IP Library Granted Patent US 12,657,286
Granted Patent B2
US 12,657,286 · App. 18/787,095 · Granted Jun 16, 2026

Early exit dynamic analysis of a virtual machine

Inventors: Esmid Idrizovic (Trumau, AT); Daniel Raygoza (Seattle, WA); Robert Jung (Albuquerque, NM); Michael S. Hughes (Davenport, FL)
Assignee: Palo Alto Networks, Inc.
G06F21/53G06F21/566G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,657,286
App. No.
18/787,095
Granted
Jun 16, 2026
Kind
B2
Abstract

Techniques for early exit dynamic analysis of a virtual machine are disclosed. In some embodiments, a system/process/computer program product for early exit dynamic analysis of a virtual machine includes initiating a dynamic analysis of a malware sample by executing the malware sample in a virtual computing environment; monitoring activities of the malware sample during execution of the malware sample in the virtual computing environment; and determining when to exit the dynamic analysis before a predetermined period of time.

Claims (43)

1 . A system, comprising:

a processor configured to:

initiate a dynamic analysis of a malware sample by executing the malware sample in a virtual computing environment for a predetermined period of time;

monitor activities of the malware sample including launching a new process during the executing of the malware sample in the virtual computing environment, wherein the monitoring of the activities of the malware sample during execution of the malware sample in the virtual computing environment includes one or more of the following: writing, copying, or moving a file; changing a registry setting; modifying a system service; and scheduling a task; and

determine when to exit the dynamic analysis before the predetermined period of time based on the monitoring of the activities of the malware sample during the executing of the malware sample in the virtual computing environment to determine that using all of the predetermined period of time for the dynamic analysis is not required to determine that the malware sample is malicious or benign based on one or more of the following:

(1) the malware sample cannot be executed in the virtual computing environment;

(2) the malware sample requires an external dependency that is not available in the virtual computing environment;

(3) the malware sample is associated with an unsupported file sub-type; and/or

(4) an analysis of the new process of the malware sample has been completed; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system recited in claim 1 , wherein the virtual computing environment comprises a virtual machine instance.

3 . The system recited in claim 1 , wherein an early exit from the dynamic analysis before the predetermined period of time is performed based on a termination of a main process associated with executing the malware sample in the virtual computing environment.

4 . The system recited in claim 1 , wherein an output of the monitored activities of the malware sample during execution of the malware sample in the virtual computing environment is automatically analyzed to determine whether the malware sample is malicious or benign.

5 . The system recited in claim 1 , wherein the processor is further configured to:

monitor memory during execution of the malware sample in the virtual computing environment.

6 . The system recited in claim 1 , wherein the processor is further configured to:

perform an early exit of the dynamic analysis of the malware sample before the predetermined period of time based on monitoring of the malware sample during execution in the virtual computing environment.

7 . The system recited in claim 1 , wherein the processor is further configured to:

perform an early exit of the dynamic analysis of the malware sample before the predetermined period of time based on monitoring of the malware sample during execution in the virtual computing environment to determine that the malware sample has completed execution and no further dynamic analysis is to be performed to determine whether the malware sample is malicious or benign.

8 . The system recited in claim 1 , wherein the processor is further configured to:

perform an early exit of the dynamic analysis of the malware sample before the predetermined period of time based on monitoring of the malware sample during execution in the virtual computing environment; and

determine that the malware sample is benign.

9 . The system recited in claim 1 , wherein the processor is further configured to:

perform an early exit of the dynamic analysis of the malware sample before the predetermined period of time based on monitoring of the malware sample during execution in the virtual computing environment; and

determine that the malware sample is malicious.

10 . A method, comprising:

initiating a dynamic analysis of a malware sample by executing the malware sample in a virtual computing environment for a predetermined period of time;

monitoring activities of the malware sample including launching a new process during the executing of the malware sample in the virtual computing environment, wherein the monitoring of the activities of the malware sample during execution of the malware sample in the virtual computing environment includes one or more of the following: writing, copying, or moving a file; changing a registry setting; modifying a system service; and scheduling a task; and

determining when to exit the dynamic analysis before the predetermined period of time based on the monitoring of the activities of the malware sample during the executing of the malware sample in the virtual computing environment to determine that using all of the predetermined period of time for the dynamic analysis is not required to determine that the malware sample is malicious or benign based on one or more of the following:

(1) the malware sample cannot be executed in the virtual computing environment;

(2) the malware sample requires an external dependency that is not available in the virtual computing environment;

(3) the malware sample is associated with an unsupported file sub-type; and/or

(4) an analysis of the new process of the malware sample has been completed.

11 . The method of claim 10 , wherein the virtual computing environment comprises a virtual machine instance.

12 . A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

initiating a dynamic analysis of a malware sample by executing the malware sample in a virtual computing environment for a predetermined period of time;

monitoring activities of the malware sample including launching a new process during the executing of the malware sample in the virtual computing environment, wherein the monitoring of the activities of the malware sample during execution of the malware sample in the virtual computing environment includes one or more of the following: writing, copying, or moving a file; changing a registry setting; modifying a system service; and scheduling a task; and

determining when to exit the dynamic analysis before the predetermined period of time based on the monitoring of the activities of the malware sample during the executing of the malware sample in the virtual computing environment to determine that using all of the predetermined period of time for the dynamic analysis is not required to determine that the malware sample is malicious or benign based on one or more of the following:

(1) the malware sample cannot be executed in the virtual computing environment;

(2) the malware sample requires an external dependency that is not available in the virtual computing environment;

(3) the malware sample is associated with an unsupported file sub-type; and/or

(4) an analysis of the new process of the malware sample has been completed.

13 . The computer program product recited in claim 12 , wherein the virtual computing environment comprises a virtual machine instance.

Continuity (2)
Continuation 17364697 · Jun 30, 2021
Related Publication 20240386092A1 · Nov 21, 2024
References Cited (12)
US 9165136B1 · VanLund · 2015 [cited by examiner]
US 9479531B1 · Watson · 2016 [cited by examiner]
US 10360371B1 · Watson · 2019 [cited by applicant]
US 10515214B1 · Michael · 2019 [cited by applicant]
US 20110247072A1 · Staniford · 2011 [cited by examiner]
US 20160048683A1 · Sanders · 2016 [cited by examiner]
US 20160366100A1 · Liu · 2016 [cited by examiner]
US 20180048660A1 · Paithane · 2018 [cited by applicant]
Lin et al., Efficient Dynamic Malware Analysis using Virtual Time Control Mechanics, Computers & Security 73 (2018), pp. 359-373. [cited by applicant]
O'Kane et al., Detecting Obfuscated Malware Using Reduced Opcode Set and Optimised Runtime Trace, Security Informatics, 2016. [cited by applicant]
Or-Meir et al., Dynamic Malware Analysis in the Modern Era—A State of the Art Survey, ACM Computing Surveys, vol. 52, No. 5, Article 88, Sep. 2019. [cited by applicant]
Yoshihiro Oyama , Skipping Sleeps in Dynamic Analysis of Multithreaded Malware, IEEE, 2018. [cited by applicant]