Patents Assigned to Zimperium, Inc.
-
Patent number: 12670238Abstract: A system and a method are disclosed for providing a code obfuscation solution. The system accesses a computer program comprising a set of instructions and a sequence in which the set of instructions are to be performed. The system determines a plurality of computing resources available to perform the set of instructions and assigns the set of instructions to be distributed among the computing resources for execution. A single one of the plurality of computing resources is computationally capable of performing an entirety of the set of instructions. The system modifies the set of instructions with at least one obfuscating instruction that instructs at runtime for the computer program to jump from one computing resource to another computing resource of the set of computing resources. The system transmits the set of modified instruction to a target device for executing the computer program.Type: GrantFiled: December 2, 2025Date of Patent: June 30, 2026Assignee: Zimperium, Inc.Inventors: Antonio Nappa, Grant Stewart Goodes, Javier Lopez Gomez
-
Patent number: 12634333Abstract: A system and a method are disclosed for generating protection actions to protect a target application. The system scans a target application to detect a potential risk associated with one or more chunks of code in the target application and determines configuration information of the one or more chunks of code. The system may input scanning results and the configuration information into machine learning models and receive an output including the one or more protection actions. The system applies the protection actions to the target application. Responsive to completing the one or more protection actions, the system re-scans the target application to determine a result of applying the one or more protection actions on the target application.Type: GrantFiled: July 15, 2025Date of Patent: May 19, 2026Assignee: Zimperium, Inc.Inventors: Grant Stewart Goodes, Nicolás Chiaraviglio, Jonathan Paterson
-
Patent number: 12547425Abstract: A system and a method are disclosed for identifying libraries used by an application based on the program code of the application. The system accesses a plurality of program codes of the application. For at least one program code, the system extracts raw type data from the program code and normalizes the raw type data to generate target normalized type data. The target normalized type data includes data type information of the program code. The system determines a set of candidate library types corresponding to the program code. The system accesses candidate raw type data associated with each candidate library type and determines a library type corresponding to the program code by comparing the program code of the application with the program code of each of the set of the candidate library types.Type: GrantFiled: April 30, 2024Date of Patent: February 10, 2026Assignee: Zimperium, Inc.Inventors: Duncan Ogilvie, Matteo Favaro, Nicolás Chiaraviglio, Jose Fernandez Portal
-
Patent number: 12493541Abstract: A system and a method are disclosed for providing a lightweight code integrity solution. The system identifies one or more target code blocks in program code and determines one or more locations in the program code where an integrity check is to be embedded to verify the integrity of the code block. The system may determine an integer value associated with a byte-pattern of machine-code instructions in the code blocks and generates the integrity check by entangling the integer value into one or more computations of the program code. The system embeds the integrity check at the determined location in the program code.Type: GrantFiled: February 10, 2025Date of Patent: December 9, 2025Assignee: Zimperium, Inc.Inventors: Grant Stewart Goodes, Javier Lopez Gomez, Ričards Dzenis, Peteris Ledins
-
Patent number: 12425418Abstract: A system and a method are disclosed for detecting a malicious website. In an embodiment, a computing device detects a uniform resource locator (URL) referencing an unknown website; pre-processes the URL to determine a first probability that the unknown website is malicious; and inputs the first probability into a machine learning model to receive a second probability that the unknown website is malicious. The machine learning model is trained using Secure Sockets Layer (SSL) certificates of known legitimate websites and known malicious websites. The computing device further determines whether the second probability is associated with at least a threshold risk. Responsive to the second probability being associated with at least the threshold risk, the computing device causes a graphical user interface of a client device to display a notification indicating a level of risk associated with the unknown website.Type: GrantFiled: August 31, 2022Date of Patent: September 23, 2025Assignee: Zimperium, Inc.Inventors: Nicolás Chiaraviglio, Santiago Andrés Rodriguez Gonzalez
-
Patent number: 12407491Abstract: A system and a method are disclosed for performing encryptions with pre- and post-standard data transformations. The system receives an input that includes cleartext data. The system may apply a pre-encryption to the input by performing one or more rounds of data transformations, and the pre-encryption transforms the cleartext data into non-cleartext data. The system applies a core encryption to the non-cleartext data. The core encryption includes a standard cipher algorithm that transforms the non-cleartext data into encrypted ciphertext. The system then applies a post-encryption to the encrypted ciphertext. The post-encryption includes one or more rounds of additional data transformations. The system generates an encryption of the input at a local client device based on an output from the post-encryption. In some embodiments, the pre-encryption, core encryption and post-encryption are under a White-box encryption to protect intermediate data.Type: GrantFiled: December 20, 2024Date of Patent: September 2, 2025Assignee: Zimperium, Inc.Inventors: Atis Straujums, Nikita Larka, Māris Valdats
-
Patent number: 12375923Abstract: System and methods are disclosed herein for dynamic detection of malicious activities on a mobile device. The mobile device maintains a file that is executable on the mobile device. The file includes a plurality of primitives, with each primitive comprising a piece of detection logic that, when executed, performs a security function on the mobile device. The mobile device receives instructions from a security service to chain a subset of primitives. The subset of primitives, when chained together, forms a detection process for a malicious activity newly identified by the security service. The system and methods then chain the subset of primitives based on instructions received from the security service and identify the malicious activity by executing the chained subset of primitives.Type: GrantFiled: April 30, 2024Date of Patent: July 29, 2025Assignee: Zimperium, Inc.Inventors: Ryan Chazen, Asaf Peleg
