IP Library Granted Patent US 12,462,016
Granted Patent B2
US 12,462,016 · App. 18/299,470 · Granted Nov 4, 2025

System and methods for sandboxed software analysis with automated vulnerability detection and patch development, deployment and validation

Inventors: Jason Crabtree (Vienna, VA); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX LLC
G06F21/53G06F8/65G06F9/455G06F21/566G06F21/577G06Q40/08H04L63/1425H04L63/1433G06F11/3058G06F2221/033G06F2221/2149G06N20/00G06Q50/01
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,462,016
App. No.
18/299,470
Granted
Nov 4, 2025
Kind
B2
Abstract

A system and method for automated software vulnerability detection and patching using sandboxed analysis. The system receives executable machine code files and identifies target device types for execution. A sandbox environment emulates device functionality and executes code while monitoring for suspicious behavior including memory scanning, unauthorized system access, and irregular network activity. Machine learning algorithms analyze execution patterns to detect security vulnerabilities and exploits. Upon identifying threats, the system automatically generates protective patches such as address space layout randomization and data execution prevention measures. These patches are deployed to real devices to prevent exploitation. The system uses reinforcement learning to improve patch effectiveness over time. This automated approach enables proactive cybersecurity protection by responding to emerging threats before malicious exploitation occurs.

Claims (38)

1 . A system for sandboxed software analysis with automated vulnerability detection, comprising:

a computing device comprising a memory and a processor;

a business operating system comprising a first plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the first plurality of programming instructions, when operating on the processor, cause the computing device to:

receive a file comprising executable machine code;

identify a type of device on which the executable machine code will operate;

transfer the executable machine code to a sandbox environment, the sandbox environment comprising a controlled environment that emulates functionality of the identified type of device;

receive an identified vulnerability from the sandbox environment; and

change an operational behavior of a real device of the identified type of device to prevent exploitation of the identified vulnerability through either address space layout randomization or data execution prevention;

wherein the sandbox environment comprises a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the second plurality of programming instructions, when operating on the processor, cause the computing device to:

receive the executable machine code from the business operating system;

create a first emulated environment configured to represent the identified type of device;

execute the executable machine code within the first emulated environment;

identify an irregularity in the execution of the executable machine code, the irregularity comprising two or more of the following activities performed in suspicious ways not normally performed by benign software: memory scanning, deletion of the file containing the executable machine code from storage media, access of system files, access of permissions, access of security settings, and access of network adapters;

identify a vulnerability of the identified type of device being targeted by the identified irregularity in the execution of the executable machine code; and

send the identified vulnerability to the business operating system.

2 . The system of claim 1 , wherein the sandbox environment is further configured to:

create a second emulated environment configured to represent a second type of device;

execute the executable machine code within the second emulated environment;

compare the execution of the executable machine code within the first and second emulated environments; and

identify an irregularity in the execution of the executable machine code in either the first or second emulated environment, the irregularity being identified based on the results of the comparison.

3 . A method for sandboxed software analysis with automated vulnerability detection, comprising the steps of:

receiving, at a business operating system, a file comprising executable machine code;

identifying a type of device on which the executable machine code will operate;

transferring the executable machine code to a sandbox environment, the sandbox environment comprising a controlled environment that emulates functionality of the identified type of device;

receiving an identified vulnerability from the sandbox environment; and

changing an operational behavior of a real device of the identified type of device to prevent exploitation of the identified vulnerability through either address space layout randomization or data execution prevention;

wherein the sandbox environment performs the steps of:

receiving the executable machine code from the business operating system;

creating a first emulated environment configured to represent the identified type of device;

executing the executable machine code within the first emulated environment;

identifying an irregularity in the execution of the executable machine code, the irregularity comprising two or more of the following activities performed in suspicious ways not normally performed by benign software: memory scanning, deletion of the file containing the executable machine code from storage media, access of system files, access of permissions, access of security settings, and access of network adapters;

identifying a vulnerability of the identified type of device being targeted by the identified irregularity in the execution of the executable machine code; and

sending the identified vulnerability to the business operating system.

4 . The method of claim 3 , further comprising the steps of:

creating a second emulated environment configured to represent a second type of device;

executing the executable machine code within the second emulated environment;

comparing the execution of the executable machine code within the first and second emulated environments; and

identifying an irregularity in the execution of the executable machine code in either the first or second emulated environment, the irregularity being identified based on the results of the comparison.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CORRECTIVE ASSIGNMENT TO CORRECT THE INVENTOR RICHARD KELLEY LAST NAME PREVIOUSLY RECORDED ON REEL 64412 FRAME 543. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 22, 2024
From: CRABTREE, JASON; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 067503/0768 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2023
From: CRABTREE, JASON; KELLY, RICHARD
To: QOMPLX, INC.
Reel/Frame 064412/0543 →
Continuity (25)
Continuation In Part 18161862 · Jan 30, 2023
Continuation In Part 17028979 · Sep 22, 2020
Continuation 15887496 · Feb 2, 2018
Continuation In Part 15823285 · Nov 27, 2017
Continuation In Part 15818733 · Nov 20, 2017
Continuation In Part 15788718 · Oct 19, 2017
Continuation In Part 15788002 · Oct 19, 2017
Continuation In Part 15787601 · Oct 18, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62568307 · Oct 4, 2017
Provisional Application 62568312 · Oct 4, 2017
Provisional Application 62568305 · Oct 4, 2017
Related Publication 20240119140A1 · Apr 11, 2024
References Cited (28)
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 7739653B2 · Venolia · 2010 [cited by applicant]
US 8805947B1 · Kuzkin et al. · 2014 [cited by applicant]
US 9141360B1 · Chen et al. · 2015 [cited by applicant]
US 9189375B1 · Bastien et al. · 2015 [cited by applicant]
US 9245114B2 · Thomas et al. · 2016 [cited by applicant]
US 9594912B1 · Thioux et al. · 2017 [cited by applicant]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9672355B2 · Titonis et al. · 2017 [cited by applicant]
US 9680824B1 · Rodgers et al. · 2017 [cited by applicant]
US 10031832B1 · Bastien et al. · 2018 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10079841B2 · Gupta et al. · 2018 [cited by applicant]
US 10210329B1 · Malik et al. · 2019 [cited by applicant]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 20050289072A1 · Sabharwal · 2005 [cited by applicant]
US 20100125900A1 · Dennerline et al. · 2010 [cited by applicant]
US 20110258610A1 · Aaraj et al. · 2011 [cited by applicant]
US 20120079596A1 · Thomas et al. · 2012 [cited by applicant]
US 20130097706A1 · Titonis et al. · 2013 [cited by applicant]
US 20160004858A1 · Chen · 2016 [cited by examiner]
US 20160021142A1 · Gafni · 2016 [cited by examiner]
US 20160099960A1 · Gerritz et al. · 2016 [cited by applicant]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20160330215A1 · Gafni et al. · 2016 [cited by applicant]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543A1 · 2017 [cited by applicant]