is malicious; and

responsive to determining that the branch instructions of the executable code mask the maliciousness of the executable code, performing one or more preventative actions with respect to the executable code.

2 . The method of claim 1 , wherein the branch instructions comprise a jump instruction.

3 . The method of claim 2 , wherein:

the jump instruction comprises a jump-if-equal instruction; and

modifying the first one or more branch instructions of the executable code comprises changing the jump-if-equal instruction to a jump-if-not-equal instruction.

4 . The method of claim 2 , wherein:

the jump instruction comprises a jump-if-overflow instruction; and

modifying the first one or more branch instructions of the executable code comprises changing the jump-if-overflow instruction to a jump-if-not-overflow instruction.

5 . The method of claim 1 , wherein:

the branch instructions comprise a call instruction; and

modifying the first one or more branch instructions of the executable code comprises changing the call instruction to a no operation instruction.

6 . The method of claim 1 , wherein:

the branch instructions comprise a return instruction; and

modifying the first one or more branch instructions of the executable code comprises changing a return address of the return instruction.

7 . The method of claim 1 , wherein modifying the first one or more branch instructions of the executable code comprises randomly selecting the first one or more branch instructions from the branch instructions of the executable code.

8 . The method of claim 1 , wherein the first testing environment comprises a virtual machine.

9 . The method of claim 1 , wherein the determining further comprises:

modifying second one or more of the branch instructions of the executable code, wherein the modified first one or more branch instructions and the modified second one or more branch instructions include different branch instructions;

causing execution of the executable code with the modified second one or more branch instructions in a second testing environment; and

evaluating a second result of the execution of the executable code with the modified second one or more branch instructions, the second result indicating whether the executable code is malicious.

10 . A system, comprising:

a memory; and

a processing device, coupled to the memory, configured to perform operations, comprising:

identifying executable code comprising branch instructions;

determining whether any of the branch instructions of the executable code mask maliciousness of the executable code, wherein the determining comprises:

modifying first one or more of the branch instructions of the executable code to alter execution behavior of the executable code,

causing execution of the executable code with the modified first one or more branch instructions in a first testing environment, and

evaluating a result of the execution of the executable code with the modified first one or more branch instructions, the result indicating whether the executable code is malicious; and

responsive to determining that the branch instructions of the executable code mask the maliciousness of the executable code, performing one or more preventative actions with respect to the executable code.

11 . The system of claim 10 , wherein:

the branch instructions comprise a jump instruction; and

modifying the first one or more branch instructions of the executable code comprises replacing the jump instruction with a complementary version of the jump instruction.

12 . The system of claim 10 , wherein the executable code comprises at least one of:

a portion of an email attachment;

a portion of a file stored in a cloud-based content management platform; or

a portion of a file downloaded using a web browser.

13 . The system of claim 10 , wherein the operations further comprise:

identifying a malware monitoring detection subroutine of the executable code, wherein the malware monitoring detection subroutine is associated with a branch instruction of the first one or more branch instructions;

modifying a return instruction of the malware monitoring detection subroutine; and

causing execution of the executable code, in a second testing environment, with the modified return instruction.

14 . The system of claim 10 , wherein the operations further comprise:

calculating a first code coverage of the executable code by causing execution of the executable code in the first testing environment;

calculating a second code coverage of the executable code with the modified first one or more branch instructions; and

responsive to the second code coverage exceeding the first code coverage, modifying second one or more branch instructions of the executable code with the modified first one or more branch instructions.

15 . The system of claim 14 , wherein the operations further comprise:

causing execution of the executable code with the modified first one or more branch instructions and the modified second one or more branch instructions in the first testing environment; and

evaluating a result of the execution of the executable code with the modified first one or more branch instructions and the modified second one or more branch instructions, the result indicating whether the executable code is malicious.

16 . The system of claim 14 wherein the modified second one or more branch instructions do not include any of the modified first one or more branch instructions.

17 . A method, comprising:

identifying executable code comprising branch instructions;

determining whether any of the branch instructions of the executable code mask maliciousness of the executable code, wherein the determining comprises:

generating a plurality of modified copies of the executable code by modifying, for each modified copy of the executable code, one or more of the branch instructions of the executable code to alter execution behavior of the executable code,

causing execution of the plurality of modified copies of the executable code with respective modified one or more branch instructions in a plurality of testing environments, and

evaluating results of the execution of the plurality of modified copies of the executable code with the respective modified one or more branch instructions, the results indicating whether the executable code is malicious; and

responsive to determining that the branch instructions of the executable code mask the maliciousness of the executable code, performing one or more preventative actions with respect to the executable code.

18 . The method of claim 17 , wherein modifying, for each modified copy of the executable code of the plurality of modified copies of the executable code, the one or more of the branch instructions of the executable code comprises randomly selecting, for each modified copy of the executable code of the plurality of modified copies of the executable code, the respective modified one or more branch instructions from the branch instructions of the executable code.

19 . The method of claim 17 , wherein modifying the one or more of the branch instructions of the executable code comprises changing a jump-if-equal instruction to a jump-if-not-equal instruction.

20 . The method of claim 17 , wherein a testing environment of the plurality of testing environments comprises a virtual machine.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2024
From: MASON, JOSHUA AARON
To: GOOGLE LLC
Reel/Frame 067518/0396 →
Continuity (1)
Related Publication 20250363214A1 · Nov 27, 2025
References Cited (13)
US 8522225B2 · Chen · 2013 [cited by examiner]
US 9003384B2 · Pizlo · 2015 [cited by examiner]
US 9817763B2 · Robertson · 2017 [cited by examiner]
US 9916144B2 · Chen · 2018 [cited by examiner]
US 9928068B2 · Alapati · 2018 [cited by examiner]
US 10860716B2 · Saldanha · 2020 [cited by examiner]
US 11288075B2 · Degioanni · 2022 [cited by examiner]
US 11711201B2 · Weiler · 2023 [cited by examiner]
US 12045322B2 · Gupta · 2024 [cited by examiner]
US 12093369B2 · Frydrych · 2024 [cited by examiner]
US 20210351922A1 · Schat et al. · 2021 [cited by applicant]
Botacin, M., et al. “RevEngE is a dish served cold: Debug-Oriented Malware Decompilation and Reassembly”, ROOTS 19, 2019, Vienna, 12 pages. [cited by applicant]
Kolbitsch, C., et al., “The Power of Procrastination: Detection and Mitigation of Execution-Stalling Malicious Code”, In Proceedings of the 18th ACM conference on Computer and communications security (pp. 285-296), Oct.… [cited by applicant]