-
Patent number: 12010517Abstract: System and methods are disclosed herein for dynamic detection of malicious activities on a mobile device. The mobile device maintains a file that is executable on the mobile device. The file includes a plurality of primitives, with each primitive comprising a piece of detection logic that, when executed, performs a security function on the mobile device. The mobile device receives instructions from a security service to chain a subset of primitives. The subset of primitives, when chained together, forms a detection process for a malicious activity newly identified by the security service. The system and methods then chain the subset of primitives based on instructions received from the security service and identify the malicious activity by executing the chained subset of primitives.Type: GrantFiled: May 10, 2021Date of Patent: June 11, 2024Assignee: Zimperium, Inc.Inventors: Ryan Chazen, Asaf Peleg
-
Patent number: 11870808Abstract: A system and a method are disclosed for detecting a malicious website. In an embodiment, a mobile device detects a URL referencing an unknown website. Responsive to detecting the URL, the mobile device retrieves a representative image of the unknown website. The mobile device determines whether the representative image matches an image of a known legitimate website. Responsive to determining that the representative image matches the image of the known legitimate website, the mobile device determines if the unknown website is malicious. The mobile device performs a security action responsive to determining that the website is malicious.Type: GrantFiled: November 14, 2022Date of Patent: January 9, 2024Assignee: Zimperium, Inc.Inventors: Nicolás Chiaraviglio, Ryan Chazen, Elad Golan, Izhak Kedar, Massimo Dragano, Asaf Peleg
-
Patent number: 11528297Abstract: A system and a method are disclosed for detecting a malicious website. In an embodiment, a mobile device detects a URL referencing an unknown website. Responsive to detecting the URL, the mobile device retrieves a representative image of the unknown website. The mobile device determines whether the representative image matches an image of a known legitimate website. Responsive to determining that the representative image matches the image of the known legitimate website, the mobile device determines if the unknown website is malicious. The mobile device performs a security action responsive to determining that the website is malicious.Type: GrantFiled: December 13, 2019Date of Patent: December 13, 2022Assignee: Zimperium, Inc.Inventors: Nicolás Chiaraviglio, Ryan Chazen, Elad Golan, Izhak Kedar, Massimo Dragano, Asaf Peleg
-
Patent number: 10929532Abstract: A trained classifier is received from a server. Static analysis is performed on a mobile application to generate a vector storing values representing the number of times the mobile application calls functions from each of multiple namespaces, and an indication of the permissions the mobile application requests. The received trained classifier is then applied to the generated vector to identify whether the mobile application contains malware. Based on the output of the trained classifier, a security policy is applied.Type: GrantFiled: September 7, 2018Date of Patent: February 23, 2021Assignee: Zimperium, Inc.Inventor: Simone Margaritelli
-
Patent number: 9503463Abstract: A method for a wireless network. The network includes at least a server and a plurality of computer devices wirelessly connected to the server. At least one of the computer devices is under attack by an ‘attacker’ device. The method provides for detection and reporting of the attack as to the location of the attack. The method includes detecting an attack by one of the computer devices, using a zCore module and transmitting an ‘attack report’ to the server. The report includes at least the attack location. The method also includes notifying at least one of the plurality of computer devices and an external computer device that the network is compromised.Type: GrantFiled: May 13, 2013Date of Patent: November 22, 2016Assignee: Zimperium, Inc.Inventors: Yaniv Karta, Itzhak Avraham
-
Patent number: 9208323Abstract: A security system receives attribute samples from one or more devices configured to simulate one or more states (such as attack states). The attribute samples are aggregated, normalized to a common format, and quantized to lower the resolution of the attribute samples. Outlier attribute samples and attribute samples determined to not be correlated to the simulated states are removed to form a pruned set of attribute samples. A set of classifiers is generated based on a first portion of the pruned set of attribute samples, and the set of classifiers is tested based on a second portion of the pruned set of attribute samples. A subset of the classifiers can be provided to a device configured to monitor attributes associated with the subset of classifiers and to identify an attack state based on the monitor attributes.Type: GrantFiled: January 13, 2014Date of Patent: December 8, 2015Assignee: Zimperium, Inc.Inventors: Yaniv Karta, Itzhak Avraham, Esteban Pellegrino
-
Patent number: 8997231Abstract: A method for providing an intrusion prevention system to prevent hacking into files located on enterprise users' endpoint devices functioning as mobile computing platforms. The method includes filtering low-level network packets for each of a plurality of received network packets, offloading the received packets to an inspecting processing module and marking suspicious packets based on at least one of a header and pattern of each of said received packets. The method also includes taking preventive measures by the system to ensure protection of the device and network, taking active steps by the system to block suspicious traffic and disconnecting the current connection by the system, when it detects suspicious traffic.Type: GrantFiled: April 18, 2013Date of Patent: March 31, 2015Assignee: Zimperium, Inc.Inventors: Yaniv Karta, Itzhak Avraham
-
Publication number: 20140181972Abstract: A method for providing an intrusion prevention system to prevent hacking into files located on enterprise users' endpoint devices functioning as mobile computing platforms. The method includes filtering low-level network packets for each of a plurality of received network packets, offloading the received packets to an inspecting processing module and marking suspicious packets based on at least one of a header and pattern of each of said received packets. The method also includes taking preventive measures by the system to ensure protection of the device and network, taking active steps by the system to block suspicious traffic and disconnecting the current connection by the system, when it detects suspicious traffic.Type: ApplicationFiled: April 18, 2013Publication date: June 26, 2014Applicant: Zimperium, Inc.Inventors: Yaniv Karta, Itzhak Avraham